Iranian Hackers Launch AI-Driven Phishing Attacks on Israelis

Iranian State-Backed Hackers Use AI-Powered Phishing to Target Israeli Journalists and Academics Amid Rising Tensions

  • An Iranian state-backed Hacking group targeted Israeli journalists, Cybersecurity professionals, and academics in a recent spear-phishing campaign.
  • The attackers used fake identities to connect with victims through email and WhatsApp, luring them to counterfeit Google login or meeting pages.
  • The campaign, attributed to Educated Manticore, used advanced phishing kits able to capture credentials and two-factor authentication codes.
  • Messages were crafted with help from Artificial Intelligence tools, making communications appear legitimate and error-free.
  • The phishing attack leveraged current geopolitical tensions, focusing on Israeli targets during the Iran-Israel conflict’s escalation.

In mid-June 2025, an Iranian state-sponsored hacking group linked to the Islamic Revolutionary Guard Corps targeted Israeli journalists, cybersecurity experts, and computer science professors with a spear-phishing campaign. The group reached out through emails and WhatsApp messages, posing as assistants to technology executives or researchers to build trust and trick individuals into visiting fake login or meeting pages.

- Advertisement -

Check Point reported these incidents, stating that the threat actors used convincing decoy messages and fake invitations to direct targets to spoofed Gmail or Google Meet sites. These custom phishing sites were built using modern web tools and closely resembled real Google login pages, as explained in their official report.

The campaign was attributed to a threat cluster tracked as Educated Manticore. This group is also known by other names such as APT35, Charming Kitten, ITG18, and TA453. According to Check Point, "The threat actors directed victims who engaged with them to fake Gmail login pages or Google Meet invitations." The messages included structured, error-free language likely crafted with artificial intelligence, designed to improve the credibility of the attack.

The initial communications were harmless, with attackers patiently establishing contact and rapport. Once trust was built, they sent links to phishing sites that replicated legitimate authentication flows and pre-filled the victim’s email address. The phishing kit captured not only passwords but also one-time use codes from two-factor authentication, and operated as a passive keylogger to collect any information entered on the site. Some schemes involved links hosted on Google Sites, with fake Google Meet images leading to credential harvesting pages.

According to Check Point, "Educated Manticore continues to pose a persistent and high-impact threat, particularly to individuals in Israel during the escalation phase of the Iran-Israel conflict." The group has been able to move quickly by setting up new domains and infrastructure and taking them down rapidly after being flagged. This strategy helps them remain effective despite increased attention from cybersecurity defenders.

- Advertisement -

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -

Latest News

Elon Musk’s xAI Raises $20B; Valuation Still Undisclosed Now

xAI raised $20 billion in an upsized Series E, surpassing a prior $15 billion...

Riot sells 2,201 BTC for $200M to fund AI data center build.

Riot Platforms sold 2,201 BTC across November and December, raising nearly $200 million in...

Aave v4 and Lido v3 Spark Major DeFi Upgrades, 2026 Outlook!

Major DeFi protocols plan substantive upgrades in early 2026.Aave is preparing a new architecture...

Hyperliquid Unlock Dilutes HYPE Holders by $331M amid $268M+

Hyperliquid unlocked 12,457,813 HYPE tokens from a founding vesting allocation, increasing circulating supply by...

Quintenz Joins SUI Group Board to Guide $200M Treasury Plan.

Brian Quintenz has been appointed to the board of Sui Group.The appointment aims to...
- Advertisement -

Must Read

How to Choose a Cryptocurrency Exchange: Major Risks and Expert Advice

During the bitcoin frenzy, in late 2017, Coinbase, one of the key players in the global cryptocurrency market, stopped trading operations. At a point...
Bitcoin (BTC) $ 93,016.00 1.36%
Ethereum (ETH) $ 3,269.36 0.75%
XRP (XRP) $ 2.29 2.01%
Bittensor (TAO) $ 291.34 7.60%
Polkadot (DOT) $ 2.21 0.97%
Cardano (ADA) $ 0.415767 1.93%
Chainlink (LINK) $ 13.89 1.52%
Hyperliquid (HYPE) $ 27.42 2.19%
Monero (XMR) $ 441.90 1.24%
Hedera (HBAR) $ 0.127376 3.15%
Toncoin (TON) $ 1.90 0.72%