Google raps Iran's APT42 for raining down spear-phishing attacks
ID: 44a029e1-387a-550b-8d4e-910c14972b24
STIX ID: report--44a029e1-387a-550b-8d4e-910c14972b24
Feed Name: The Register (Security)
Threat Score
This report describes an intensified phishing campaign by Iranian state-linked APT42 targeting US political figures and Israeli officials, using Cluster C spear-phishing, spoofed meeting and cloud-hosted pages, link shorteners, and credential-harvesting kits (notably GCollection) that can simulate MFA flows; Google TAG blocked numerous attempts and tied the activity to an incident that led to data leakage from the Trump re-election campaign.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
