darkatlas.io APT42 Expands AI-Assisted Phishing Operations Targeting Government Officials
Article Content
- •APT42 is using AI to enhance phishing tactics against government officials.
- •The upgraded TAMECAT malware allows for prolonged access to sensitive identities.
- •The campaign employs advanced social engineering and cloud abuse techniques.
Iran-linked APT42 has intensified its cyber espionage efforts by utilizing AI-assisted phishing techniques and an upgraded version of its TAMECAT malware. The group is now targeting high-profile government and defense officials, as well as their family members, using convincing personas and advanced social engineering tactics. This campaign marks a shift from traditional phishing methods to more sophisticated approaches that complicate detection and response. The TAMECAT backdoor has been enhanced for long-term access, focusing on sensitive identities rather than just endpoints. The integration of cloud abuse and fileless PowerShell techniques further increases the complexity of the attacks. Recent reports indicate that APT42 is leveraging AI for more effective reconnaissance and targeting. The current status of the campaign suggests ongoing activity with no immediate resolution in sight.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (4)
Following this threat?
Track APT42 and Tamecat in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Social Engineering Campaign Hijacks Microsoft 365 Accounts via Passkey Alerts A social engineering campaign impersonating IT support staff is actively hijacking Microsoft 365 accounts. The attackers use passkey-themed lures to trick users into providing credentials, leading to unauthorized access and data exfiltration. Microsoft Security Research has tracked these intrusions since May 2026…
Critical Cisco FMC Vulnerabilities Under Active Exploitation Cisco's Secure Firewall Management Center (FMC) Software has two critical vulnerabilities, CVE-2026-20079 and CVE-2026-20316, that are currently being exploited by state-sponsored and ransomware actors. CVE-2026-20079, rated 10.0 on the CVSS scale, allows unauthenticated remote attackers to bypass authentication and…