⤷ Title: Iran APT SpearSpecter Uses Weeks-Long WhatsApp Lures and Fileless TAMECAT Backdoor to Hit Defense
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 18 Nov 2025 00:30:42 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #APT42 #Cloudflare C2 #fileless backdoor #IRGC_IO #SpearSpecter #TAMECAT #WebDAV Abuse #WhatsApp Espionage
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 18 Nov 2025 00:30:42 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #APT42 #Cloudflare C2 #fileless backdoor #IRGC_IO #SpearSpecter #TAMECAT #WebDAV Abuse #WhatsApp Espionage
Daily CyberSecurity
Iran APT SpearSpecter Uses Weeks-Long WhatsApp Lures and Fileless TAMECAT Backdoor to Hit Defense
Israel disclosed SpearSpecter: an IRGC-IO espionage campaign using weeks-long WhatsApp social engineering and search-ms/WebDAV abuse to deploy the fileless TAMECAT PowerShell backdoor with Discord/Telegram C2.