APT42 Uses AI-Assisted Phishing and TAMECAT Malware to Target Government and Defense Officials

In Cybersecurity News - Original News Source is cybersecuritynews.com by Blog Writer

Spread the love

APT42, an Iran-linked cyber espionage group, has expanded its phishing operations with AI-assisted research, convincing personas, and a more resilient version of its TAMECAT malware.

The campaign has targeted senior government and defense officials, policy experts, and, in some cases, family members connected to high-value individuals.

Rather than relying on large volumes of suspicious emails, the group builds trust through realistic invitations, extended conversations, and messages sent through personal email, corporate accounts, and WhatsApp.

This approach makes familiar Iranian APT42 phishing group activity harder to spot before a victim clicks a link or opens a document.

Analysts at DarkAtlas identified the latest activity as a combination of relationship-based phishing, credential theft, and malware delivery.

The remote .lnk file presented as a PDF after Explorer (Source – DarkAtlas)

DarkAtlas said in a report shared with Cyber Security News (CSN) that the group uses generative AI to research targets, create believable identities, translate messages, develop code, and improve its social-engineering lures.

The result is a campaign that can steal both credentials and long-term access to a victim’s device. The group’s latest TAMECAT activity shows that attackers are not depending on one delivery method, one hosting provider, or one command channel to keep an operation alive.

APT42 Uses AI-Assisted Phishing and TAMECAT Malware

The SpearSpecter campaign used professional themes such as conference invitations, interviews, and meeting documents to approach targets.

Operators reportedly spent days or weeks building rapport before sending a malicious link, making AI spear phishing risks more difficult to identify through poor grammar or generic wording alone.

Final process (Source – DarkAtlas)

In one malware path, victims were directed to a page that triggered the Windows search-ms handler and asked them to open File Explorer.

If the user approved the prompt, Explorer connected to an attacker-controlled WebDAV share, where a shortcut file disguised as a PDF waited for execution.

The shortcut then launched Command Prompt, downloaded a batch file, and used PowerShell to retrieve further components.

This chain reflects wider Windows WebDAV delivery abuse that can make remote files appear less suspicious to users who believe they are opening a normal document.

TAMECAT is more than a simple downloader. The malware can collect browser cookies and credentials, search for files, capture screenshots, access Outlook mailbox data, run commands, package stolen information, and send it out through several channels, including HTTPS, Discord, and Telegram.

The browser-cookie capability creates a serious identity risk because a password reset alone may not remove an attacker’s access.

Organizations should revoke active sessions and refresh tokens, review browser-stored credentials, and investigate suspicious sign-ins after a suspected infection.

Detection Requires Context

APT42’s phishing activity also includes credential-harvesting pages that imitate cloud document services.

In a March 2026 operation, a benign OneDrive-hosted PDF was used first to establish trust, while a later link redirected the target to an attacker-controlled login page, a tactic similar to recent OneDrive credential phishing attacks.

Security teams should review the whole conversation rather than treating a legitimate first link as proof that a sender is safe.

PDF-Themed LNK Delivery (Source – DarkAtlas)

A sudden move from personal email to corporate email or WhatsApp, a changed document destination, or a request to sign in again should trigger verification through an independent channel.

Endpoint monitoring should focus on connected events: a browser opening search-ms, rundll32.exe using davclnt.dll to create WebDAV access, a remote LNK file launching cmd.exe, and curl or PowerShell retrieving content.

That sequence provides a stronger warning than a domain, file hash, or process event viewed alone.

High-risk users should use phishing-resistant MFA such as FIDO2 security keys or passkeys, while organizations should disable legacy authentication where possible.

Teams should also monitor unusual inbox rules, forwarding changes, new OAuth permissions, recovery-method changes, and session-token reuse following suspicious communications.

The campaign shows how patient social engineering and adaptable malware can work together against targets whose accounts and devices hold sensitive information.

Defenders need to combine email history, endpoint telemetry, identity logs, and infrastructure intelligence to determine whether an attempted approach became a compromise.

