A hacking group backed by Iran – TA453 – uses a new, sophisticated phishing technique that employs multiple personas and email accounts to lure targets into thinking it is a realistic conversation via email.
See also: WPGateway: Serious zero-day bug found in WordPress plugin

The intruders send an email to targets while CC'ing another email address under their control and then reply from that email, participating in a fake conversation.
See also: Trend Micro warns of Apex One RCE vulnerability
It was called “multi-persona impersonation» (MPI) by researchers at Proofpoint who observed it for the first time, the technique leverages the psychological principle of “social proof» to cloud logical thinking and add an element of credibility to phishing threads.
TA453 is an Iranian threat group believed to operate through the IRGC (Islamic Revolutionary Guard Corps), which in the past appears to have impersonated journalists to target academics and policy experts in the Middle East.
Multi-persona impersonation
The new tactic of the TA453 group requires much more effort on its part to carry out phishing attacks, as each target must be trapped in an elaborate realistic conversation conducted by fake personas.
However, the extra effort pays off, as it creates a realistic email exchange, which makes the conversation appear genuine.
An example shared in the Proofpoint report dates back to June 2022, with the sender masquerading as Research Director at FRPI and the email sent to the target assuming the role of Director of Global Research on Stances at the PEW Research Center.

The next day, the impersonated director of PEW answered the questions sent by the director of FRPI, creating a false sense of a sincere conversation that would lure the target into participating.
In another case Proofpoint saw, involving scientists specializing in genomic research, the CC persona responded with a OneDrive link that led to the download of a DOCX document with malicious macros.
See also: Stolen children's identities sold by fraud ring
In a third MPI phishing attack launched by the TA453 group against two academics specializing in nuclear weapons control, the threat actors performed CC on three individuals, moving to an even more complex attack.

In all cases, the threat actors used personal email addresses (Gmail, Outlook, AOL, Hotmail) for both senders and CC recipients instead of corporate ones, which is a clear sign of suspicious activity.
The malicious payload
The documents that targets were tricked into downloading via OneDrive links in TA453's recent campaign are password that perform template injection.
The researchers were unable to get beyond the information recognition stage, but hypothesized that additional exploitation occurs in subsequent steps to give remote threat actors code execution on hosts.
Information source: bleepingcomputer.com
