/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Google Threat Analysis Group says it tracks 270+ state-backed threat actors, and sent 50K+ alerts for email phishing attacks to Gmail users in 2021, up ~33% YoY

The Google Threat Analysis Group said today that its security researchers are currently tracking more than 270 different … Source: The Keyword .

The Record Catalin Cimpanu

Context & Ripple Effects

Google had already reported 40,000 nation-state phishing or malware warnings in 2019, even as impersonation of journalists and news outlets was increasing. The 2021 alert count therefore marks a reversal from that earlier decline and a larger operating burden for Gmail's targeted-attack defenses.

The threat mix was also becoming more tailored: TAG had identified Indian hack-for-hire activity spoofing WHO Gmail accounts and later detailed a North Korean campaign aimed at security researchers. Tracking more than 270 state-backed groups puts the alert increase in the context of a broad, persistent targeting ecosystem.

First-order effects

  • Gmail users received more than 50,000 warnings about state-backed phishing in 2021, while Google's Threat Analysis Group had to track and attribute activity across more than 270 threat actors.
  • Targeted phishing campaigns against Gmail users faced faster exposure to intended recipients through Google's warning system, rather than relying solely on victims recognizing a spoofed message.

Second-order effects

  • The rise in alerts increases pressure on state-linked and hack-for-hire operators to vary impersonation tactics, as prior TAG reporting had already documented both institutional-account spoofing and researcher-targeting lures.
  • Organizations whose staff use Gmail face a larger stream of high-risk warnings, making user response and internal incident handling a more important complement to Google's detection.

Third-order effects

  • The combined record points to state-backed intrusion groups maintaining multiple access paths: phishing remains active alongside the later pattern in which espionage actors account for a large share of zero-day exploits observed in the wild.
  • If that pattern persists, email providers' security role shifts further from filtering mass spam to continuously disrupting tailored campaigns run by state and commercial surveillance-linked operators.

The trend: State-linked intrusion activity is becoming a sustained, multi-vector defense problem for large communication platforms, combining tailored phishing with increasingly sophisticated exploit use.

Discussion

  • @iranintl_en @iranintl_en on x
    In a new blog post today, Google discusses the activities of APT35, an #Iran hacking group, which regularly conducts phishing campaigns targeting high risk users. https://blog.google/...
  • @royalhansen Royal Hansen on x
    Latest research out from @google TAG explores some of the most notable campaigns they've disrupted from government-backed attacker: APT35, an Iranian group, which regularly conducts phishing campaigns on high risk users Read more: https://blog.google/...
  • @profwoodward Alan Woodward on x
    The Russians group Fancy Bear has been busy - worth a read from @iblametom on the increase in warnings being issues to those being targeted. https://twitter.com/...
  • @jennamc_laugh Jenna McLaughlin on x
    As someone who has tried to register for some high-level conferences with pretty terrible websites/user interfaces to begin with, these kinds of lures from Iran Google discovered are pretty troubling: https://blog.google/...
  • @iblametom Thomas Brewster on x
    Google has a new report out on an Iranian hacking group, APT35. Notes at the top that it's sent 50,000 warnings to people about being possible targets of government hacking campaigns, mostly because of Fancy Bear (Russia). https://blog.google/...
  • @shanehuntley Shane Huntley on x
    New TAG post on Countering Threats from Iran https://blog.google/... Aim is to provide some new details on what Ajax and the team discovered and blocked from APT35 (also known as Rocket Kitten and some other names)
  • @campuscodi Catalin Cimpanu on x
    Google says it tracks 270 state-sponsored groups based across 50+ countries (groups cover both cyber-espionage and disinformation campaigns) https://therecord.media/... https://twitter.com/...