Iranian Spies Now Use AI Lures, Telegram C2, and a Backdoor That Survives Password Resets

Iranian state-sponsored hackers, known as APT42, are utilizing generative AI to create highly convincing spear-phishing lures. These sophisticated attacks bypass traditional security measures by maintaining persistent access even after password resets.
A senior defense official who gets a conference invitation this week might receive a message written by a human operator and polished by a language model, sent from a persona that spent weeks cultivating trust on WhatsApp, linking to a shortcut file that installs a backdoor controlled through Telegram - and find, after their organization's IT team resets their password, that the attacker is still inside. That is the precise threat the Islamic Revolutionary Guard Corps Intelligence Organization is running right now, documented in a July 21 DarkAtlas threat intelligence report and independently corroborated by Israel's National Digital Agency, whose own SpearSpecter research was first published in November 2025.
Get the full story
Sign up for Headlinne to unlock AI insights, political bias analysis, and your personalized news feed.
Create free accountAlready have an account? Sign in