APT42, an Iran-linked cyber espionage group, has expanded its phishing operations with AI-assisted research, convincing personas, and a more resilient version of its TAMECAT malware.
The campaign has targeted senior government and defense officials, policy experts, and, in some cases, family members connected to high-value individuals.
Rather than relying on large volumes of suspicious emails, the group builds trust through realistic invitations, extended conversations, and messages sent through personal email, corporate accounts, and WhatsApp.
This approach makes familiar Iranian APT42 phishing group activity harder to spot before a victim clicks a link or opens a document.
Analysts at DarkAtlas identified the latest activity as a combination of relationship-based phishing, credential theft, and malware delivery.

DarkAtlas said in a report shared with Cyber Security News (CSN) that the group uses generative AI to research targets, create believable identities, translate messages, develop code, and improve its social-engineering lures.
The result is a campaign that can steal both credentials and long-term access to a victim’s device. The group’s latest TAMECAT activity shows that attackers are not depending on one delivery method, one hosting provider, or one command channel to keep an operation alive.
APT42 Uses AI-Assisted Phishing and TAMECAT Malware
The SpearSpecter campaign used professional themes such as conference invitations, interviews, and meeting documents to approach targets.
Operators reportedly spent days or weeks building rapport before sending a malicious link, making AI spear phishing risks more difficult to identify through poor grammar or generic wording alone.

In one malware path, victims were directed to a page that triggered the Windows search-ms handler and asked them to open File Explorer.
If the user approved the prompt, Explorer connected to an attacker-controlled WebDAV share, where a shortcut file disguised as a PDF waited for execution.
The shortcut then launched Command Prompt, downloaded a batch file, and used PowerShell to retrieve further components.
This chain reflects wider Windows WebDAV delivery abuse that can make remote files appear less suspicious to users who believe they are opening a normal document.
TAMECAT is more than a simple downloader. The malware can collect browser cookies and credentials, search for files, capture screenshots, access Outlook mailbox data, run commands, package stolen information, and send it out through several channels, including HTTPS, Discord, and Telegram.
The browser-cookie capability creates a serious identity risk because a password reset alone may not remove an attacker’s access.
Organizations should revoke active sessions and refresh tokens, review browser-stored credentials, and investigate suspicious sign-ins after a suspected infection.
Detection Requires Context
APT42’s phishing activity also includes credential-harvesting pages that imitate cloud document services.
In a March 2026 operation, a benign OneDrive-hosted PDF was used first to establish trust, while a later link redirected the target to an attacker-controlled login page, a tactic similar to recent OneDrive credential phishing attacks.
Security teams should review the whole conversation rather than treating a legitimate first link as proof that a sender is safe.

