What happened
On 14 August 2024 Google's Threat Analysis Group reported that the Iranian government-backed group APT42 had intensified credential phishing against Israeli and US targets over the preceding six months. Targets included current and former government officials, political campaigns, diplomats, think tank staff, NGO and academic personnel, former Israeli military leaders and aerospace executives, and individuals associated with both US presidential campaigns.
How the deception worked
APT42 impersonated credible institutions such as the Washington Institute for Near East Policy and the Institute for the Study of War, registering typosquatted domains so that correspondence appeared to come from organisations the targets already engage with professionally. Lures included benign PDF attachments paired with malicious links, and fraudulent petition pages hosted on Google Sites with embedded image text and redirect services to evade detection. Victims who followed the links reached phishing kits, tracked as GCollection, LCollection, YCollection and DWP, that harvested Google, Hotmail and Yahoo credentials, with some versions capable of capturing multi-factor codes.
AI involvement · Unknown
Google's report describes impersonation and phishing kits; it does not attribute the lure content to generative AI.
The control that would have caught it· our reading, not a claim from the sources
High-risk officials should be enrolled in hardware-key or advanced protection programmes, since MFA-capable phishing kits defeat one-time codes but not origin-bound authenticators.
Sources (1)
This entry summarises public reporting. It is not a legal finding, and details can change as investigations conclude. Found an error? Send a correction.