The Iran-linked threat actor APT42 is using AI-assisted phishing attacks to target U.S. organizations amidst the Iran-US war, according to researchers at DarkAtlas.
“APT42 remains an intelligence-collection threat whose advantage comes from patient human targeting, now accelerated by AI and supported by more resilient malware when needed,” the researchers write. “The recent TAMECAT activity shows that the group continues to evolve its delivery, persistence, and recovery options. SpearSpecter increased the technical depth of the malware chain, but the actor still depends on the victim accepting a relationship, opening a prompt, clicking a link, or submitting credentials.”
APT42’s use of generative AI doesn’t fundamentally change how the group uses phishing attacks, but it makes them much more effective. While translation tools have existed for years, legitimate AI platforms like ChatGPT and Gemini can craft more believable sentences in non-native languages. Attackers are abusing this functionality to converse with targets in extended social engineering attacks.
“Language quality is now a weak phishing indicator,” the researchers write. “APT42 already relied on rapport-building, multi-message engagement, and believable social engineering. Generative AI makes it easier to sustain a coherent persona across multiple messages, languages, and communication channels.”
The researchers advise users to be on the lookout for the following red flags:
- “Does the final document link move from a trusted platform to an unrelated domain?
- Does the sender’s address match the claimed institution?
- Does the proposed event exist on an official channel?
- Did the conversation unexpectedly move from personal email to corporate email or WhatsApp?”
KnowBe4 empowers your workforce to make smarter security decisions every day. Over 70,000 organizations worldwide trust the KnowBe4 Platform to strengthen their security culture and reduce human risk.
DarkAtlas has the story: https://darkatlas.io/blog/apt42-ai-assisted-phishing-tamecat-analysis
