<img height="1" width="1" style="display: none" alt="" src="https://px.ads.linkedin.com/collect/?pid=1098858&amp;fmt=gif">

Iranian Hackers Target US Think Tank Experts in Sophisticated Phishing Campaign

Iranian hackers target US think tanks in 2025, using hybrid tactics and phishing to steal credentials via fake emails.
Content Team

Iranian government hackers launched targeted phishing attacks against prominent US think tanks between June and August 2025, impersonating influential policy experts like Brookings Institution's Suzanne Maloney. The mysterious group, dubbed "UNK_SmudgedSerpent" by Proofpoint researchers, sent fake collaboration emails to 20 think tank members, later directing victims to credential-stealing Microsoft 365 login pages disguised as OnlyOffice or Teams links.

What makes this campaign unusual is how it blends tactics from multiple known Iranian hacking groups. The phishing approach mirrors Charming Kitten's methods, while the infrastructure resembles TA455's setup, and it's the only Iranian group besides MuddyWater known to use remote monitoring software. This hybrid approach suggests possible reorganization, collaboration, or resource-sharing between Iran's cyber units.

Source: Dark Reading

Share this article
Share on facebook Share on linkedin Share on twitter Share on email
blog_book_a_demo_cta_3x
Have questions about protecting your software?
Our escrow experts are standing by to help.
Book a free demo