Iranian Spies Now Use AI Lures, Telegram C2, and a Backdoor That Survives Password Resets

Iranian state-sponsored hackers, known as APT42, are utilizing generative AI to create highly convincing spear-phishing lures. These sophisticated attacks bypass traditional security measures by maintaining persistent access even after password resets.
Why it matters
The integration of AI into state-sponsored cyber warfare significantly lowers the barrier for effective social engineering, making traditional phishing detection methods obsolete.
A senior defense official who gets a conference invitation this week might receive a message written by a human operator and polished by a language model, sent from a persona that spent weeks cultivating trust on WhatsApp, linking to a shortcut file that installs a backdoor controlled through Telegram - and find, after their organization's IT team resets their password, that the attacker is still inside. That is the precise threat the Islamic Revolutionary Guard Corps Intelligence Organization is running right now, documented in a July 21 DarkAtlas threat intelligence report and independently corroborated by Israel's National Digital Agency, whose own SpearSpecter research was first published in November 2025.
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in