Threat Advisory

Iranian APT42 Deploys New TAMECAT Malware

Threat: Malware Campaign
Threat Actor Name: APT42
Threat Actor Type: State-Sponsored
Targeted Region: United States
Threat Actor Region: Iran
Targeted Sector: Government & Defense, Energy & Utilities
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY

APT42, an Iran-aligned threat group, is conducting a targeted espionage campaign known as SpearSpecter against senior defense and government officials. This operation combines multi-channel social engineering with the deployment of the TAMECAT backdoor to steal sensitive information and credentials. The attackers focus on high-value individuals, often engaging targets through extended conversations on personal and corporate platforms before striking. Their primary goal is long-term intelligence gathering rather than financial disruption, using advanced techniques to bypass traditional security controls and maintain persistent access within victim environments.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY

APT42, an Iran-aligned threat group, is conducting a targeted espionage campaign known as SpearSpecter against senior defense and government officials. This operation combines multi-channel social engineering with the deployment of the TAMECAT backdoor to steal sensitive information and credentials. The attackers focus on high-value individuals, often engaging targets through extended conversations on personal and corporate platforms before striking. Their primary goal is long-term intelligence gathering rather than financial disruption, using advanced techniques to bypass traditional security controls and maintain persistent access within victim environments.[emaillocker id="1283"]

The attack chain begins with spear-phishing lures that trick users into initiating a Windows search protocol, which connects to a remote WebDAV server. Victims then download a malicious shortcut file disguised as a document, triggering a script loader that fetches and executes the TAMECAT backdoor. Once inside the system, the malware establishes persistence and uses modular components to profile the host, steal browser cookies, and exfiltrate data. Command and control traffic flows through encrypted messaging platforms and web services, blending with normal network activity to avoid detection.

This campaign is particularly dangerous because the group uses generative AI to create highly convincing phishing messages that bypass standard verification checks. The malware also abuses legitimate system tools, making it difficult to distinguish from normal administrative work. Defenders should implement phishing-resistant multi-factor authentication and closely monitor identity telemetry for unusual session activity. Since the attackers can steal active session tokens, simply resetting passwords is often insufficient. Organizations must revoke active sessions, inspect endpoint logs for unusual protocol usage, and train staff to verify communication channels through secondary means.

THREAT PROFILE:

Tactic Technique ID Technique Sub-technique
Reconnaissance T1589 Gather Victim Identity Information
Initial Access T1566.001 Phishing Spearphishing Attachment
Defense Evasion T1218.001 System Binary Proxy Execution Compiled HTML File
Execution T1059.003 Command and Scripting Interpreter Windows Command Shell
Execution T1059.001 Command and Scripting Interpreter PowerShell
Persistence T1547.001 Boot or Logon Autostart Execution Registry Run Keys / Startup Folder
Defense Evasion T1027.005 Obfuscated Files or Information Indicator Removal from Tools
Credential Access T1552.001 Unsecured Credentials Credentials In Files
Discovery T1082 System Information Discovery
Command and Control T1071.001 Application Layer Protocol Web Protocols
Exfiltration T1048.003 Exfiltration Over Alternative Protocol Exfiltration Over Unencrypted Non-C2 Protocol

REFERENCES:

The following reports contain further technical details:

https://cybersecuritynews.com/apt42-uses-ai-assisted-phishing-and-tamecat-malware/
https://darkatlas.io/blog/apt42-ai-assisted-phishing-tamecat-analysis

[/emaillocker]
crossmenu