APT42 Uses AI-Assisted Phishing and TAMECAT Malware to Target Government and Defense Officials
ID: 75564891-be04-538f-8180-e81682cc0032
STIX ID: report--75564891-be04-538f-8180-e81682cc0032
Feed Name: cybersecurityNews.com
APT42 (Iran-linked) conducted a patient, AI-assisted spear-phishing campaign (SpearSpecter) targeting government and defense-related individuals using realistic personas and extended conversations to build trust, then delivered the TAMECAT infostealer via multiple delivery chains (WebDAV + PDF-themed .lnk, PowerShell, batch stages). The malware harvests browser cookies/credentials, mailbox data, screenshots, and files and exfiltrates via HTTPS/Discord/Telegram; the report includes detailed IoCs (domains, IPs, file hashes, registry keys), TTPs, and practical detection/mitigation recommendations such as session revocation and phishing-resistant MFA.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
