APT42 Lures Targets With Podcast Invites

The Hacker News · High sophistication
Last updated August 18, 2026

Researchers report Iranian-linked APT groups using legitimate cloud services to hide command-and-control traffic, and separately running spear-phishing campaigns. In the phishing cases, attackers used credible “podcast” or “interview invitation” themes to persuade targets to open a Windows shortcut (LNK) disguised as a PDF, leading to installation of the TAMECAT spying toolkit.

How the attack worked

According to DarkAtlas reporting, APT42 ran a spear-phishing campaign in April and May 2026 that targeted individuals associated with the nuclear energy sector. The lure was a podcast or interview invitation, a pretext designed to feel like a normal professional opportunity rather than an attack. Targets included nuclear energy staff, researchers, engineers, and executives.

The email carried an attachment presented as a PDF invitation. In reality, the file was a Windows shortcut (LNK), a format that can execute commands when opened. Clicking the attachment led to installation of the TAMECAT surveillance framework, giving the attacker a foothold for further activity.

Why it succeeded

The lure worked because it leaned on a routine, low-suspicion scenario. A podcast or interview request from someone claiming to be a host or journalist does not automatically raise alarms, especially for staff who are accustomed to being asked to speak publicly about their work. The pretext gave a plausible reason to open an attachment quickly, and the file's disguise as a PDF reduced the chance that a recipient would question its true format before opening it.

This fits a broader pattern described in the reporting: threat actors abusing legitimate-looking channels, whether that is a believable professional request or, in related campaigns, legitimate cloud services used to mask command-and-control traffic. In both cases, the surface appearance of normalcy is what lowers a target's guard.

What to watch for

  • Unsolicited invitations to appear on a podcast, give an interview, or speak at an event, particularly when they arrive with an attachment.
  • Attachments that claim to be PDFs but are actually Windows shortcut (LNK) files.
  • Pressure, explicit or implicit, to open a file quickly to see interview details or questions.
  • Sender identities for these invitations that have not been verified through an independent channel, such as a known contact or the organization's own website.

How to build resistance

  • Treat unsolicited professional opportunities, including podcast and interview requests, as higher risk until the sender is verified independently.
  • Configure mail and endpoint controls to block or strongly flag LNK attachments, especially when they are disguised as other file types like PDFs.
  • Train staff, particularly those in visible or research-facing roles, to pause before opening attachments tied to unexpected outreach, even when the request looks professional and credible.
  • Reinforce that normal-looking traffic or a legitimate-seeming request is not proof of safety, since attackers deliberately design lures and infrastructure to blend in with routine activity.

Key findings

  • Kaspersky described Cavern/CAV3RN C2 communications that can switch between direct HTTPS and a Google Apps Script relay based on DNS A-record responses.
  • Group-IB described HOLLOWGRAPH using Microsoft 365 calendar events as a covert “dead-drop” channel, with events dated far in the future to avoid notice.
  • DarkAtlas reported APT42 spear-phishing in April–May 2026 targeting people linked to the nuclear energy sector, using “podcast and interview invitations.”
  • Those phishing emails delivered LNK files disguised as PDF documents, ultimately installing the TAMECAT surveillance framework.

Who’s being targeted

  • Commonly targeted roles: Executives, Engineering, Research staff, Energy/nuclear operations, Administrative assistants, IT helpdesk.
  • Affected industries: Nuclear energy sector, Government, Defense, Critical infrastructure.
  • Attack channels: email.
  • Impersonated: Podcast host / journalist / conference interviewer.

Red flags to watch for

  • Attachment is a Windows shortcut (LNK) pretending to be a PDF
  • Unexpected interview/podcast request that pushes you to open a file
  • Sender identity not independently verified
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

What pretext did APT42 use in these phishing attacks?

APT42 used podcast and interview invitations as a social-engineering theme, presenting the request as a credible professional engagement before delivering malware.

How did the malicious file try to evade detection?

The attackers sent Windows shortcut (LNK) files disguised as PDF documents, which if opened led to installation of the TAMECAT surveillance framework.

Who was targeted in this campaign?

DarkAtlas reported that APT42 targeted individuals associated with the nuclear energy sector between April and May 2026, including researchers, engineers, and executives.

Why is normal-looking network traffic not a reliable safety signal?

Attackers can hide command-and-control traffic behind legitimate services like calendar events or cloud scripting platforms, making it blend in with normal activity and complicating detection.

Read the video transcript

You get an email: a podcast wants to interview you about your work. Sounds flattering, right? APT42 is sending these fake podcast and interview invites. The 'PDF' they attach is actually a Windows shortcut, an LNK file that installs their TAMECAT spying toolkit. Here’s the trap: the invite looks professional, the traffic looks like normal cloud use, but the attachment type gives it away. A '.lnk' file pretending to be 'something.pdf' is the red flag. If you get an unsolicited podcast or interview invite with a 'PDF' attached, stop. Don’t open it. Forward it to security and ask them to check the file type.

Similar attacks

Phishing PDF Drops Malware Via Fake Edge Loader

Phishing PDF Drops Malware Via Fake Edge Loader

Researchers describe BraZetsu, a Windows malware framework used by an initial-access broker to turn infected PCs into "access for sale" on a criminal marketplace. While the malware itself is technical, the article includes real-world delivery details pointing to phishing: victims are tricked into…

September 3, 2026
Fake Freelancer Accounts Pushed Malicious Excel Macros

Fake Freelancer Accounts Pushed Malicious Excel Macros

U.S. prosecutors say a Russian national used hundreds of fake accounts on a freelance platform to send Excel files that tricked users into enabling macros, which then downloaded remote-control malware. The campaign targeted tens of thousands of users and led to thousands of infections, enabling…

September 2, 2026
Job Offer & Doc-Link Phishing Drive Real Breaches

Job Offer & Doc-Link Phishing Drive Real Breaches

This weekly threat bulletin describes real incidents where attackers used human manipulation to break in, including social engineering at Levi Strauss and a Microsoft 365 credential-theft phish at defense supplier IEH. It also highlights a Lazarus-linked campaign using fake job offers and…

August 17, 2026
Fake Recruiter Lure Drops NodeRabbit RAT

Fake Recruiter Lure Drops NodeRabbit RAT

Researchers tied Mirage Kitten to a job-recruiting scam that targets developers via LinkedIn and job platforms. Victims are sent a “technical assessment” ZIP file hosted on legitimate cloud storage; running the project silently installs a remote-access trojan (NodeRabbit) that lets attackers…

September 1, 2026
Fake Recruiters & Cloud Email Fuel New Phishing

Fake Recruiters & Cloud Email Fuel New Phishing

This roundup describes real-world social engineering where attackers impersonate recruiters on LinkedIn and lure developers into running “coding tests” that install malware. It also outlines active phishing campaigns that abuse trusted cloud services (Google, AWS, Azure, Cloudflare) to send…

September 2, 2026
SilkParasite Hits Central Asia via Phish Docs

SilkParasite Hits Central Asia via Phish Docs

Bitdefender reports a China-linked espionage campaign (“SilkParasite”) targeting government bodies in Central Asia using spearphishing emails carrying malicious Microsoft Office documents. The malware is designed to stay quiet and blend in, including using Google Drive as a communications channel…

August 20, 2026