Google’s security researchers has uncovered a series of cyber activities by an Iranian government-backed group, known as APT42, that aimed at compromising the personal email accounts of individuals linked to the US presidential elections.
The targets, according to the Google, included those associated with President Biden and former President Trump, as well as other high-profile figures within the US government.
In a recent blog post, Google’s Threat Analysis Group (TAG) revealed that APT42 attempted to breach the accounts of a dozen individuals connected to the Biden and Trump campaigns during May and June. Google reported that its security measures successfully blocked many of these attempts, although some breaches across multiple email providers were confirmed, including the account of a prominent political consultant.
The company noted that in the 2020 US presidential election, it thwarted similar attempts by APT42 to infiltrate accounts associated with the major campaigns.
Who is APT42
APT42, believed to be linked to Iran’s Islamic Revolutionary Guard Corps (IRGC), is known for targeting high-profile individuals in both the United States and Israel. Their tactics typically involve phishing campaigns, which often use services like Google Drive, Dropbox, and OneDrive to deliver malware or redirect victims to malicious websites.
In response to the recent attacks, Google said it took swift action to secure compromised accounts and referred the matter to law enforcement in early July. The tech giant also provided warnings to affected individuals and campaign officials, highlighting the ongoing threat posed by foreign state actors.
APT42’s phishing campaigns extend beyond the U.S. elections. The group has consistently targeted military officials, diplomats, academics, and civil society figures, particularly in Israel. Their methods often involve sophisticated social engineering tactics, including impersonating legitimate organizations like the Washington Institute for Near East Policy and the Brookings Institution. These campaigns have been used to elicit engagement from victims before attempting to compromise their accounts.