2 Sources
[1]
WhatsApp chat from infosec expert could be Iranian phish
Charming Kitten unsheathes its claws and tries to catch credentials The cyber-ops arm of Iran's Islamic Revolutionary Guard Corps has started a spear-phishing campaign intent on stealing credentials from Israeli journalists, cybersecurity experts, and computer science professors from leading
[2]
Iranian APT35 Hackers Targeting Israeli Tech Experts with AI-Powered Phishing Attacks
An Iranian state-sponsored hacking group associated with the Islamic Revolutionary Guard Corps (IRGC) has been linked to a spear-phishing campaign targeting journalists, high-profile cyber security experts, and computer science professors in Israel. "In some of those campaigns, Israeli technology
Share
Copy Link
Iranian state-sponsored hackers are using AI-generated phishing messages to target Israeli cybersecurity experts and academics, aiming to steal credentials and potentially set up in-person meetings.
A sophisticated phishing campaign, attributed to the Iranian state-sponsored hacking group known as Charming Kitten (also APT35 or Educated Manticore), has been uncovered targeting Israeli cybersecurity experts, journalists, and academics. The campaign, which began in mid-June 2025 following escalated tensions between Iran and Israel, employs advanced social engineering tactics and AI-generated content to lure victims
1
2
.
Source: Hacker News
The attackers are leveraging artificial intelligence to craft convincing phishing messages, demonstrating an evolution in their tactics. These messages, sent via email and WhatsApp, are tailored to each target and often impersonate cybersecurity professionals from legitimate Israeli firms
1
. For instance, one fraudulent email from a "Sarah Novominski" sought advice on securing energy infrastructure against cyber threats1
.Check Point Research has identified over 130 unique domains and numerous subdomains used in this campaign, with each target being approached through one or two dedicated domains
1
. The phishing sites meticulously mimic Gmail login pages and Google Meet invitations, employing modern web technologies such as React-based Single Page Applications and real-time WebSocket connections to enhance credibility2
.The custom phishing kit employed by Charming Kitten is designed to capture not only login credentials but also two-factor authentication (2FA) codes, enabling full account takeovers. The kit includes a passive keylogger to record all keystrokes, ensuring data capture even if the victim abandons the process midway
2
.Researchers warn that this campaign may extend beyond cyberspace. Given Iran's history of luring Israeli businessmen and academics into in-person meetings for kidnapping or intelligence gathering, there's concern that some phishing attempts might be precursors to physical threats
1
.Related Stories
The timing of this campaign, shortly after Israeli airstrikes against Iran, underscores the interplay between geopolitical events and cyber operations. Interestingly, one of the phishing lures referenced an "Iranian invasion and 700 percent cyberattack surge since June 12," proposing discussions about AI-powered defenses
1
2
.Check Point emphasizes that Educated Manticore poses a persistent and high-impact threat, particularly to individuals in Israel during the current conflict escalation. The group's agility in setting up and taking down infrastructure allows them to remain effective despite increased scrutiny
2
.As this campaign demonstrates, the intersection of AI, geopolitics, and cybersecurity continues to present new challenges, requiring constant vigilance and adaptive defense strategies from potential targets and cybersecurity professionals alike.
Summarized by
Navi
[1]
11 Mar 2026•Technology

09 Aug 2024

29 May 2026•Technology

1
Technology

2
Technology

3
Policy and Regulation
