UNK_SmudgedSerpent
Named by ProofpointSuspected state sponsor: Islamic Republic of IranUNK_SmudgedSerpent is Proofpoint's designation for a previously unknown Iranian-linked threat cluster active between June and August 2025, targeting US-based academics and foreign policy experts focused on Iran, the IRGC, and Middle East geopolitics. The group conducted highly targeted phishing campaigns impersonating prominent think tank figures — including individuals from the Brookings Institution — using politically relevant lures about Iranian societal change and IRGC militarization to initiate benign correspondence before delivering credential harvesting links disguised as Microsoft Teams or OnlyOffice invitations. In some cases, the group deployed legitimate RMM software (PDQ Connect and ISL Online) as post-access tools. Proofpoint identified significant TTP overlaps with TA453 (Charming Kitten), TA455 (Smoke Sandstorm), and TA450 (MuddyWater), but found the combination of techniques insufficient for high-confidence attribution to any single group. The campaign's targeting and operational period align with Iranian intelligence collection priorities during heightened Iran-Israel geopolitical tensions in 2025, and Proofpoint assessed related activity likely remained ongoing after August 2025.
Targeted Regions
United StatesUnited States
Jun 2025 ~ Nov 2025
Jun 2025 ~ Nov 2025
Jun 2025 ~ Nov 2025
Jun 2025 ~ Nov 2025
Jun 2025 ~ Nov 2025
Targeted Sectors
Recent Indexed Reports
Disclaimer: We are working on indexing and analyzing relevant data and this process is not fully completed yet. Therefore, displayed details and statistics may will change in the future.