Facebook Says Iranian Hackers Targeted US, Europe Defence Workers Using Fake Accounts

Facebook said Iran-based cyber espionage rings used fake accounts posing as company job recruiters to dupe targets.

Advertisement
By Reuters | Updated: 16 July 2021 10:58 IST
Highlights
  • The group made fictitious profiles across multiple social media platforms
  • LinkedIn said it had removed a number of accounts
  • Twitter was "actively investigating" the information in Facebook's report

Facebook said the group used email, messaging, and collaboration services to distribute the malware

Facebook said on Thursday it had taken down about 200 accounts run by a group of hackers in Iran as part of a cyber-spying operation that targeted mostly US military personnel and people working at defense and aerospace companies.

The social media giant said the group, dubbed 'Tortoiseshell' by security experts, used fake online personas to connect with targets, build trust sometimes over the course of several months and drive them onto other sites where they were tricked into clicking malicious links that would infect their devices with spying malware.

"This activity had the hallmarks of a well-resourced and persistent operation, while relying on relatively strong operational security measures to hide who's behind it," Facebook's investigations team said in a blog post.

Advertisement

The group, Facebook said, made fictitious profiles across multiple social media platforms to appear more credible, often posing as recruiters or employees of aerospace and defense companies. Microsoft-owned LinkedIn said it had removed a number of accounts and Twitter said it was "actively investigating" the information in Facebook's report.

Advertisement

Facebook said the group used email, messaging, and collaboration services to distribute the malware, including through malicious Microsoft Excel spreadsheets. A Microsoft spokesperson said in a statement it was aware of and tracking this actor and that it takes action when it detects malicious activity.

Alphabet's Google said it had detected and blocked phishing on Gmail and issued warnings to its users. Workplace messaging app Slack said it had acted to take down the hackers who used the site for social engineering and shut down all Workspaces that violated its rules.

Advertisement

The hackers also used tailored domains to attract its targets, Facebook said, including fake recruiting websites for defense companies, and it set up online infrastructure that spoofed a legitimate job search website for the US Department of Labor.

Facebook said the hackers mostly targeted people in the United States, as well as some in the United Kingdom and Europe, in a campaign running since mid-2020. It declined to name the companies whose employees were targeted but its head of cyber espionage Mike Dvilyanski said it was notifying the "fewer than 200 individuals" who were targeted.

Advertisement

The campaign appeared to show an expansion of the group's activity, which had previously been reported to concentrate mostly on the I.T. and other industries in the Middle East, Facebook said. The investigation found that a portion of the malware used by the group was developed by Mahak Rayan Afraz (MRA), an IT company based in Tehran with ties to the Islamic Revolutionary Guard Corps.

Reuters could not immediately locate contact information for Mahak Rayan Afraz and former employees of the firm did not immediately return messages sent via LinkedIn. Iran's mission to the United Nations in New York did not immediately respond to a request for comment.

MRA's alleged connection to Iranian state cyber espionage is not new. Last year cybersecurity company Recorded Future said MRA was one of several contractors suspected of serving the IRGC's elite Quds Force.

Iranian government spies - like other espionage services - have long been suspected of farming out their mission to a host of domestic contractors.

Facebook said it had blocked the malicious domains from being shared and Google said it had added the domains to its "blocklist."

© Thomson Reuters 2021


What is the best phone to buy right now? We discussed this on Orbital, the Gadgets 360 podcast. Orbital is available on Apple Podcasts, Google Podcasts, Spotify, Amazon Music and wherever you get your podcasts.
Affiliate links may be automatically generated - see our ethics statement for details.
 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Further reading: Facebook, hackers, cybersecurity
Advertisement

Related Stories

Popular Mobile Brands
  1. Moto G67 Power 5G Specifications Revealed: See Storage Variants, Features
  2. This Is How You Can Get ChatGPT Go Subscription for Free
  3. Samsung Galaxy S26 Ultra Said to Get a Major Design Upgrade
  4. Samsung Galaxy S26 Series Might Be More Expensive Due to This Reason
  5. Episodic Superhero Game Dispatch Sells 1 Million Copies in 10 Days
  6. OpenAI Turns to Amazon in $38 Billion Cloud Services Deal After Restructuring
  1. Dispatch, Episodic Superhero Game Starring Breaking Bad's Aaron Paul, Sells 1 Million Copies in 10 Days
  2. Nothing Phone 3a Lite Owners Can Uninstall Meta Services After Company Faces Backlash Over Preloaded Apps
  3. Lovable Partners With Guardio to Detect and Block Malicious Websites Created via Vibe Coding
  4. Stream Finance Discloses $93 Million Loss After Probe, Halts Operations
  5. Samsung Galaxy S26 Series Price Hike Likely Due to Rising Price of Key Components: Report
  6. Hong Kong Unveils Fintech 2030 Strategy to Accelerate AI, RWA Tokenisation
  7. Raat Akeli Hai: The Bansal Murders to Release on OTT Soon: Everything You Need to Know
  8. OpenAI Faces Backlash from Studio Ghibli, Bandai Namco Over AI-Generated Anime Videos
  9. OnePlus Ace 6 Pro Max Retail Box Leak Hints at Imminent Launch, Snapdragon 8 Gen 5 SoC
  10. Nintendo Switch 2 Crosses 10 Million Units Sold, Nintendo Hikes Full-Year Sales Forecast
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.