FlagThis — Daily Cybersecurity Intelligence Briefing

FILTERING BY: CLEAR FILTER

Iranian APT42 and APT35 Utilizing LLMs for AI-Augmented Spear-Phishing and Tamecat Malware Deployment

Iranian state-sponsored threat actors APT42 and APT35 (linked to the IRGC) are integrating Large Language Models (LLMs) to automate and refine spear-phishing campaigns. By leveraging Generative AI, these actors produce linguistically precise lures that evade traditional natural language processing (NLP)-based detection. Technical execution involves the deployment of Tamecat, a PowerShell-based backdoor, and EP3 malware to establish persistent access within high-value targets, including U.S. government officials and critical infrastructure. This tactical evolution shifts from manual social engineering to scalable, AI-driven reconnaissance and weaponized phishing, significantly increasing the efficacy of initial access attempts against geopolitical adversaries.

Iranian APT Escalation: Massive Surge in Cyber Operations Against Israeli Infrastructure

Following a U.S.-Israeli military offensive, Iranian-linked Advanced Persistent Threat (APT) actors have executed a massive escalation in cyber warfare, resulting in a 300% increase in hostile incidents. Intelligence indicates 4,800 recorded attacks in June 2026, compared to approximately 1,600 in June 2025. This campaign is characterized by the tactical unification of various Iranian hacking groups utilizing shared infrastructure and coordinated Tactics, Techniques, and Procedures (TTPs). Targeting has expanded from specialized government networks to include critical infrastructure and Small and Medium-sized Businesses (SMBs) to maximize systemic disruption and social impact.


LINK COPIED TO CLIPBOARD