An Iranian-backed hacking group called Educated Manticore, linked to IRGC, has launched spear-phishing campaigns targeting Israeli professionals amid geopolitical tensions. The attacks involve AI-crafted messages and sophisticated fake login pages to steal credentials and enable 2FA relay attacks. #IRGC #CharmingKitten
Keypoints
- Educated Manticore is associated with Iranβs IRGC and conducts social engineering attacks against Israeli targets.
- The group uses AI tools to craft convincing fake emails, messages, and meeting invitations.
- Attacks involve fake Google login pages and Google Meet clones to harvest credentials and 2FA codes.
- The phishing kits use advanced web technologies like React and WebSocket for real-time data exfiltration.
- They exhibit rapid infrastructure deployment and takedown capabilities to stay ahead of detection.
Read More: https://thehackernews.com/2025/06/iranian-apt35-hackers-targeting-israeli.html