logo

Google raps Iran's APT42 for raining down spear-phishing attacks

ID: 44a029e1-387a-550b-8d4e-910c14972b24

STIX ID: report--44a029e1-387a-550b-8d4e-910c14972b24

Feed Name: The Register (Security)

Threat Score
88/100

Date Published: 2024-08-15

Date Updated: 2026-04-26

Author: Connor Jones

...
...

This report describes an intensified phishing campaign by Iranian state-linked APT42 targeting US political figures and Israeli officials, using Cluster C spear-phishing, spoofed meeting and cloud-hosted pages, link shorteners, and credential-harvesting kits (notably GCollection) that can simulate MFA flows; Google TAG blocked numerous attempts and tied the activity to an incident that led to data leakage from the Trump re-election campaign.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.