Experts from SecureWorks discovered a large phishing campaign targeting universities. The campaign was carried out by an Iran-linked threat actor COBALT DICKENS APT. It involved sixteen domains hosting more than 300 spoofed websites for 76 universities in 14 countries, including Australia, Canada, China, Israel, Japan, Switzerland, Turkey, the United Kingdom, and the United States. Most of the websites spoofed universities online library systems, the attackers were interested in accessing those resources and gather intelligence.”]
Source: https://securityaffairs.co/wordpress/75710/cyber-warfare-2/cobalt-dickens-iran-attacks.html

