{"id":4894,"date":"2024-08-15T12:21:38","date_gmt":"2024-08-15T17:21:38","guid":{"rendered":"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/google-iran-charming-kitten-targets-presidential-elections-israeli-military"},"modified":"2024-08-15T12:21:38","modified_gmt":"2024-08-15T17:21:38","slug":"google-irans-charming-kitten-targets-us-presidential-elections-israeli-military","status":"publish","type":"post","link":"https:\/\/ddi.mohflo.net\/index.php\/2024\/08\/15\/google-irans-charming-kitten-targets-us-presidential-elections-israeli-military\/","title":{"rendered":"Google: Iran&#8217;s Charming Kitten Targets US Presidential Elections, Israeli Military"},"content":{"rendered":"<div class=\"media_block\"><a href=\"https:\/\/i0.wp.com\/eu-images.contentstack.com\/v3\/assets\/blt6d90778a997de1cd\/blt2ea68f74c06436be\/66be08c97a9fb934adb3e2bb\/CharmingKitten_Jakub_Dvor%CC%8Ca%CC%81k_Alamy.jpeg?ssl=1\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/google-irans-charming-kitten-targets-us-presidential-elections-israeli-military.png?w=640&#038;ssl=1\" class=\"media_thumbnail\"><\/a><\/div>\n<div><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/google-irans-charming-kitten-targets-us-presidential-elections-israeli-military.png?w=640&#038;ssl=1\" class=\"ff-og-image-inserted\"><\/div>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">A threat group linked to Iran&#8217;s Islamic Revolutionary Guard Corps (IRGC) has launched new cyberattacks against email accounts associated with the upcoming US presidential election as well as high-profile military and other political targets in Israel. The activity \u2014 which predominantly comes in the form of socially engineered phishing campaigns \u2014 are in retaliation for Israel&#8217;s ongoing military campaign in Gaza and the US&#8217; support for it, and are expected to continue as tensions rise in the region.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Google&#8217;s Threat Analysis Group (TAG) <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/blog.google\/threat-analysis-group\/iranian-backed-group-steps-up-phishing-campaigns-against-israel-us\/\" rel=\"noopener\">detected and blocked<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> &#8220;numerous&#8221; attempts by Iran-backed <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/vulnerabilities-threats\/iran-linked-apt-cozies-up-enemies-trust-based-spy-game\" rel=\"noopener\">APT42<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, perhaps best known as <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/vulnerabilities-threats\/iran-backed-charming-kitten-stages-fake-webinar-platform-to-ensnare-targets\" rel=\"noopener\">Charming Kitten<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, to log in to the personal email accounts of about a dozen individuals affiliated with President Biden and with former President Trump, according to a blog post published yesterday. Targets of the activity included current and former US government officials as well as individuals associated with the respective campaigns.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Moreover, the threat group remains persistent in its ongoing efforts to attempt to compromise the personal accounts of individuals affiliated with the current US Vice President and now presidential candidate Kamala Harris, and former President Trump, &#8220;including current and former government officials and individuals associated with the campaign,&#8221; according to the post.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The discovery comes as a Telegram-based bot service called &#8220;IntelFetch&#8221; has also been found to be <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/dnc-credentials-compromised-intelfetch-telegram-bot\" rel=\"noopener\">aggregating compromised credentials<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> linked to the DNC and Democratic Party websites.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Charming Kitten Bats Around Israeli Targets\">Charming Kitten Bats Around Israeli Targets<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">In addition to election-related attacks, TAG researchers also have been tracking various phishing campaigns against Israeli military and political targets \u2014 including people with connections to the defense sector, as well as diplomats, academics, and NGOs \u2014 that have ramped up significantly since April, according to the post.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Google recently took down multiple Google Sites pages created by the group &#8220;masquerading as a petition from the legitimate Jewish Agency for Israel calling on the <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cybersecurity-operations\/israel-czech-republic-reinforce-cyber-partnership-hamas-war\" rel=\"noopener\">Israeli government<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> to enter into mediation to end the conflict,&#8221; according to the post.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Charming Kitten also abused Google Sites in an April phishing campaign targeting Israeli military, defense, diplomats, academics, and civil society by sending emails that impersonated a journalist requesting comment on recent air strikes to target former senior Israeli military officials and an aerospace executive.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;Over the last six months, we have systematically disrupted these attackers&#8217; ability to abuse Google Sites in more than 50 similar campaigns,&#8221; according to Google TAG.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">One such campaign involved a phishing lure that featured an attacker-controlled Google Sites link that would direct the victim to a fake Google Meet landing page, while other lures included OneDrive, Dropbox, and Skype.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"New &amp; Ongoing APT42 Phishing Activity\">New &amp; Ongoing APT42 Phishing Activity<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">In other attacks, Charming Kitten has engaged in a diverse range of social engineering tactics in phishing campaigns that reflect its geopolitical stance. The activity is not likely to let up for the forseeable future, according to Google TAG.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">A recent campaign against Israeli diplomats, academics, NGOs, and political entities came from accounts hosted by a variety of email service providers, they discovered. Though the messages did not contain malicious content, Google TAG surmised that they were &#8220;likely meant to elicit engagement from the recipients before APT42 attempted to compromise the targets,&#8221; and Google suspended Gmail accounts associated with the APT.