Researchers report Iranian-linked APT groups using legitimate cloud services to hide command-and-control traffic, and separately running spear-phishing campaigns. In the phishing cases, attackers used credible “podcast” or “interview invitation” themes to persuade targets to open a Windows shortcut (LNK) disguised as a PDF, leading to installation of the TAMECAT spying toolkit.
How the attack worked
According to DarkAtlas reporting, APT42 ran a spear-phishing campaign in April and May 2026 that targeted individuals associated with the nuclear energy sector. The lure was a podcast or interview invitation, a pretext designed to feel like a normal professional opportunity rather than an attack. Targets included nuclear energy staff, researchers, engineers, and executives.
The email carried an attachment presented as a PDF invitation. In reality, the file was a Windows shortcut (LNK), a format that can execute commands when opened. Clicking the attachment led to installation of the TAMECAT surveillance framework, giving the attacker a foothold for further activity.
Why it succeeded
The lure worked because it leaned on a routine, low-suspicion scenario. A podcast or interview request from someone claiming to be a host or journalist does not automatically raise alarms, especially for staff who are accustomed to being asked to speak publicly about their work. The pretext gave a plausible reason to open an attachment quickly, and the file's disguise as a PDF reduced the chance that a recipient would question its true format before opening it.
This fits a broader pattern described in the reporting: threat actors abusing legitimate-looking channels, whether that is a believable professional request or, in related campaigns, legitimate cloud services used to mask command-and-control traffic. In both cases, the surface appearance of normalcy is what lowers a target's guard.
What to watch for
- Unsolicited invitations to appear on a podcast, give an interview, or speak at an event, particularly when they arrive with an attachment.
- Attachments that claim to be PDFs but are actually Windows shortcut (LNK) files.
- Pressure, explicit or implicit, to open a file quickly to see interview details or questions.
- Sender identities for these invitations that have not been verified through an independent channel, such as a known contact or the organization's own website.
How to build resistance
- Treat unsolicited professional opportunities, including podcast and interview requests, as higher risk until the sender is verified independently.
- Configure mail and endpoint controls to block or strongly flag LNK attachments, especially when they are disguised as other file types like PDFs.
- Train staff, particularly those in visible or research-facing roles, to pause before opening attachments tied to unexpected outreach, even when the request looks professional and credible.
- Reinforce that normal-looking traffic or a legitimate-seeming request is not proof of safety, since attackers deliberately design lures and infrastructure to blend in with routine activity.
Key findings
- Kaspersky described Cavern/CAV3RN C2 communications that can switch between direct HTTPS and a Google Apps Script relay based on DNS A-record responses.
- Group-IB described HOLLOWGRAPH using Microsoft 365 calendar events as a covert “dead-drop” channel, with events dated far in the future to avoid notice.
- DarkAtlas reported APT42 spear-phishing in April–May 2026 targeting people linked to the nuclear energy sector, using “podcast and interview invitations.”
- Those phishing emails delivered LNK files disguised as PDF documents, ultimately installing the TAMECAT surveillance framework.
Who’s being targeted
- Commonly targeted roles: Executives, Engineering, Research staff, Energy/nuclear operations, Administrative assistants, IT helpdesk.
- Affected industries: Nuclear energy sector, Government, Defense, Critical infrastructure.
- Attack channels: email.
- Impersonated: Podcast host / journalist / conference interviewer.
Red flags to watch for
- Attachment is a Windows shortcut (LNK) pretending to be a PDF
- Unexpected interview/podcast request that pushes you to open a file
- Sender identity not independently verified
Frequently asked questions
What pretext did APT42 use in these phishing attacks?
APT42 used podcast and interview invitations as a social-engineering theme, presenting the request as a credible professional engagement before delivering malware.
How did the malicious file try to evade detection?
The attackers sent Windows shortcut (LNK) files disguised as PDF documents, which if opened led to installation of the TAMECAT surveillance framework.
Who was targeted in this campaign?
DarkAtlas reported that APT42 targeted individuals associated with the nuclear energy sector between April and May 2026, including researchers, engineers, and executives.
Why is normal-looking network traffic not a reliable safety signal?
Attackers can hide command-and-control traffic behind legitimate services like calendar events or cloud scripting platforms, making it blend in with normal activity and complicating detection.
Read the video transcript
You get an email: a podcast wants to interview you about your work. Sounds flattering, right? APT42 is sending these fake podcast and interview invites. The 'PDF' they attach is actually a Windows shortcut, an LNK file that installs their TAMECAT spying toolkit. Here’s the trap: the invite looks professional, the traffic looks like normal cloud use, but the attachment type gives it away. A '.lnk' file pretending to be 'something.pdf' is the red flag. If you get an unsolicited podcast or interview invite with a 'PDF' attached, stop. Don’t open it. Forward it to security and ask them to check the file type.