TA453
Attribution profile
STIX characteristics
Threat actor characteristics are available to members.
Profile narrative
TA453, also tracked as Seaborgium, is described by Proofpoint as an Iranian state‑aligned actor that operates with high confidence in support of the Islamic Revolutionary Guard Corps’ intelligence collection efforts. The group’s known aliases include TA453 and Seaborgium. Its targeting focuses on senior personnel at think tanks, journalists who specialize in Middle Eastern affairs, and professors at academic institutions. The stated objective of these operations is to gather intelligence of interest to the Iranian government. Attribution to the IRGC’s intelligence mission is based on observed TTP similarities and targeting patterns.
The actor’s typical approach begins with posing as a British scholar affiliated with the School of Oriental and African Studies (SOAS) at the University of London, using email addresses such as [email protected] and [email protected] to initiate contact. In these messages the actor offers invitations to online conferences on topics like US security challenges in the Middle East and often asks for the target’s mobile phone number or proposes a videoconference. After establishing rapport, the actor sends a personalized link that appears to be a registration link for a webinar control panel hosted on a legitimate but compromised website, specifically soasradio.org/connect/?memberemailid= followed by the target’s initials and a random string. The compromised site hosts a credential‑harvesting page that mimics a legitimate login service, representing a shift from the actor’s historical reliance on attacker‑controlled phishing sites. By leveraging a trusted academic domain, the actor increases the likelihood that targets will trust the link and enter their credentials. The collected mobile numbers are noted as a possible avenue for follow‑on mobile‑based phishing or malware delivery.
The activity described above was documented by Proofpoint in a campaign dubbed Operation SpoofedScholars, which began at least as early as January 2021 and involved sustained email conversations with individuals of intelligence interest to Iran. Unlike earlier tactics that relied on domains directly controlled by the actor, this operation used a compromised legitimate academic site to host the phishing infrastructure, indicating an evolution in tradecraft. The campaign’s focus on gathering credentials from academics, journalists, and think‑tank experts aligns with the broader goal of supporting IRGC intelligence collection. Proofpoint highlighted specific indicators such as traffic to soasradio.org and messages from the identified Gmail accounts as mitigation points for defenders. No public attribution to a criminal syndicate or financial motive has been made; the activity is consistently linked to state‑aligned espionage.
Incidents
Attributed incidents are available to members.
0 incidents