logo

Iranian APT Launches AI-Assisted Spear Phishing Attacks

ID: cb6a22c4-fcf4-5248-b35d-978e85f9674c

STIX ID: report--cb6a22c4-fcf4-5248-b35d-978e85f9674c

Feed Name: KnowBe4 Blog

Threat Score
85/100

Date Published: 2026-08-13

Date Updated: 2026-08-13

Author: KnowBe4 Team

...
...

DarkAtlas reports that Iran-linked APT42 is using generative AI (e.g., ChatGPT, Gemini) to enhance spear-phishing against U.S. organizations, improving multilingual conversational social engineering and sustaining believable personas across messages and channels; the group (TAMECAT / SpearSpecter) has also evolved its delivery, persistence, and recovery options and may deploy more resilient malware. Researchers advise monitoring red flags such as transitions from trusted platforms to unrelated domains, sender address mismatches, absence of official event listings, and unexpected channel shifts.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.