Iranian Cyber Spies Unleash New Phishing Frenzy on U.S. Political Campaigns

Iranian threat group GreenCharlie has been linked to new network infrastructure targeting U.S. political campaigns. Leveraging dynamic DNS providers and social engineering, they employ phishing domains with themes like “cloud” and “doceditor.” GreenCharlie’s malware arsenal includes POWERSTAR and GORBLE, with ongoing operations obscured by Proton VPN and Proton Mail.

Pro Dashboard

Hot Take:

Iranian cyber actors are back at it, and they’re not just playing around—they’re conducting sophisticated, multi-stage phishing attacks. But hey, maybe they’re just really passionate about cloud services and document sharing? Someone needs to tell them there’s an easier way to get free storage space!

Key Points:

  • GreenCharlie, an Iranian threat group, is linked to recent phishing campaigns targeting U.S. political campaigns.
  • The group uses dynamic DNS providers to register domains with themes like “cloud” and “doceditor” to lure victims.
  • They predominantly use the .info top-level domain now, a shift from previous choices like .xyz and .online.
  • Malware like POWERSTAR, GORBLE, and TAMECAT are deployed in these attacks, often through social engineering techniques.
  • Recorded Future’s findings indicate a large number of DDNS domains registered since May 2024, with connections to Iran-based IP addresses.

Membership Required

 You must be a member to access this content.

View Membership Levels
Already a member? Log in here
The Nimble Nerd
Confessional Booth of Our Digital Sins

Okay, deep breath, let's get this over with. In the grand act of digital self-sabotage, we've littered this site with cookies. Yep, we did that. Why? So your highness can have a 'premium' experience or whatever. These traitorous cookies hide in your browser, eagerly waiting to welcome you back like a guilty dog that's just chewed your favorite shoe. And, if that's not enough, they also tattle on which parts of our sad little corner of the web you obsess over. Feels dirty, doesn't it?