logo

Iranian hackers impersonate journalists in social engineering campaign 

ID: bc2eea9b-1fec-5a00-9779-f0888bfa3d17

STIX ID: report--bc2eea9b-1fec-5a00-9779-f0888bfa3d17

Feed Name: CyberScoop

Threat Score
85/100

Date Published: 2024-05-02

Date Updated: 2026-04-21

Author: djohnson

...
...

Mandiant and Google Cloud report that Iran-linked APT42 (Charming Kitten) ran an extended social-engineering campaign impersonating journalists, media outlets, and think tanks to harvest credentials and bypass MFA—using cloned login pages, decoy documents on legitimate services, and push-based MFA prompts—to access Microsoft 365 and other cloud environments and exfiltrate data for intelligence collection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.