Educated Manticore
0 incidentes
0 paises
0 sectores
apt IR Ultimo: -
Educated Manticore is an Iranian-aligned threat actor, assessed to be associated with the Islamic Revolutionary Guard Corps' Intelligence Organization (IRGC-IO), formally named by Check Point in April 2023 after initial activity was observed in January 2023. This group has consistently evolved its capabilities, notably adopting rarely seen techniques such as .NET mixed-mode assemblies in its malware and employing highly adaptive, multi-channel spear-phishing campaigns to achieve its primary motivation of cyber-espionage in support of Iranian state interests. The group is distinguished by its agility in rapidly establishing and dismantling infrastructure, and its strategic focus on high-trust impersonation to target specific individuals, including academics, journalists, and cybersecurity experts, particularly those within Israel. Educated Manticore's activities overlap significantly with those attributed to other Iranian groups known as APT42, Charming Kitten, Mint Sandstorm, and Phosp