logo

That WhatsApp from an Israeli infosec expert could be a Iranian phish

ID: 8756ed97-c226-5424-a8e1-dd59e1b5a62f

STIX ID: report--8756ed97-c226-5424-a8e1-dd59e1b5a62f

Feed Name: The Register (Security)

Threat Score
85/100

Date Published: 2025-06-26

Date Updated: 2026-04-26

Author: Jessica Lyons

...
...

Check Point attributes a recent spear-phishing campaign to Iran’s Charming Kitten (aka APT42 / Educated Manticore) that used more than 130 domains, email and WhatsApp lures, and impersonation of Israeli security analysts to phish credentials and two-factor codes from journalists, cybersecurity experts, and university researchers; phishing pages mimicked Google authentication and were pre-filled with victims’ addresses to enable account takeover, and attackers may also be pursuing in-person meetings for further intelligence or harm.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.