Iranian APT Launches AI-Assisted Spear Phishing Attacks

KnowBe4 Team | Aug 13, 2026

The Iran-linked threat actor APT42 is using AI-assisted phishing attacks to target U.S. organizations amidst the Iran-US war, according to researchers at DarkAtlas.

“APT42 remains an intelligence-collection threat whose advantage comes from patient human targeting, now accelerated by AI and supported by more resilient malware when needed,” the researchers write. “The recent TAMECAT activity shows that the group continues to evolve its delivery, persistence, and recovery options. SpearSpecter increased the technical depth of the malware chain, but the actor still depends on the victim accepting a relationship, opening a prompt, clicking a link, or submitting credentials.”

APT42’s use of generative AI doesn’t fundamentally change how the group uses phishing attacks, but it makes them much more effective. While translation tools have existed for years, legitimate AI platforms like ChatGPT and Gemini can craft more believable sentences in non-native languages. Attackers are abusing this functionality to converse with targets in extended social engineering attacks.

“Language quality is now a weak phishing indicator,” the researchers write. “APT42 already relied on rapport-building, multi-message engagement, and believable social engineering. Generative AI makes it easier to sustain a coherent persona across multiple messages, languages, and communication channels.”

The researchers advise users to be on the lookout for the following red flags:

  • “Does the final document link move from a trusted platform to an unrelated domain?
  • Does the sender’s address match the claimed institution?
  • Does the proposed event exist on an official channel?
  • Did the conversation unexpectedly move from personal email to corporate email or WhatsApp?”

KnowBe4 empowers your workforce to make smarter security decisions every day. Over 70,000 organizations worldwide trust the KnowBe4 Platform to strengthen their security culture and reduce human risk.

DarkAtlas has the story: https://darkatlas.io/blog/apt42-ai-assisted-phishing-tamecat-analysis

See KnowBe4 Security Awareness Training in Action

See how you can efficiently safeguard your organization from sophisticated social engineering threats.

Request a Demo

Secure the Digital Workforce: Human + AI

KnowBe4 empowers the modern workforce to make smarter security decisions every day. Trusted by more than 70,000 organizations worldwide, KnowBe4 is the pioneer of digital workforce security, securing both AI agents and humans. The KnowBe4 Platform provides attack simulation and training, collaboration security, and agent security powered by AIDA (Artificial Intelligence Defense Agents) and a proprietary Risk Score. The platform leverages 15 years of behavioral data to combat advanced threats including social engineering, prompt injection, and shadow AI. By securing humans and agents, KnowBe4 leads the industry in workforce trust and defense.