A previously unidentified threat group, dubbed UNK_SmudgedSerpent, conducted a series of targeted phishing attacks against U.S.-based academics and foreign policy experts between June and August 2025. The campaign coincided with heightened Iran–Israel tensions and leveraged lures related to Iranian domestic politics and the Islamic Revolutionary Guard Corps (IRGC). Attackers impersonated prominent U.S. foreign policy figures, including those from think tanks such as the Brookings Institution and the Washington Institute, to increase the credibility of their phishing attempts. The emails often initiated benign conversations before escalating to credential phishing, sometimes delivering malicious URLs disguised as Microsoft Teams installers that ultimately deployed legitimate Remote Monitoring and Management (RMM) tools like PDQ Connect.
Proofpoint researchers noted that the tactics, techniques, and procedures (TTPs) used by UNK_SmudgedSerpent overlapped with those of established Iranian APTs, including TA453 (Charming Kitten), TA455 (Smoke Sandstorm), and TA450 (MuddyWater), but the precise attribution remains unclear. The group targeted over 20 subject matter experts focused on Iran policy, with some attacks involving additional social engineering steps such as identity verification requests. The campaign highlights the evolving sophistication of Iranian cyber espionage efforts and the persistent targeting of individuals shaping U.S. policy on Iran.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
On November 5, 2025, Proofpoint published research on UNK_SmudgedSerpent, describing the campaign and assessing that its tactics and infrastructure overlapped with multiple Iranian-aligned groups including TA453, TA455, and TA450. Because of the mixed indicators, Proofpoint said attribution remained low confidence and kept the activity tracked as a distinct cluster.
Proofpoint reported that it did not observe further email campaign activity from UNK_SmudgedSerpent after early August 2025. The company noted, however, that related operations may have continued beyond the visible email activity.
In at least some cases during the June-August 2025 operation, when credential theft appeared unsuccessful or was suspected, the actor shifted to malware delivery. Victims were sent archives or MSI installers disguised as collaboration software that installed legitimate remote monitoring and management tools including PDQ Connect, followed in some cases by ISL Online for suspected hands-on-keyboard access.
During the campaign, the threat actor impersonated prominent U.S. foreign policy figures and think-tank affiliations in benign-looking email exchanges that evolved into phishing. Victims were sent OnlyOffice, Microsoft Teams, or Microsoft 365-themed links leading to customized credential-harvesting pages for Microsoft accounts.
Between June and August 2025, a previously unidentified threat cluster tracked by Proofpoint as UNK_SmudgedSerpent conducted targeted cyber-espionage activity against U.S. think tanks, academics, and foreign policy experts. The lures focused on Iran-related topics amid heightened Iran–Israel tensions.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
thehackernews.com
Open sourcedarkreading.com
Open sourceproofpoint.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.