Skip to content
Malware

APT42 Uses AI-Assisted Phishing and TAMECAT Malware to Target Government and Defense Officials

APT42, an Iran-linked cyber espionage group, has expanded its phishing operations with AI-assisted research, convincing personas, and a more resilient version of its TAMECAT malware. The campaign has targeted senior government and defense officials, policy experts, and, in some cases, family members...

· Jul 22, 2026 · 6 min read · 👁 6 views
APT42 Uses AI-Assisted Phishing and TAMECAT Malware to Target Government and Defense Officials

APT42, an Iran-linked cyber espionage group, has expanded its phishing operations with AI-assisted research, convincing personas, and a more resilient version of its TAMECAT malware.

The campaign has targeted senior government and defense officials, policy experts, and, in some cases, family members connected to high-value individuals.

Rather than relying on large volumes of suspicious emails, the group builds trust through realistic invitations, extended conversations, and messages sent through personal email, corporate accounts, and WhatsApp.

This approach makes familiar Iranian APT42 phishing group activity harder to spot before a victim clicks a link or opens a document.

Analysts at DarkAtlas identified the latest activity as a combination of relationship-based phishing, credential theft, and malware delivery.

The remote .lnk file presented as a PDF after Explorer (Source - DarkAtlas)
The remote .lnk file presented as a PDF after Explorer (Source – DarkAtlas)

DarkAtlas said in a report shared with Cyber Security News (CSN) that the group uses generative AI to research targets, create believable identities, translate messages, develop code, and improve its social-engineering lures.

The result is a campaign that can steal both credentials and long-term access to a victim’s device. The group’s latest TAMECAT activity shows that attackers are not depending on one delivery method, one hosting provider, or one command channel to keep an operation alive.

APT42 Uses AI-Assisted Phishing and TAMECAT Malware

The SpearSpecter campaign used professional themes such as conference invitations, interviews, and meeting documents to approach targets.

Operators reportedly spent days or weeks building rapport before sending a malicious link, making AI spear phishing risks more difficult to identify through poor grammar or generic wording alone.

Final process (Source - DarkAtlas)
Final process (Source – DarkAtlas)

In one malware path, victims were directed to a page that triggered the Windows search-ms handler and asked them to open File Explorer.

If the user approved the prompt, Explorer connected to an attacker-controlled WebDAV share, where a shortcut file disguised as a PDF waited for execution.

The shortcut then launched Command Prompt, downloaded a batch file, and used PowerShell to retrieve further components.

This chain reflects wider Windows WebDAV delivery abuse that can make remote files appear less suspicious to users who believe they are opening a normal document.

TAMECAT is more than a simple downloader. The malware can collect browser cookies and credentials, search for files, capture screenshots, access Outlook mailbox data, run commands, package stolen information, and send it out through several channels, including HTTPS, Discord, and Telegram.

The browser-cookie capability creates a serious identity risk because a password reset alone may not remove an attacker’s access.

Organizations should revoke active sessions and refresh tokens, review browser-stored credentials, and investigate suspicious sign-ins after a suspected infection.

Detection Requires Context

APT42’s phishing activity also includes credential-harvesting pages that imitate cloud document services.

In a March 2026 operation, a benign OneDrive-hosted PDF was used first to establish trust, while a later link redirected the target to an attacker-controlled login page, a tactic similar to recent OneDrive credential phishing attacks.

Security teams should review the whole conversation rather than treating a legitimate first link as proof that a sender is safe.

PDF-Themed LNK Delivery (Source - DarkAtlas)
PDF-Themed LNK Delivery (Source – DarkAtlas)

A sudden move from personal email to corporate email or WhatsApp, a changed document destination, or a request to sign in again should trigger verification through an independent channel.

Endpoint monitoring should focus on connected events: a browser opening search-ms, rundll32.exe using davclnt.dll to create WebDAV access, a remote LNK file launching cmd.exe, and curl or PowerShell retrieving content.

That sequence provides a stronger warning than a domain, file hash, or process event viewed alone.

High-risk users should use phishing-resistant MFA such as FIDO2 security keys or passkeys, while organizations should disable legacy authentication where possible.

Teams should also monitor unusual inbox rules, forwarding changes, new OAuth permissions, recovery-method changes, and session-token reuse following suspicious communications.

The campaign shows how patient social engineering and adaptable malware can work together against targets whose accounts and devices hold sensitive information.

Defenders need to combine email history, endpoint telemetry, identity logs, and infrastructure intelligence to determine whether an attempted approach became a compromise.

