Protests Don't Impede Iranian Spying on Expats, Syrians, Israelis
ID: 3d4d0e80-7c14-5e3a-9458-790393d55ac6
STIX ID: report--3d4d0e80-7c14-5e3a-9458-790393d55ac6
Feed Name: Dark Reading
Researchers observed an active, multi-platform spear-phishing campaign—attributed to IRGC-linked actors—that targeted dissidents, activists, journalists, diplomats, and others outside Iran. Attackers used WhatsApp-themed links, fake Gmail/Telegram/X lures, and QR-based account-takeover flows to harvest credentials and 2FA codes; compromised infrastructure exposed ~850 stolen records and enabled persistent spying (geolocation, microphone, camera), while some infrastructure overlapped with cybercrime activity.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
