Iranian Hacker Group APT42 Unleashes Widespread Phishing Assault Targeting U.S. Presidential Race

An Iranian state-sponsored hacking group known as APT42 has initiated a phishing operation targeting the U.S. presidential election.

Google’s Threat Analysis Group (TAG) has identified this advanced cyber actor, connected to Iran’s Islamic Revolutionary Guard Corps (IRGC), as focusing on prominent individuals from both the Biden and Trump campaigns.
This effort is part of APT42’s larger mission to advance Iran’s political and military objectives through cyber espionage.


Historically, APT42 has targeted government officials, political campaigns, diplomats, and members of think tanks and NGOs.

Recently, their focus has sharpened on the U.S. and Israel, which together represent about 60% of their known targets.

APT42 is known for its aggressive, multi-faceted attempts to infiltrate sensitive accounts and gather intelligence.

Tactics and Techniques

APT42 uses a variety of methods in its phishing operations, including the deployment of malware, creation of phishing websites, and use of malicious redirects. The group frequently abuses popular platforms like Google Sites, Drive, Gmail, Dropbox, and OneDrive to host harmful content.

A key tactic involves the creation of fake domains mimicking legitimate organizations, known as typosquatting.
For instance, they have falsely represented entities like the Washington Institute for Near East Policy and the Brookings Institution to mislead their targets.


APT42’s phishing campaigns are meticulously tailored, relying heavily on social engineering to appear authentic. The phishing links are typically embedded directly in emails or within seemingly harmless PDF attachments.

These emails are crafted to engage the recipient and entice them into entering their credentials on a fraudulent landing page. APT42’s phishing kits are sophisticated enough to bypass multi-factor authentication, making them particularly dangerous.

Impact and Response

APT42’s actions have had a substantial impact, successfully compromising accounts across various email providers.

TAG has identified and thwarted numerous attempts by APT42 to infiltrate the personal email accounts of individuals linked to the U.S. presidential campaigns, including those of current and former government officials, political advisors, and campaign staff.
In response, Google has taken proactive steps to secure compromised accounts and issued government-backed attacker alerts to those targeted.

Google has also referred these malicious activities to law enforcement and continues to collaborate with authorities to reduce the threat.

Moreover, campaign officials have been notified of the increased risk and advised to strengthen security on their personal email accounts.

APT42’s activities highlight the ongoing threat that state-sponsored cyber groups pose to democratic processes. As the U.S. presidential election draws near, the risk of foreign interference remains a significant concern.

Google’s ongoing efforts to monitor and counteract APT42’s operations are vital in protecting the integrity of the electoral process.

High-risk individuals, including elected officials, candidates, and campaign staff, are urged to enroll in Google’s Advanced Protection Program to enhance their defenses against sophisticated cyber threats.

With tensions between Iran and other nations rising, the cyber environment is expected to become even more contentious.

Maintaining vigilance and robust cybersecurity practices is crucial to protecting sensitive information and ensuring the security of democratic institutions.

More Articles & Posts