Indicators of Compromise (IoCs):-

Type Indicator Description
File name Document.pdf.lnk PDF-themed Windows shortcut used in the TAMECAT delivery chain
SHA-256 783a55c215ff18ea618f5a63936e08044448901096ee4de2d23fcda740abe104 SHA-256 hash for Document.pdf.lnk
Domain/URL cloudfilenow.online:8050/filebgeu/document.pdf.lnk External LNK staging location
IP/URL 107.189.25.188:8050/filebgeu/document.pdf.lnk IP-based LNK staging location
Domain/URL synctimenow.org:8050/filebgeu/document.pdf.lnk LNK staging location and observed DGA-generated domain
Domain/URL personal-store.netlify.app/yo3u Confirmed LNK delivery endpoint
Domain projects-shared.netlify.app Confirmed TAMECAT controller and PowerShell module-delivery host
Domain/URL projects-shared.netlify.app/Top4d DGA-stage delivery endpoint
Domain/URL projects-shared.netlify.app/home Module result-upload path
SHA-256 5c38af2f39802c0362a72247bfd52a35e16b93f45dfe1a2b573a2e620c8d1189 Confirmed batch-stage hash
File name 8.cmd Batch file saved and executed by the LNK stage
Tracking value bgeuYESS LNK POST value
Session key bgeu Batch and PowerShell session-key fragment
HTTP parameter RNE2randomINE2 Form value used to request the DGA batch stage
HTTP field N Base64 tasking form field used by the batch controller
HTTP field Data Module-result upload form field
File name TEMP.txt Temporary file used by the PersistenceMonitor module
Registry value systemUpdating RunOnce value used by the macro-enabled workbook
Domain hsta.xyz Workbook staging host
Domain/URL 1thebstack1.xyz/ApiSession PowerWindows controller endpoint
Email address [email protected] Attacker-controlled account impersonating a researcher
Domain transfergocompany.com TA453-controlled redirector
Hostname fileportalshare.netlify.app OneDrive-themed credential-harvesting page
SHA-256 16db04b632668dae081359fc07c97e5a9b79dad61713642e48b494aa6b7828be Benign lure PDF hash
SHA-256 114706e160803e8c7a52718ffcbbe821dbc31a367f543aebc9a69f78c9589405 Applications module
SHA-256 e15ae10a292d13b866b320ce31603fe1d278102ea13feeffd160844e73a7ffad InveProcesse module
SHA-256 dcf42e20f7c1b0ee3860586e62cd19bf99318165e27cc113ecbc016d857936bc Persistencebootstrap module
SHA-256 02a2388a5e08545b513e6dd24cfc5d93cb6456bd9207e7e3900d81b9a22643ed RetstagDGA batch stage
SHA-256 2a286e342929d7f8fdb45ed80e21f864c7e3273898eeb6df587deeb0b0f97b31 Telegram persistence component
SHA-256 c308b143c8b8ae1d6c9e0305199eda73e80b8c3855ef3ba8ec7d79e7b4816336 RetconPersistenceMonitor module
SHA-256 a951ea15ce178f258d97c78c66af97f394375b7c504831aefa4bf9383fd8331d ColAppNormal module
SHA-256 0b20c41fce4840fb897b49a93155a5ab7655197d84fe6aca93953b6da3d18c8e BeaPowtemconmaFileManager module
SHA-256 09fa558298d33756000ce86a93b9cabd0c291f06b1183a1301d848e74d589d37 ListsexccactoFobsCrawler module
SHA-256 36ed7f9f9324b5241b9bfd93afae426b288ac5b006be7297a2984f737b26bc0b SeaextepatDownload module
SHA-256 31ac4dfe2e95c9a8e921112428a7a6daea4e221bc6811ef1ae51bee987f02102 Download variant
SHA-256 e3403602c46aa591958b3d8d1f04819cabad765386ee8b468e834b84f361c5e6 Download variant
SHA-256 e4c279d206c0ce3fa6cd7852c3a8a1f77f75321653b05bd2083fb1081807cad9 RestartPC module
SHA-256 a2a643147e077989f3b17b8e6824bfd13f1449b5e1452b218a992654f4fdcd13 PowerShell module
Reversed string boJ-tratS Reversed string embedded in the Normal module

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

! ALERT: 20+ government sites delivered malware to businesses and citizens. See full attack research to check your own exposure