Indicators of Compromise (IoCs):-

TypeIndicatorDescription
File nameDocument.pdf.lnkPDF-themed Windows shortcut used in the TAMECAT delivery chain
SHA-256783a55c215ff18ea618f5a63936e08044448901096ee4de2d23fcda740abe104SHA-256 hash for Document.pdf.lnk
Domain/URLcloudfilenow.online:8050/filebgeu/document.pdf.lnkExternal LNK staging location
IP/URL107.189.25.188:8050/filebgeu/document.pdf.lnkIP-based LNK staging location
Domain/URLsynctimenow.org:8050/filebgeu/document.pdf.lnkLNK staging location and observed DGA-generated domain
Domain/URLpersonal-store.netlify.app/yo3uConfirmed LNK delivery endpoint
Domainprojects-shared.netlify.appConfirmed TAMECAT controller and PowerShell module-delivery host
Domain/URLprojects-shared.netlify.app/Top4dDGA-stage delivery endpoint
Domain/URLprojects-shared.netlify.app/homeModule result-upload path
SHA-2565c38af2f39802c0362a72247bfd52a35e16b93f45dfe1a2b573a2e620c8d1189Confirmed batch-stage hash
File name8.cmdBatch file saved and executed by the LNK stage
Tracking valuebgeuYESSLNK POST value
Session keybgeuBatch and PowerShell session-key fragment
HTTP parameterRNE2randomINE2Form value used to request the DGA batch stage
HTTP fieldNBase64 tasking form field used by the batch controller
HTTP fieldDataModule-result upload form field
File nameTEMP.txtTemporary file used by the PersistenceMonitor module
Registry valuesystemUpdatingRunOnce value used by the macro-enabled workbook
Domainhsta.xyzWorkbook staging host
Domain/URL1thebstack1.xyz/ApiSessionPowerWindows controller endpoint
Email addressMcManus.Michael@hotmail.comAttacker-controlled account impersonating a researcher
Domaintransfergocompany.comTA453-controlled redirector
Hostnamefileportalshare.netlify.appOneDrive-themed credential-harvesting page
SHA-25616db04b632668dae081359fc07c97e5a9b79dad61713642e48b494aa6b7828beBenign lure PDF hash
SHA-256114706e160803e8c7a52718ffcbbe821dbc31a367f543aebc9a69f78c9589405Applications module
SHA-256e15ae10a292d13b866b320ce31603fe1d278102ea13feeffd160844e73a7ffadInveProcesse module
SHA-256dcf42e20f7c1b0ee3860586e62cd19bf99318165e27cc113ecbc016d857936bcPersistencebootstrap module
SHA-25602a2388a5e08545b513e6dd24cfc5d93cb6456bd9207e7e3900d81b9a22643edRetstagDGA batch stage
SHA-2562a286e342929d7f8fdb45ed80e21f864c7e3273898eeb6df587deeb0b0f97b31Telegram persistence component
SHA-256c308b143c8b8ae1d6c9e0305199eda73e80b8c3855ef3ba8ec7d79e7b4816336RetconPersistenceMonitor module
SHA-256a951ea15ce178f258d97c78c66af97f394375b7c504831aefa4bf9383fd8331dColAppNormal module
SHA-2560b20c41fce4840fb897b49a93155a5ab7655197d84fe6aca93953b6da3d18c8eBeaPowtemconmaFileManager module
SHA-25609fa558298d33756000ce86a93b9cabd0c291f06b1183a1301d848e74d589d37ListsexccactoFobsCrawler module
SHA-25636ed7f9f9324b5241b9bfd93afae426b288ac5b006be7297a2984f737b26bc0bSeaextepatDownload module
SHA-25631ac4dfe2e95c9a8e921112428a7a6daea4e221bc6811ef1ae51bee987f02102Download variant
SHA-256e3403602c46aa591958b3d8d1f04819cabad765386ee8b468e834b84f361c5e6Download variant
SHA-256e4c279d206c0ce3fa6cd7852c3a8a1f77f75321653b05bd2083fb1081807cad9RestartPC module
SHA-256a2a643147e077989f3b17b8e6824bfd13f1449b5e1452b218a992654f4fdcd13PowerShell module
Reversed stringboJ-tratSReversed string embedded in the Normal module

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Source: CybersecurityNews.com

Follow ShomoySoft for more: Follow on Facebook

💬 Comments (0)

Login to join the discussion.

No comments yet. Be the first!

Related Articles

Recommended for you