Skip to Main Content
Iranian backed group steps up phishing campaigns against Israel, U.S.
["How is Gemini changing Maps?", "What is \"vibe design?\"", "How can I learn new AI skills?"]

Threat Analysis Group

Iranian backed group steps up phishing campaigns against Israel, U.S.



Between February and late July 2024, APT42 heavily targeted users in Israel and the U.S.

a chart showing that over 60% of users targeted by APT42 are in the US and Israel

Targeted APT42 credential phishing campaigns focused on Israel between February and late July 2024

a chart showing increases in users targeted

Government-backed attacker warning

an image showing a blue shield and the warning "Government backed attackers may be trying to steal your password"ing to

APT42 Google Sites abuse from an April 2024 phishing campaign

a phishing campaign card reading "7 terrible hours - Qatar Offers Mediation"
image of a PDF with the header "Project Aladin"

Benign PDF leading to an APT42 phishing kit landing page

image of a Spoofed Google Drive page that says "Access is required"

Spoofed Google Drive page

image of a APT42 phishing kit landing page that reads "Sign in"

APT42 phishing kit landing page