Biden, Trump campaigns targeted by Chinese and Iranian hackers

Biden, Trump campaigns targeted by Chinese and Iranian hackers

Hackers with ties to China and Iran have targeted with spear phishing attacks the campaign staffs working on the U.S. presidential campaigns of Democrat Joe Biden and Republican President Donald Trump, according to a researcher with Google’s Threat Analysis Group.

“Recently TAG saw China APT group targeting Biden campaign staff & Iran APT targeting Trump campaign staff with phishing,” said Shane Huntley, head of Google TAG.

Huntley said that there is no sign the attacks were successful and that targeted users and law enforcement were notified about phishing attempts.

Biden’s staffers were targeted by APT31, whereas APT35 was behind the attacks aimed at Trump’s campaign.

APT31 (aka Zirconium) is a hacking group believed to be operating from China that has been active since at least 2016. The group’s target list includes foreign companies and diplomatic entities.

APT35 (aka Newscaster) is a cyber-espionage group backed by Iranian government. The group has been known to target the US and Middle Eastern militaries, diplomatic and government personnel, organizations in the media, energy and the engineering, business services, and telecommunications sectors.

“The Trump campaign has been briefed that foreign actors unsuccessfully attempted to breach the technology of our staff. We are vigilant about cybersecurity and do not discuss any of our precautions,” a Trump campaign representative said.

“We have known from the beginning of our campaign that we would be subject to such attacks and we are prepared for them,” the Biden campaign said in a statement regarding the cyber attacks.

Back to the list

Latest Posts

AI chatbots fall for phishing scams

AI chatbots fall for phishing scams

The models provided the correct URL only 66% of the time; nearly 30% of responses pointed users to dead or suspended domains.
3 July 2025
Chinese hackers exploited Ivanti flaws in attacks against French government

Chinese hackers exploited Ivanti flaws in attacks against French government

ANSSI believes that the Houken campaign is operated by ‘UNC5174’, an entity believed to act as an initial access broker for China’s Ministry of State Security.
2 July 2025
Threat actors exploit Vercel's AI tool v0 to build sophisticated phishing pages

Threat actors exploit Vercel's AI tool v0 to build sophisticated phishing pages

The malicious actors used v0.dev to create fake login pages mimicking legitimate brands.
2 July 2025