Iranian state-sponsored hackers APT42 are targeting individuals and organizations of interest to the Islamic Revolutionary Guard Corps (IRGC) in a new campaign espionage. The activity, detected in early September 2025 and estimated to be ongoing to this day, has been codenamed SpearSpecter by the Israel National Digital Agency (INDA).

“ The campaign has systematically targeted senior officials in the defense and government using tailored social engineering tactics sector ,” said INDA researchers Shimi Cohen, Adi Pick, Idan Beit-Yosef, Hila David and Yaniv Goldman. “ These attacks include inviting targets to supposedly prestigious conferences or organizing important meetings .”
It is notable that the attack extends to members of the targets' families, creating a broader attack surface that puts more pressure on the main targets.
See also: Jaguar Land Rover: Cyberattack cost £196 million
Iranian hackers APT42
APT42 was first publicly documented in late 2022 by Google Mandiant, which observed overlaps with another IRGC threat cluster tracked as APT35, CALANQUE, Charming Kitten, CharmingCypress, Cobalt Illusion, Educated Manticore, GreenCharlie, ITG18, Magic Hound, Mint Sandstorm (formerly Phosphorus), TA453, and Yellow Garuda.
One of the group's hallmarks is its ability to conduct persuasive social engineering campaigns, which can take days or weeks to build trust with targets. Sometimes, attackers impersonate known contacts to create an illusion of authenticity before sending a malicious payload or misleading users into clicking on malicious links.
In June 2025, Check Point described a wave of attacks in which threat actors approached Israeli technology and cybersecurity posing as technology executives or researchers. The approach was made via emails and WhatsApp messages.

Goldman told The Hacker News that SpearSpecter and the June 2025 campaign are separate and have been linked to two different subgroups within APT42.
See also: Dark web leaks: How companies monitor and deal with data leaks
“While our campaign was carried out by APT42’s D cluster (which focuses more on malware-based operations), the campaign described by Check Point was carried out by the same group’s B cluster (which focuses more on credential harvesting),” Goldman added.
SpearSpecter
INDA said SpearSpecter is flexible, as the adversary adapts its approach based on the value of the target and operational objectives. In one set of attacks, victims are redirected to fake meeting pagesdesigned to capture their credentials. Conversely, if the ultimate goal is persistent long-term access, the attacks lead to the deployment of a well-known PowerShell backdoor called TAMECAT that has been used repeatedly in recent years.
Attackers impersonate trusted WhatsApp contacts to send a malicious link, which leads to a supposedly required document for an upcoming meeting or conference. When the link is clicked, it starts a redirect chain to serve a Windows shortcut (LNK) hosted on WebDAV and pretending to be a PDF file, exploiting the “search-ms:” protocol handler.
The LNK file contacts a Cloudflare Workers subdomain to retrieve a batch script that acts as a loader for TAMECAT, which uses various modular components to facilitate data extraction and remote control.
The PowerShell framework uses three distinct channels—HTTPS, Discord, and Telegram—for command and control (C2), suggesting the threat actor's goal is to maintain persistent access to compromised computers even if one path is identified and blocked.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Additionally, TAMECAT is equipped with functions to conduct reconnaissance, collect files matching specific extensions, steal data from web browsers (such as Google Chrome and Microsoft Edge), collect Outlook mailboxes , and take screenshots at 15-second intervals. The data is removed via HTTPS or FTP.
See also: RCE vulnerability hits AI export frameworks at Meta, Nvidia, and Microsoft

It also adopts a variety of stealth techniques to evade detection and resist analysis attempts. These include encrypting telemetry and controller payloads, source code obfuscation, using living-off-the-land binaries (LOLBins) to hide malicious activity , and operating primarily in memory, thus leaving small traces on disk.
“The SpearSpecter campaign infrastructure reflects a sophisticated blend of agility, stealth, and operational security designed to sustain sustained espionage against high-value targets,” INDA said. “Operators leverage a multifaceted infrastructure that combines legitimate cloud services with attacker-controlled resources, enabling unhindered initial access, continuous communication with command-and-control (C2) infrastructure, and covert data removal.”
