Skip to main content

Threats Tagged 'overlapping ttps'

View all threats tagged with 'overlapping ttps'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: overlapping ttps

Threats Tagged 'overlapping ttps'

Click on any threat for detailed analysis and mitigation recommendations

The UNK_SmudgedSerpent threat actor, likely linked to Iranian espionage efforts, targeted academics and foreign policy experts from June to August 2025 using phishing campaigns with domestic political and health-related lures. The actor employed Remote Management & Monitoring (RMM) tools and credential harvesting techniques, showing overlapping tactics with known Iranian groups such as TA455, TA453, and TA450. Although attribution is not definitive, the targeting aligns with Iranian intelligence priorities, focusing on sensitive policy and academic sectors. The campaign's medium severity reflects moderate impact potential without known exploits in the wild. European organizations involved in foreign policy, academia, and research are at risk, especially in countries with strong diplomatic ties or geopolitical interest in Iran. Mitigation requires targeted user awareness, strict monitoring of RMM tool usage, and enhanced email filtering tuned to political and health-themed lures. Countries like Germany, France, the UK, Italy, and the Netherlands are most likely affected due to their active academic communities and diplomatic engagement with Iran. The threat's medium severity is due to its espionage focus, moderate ease of exploitation via phishing, and the absence of widespread destructive payloads or zero-day exploits. Defenders should prioritize detection of credential harvesting and suspicious RMM activity while maintaining vigilance for evolving Iranian espionage tactics.

Join the discussion

Showing 1 to 1 of 1 result

Filters:Tag: overlapping ttps
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses