The Iran-linked cyber espionage group APT42 has intensified its phishing operations by incorporating AI-assisted techniques and deploying a more resilient version of its TAMECAT malware. This campaign is particularly targeting senior government and defense officials, policy experts, and sometimes even family members of high-value individuals. Unlike traditional phishing tactics that rely on mass emailing, APT42's approach involves building trust with targets through realistic interactions over personal and corporate email accounts as well as WhatsApp.
The group's latest activities, identified by analysts at DarkAtlas, combine relationship-based phishing, credential theft, and malware deployment. The use of generative AI helps APT42 in researching targets, crafting believable personas, translating messages, and refining social-engineering techniques. These advanced methods enable the group to gain both credentials and sustained access to victims' devices. Their TAMECAT malware is not limited to a single delivery method, hosting provider, or command channel, making it highly versatile in maintaining persistent operations.
The SpearSpecter campaign employed professional themes like conference invitations and interview requests to engage with targets. Attackers invested significant time in building rapport before sending malicious links, which makes AI-driven spear phishing difficult to detect based on superficial cues like grammar errors. In one attack vector, targets were led to a page activating the Windows search-ms handler, prompting them to open File Explorer. If accepted, this sequence connected to an attacker-controlled WebDAV share, executing a malicious shortcut masquerading as a PDF. This method highlights a broader trend of exploiting Windows WebDAV for making remote files seem innocuous.
TAMECAT is more than a mere downloader; it can capture browser cookies and credentials, search files, take screenshots, access Outlook data, run commands, and exfiltrate data through various channels like HTTPS, Discord, and Telegram. This capability poses severe identity risks since a simple password reset may not revoke an attacker’s access. Organizations are advised to revoke active sessions, refresh tokens, and scrutinize browser-stored credentials following a breach.
APT42 also utilizes credential-harvesting pages mimicking cloud document services. For instance, a benign OneDrive-hosted PDF was initially used to gain trust, followed by a link redirecting to an attacker-controlled login page. Security teams should evaluate entire conversations rather than assuming safety from a legitimate first link. Sudden shifts from personal to corporate emails or document redirection should prompt verification through an independent channel.
Monitoring should focus on endpoint events such as a browser triggering search-ms, rundll32.exe creating WebDAV access, remote LNK files launching cmd.exe, and content retrieval via PowerShell. High-risk users should employ phishing-resistant MFA like FIDO2 security keys, and organizations should disable legacy authentication where feasible. Following suspicious communications, teams should also monitor for unusual inbox activity, new OAuth permissions, and session-token reuse. This campaign underscores the need for defenders to integrate email history, endpoint telemetry, identity logs, and infrastructure intelligence to assess potential compromises.


