Threats Feed|APT42|Last Updated 02/10/2024|AuthorCertfa Radar|Publish Date23/08/2024

APT42’s Fake Support Agents on WhatsApp Target Political Officials

  • Actor Motivations: Espionage,Exfiltration
  • Attack Vectors: Phishing
  • Attack Complexity: Low
  • Threat Risk: Low Impact/High Probability

Threat Overview

APT42 used fake WhatsApp accounts posing as technical support from AOL, Google, Yahoo and Microsoft companies to target individuals in Israel, Palestine, Iran, the United States and the United Kingdom. Targets included political and diplomatic officials, as well as public figures associated with the Biden and Trump administrations. The campaign, identified through user reports, included phishing attempts but did not result in account compromise. APT42 is known for phishing credential theft, with previous campaigns targeting public officials, activists and academics.

Detected Targets

TypeDescriptionConfidence
SectorDissident
Verified
SectorHuman Rights
Verified
SectorJournalists
Verified
SectorMilitary
Verified
SectorPolitical
Verified
RegionIran
Verified
RegionIsrael
Verified
RegionPalestine
Verified
RegionUnited Kingdom
Verified
RegionUnited States
Verified