Actors Insights|Latest update04/07/2026

UNK_SmudgedSerpent

Named by ProofpointSuspected state sponsor: Islamic Republic of Iran

UNK_SmudgedSerpent is Proofpoint's designation for a previously unknown Iranian-linked threat cluster active between June and August 2025, targeting US-based academics and foreign policy experts focused on Iran, the IRGC, and Middle East geopolitics. The group conducted highly targeted phishing campaigns impersonating prominent think tank figures — including individuals from the Brookings Institution — using politically relevant lures about Iranian societal change and IRGC militarization to initiate benign correspondence before delivering credential harvesting links disguised as Microsoft Teams or OnlyOffice invitations. In some cases, the group deployed legitimate RMM software (PDQ Connect and ISL Online) as post-access tools. Proofpoint identified significant TTP overlaps with TA453 (Charming Kitten), TA455 (Smoke Sandstorm), and TA450 (MuddyWater), but found the combination of techniques insufficient for high-confidence attribution to any single group. The campaign's targeting and operational period align with Iranian intelligence collection priorities during heightened Iran-Israel geopolitical tensions in 2025, and Proofpoint assessed related activity likely remained ongoing after August 2025.

First Seen:Jun 2025
Last Seen:Nov 2025
Indexed Reports:1
Public IOCs:75
Cluster: Unclassified
also known as:
UNK_SmudgedSerpent

Targeted Regions

United States
US
United States
United States
Jun 2025 ~ Nov 2025
Jun 2025 ~ Nov 2025
Jun 2025 ~ Nov 2025
Jun 2025 ~ Nov 2025
Jun 2025 ~ Nov 2025
Jan 2025Dec 2026

Targeted Sectors

Pro-DemocracyResearchers

Disclaimer: We are working on indexing and analyzing relevant data and this process is not fully completed yet. Therefore, displayed details and statistics may will change in the future.