Iran-linked APT42 has expanded its targeted espionage activity through the SpearSpecter campaign, using personalized social-engineering lures against senior government and defense officials and, in some cases, their family members.
The campaign combines long-running WhatsApp conversations, trusted cloud services, credential theft, and the modular TAMECAT PowerShell backdoor.
APT42, also tracked in some reporting as TA453, is known for targeted phishing and identity-focused espionage rather than broad malware spam.
The group builds believable personas, impersonates researchers or event organizers, and communicates with victims through personal email, corporate email, and WhatsApp before sending a lure.
SpearSpecter shows how this approach has evolved. Operators first establish trust through professional invitations, conference documents, or interview requests.
Victims may then receive either a credential-harvesting page or a malicious document chain designed to install TAMECAT.
SpearSpecter Deploys TAMECAT Lures
The malware delivery flow abuses the Windows search-ms protocol handler to open Explorer and display attacker-controlled files hosted through WebDAV.
The victim is prompted to approve opening Windows Explorer, after which the system connects to a remote WebDAV location. A PDF-themed .lnk shortcut is then presented as if it were a legitimate document.
When opened, the shortcut can launch cmd.exe, download a batch loader, and execute obfuscated PowerShell payloads, often while displaying a benign decoy document to reduce suspicion.

.lnk file presented as a PDF after Explorer connects to the attacker-controlled WebDAV share (Source: darkatlas)This chain creates several strong detection opportunities.
Security teams should correlate browser activity involving search-ms, rundll32.exe invoking davclnt.dll, DavSetCookie, remote WebDAV paths, .lnk execution, cmd.exe, curl.exe, and follow-on PowerShell activity.
Elastic specifically highlights remote WebDAV execution, suspicious process lineage, and @SSL or DavWWWRoot paths as useful hunting signals
TAMECAT is a PowerShell-based backdoor associated with APT42 that supports command execution and modular data collection.
Reported capabilities include system discovery, browser credential and cookie theft, screenshot capture, Outlook mailbox collection, file staging, and exfiltration through multiple command-and-control channels.
The browser-collection capability presents a serious identity risk.
TAMECAT can reportedly use Microsoft Edge remote debugging to retrieve browser data and may suspend Chrome to access locked browser databases, making a password reset alone insufficient after a confirmed endpoint compromise.

Incident responders should revoke active sessions and refresh tokens, investigate browser-stored credentials, review OAuth grants, and examine mailbox forwarding rules alongside resetting passwords.
This is especially important for high-risk users whose personal accounts may be used for official communications, darkatlas said.
APT42 also relies on legitimate services and common platforms to blend into normal traffic. Its operations have used cloud-hosted lures and low-footprint tooling, so blocking a single platform or hash is unlikely to stop the campaign reliably.
SpearSpecter’s main advantage is not a completely new implant. It is APT42’s ability to combine patient relationship-building, credible cloud-hosted content, identity theft, and selective fileless malware into a single intrusion path.
Prevent critical incidents and financial loss with stronger proactive defense. Integrate a live threat feed from 15K SOCs