logo

APT42 Hackers Pose as Journalists to Harvest Credentials and Access Cloud Data

ID: 7a5f9afb-9eb3-5fd3-910c-fee9720a40c0

STIX ID: report--7a5f9afb-9eb3-5fd3-910c-fee9720a40c0

Feed Name: The Hacker News

Threat Score
85/100

Date Published: 2024-05-07

Date Updated: 2026-05-05

Author: [email protected] (The Hacker News)

...
...

Mandiant reports that Iranian state-backed APT42 conducts sophisticated social-engineering campaigns—posing as journalists and event organizers—to harvest credentials, bypass MFA, and access cloud environments of Western and Middle Eastern NGOs, media, academia, legal services, and activists; the actor uses minimal-footprint techniques, open-source tools, OneDrive exfiltration, anonymized infrastructure, and custom backdoors (NICECURL/BASICSTAR and TAMECAT) to covertly collect strategic intelligence for Iran.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.