logo

APT42 Expands AI-Assisted Phishing Operations Targeting Government Officials

ID: 4fefd476-ab3f-534d-9669-d922cea68ffa

STIX ID: report--4fefd476-ab3f-534d-9669-d922cea68ffa

Feed Name: ThreatCluster

Threat Score
88/100

Date Published: 2026-07-21

Date Updated: 2026-07-22

...
...

Iran-linked APT42 has intensified espionage against high-profile government and defense targets by using AI-assisted phishing personas and advanced social engineering; the group deployed an upgraded TAMECAT backdoor focused on long-term access to sensitive identities and leveraged cloud abuse and fileless PowerShell techniques. Reports indicate the campaign is ongoing and poses a sophisticated, persistent threat to targeted individuals and organizations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.