Researchers and industry defenders linked the Iranian threat cluster tracked as TA453, ITG18, Charming Kitten, and Phosphorus to sustained espionage operations targeting people of intelligence interest, including Middle East policy experts, senior academics, journalists, and individuals aligned with Iran’s Reformist movement. Proofpoint said the actor used Operation SpoofedScholars, in which operators posed as UK academics, built trust through extended email exchanges, and then sent “registration” links to credential-harvesting pages hosted on a compromised SOAS website to steal email credentials across multiple identity providers.
IBM Security X-Force reported the same broader cluster also deployed a custom Android surveillance backdoor, LittleLooter, disguised as WhatsApp.apk, and successfully compromised roughly 20 victims between August 2020 and May 2021, exfiltrating about 120 GB of data with Telegram content prominently represented. The malware supported audio and video recording, message and contact theft, call and location collection, browser-history access, and remote file and connectivity management, while investigators also found repeated operational security failures, including open servers and exposed victim archives; Microsoft separately highlighted legal and technical steps to protect customers from nation-state hacking tied to Iranian operators.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
12 events from the most recent confirmed update back to the earliest known activity.
On February 24, 2023, suspicious activity was reported involving a fake persona named Sara Shokouhi who claimed to work for the Atlantic Council and contacted researchers focused on Middle Eastern political affairs. Secureworks assessed that the campaign showed multiple hallmarks of COBALT ILLUSION/TA453, including rapport-building outreach over social media and links consistent with credential-phishing tradecraft.
Certfa published a report describing multiple APT42/TA453 credential-phishing campaigns active since late 2021 that used prolonged trust-building, fake meeting invitations, and impersonation of figures including Samuel Valable, Paul Salem, and Hagar Hajjar Chemali. The report also identified related phishing infrastructure on Hetzner and Google Sites and said some operations were still active at the time of publication.
Google Threat Analysis Group published a report on a new data-extraction tool associated with an Iranian APT actor, adding a new technical disclosure to reporting on the group's operations.
In June 2022, TA453 used multiple impersonated personas in the same email threads to pressure targets into responding, including campaigns against Middle East policy and genome research targets. Proofpoint said some of these lures delivered password-protected Word documents via OneDrive that used remote template injection to fetch the Korg macro template, which collected host reconnaissance data and exfiltrated it through Telegram.
IBM Security X-Force reported continued ITG18 activity and linked the group to the custom Android surveillance backdoor LittleLooter, which had been hosted as "WhatsApp.apk" on infrastructure associated with the actor.
Proofpoint publicly reported TA453's Operation SpoofedScholars, describing the actor's use of lengthy rapport-building emails and credential-harvesting pages on the compromised SOASRadio site to target experts and journalists.
In mid-May, TA453 resumed outreach using the email address hanse.kendel4[@]gmail.com to recruit targets for a webinar, reflecting an adjustment in the campaign's tradecraft.
Proofpoint said TA453 had been covertly approaching targets since at least January 2021 while masquerading as UK academics in a credential-phishing campaign later dubbed Operation SpoofedScholars.
From August 2020 through May 2021, IBM X-Force observed ITG18 successfully compromising multiple victims aligned with Iran's Reformist movement and stealing roughly 120 GB of data from about 20 individuals.
IBM X-Force reported that the command-and-control server for the Android surveillance malware LittleLooter had been active since July 2020 and masqueraded as an American flower shop.
Microsoft published an announcement describing new steps to protect customers from hacking. The provided reference includes the publication metadata but no additional event details in the content excerpt.
IBM X-Force reported that publicly accessible ITG18 servers had exposed nearly 2 TB of compressed exfiltrated victim data since 2018, reflecting repeated operational security failures by the group.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
8 references tracked. Mallory keeps watching after this page renders.
secureworks.com
Open sourcehrw.org
Open sourceproofpoint.com
Open sourceblog.certfa.com
Open sourceblog.google
Open sourcesecurityintelligence.com
Open sourceproofpoint.com
Open sourceblogs.microsoft.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.