APT42 Hackers Pose as Journalists to Harvest Credentials and Access Cloud Data
ID: 7a5f9afb-9eb3-5fd3-910c-fee9720a40c0
STIX ID: report--7a5f9afb-9eb3-5fd3-910c-fee9720a40c0
Feed Name: The Hacker News
Mandiant reports that Iranian state-backed APT42 conducts sophisticated social-engineering campaigns—posing as journalists and event organizers—to harvest credentials, bypass MFA, and access cloud environments of Western and Middle Eastern NGOs, media, academia, legal services, and activists; the actor uses minimal-footprint techniques, open-source tools, OneDrive exfiltration, anonymized infrastructure, and custom backdoors (NICECURL/BASICSTAR and TAMECAT) to covertly collect strategic intelligence for Iran.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
