Iranian hackers impersonate journalists in social engineering campaign
ID: bc2eea9b-1fec-5a00-9779-f0888bfa3d17
STIX ID: report--bc2eea9b-1fec-5a00-9779-f0888bfa3d17
Feed Name: CyberScoop
Threat Score
Mandiant and Google Cloud report that Iran-linked APT42 (Charming Kitten) ran an extended social-engineering campaign impersonating journalists, media outlets, and think tanks to harvest credentials and bypass MFA—using cloned login pages, decoy documents on legitimate services, and push-based MFA prompts—to access Microsoft 365 and other cloud environments and exfiltrate data for intelligence collection.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