A sudden move from personal email to corporate email or WhatsApp, a changed document destination, or a request to sign in again should trigger verification through an independent channel.
Endpoint monitoring should focus on connected events: a browser opening search-ms, rundll32.exe using davclnt.dll to create WebDAV access, a remote LNK file launching cmd.exe, and curl or PowerShell retrieving content.
That sequence provides a stronger warning than a domain, file hash, or process event viewed alone.
High-risk users should use phishing-resistant MFA such as FIDO2 security keys or passkeys, while organizations should disable legacy authentication where possible.
Teams should also monitor unusual inbox rules, forwarding changes, new OAuth permissions, recovery-method changes, and session-token reuse following suspicious communications.
The campaign shows how patient social engineering and adaptable malware can work together against targets whose accounts and devices hold sensitive information.
Defenders need to combine email history, endpoint telemetry, identity logs, and infrastructure intelligence to determine whether an attempted approach became a compromise.
Indicators of Compromise (IoCs):-
| Type | Indicator | Description |
|---|---|---|
| File name | Document.pdf.lnk | PDF-themed Windows shortcut used in the TAMECAT delivery chain |
| SHA-256 | 783a55c215ff18ea618f5a63936e08044448901096ee4de2d23fcda740abe104 | SHA-256 hash for Document.pdf.lnk |
| Domain/URL | cloudfilenow.online:8050/filebgeu/document.pdf.lnk | External LNK staging location |
| IP/URL | 107.189.25.188:8050/filebgeu/document.pdf.lnk | IP-based LNK staging location |
| Domain/URL | synctimenow.org:8050/filebgeu/document.pdf.lnk | LNK staging location and observed DGA-generated domain |
| Domain/URL | personal-store.netlify.app/yo3u | Confirmed LNK delivery endpoint |
| Domain | projects-shared.netlify.app | Confirmed TAMECAT controller and PowerShell module-delivery host |
| Domain/URL | projects-shared.netlify.app/Top4d | DGA-stage delivery endpoint |
| Domain/URL | projects-shared.netlify.app/home | Module result-upload path |
| SHA-256 | 5c38af2f39802c0362a72247bfd52a35e16b93f45dfe1a2b573a2e620c8d1189 | Confirmed batch-stage hash |
| File name | 8.cmd | Batch file saved and executed by the LNK stage |
| Tracking value | bgeuYESS | LNK POST value |
| Session key | bgeu | Batch and PowerShell session-key fragment |
| HTTP parameter | RNE2randomINE2 | Form value used to request the DGA batch stage |
| HTTP field | N | Base64 tasking form field used by the batch controller |
| HTTP field | Data | Module-result upload form field |
| File name | TEMP.txt | Temporary file used by the PersistenceMonitor module |
| Registry value | systemUpdating | RunOnce value used by the macro-enabled workbook |
| Domain | hsta.xyz | Workbook staging host |
| Domain/URL | 1thebstack1.xyz/ApiSession | PowerWindows controller endpoint |
| Email address | McManus.Michael@hotmail.com | Attacker-controlled account impersonating a researcher |
| Domain | transfergocompany.com | TA453-controlled redirector |
| Hostname | fileportalshare.netlify.app | OneDrive-themed credential-harvesting page |
| SHA-256 | 16db04b632668dae081359fc07c97e5a9b79dad61713642e48b494aa6b7828be | Benign lure PDF hash |
| SHA-256 | 114706e160803e8c7a52718ffcbbe821dbc31a367f543aebc9a69f78c9589405 | Applications module |
| SHA-256 | e15ae10a292d13b866b320ce31603fe1d278102ea13feeffd160844e73a7ffad | InveProcesse module |
| SHA-256 | dcf42e20f7c1b0ee3860586e62cd19bf99318165e27cc113ecbc016d857936bc | Persistencebootstrap module |
| SHA-256 | 02a2388a5e08545b513e6dd24cfc5d93cb6456bd9207e7e3900d81b9a22643ed | RetstagDGA batch stage |
| SHA-256 | 2a286e342929d7f8fdb45ed80e21f864c7e3273898eeb6df587deeb0b0f97b31 | Telegram persistence component |
| SHA-256 | c308b143c8b8ae1d6c9e0305199eda73e80b8c3855ef3ba8ec7d79e7b4816336 | RetconPersistenceMonitor module |
| SHA-256 | a951ea15ce178f258d97c78c66af97f394375b7c504831aefa4bf9383fd8331d | ColAppNormal module |
| SHA-256 | 0b20c41fce4840fb897b49a93155a5ab7655197d84fe6aca93953b6da3d18c8e | BeaPowtemconmaFileManager module |
| SHA-256 | 09fa558298d33756000ce86a93b9cabd0c291f06b1183a1301d848e74d589d37 | ListsexccactoFobsCrawler module |
| SHA-256 | 36ed7f9f9324b5241b9bfd93afae426b288ac5b006be7297a2984f737b26bc0b | SeaextepatDownload module |
| SHA-256 | 31ac4dfe2e95c9a8e921112428a7a6daea4e221bc6811ef1ae51bee987f02102 | Download variant |
| SHA-256 | e3403602c46aa591958b3d8d1f04819cabad765386ee8b468e834b84f361c5e6 | Download variant |
| SHA-256 | e4c279d206c0ce3fa6cd7852c3a8a1f77f75321653b05bd2083fb1081807cad9 | RestartPC module |
| SHA-256 | a2a643147e077989f3b17b8e6824bfd13f1449b5e1452b218a992654f4fdcd13 | PowerShell module |
| Reversed string | boJ-tratS | Reversed string embedded in the Normal module |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.