Iranian Hackers Launch AI-Driven Phishing Attacks on Israelis

Iranian State-Backed Hackers Use AI-Powered Phishing to Target Israeli Journalists and Academics Amid Rising Tensions

  • An Iranian state-backed Hacking group targeted Israeli journalists, Cybersecurity professionals, and academics in a recent spear-phishing campaign.
  • The attackers used fake identities to connect with victims through email and WhatsApp, luring them to counterfeit Google login or meeting pages.
  • The campaign, attributed to Educated Manticore, used advanced phishing kits able to capture credentials and two-factor authentication codes.
  • Messages were crafted with help from Artificial Intelligence tools, making communications appear legitimate and error-free.
  • The phishing attack leveraged current geopolitical tensions, focusing on Israeli targets during the Iran-Israel conflict’s escalation.

In mid-June 2025, an Iranian state-sponsored hacking group linked to the Islamic Revolutionary Guard Corps targeted Israeli journalists, cybersecurity experts, and computer science professors with a spear-phishing campaign. The group reached out through emails and WhatsApp messages, posing as assistants to technology executives or researchers to build trust and trick individuals into visiting fake login or meeting pages.

- Advertisement -

Check Point reported these incidents, stating that the threat actors used convincing decoy messages and fake invitations to direct targets to spoofed Gmail or Google Meet sites. These custom phishing sites were built using modern web tools and closely resembled real Google login pages, as explained in their official report.

The campaign was attributed to a threat cluster tracked as Educated Manticore. This group is also known by other names such as APT35, Charming Kitten, ITG18, and TA453. According to Check Point, "The threat actors directed victims who engaged with them to fake Gmail login pages or Google Meet invitations." The messages included structured, error-free language likely crafted with artificial intelligence, designed to improve the credibility of the attack.

The initial communications were harmless, with attackers patiently establishing contact and rapport. Once trust was built, they sent links to phishing sites that replicated legitimate authentication flows and pre-filled the victim’s email address. The phishing kit captured not only passwords but also one-time use codes from two-factor authentication, and operated as a passive keylogger to collect any information entered on the site. Some schemes involved links hosted on Google Sites, with fake Google Meet images leading to credential harvesting pages.

According to Check Point, "Educated Manticore continues to pose a persistent and high-impact threat, particularly to individuals in Israel during the escalation phase of the Iran-Israel conflict." The group has been able to move quickly by setting up new domains and infrastructure and taking them down rapidly after being flagged. This strategy helps them remain effective despite increased attention from cybersecurity defenders.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -

Latest News

Trump Tariff Threat Derails BRICS Push for Common Currency

BRICS alliance slowed its efforts to challenge the U.S. dollar following tariff threats from...

Lithuania’s Axiology Gains DLT License for Digital Bond Trading

Axiology received a DLT Pilot Regime license to run a combined digital trading and...

BlackRock Invests $916M in Bitcoin, Ethereum as Crypto Holdings Surge

BlackRock raised its Bitcoin holdings by $416 million, now controlling $85.47 billion in Bitcoin...

Bitcoin Hits $123K as Trump Task Force Report Sparks Market Buzz

Bitcoin set a record price of $123,000, with markets watching for further movement. The digital...

XRP Nears $200B Market Cap, Surges 35% Against Bitcoin in July

XRP is approaching a $200 billion market cap for the first time. The price of...

Must Read

Tutorial: How to Buy a Domain Name Permanently? (Super Easy)

Are you ready to establish a permanent online presence and you want to buy a domain forever?In this tutorial, we'll show you how to...