The Iran-affiliated APT known as Charming Kitten is back with a new approach, impersonating Persian-speaking journalists via WhatsApp and LinkedIn. The targets are Israeli scholars from Haifa and Tel Aviv universities, and U.S. government employees. The end game is to convince a target to click on a malicious link, which takes users to a phishing page to steal credentials. The malicious link is embedded in a legitimate, compromised Deutsche Welle domain, with waterhole methods.
Source: https://threatpost.com/charming-kitten-whatsapp-linkedin-effort/158813/

