Threat Analysis Group

Countering threats from Iran



Phishing page hosted on a compromised website

Phishing page hosted on a compromised website

Spyware app disguised as a VPN utility

Spyware app disguised as a VPN utility

Google Sites page disguised as a Google Form to redirect to a phishing site

Google Sites page disguised as a Google Form to redirect to a phishing site

Public Telegram channel used for attacker notifications

Public Telegram channel used for attacker notifications