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">A separate June campaign targeted Israeli NGOs using a benign PDF email attachment impersonating a legitimate political entity that contained a shortened URL link that redirected to a phishing kit landing page designed to harvest Google login credentials. Indeed, APT42 often uses phishing links embedded either directly in the body of the email or as a link in an otherwise innocuous PDF attachment, the researchers noted.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;In such cases, APT42 would engage their target with a social engineering lure to set-up a video meeting and then link to a landing page where the target was prompted to login and sent to a phishing page,&#8221; according to the post.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Another APT42 campaign template is sending legitimate PDF attachments as part of a social engineering lure to build trust and encourage the target to engage on other platforms like Signal, Telegram, or WhatsApp, most likely as a way to send a phishing kit to harvest credentials, according to Google TAG.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Politically Motivated Attacks to Continue\">Politically Motivated Attacks to Continue<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">All of this is common hunting for APT42\/Charming Kitten, which is well known for politically motivated cyberattacks. Of late, it has been <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/ics-ot-security\/iran-israel-cyber-war-goes-global\" rel=\"noopener\">extremely active<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> against Israel, the US, and other global targets since Israel&#8217;s military campaign in Gaza in retaliation for the Hamas Oct. 7 attack in Israel.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Iran overall has a <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/iranian-threat-activity-warnings-indictments-us-government\" rel=\"noopener\">long history<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> of responding to tensions in the region with cyberattacks against Israel and the US. In the past six months alone, the US and Israel accounted for roughly 60% of APT42&#8217;s known geographic targeting, according to Google TAG. More activity is expected after the Israel&#8217;s recent assassination of top Hamas leader on Iranian soil, as experts believe that cyberspace will remain a primary battleground for Iran-backed threat actors.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;APT42 is a sophisticated, persistent threat actor and they show no signs of stopping their attempts to target users and deploy novel tactics,&#8221; according to Google TAG. &#8220;As hostilities between Iran and Israel intensify, we can expect to see increased campaigns there from APT42.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The researchers also included a list of indicators of compromise (IoCs) in its post that include domains and IP addresses known to be used by APT42. Organizations who may be targeted also should remain vigilant for the various social engineering and phishing tactics used by the group in its recently discovered threat campaigns.<\/span><\/p>\n<p><a href=\"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/google-iran-charming-kitten-targets-presidential-elections-israeli-military\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>A threat group linked to Iran&#8217;s Islamic Revolutionary Guard Corps<\/p>\n","protected":false},"author":12,"featured_media":4895,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1],"tags":[809],"class_list":["post-4894","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-dark-reading"],"featured_image_urls":{"full":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/google-irans-charming-kitten-targets-us-presidential-elections-israeli-military.png?fit=1920%2C1080&ssl=1",1920,1080,false],"thumbnail":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/google-irans-charming-kitten-targets-us-presidential-elections-israeli-military.png?resize=150%2C150&ssl=1",150,150,true],"medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/google-irans-charming-kitten-targets-us-presidential-elections-israeli-military.png?fit=300%2C169&ssl=1",300,169,true],"medium_large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/google-irans-charming-kitten-targets-us-presidential-elections-israeli-military.png?fit=640%2C360&ssl=1",640,360,true],"large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/google-irans-charming-kitten-targets-us-presidential-elections-israeli-military.png?fit=640%2C360&ssl=1",640,360,true],"1536x1536":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/google-irans-charming-kitten-targets-us-presidential-elections-israeli-military.png?fit=1536%2C864&ssl=1",1536,864,true],"2048x2048":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/google-irans-charming-kitten-targets-us-presidential-elections-israeli-military.png?fit=1920%2C1080&ssl=1",1920,1080,true],"chromenews-featured":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/google-irans-charming-kitten-targets-us-presidential-elections-israeli-military.png?fit=1024%2C576&ssl=1",1024,576,true],"chromenews-large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/google-irans-charming-kitten-targets-us-presidential-elections-israeli-military.png?resize=825%2C575&ssl=1",825,575,true],"chromenews-medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/google-irans-charming-kitten-targets-us-presidential-elections-israeli-military.png?resize=590%2C410&ssl=1",590,410,true]},"author_info":{"display_name":"Dark Reading","author_link":"https:\/\/ddi.mohflo.net\/index.php\/author\/darkreading\/"},"category_info":"<a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/uncategorized\/\" rel=\"category tag\">Uncategorized<\/a>","tag_info":"Uncategorized","comment_count":"0","jetpack_featured_media_url":"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/google-irans-charming-kitten-targets-us-presidential-elections-israeli-military.png?fit=1920%2C1080&ssl=1","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/4894","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/comments?post=4894"}],"version-history":[{"count":0,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/4894\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media\/4895"}],"wp:attachment":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media?parent=4894"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/categories?post=4894"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/tags?post=4894"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}