APT 42, an Iranian-linked group also known as TA453, has enhanced its TAMECAT backdoor using AI for spear-phishing targeting notable figures in defense, government, and the nuclear sector. Their techniques include social engineering through believable personas and fraudulent document links. Recent analysis from DarkAtlas reveals TAMECAT's capabilities, allowing it to extract sensitive information like browser cookies and Outlook mail accounts.
The integration of generative AI in their methods has improved language quality, making traditional indicators of phishing less reliable. This campaign marks a shift from mass phishing to highly targeted efforts, and U.S. authorities have already charged several related operatives.