logo

TA453__2021__BadBlood_TA453_Targets_US_and_Israeli_Medical_Research_Personnel_in_Credential_Phishing_Campaigns_Proofpoint_US.pdf

ID: f1d423f8-bae4-43af-a8ec-87f253a5d5bb

STIX ID: report--f1d423f8-bae4-43af-a8ec-87f253a5d5bb

Threat Score

70/100

Uploaded: 2026-08-19

Published Date: 2021-04-01

Last Modified Date: 2021-04-01

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Proofpoint describes the BadBlood campaign by the Iranian-nexus TA453 threat actor targeting senior medical researchers in the US and Israel with credential phishing via actor-controlled domains and fake Microsoft login pages; successful harvesting of credentials could enable account compromise and potential inbox exfiltration, with references to related infrastructure and attribution suggesting IRGC-aligned operations and evolving targeting toward the medical sector.