BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

Iranian Hackers Launch AI-Driven Phishing Attacks on Israelis

Iranian State-Backed Hackers Use AI-Powered Phishing to Target Israeli Journalists and Academics Amid Rising Tensions

  • An Iranian state-backed Hacking group targeted Israeli journalists, Cybersecurity professionals, and academics in a recent spear-phishing campaign.
  • The attackers used fake identities to connect with victims through email and WhatsApp, luring them to counterfeit Google login or meeting pages.
  • The campaign, attributed to Educated Manticore, used advanced phishing kits able to capture credentials and two-factor authentication codes.
  • Messages were crafted with help from Artificial Intelligence tools, making communications appear legitimate and error-free.
  • The phishing attack leveraged current geopolitical tensions, focusing on Israeli targets during the Iran-Israel conflict’s escalation.

In mid-June 2025, an Iranian state-sponsored hacking group linked to the Islamic Revolutionary Guard Corps targeted Israeli journalists, cybersecurity experts, and computer science professors with a spear-phishing campaign. The group reached out through emails and WhatsApp messages, posing as assistants to technology executives or researchers to build trust and trick individuals into visiting fake login or meeting pages.

- Advertisement -

Check Point reported these incidents, stating that the threat actors used convincing decoy messages and fake invitations to direct targets to spoofed Gmail or Google Meet sites. These custom phishing sites were built using modern web tools and closely resembled real Google login pages, as explained in their official report.

The campaign was attributed to a threat cluster tracked as Educated Manticore. This group is also known by other names such as APT35, Charming Kitten, ITG18, and TA453. According to Check Point, "The threat actors directed victims who engaged with them to fake Gmail login pages or Google Meet invitations." The messages included structured, error-free language likely crafted with artificial intelligence, designed to improve the credibility of the attack.

The initial communications were harmless, with attackers patiently establishing contact and rapport. Once trust was built, they sent links to phishing sites that replicated legitimate authentication flows and pre-filled the victim’s email address. The phishing kit captured not only passwords but also one-time use codes from two-factor authentication, and operated as a passive keylogger to collect any information entered on the site. Some schemes involved links hosted on Google Sites, with fake Google Meet images leading to credential harvesting pages.

According to Check Point, "Educated Manticore continues to pose a persistent and high-impact threat, particularly to individuals in Israel during the escalation phase of the Iran-Israel conflict." The group has been able to move quickly by setting up new domains and infrastructure and taking them down rapidly after being flagged. This strategy helps them remain effective despite increased attention from cybersecurity defenders.

- Advertisement -

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Theta Labs Adds Alibaba Cloud, Expands AI to Twitch in April

Theta EdgeCloud now offers developers a 5% rebate in TDROP tokens on all GPU...

World Liberty Financial Sues Justin Sun for Defamation

World Liberty Financial filed a defamation lawsuit against Justin Sun in Florida, escalating a...

Court to Rule on North Korea-Linked Crypto From Kelp Hack

A legal battle over $71 million in crypto seized from North Korean Hackers will...

OpenMythos Publishes Open-Source “Claude Mythos” Clone

Developer Kye Gomez has published OpenMythos, an open-source architectural guess at Anthropic's unreleased Claude...

Securitize Wins FINRA Approval For Full Broker-Dealer Custody

Securitize has received FINRA approval to custody tokenized securities within its existing broker-dealer, a...

Must Read

Buy Domain With Bitcoin: Top 8 Domain Registrars That Accept Bitcoin And Crypto

You are here because you want to buy a domain with bitcoin, right? If you are looking for domain registrars that accept bitcoin or...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading