Google says it has found Iranian hackers hitting top US presidential election targets

Google's Mountain View headquarters
(Image credit: Shutterstock / Michael Vi)

Google has issued a warning about Iranian threat actors targeting the US presidential elections.

Following earlier research from Microsoft lifting the lid on similar threats, Google has now published an intelligence report showing that a threat actor tracked as APT42 has targeted a number of organizations related to the US presidential election.

Article continues below

APT42 targeting US elections

APT42 has connections to the Islamic Revolutionary Guard Corps (IRGC), and has launched a number of social engineering campaigns using fake pages that disguise themselves as the Jewish Agency for Israel calling for a ceasefire. APT42 has also targeted a number of military, defense, diplomatic, academic, and civil targets with phishing campaigns for credential theft.

In the US however, APT42 has targeted both the Trump and Biden campaigns in phishing attacks aimed at the personal email accounts of many former US government and campaign officials. Several of these attacks were successful, including one against a high-profile political consultant.

These phishing campaigns have not ceased, and Google states that it is seeing continued unsuccessful attacks against individuals related to President Biden, Vice-President Kamala Harris, and former president Donald Trump.

APT42 has been observed using tactics such as identifying accounts that use Device Prompts for two-factor authentication, and then use login or account recovery attempts spoofed to appear in the same geographic location alongside their credentials to appear as an authentic second factor prompt.

Google recommends high-risk individuals, including elected officials, candidates, campaign workers, journalists, election workers, government officials, should sign up to Google’s Advanced Protection Program, which provides free additional protection measures against phishing and unauthorized access.

More from TechRadar Pro

TOPICS
Benedict Collins
Senior Writer, Security

Benedict is a Senior Security Writer at TechRadar Pro, where he has specialized in covering the intersection of geopolitics, cyber-warfare, and business security.

Benedict provides detailed analysis on state-sponsored threat actors, APT groups, and the protection of critical national infrastructure, with his reporting bridging the gap between technical threat intelligence and B2B security strategy.

Benedict holds an MA (Distinction) in Security, Intelligence, and Diplomacy from the University of Buckingham Centre for Security and Intelligence Studies (BUCSIS), with his specialization providing him with a robust academic framework for deconstructing complex international conflicts and intelligence operations, and the ability to translate intricate security data into actionable insights.