PULSE NAME
Crossed wires: a case study of Iranian espionage and attribution
WHITE UNK_SmudgedSerpent AlienVault 2025-11-05 Modified: 2025-11-05
58
IOCs
HIGH VOLUME
This analysis examines a newly identified threat actor dubbed UNK_SmudgedSerpent that targeted academics and foreign policy experts between June and August 2025. The actor used domestic political lures related to Iran, benign conversation starters, health-themed infrastructure, and Remote Management & Monitoring tools. The investigation revealed overlapping tactics with several Iranian threat groups, including TA455, TA453, and TA450. While attribution remains uncertain, the targeting and techniques align with Iranian intelligence priorities. The analysis explores possible explanations for the convergence of tactics, such as shared resources, personnel mobility, or collaboration between Iranian agencies.
Indicators of Compromise (1 / 58 total)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256 domain hostname
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 f63ceb9f6b3a28b6858976e5549d3247 2025-11-05