Get all your news in one place.
100’s of premium titles.
One app.
Start reading
TechRadar
TechRadar
Benedict Collins

Google says it has found Iranian hackers hitting top US presidential election targets

Google's Mountain View headquarters.

Google has issued a warning about Iranian threat actors targeting the US presidential elections.

Following earlier research from Microsoft lifting the lid on similar threats, Google has now published an intelligence report showing that a threat actor tracked as APT42 has targeted a number of organizations related to the US presidential election.

The report claims 60% of the attacks from APT42 have targeted Israel and the US over the past six months, including phishing attacks and social engineering to compromise Gmail accounts of high-profile individuals.

APT42 targeting US elections

APT42 has connections to the Islamic Revolutionary Guard Corps (IRGC), and has launched a number of social engineering campaigns using fake pages that disguise themselves as the Jewish Agency for Israel calling for a ceasefire. APT42 has also targeted a number of military, defense, diplomatic, academic, and civil targets with phishing campaigns for credential theft.

In the US however, APT42 has targeted both the Trump and Biden campaigns in phishing attacks aimed at the personal email accounts of many former US government and campaign officials. Several of these attacks were successful, including one against a high-profile political consultant.

These phishing campaigns have not ceased, and Google states that it is seeing continued unsuccessful attacks against individuals related to President Biden, Vice-President Kamala Harris, and former president Donald Trump.

APT42 has been observed using tactics such as identifying accounts that use Device Prompts for two-factor authentication, and then use login or account recovery attempts spoofed to appear in the same geographic location alongside their credentials to appear as an authentic second factor prompt.

Google recommends high-risk individuals, including elected officials, candidates, campaign workers, journalists, election workers, government officials, should sign up to Google’s Advanced Protection Program, which provides free additional protection measures against phishing and unauthorized access.

More from TechRadar Pro

Sign up to read this article
Read news from 100’s of titles, curated specifically for you.
Already a member? Sign in here
Related Stories
Top stories on inkl right now
Our Picks
Fourteen days free
Download the app
One app. One membership.
100+ trusted global sources.