Iranian Hackers Launch AI-Driven Phishing Attacks on Israelis

Iranian State-Backed Hackers Use AI-Powered Phishing to Target Israeli Journalists and Academics Amid Rising Tensions

  • An Iranian state-backed Hacking group targeted Israeli journalists, Cybersecurity professionals, and academics in a recent spear-phishing campaign.
  • The attackers used fake identities to connect with victims through email and WhatsApp, luring them to counterfeit Google login or meeting pages.
  • The campaign, attributed to Educated Manticore, used advanced phishing kits able to capture credentials and two-factor authentication codes.
  • Messages were crafted with help from Artificial Intelligence tools, making communications appear legitimate and error-free.
  • The phishing attack leveraged current geopolitical tensions, focusing on Israeli targets during the Iran-Israel conflict’s escalation.

In mid-June 2025, an Iranian state-sponsored hacking group linked to the Islamic Revolutionary Guard Corps targeted Israeli journalists, cybersecurity experts, and computer science professors with a spear-phishing campaign. The group reached out through emails and WhatsApp messages, posing as assistants to technology executives or researchers to build trust and trick individuals into visiting fake login or meeting pages.

- Advertisement -

Check Point reported these incidents, stating that the threat actors used convincing decoy messages and fake invitations to direct targets to spoofed Gmail or Google Meet sites. These custom phishing sites were built using modern web tools and closely resembled real Google login pages, as explained in their official report.

The campaign was attributed to a threat cluster tracked as Educated Manticore. This group is also known by other names such as APT35, Charming Kitten, ITG18, and TA453. According to Check Point, "The threat actors directed victims who engaged with them to fake Gmail login pages or Google Meet invitations." The messages included structured, error-free language likely crafted with artificial intelligence, designed to improve the credibility of the attack.

The initial communications were harmless, with attackers patiently establishing contact and rapport. Once trust was built, they sent links to phishing sites that replicated legitimate authentication flows and pre-filled the victim’s email address. The phishing kit captured not only passwords but also one-time use codes from two-factor authentication, and operated as a passive keylogger to collect any information entered on the site. Some schemes involved links hosted on Google Sites, with fake Google Meet images leading to credential harvesting pages.

According to Check Point, "Educated Manticore continues to pose a persistent and high-impact threat, particularly to individuals in Israel during the escalation phase of the Iran-Israel conflict." The group has been able to move quickly by setting up new domains and infrastructure and taking them down rapidly after being flagged. This strategy helps them remain effective despite increased attention from cybersecurity defenders.

- Advertisement -

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -

Latest News

Aeva 4D LiDAR Selected for Nvidia DRIVE Hyperion – L3/L4 AVs

Aeva's FMCW 4D LiDAR was selected for NVIDIA's Hyperion autonomous vehicle platform.The sensor adds...

Amazon launches Alexa.com web AI chat with shopping, devices

Amazon launched a browser-based chat interface called Alexa.com for its Alexa+ assistant.Early Access users...

Micron Rockets Past $310, Emerging as 2026 AI Darling Rally!

Micron shares climbed above $310, breaching $310.52 on Monday.MU has surged over 30% since...

Nvidia unveils Alpamayo VLA for reasoning AVs at CES 2026…

NVIDIA unveiled the open reasoning vision-language-action system “Alpamayo” at CES 2026.Alpamayo includes the 10-billion-parameter...

NFT Paris, RWA Paris canceled amid market collapse; refunds.

Organizers cancelled NFT Paris and RWA Paris, which were scheduled for February 2026, citing...
- Advertisement -

Must Read

What Is Bcrypt Password Hashing Function?

KEY TAKEAWAYSBcrypt is a password hashing function that transforms plain passwords into unique alphanumeric sequences.It is a one-way process, ensuring that passwords cannot be...
Bitcoin (BTC) $ 93,706.00 0.62%
Ethereum (ETH) $ 3,220.78 0.83%
XRP (XRP) $ 2.39 11.54%
Bittensor (TAO) $ 273.81 2.52%
Polkadot (DOT) $ 2.21 2.57%
Cardano (ADA) $ 0.425126 5.04%
Chainlink (LINK) $ 13.80 0.42%
Hyperliquid (HYPE) $ 26.31 1.03%
Monero (XMR) $ 441.61 4.64%
Hedera (HBAR) $ 0.131609 2.72%
Toncoin (TON) $ 1.89 0.70%