Iran increases phishing attempts on U.S., Israeli targets
Full article858 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
APT42 targeted the Biden and Trump presidential campaigns from May to June, Google researchers found.
Hackers linked to Iran’s Islamic Revolutionary Guard Corps targeted the Trump and Biden presidential campaigns amid increased phishing attacks against U.S. and Israeli officials and institutions, according to a new report from Google’s Threat Analysis Group.
Google TAG researchers saw “small but steady” attempts by IRGC this election cycle to steal credential information from people associated with President Joe Biden and former President Donald Trump. The report also noted an increase in phishing attacks against Israeli military, defense, academic institutions and civil society organizations starting in April.
“This spring and summer, they have shown the ability to run numerous simultaneous phishing campaigns, particularly focused on Israel and the U.S. As hostilities between Iran and Israel intensify, we can expect to see increased campaigns there from APT42,” Google’s report noted, using Mandiant’s threat actor naming convention.
Last week, the Trump campaign alleged that Iran was the source of an attempted hack-and-leak operation by a persona dubbed “Robert” that claimed to multiple media outlets that they had inside access to campaign materials for the Trump campaign.
Former National Security Agency cybersecurity head Rob Joyce said Sunday at the DEF CON conference in Las Vegas that hack-and-leak operations of that kind — which harken back to the 2016 presidential election and efforts by Russia to sway the election using stolen emails — will likely ramp up as election day draws closer.
From May to June, researchers saw the IRGC attempt to steal logins of “roughly a dozen” former and current U.S. government officials, as well as individuals connected to the presidential campaigns of both Trump and Biden months before he dropped out and was replaced at the top of the Democratic ticket by Vice President Kamala Harris.
Google also confirmed Microsoft’s report last week that the IRGC successfully infiltrated the email of a “high-profile political consultant.”
Iran has been described as a “chaos agent” by intelligence officials and Google’s report noted that the U.S. and Israel combined to make up more than half of the IRGC’s geographic targeting.
The IRGC has been steadily targeting high-profile individuals with connections to Israeli defense, diplomatic and civil society organizations. Hackers used a combination of social engineering and fake Google services masquerading as Gmail, Google Sites or Drive, or other fake sites impersonating Dropbox and OneDrive, the report noted.
In one case, the IRGC attempted to social engineer former senior Israeli military and aerospace officials by acting as a journalist looking for comment on air strikes. The emails would not have malicious links or malware attached, but hackers would try to use the engagement to further trick the target down the line by using a fake landing page where they would be prompted to enter their credentials.
The state-backed hackers also imitated organizations like the Institute for the Study of War and the Brookings Institution using similar website or email domains, the report found.
More Scoops
Officials offer $10M reward for information on IRGC-linked leader and close associate
Mohammad Bagher Shirinkar and Fatemeh Sedighian Kashi are accused of maintaining a close relationship planning and conducting cyberattacks of interest to the Iranian government.
Google previews cyber ‘disruption unit’ as U.S. government, industry weigh going heavier on offense
Iran’s financial sector takes another hit as largest crypto exchange is targeted
Latest Podcasts
Government
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
Feds accuse China of ‘systematic’ distillation of U.S. AI models
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
The G7 tells industry to hurry up and prep for post-quantum encryption
Technology
Threats
Microsoft discloses two actively exploited zero-days among 974 vulnerabilities
Russian national extradited to US for alleged involvement in bank-account takeover scheme
Attackers exploit zero-days in consistently besieged SonicWall product
Jail time for Maine child in 764 marks turning point in federal law enforcement
Policy
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/iran-israel-hacking-phishing/