Threat Analysis Group

Iranian backed group steps up phishing campaigns against Israel, U.S.



Between February and late July 2024, APT42 heavily targeted users in Israel and the U.S.

a chart showing that over 60% of users targeted by APT42 are in the US and Israel

Targeted APT42 credential phishing campaigns focused on Israel between February and late July 2024

a chart showing increases in users targeted

Government-backed attacker warning

an image showing a blue shield and the warning "Government backed attackers may be trying to steal your password"ing to

APT42 Google Sites abuse from an April 2024 phishing campaign

a phishing campaign card reading "7 terrible hours - Qatar Offers Mediation"

Benign PDF leading to an APT42 phishing kit landing page

Spoofed Google Drive page

APT42 phishing kit landing page