Iranian Hackers Deploy AI-Powered Deception to Infiltrate Israel’s Top Cybersecurity Minds


# Iranian Hackers Target Israeli Cybersecurity Experts in Sophisticated Phishing Campaign

An Iranian state-sponsored hacking group linked to the Islamic Revolutionary Guard Corps (IRGC) has launched a targeted spear-phishing campaign against Israeli journalists, cybersecurity professionals, and computer science professors.

## The Attack Strategy

According to a Check Point report, attackers posed as fictitious assistants to technology executives and researchers, contacting victims through emails and WhatsApp messages. The cybercriminals directed targets to fake Gmail login pages and fraudulent Google Meet invitations to steal credentials.

## Behind the Attacks

Check Point attributes this activity to “Educated Manticore,” a threat group that overlaps with several known Iranian APT groups including APT35, APT42, Charming Kitten, and Mint Sandstorm. This advanced persistent threat group has an extensive history of conducting social engineering attacks using fake personas across platforms like Facebook and LinkedIn.

## Recent Campaign Details

The latest wave of attacks began in mid-June 2025, coinciding with escalating Iran-Israel tensions. The attackers crafted highly personalized messages, likely using artificial intelligence tools, as evidenced by their structured layout and grammatical accuracy.

One WhatsApp message exploited current geopolitical tensions, claiming the victim’s urgent assistance was needed for an AI-based threat detection system to counter increased cyber attacks against Israel.

## Sophisticated Phishing Techniques

The attack follows a multi-stage approach:

1. **Trust Building**: Initial messages contain no malicious content and focus on establishing rapport with targets
2. **Credential Harvesting**: Once trust is established, attackers share links to fake landing pages designed to steal Google account credentials
3. **Enhanced Credibility**: Attackers request victims’ email addresses to pre-fill phishing pages, mimicking legitimate Google authentication flows

## Advanced Technical Capabilities

The custom phishing kit demonstrates sophisticated features:
– Closely imitates legitimate Google login pages using modern web technologies like React-based applications
– Captures both passwords and two-factor authentication codes
– Includes passive keyloggers to record all keystrokes
– Uses real-time WebSocket connections for data theft
– Employs Google Sites domains to host fake Google Meet pages

## Ongoing Threat Assessment

Check Point warns that Educated Manticore remains a persistent, high-impact threat, particularly during the current Iran-Israel conflict escalation. The group demonstrates remarkable agility through aggressive spear-phishing tactics, rapid infrastructure deployment, and quick takedown responses when detected, allowing them to maintain effectiveness despite increased security scrutiny.

Share This Article