Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Government

US Agencies Warn Political Campaigns of Iranian Phishing Attacks

CISA and the FBI have issued a warning on Iranian phishing attacks targeting national political organizations and campaigns.

Iranian hacker

The US cybersecurity agency CISA and the FBI have issued a warning about Iranian threat actors targeting and breaking into the email accounts of individuals associated with national political entities.

Aiming to stir up conflict and undermine confidence in the US democracy, threat actors linked to the Iranian Government’s Islamic Revolutionary Guard Corps (IRGC) have been targeting government officials, activists, journalists, think tank personnel, and lobbyists, the agencies say in a joint advisory.

“IRGC actors seek access to American personal and business accounts using social engineering techniques that target email and chat applications,” it added.

The adversaries were seen impersonating known individuals, sending requests for interviews, invites for high-profile events, and solicitations from US campaigns and elections to deceit the intended victims into accessing a spoofed email login page.

The phishing page prompts victims to enter their usernames and passwords, which are harvested by the threat actors and used to access their accounts.

“Although we have not seen this actor do so, some nation-state actors use generative artificial intelligence capabilities to increase the believability of social engineering efforts,” the agencies said.

Advertisement. Scroll to continue reading.

Organizations and individuals at risk of such phishing attempts are advised to enhance their security and resilience, and CISA and the FBI have provided mitigation recommendations, such as using phishing-resistant multi-factor authentication (MFA).

Entities associated with national political campaigns and elections are advised to be wary of unsolicited contacts from unknown individuals or people claiming to use new accounts or phone numbers, unusual emails from known individuals, accounts delivering links or files via social media, emails conveying suspicious alerts, and unsolicited messages containing shortened links.

In addition to using phishing-resistant MFA for all accounts, at-risk individuals are urged to use password manager, refrain from clicking on links in emails, chat messages, or social media alerts, and ensure OS and applications are fully patched.

Related: US Charges 3 Iranians Over Presidential Campaign Hacking

Related: Iran Behind Text Messages Calling for Revenge Over Quran Burnings

Related: False Air Raid Sirens Possibly Triggered by Iranian Cyberattack

Written By

Ionut Arghire is an international correspondent for SecurityWeek.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join this live webinar as we break down why email-layer defenses alone can't keep pace with the modern phishing ecosystem, how agentic AI is changing the capacity equation for security teams, and more.

Register

This year's summit will help organizations learn how to utilize tools, controls, and design models needed to properly secure cloud environments. Interact with leading solution providers and other end users facing similar challenges in securing a variety of cloud deployments.

Register

People on the Move

Fable Security has appointed Jacob Berry as Chief Information Security Officer.

iCOUNTER has named Ali Waezzadah as Chief Information Security Officer.

Roger Hale has joined 1Kosmos as Chief Information Security Officer.

More People On The Move

Expert Insights

Four decades of incident response experience suggest that exploits are often the symptom, not the root cause, of today’s cybersecurity failures.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.