TA453__2021__BadBlood_TA453_Targets_US_and_Israeli_Medical_Research_Personnel_in_Credential_Phishing_Campaigns_Proofpoint_US.pdf
ID: f1d423f8-bae4-43af-a8ec-87f253a5d5bb
STIX ID: report--f1d423f8-bae4-43af-a8ec-87f253a5d5bb
Threat Score
70/100
Uploaded: 2026-08-19
Published Date: 2021-04-01
Last Modified Date: 2021-04-01
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Proofpoint describes the BadBlood campaign by the Iranian-nexus TA453 threat actor targeting senior medical researchers in the US and Israel with credential phishing via actor-controlled domains and fake Microsoft login pages; successful harvesting of credentials could enable account compromise and potential inbox exfiltration, with references to related infrastructure and attribution suggesting IRGC-aligned operations and evolving targeting toward the medical sector.
