Facebook Says Iranian Hackers Targeted US, Europe Defence Workers Using Fake Accounts

Facebook said Iran-based cyber espionage rings used fake accounts posing as company job recruiters to dupe targets.

Advertisement
By Reuters | Updated: 16 July 2021 10:58 IST
Highlights
  • The group made fictitious profiles across multiple social media platforms
  • LinkedIn said it had removed a number of accounts
  • Twitter was "actively investigating" the information in Facebook's report

Facebook said the group used email, messaging, and collaboration services to distribute the malware

Facebook said on Thursday it had taken down about 200 accounts run by a group of hackers in Iran as part of a cyber-spying operation that targeted mostly US military personnel and people working at defense and aerospace companies.

The social media giant said the group, dubbed 'Tortoiseshell' by security experts, used fake online personas to connect with targets, build trust sometimes over the course of several months and drive them onto other sites where they were tricked into clicking malicious links that would infect their devices with spying malware.

Advertisement

"This activity had the hallmarks of a well-resourced and persistent operation, while relying on relatively strong operational security measures to hide who's behind it," Facebook's investigations team said in a blog post.

The group, Facebook said, made fictitious profiles across multiple social media platforms to appear more credible, often posing as recruiters or employees of aerospace and defense companies. Microsoft-owned LinkedIn said it had removed a number of accounts and Twitter said it was "actively investigating" the information in Facebook's report.

Advertisement

Facebook said the group used email, messaging, and collaboration services to distribute the malware, including through malicious Microsoft Excel spreadsheets. A Microsoft spokesperson said in a statement it was aware of and tracking this actor and that it takes action when it detects malicious activity.

Alphabet's Google said it had detected and blocked phishing on Gmail and issued warnings to its users. Workplace messaging app Slack said it had acted to take down the hackers who used the site for social engineering and shut down all Workspaces that violated its rules.

Advertisement

The hackers also used tailored domains to attract its targets, Facebook said, including fake recruiting websites for defense companies, and it set up online infrastructure that spoofed a legitimate job search website for the US Department of Labor.

Facebook said the hackers mostly targeted people in the United States, as well as some in the United Kingdom and Europe, in a campaign running since mid-2020. It declined to name the companies whose employees were targeted but its head of cyber espionage Mike Dvilyanski said it was notifying the "fewer than 200 individuals" who were targeted.

Advertisement

The campaign appeared to show an expansion of the group's activity, which had previously been reported to concentrate mostly on the I.T. and other industries in the Middle East, Facebook said. The investigation found that a portion of the malware used by the group was developed by Mahak Rayan Afraz (MRA), an IT company based in Tehran with ties to the Islamic Revolutionary Guard Corps.

Reuters could not immediately locate contact information for Mahak Rayan Afraz and former employees of the firm did not immediately return messages sent via LinkedIn. Iran's mission to the United Nations in New York did not immediately respond to a request for comment.

MRA's alleged connection to Iranian state cyber espionage is not new. Last year cybersecurity company Recorded Future said MRA was one of several contractors suspected of serving the IRGC's elite Quds Force.

Iranian government spies - like other espionage services - have long been suspected of farming out their mission to a host of domestic contractors.

Facebook said it had blocked the malicious domains from being shared and Google said it had added the domains to its "blocklist."

© Thomson Reuters 2021


What is the best phone to buy right now? We discussed this on Orbital, the Gadgets 360 podcast. Orbital is available on Apple Podcasts, Google Podcasts, Spotify, Amazon Music and wherever you get your podcasts.
Affiliate links may be automatically generated - see our ethics statement for details.
 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Further reading: Facebook, hackers, cybersecurity
Advertisement

Related Stories

Popular Mobile Brands
  1. HTX Delists USD1 Stablecoin, Asks WLFI to Reverse Freeze
  2. Redmi Turbo 5 Confirmed to Launch in India With This Rear Camera Setup
  3. Samsung Galaxy S27 Pro's Battery May Match the One on the Galaxy S26 Ultra
  4. New Leak Shows Us What Apple's Foldable iPhone Might Look Like
  5. Vivo X300 FE, iQOO 15R and More Discounted During Amazon Mega Deal Days Sale
  6. OnePlus Turbo 6X Series Will Launch in China on This Date
  7. Samsung Galaxy A27 Spotted in Leaked Mint Colourway, Might Launch Soon
  8. Vivo V70 Lite 5G Silently Launched in Select Markets With These Features
  1. HTX Delists USD1 Stablecoin, Asks World Liberty Financial to Reverse Freeze on Exchange's Addresses
  2. Redmi Turbo 5 Confirmed to Launch in India With Identical Dual Rear Camera Setup as Chinese Variant
  3. OnePlus Turbo 6X Series Launch Date Announced Along With Key Specifications, Features
  4. WWDC 2026: Tim Cook’s Final Apple Keynote Marks the End of an Era
  5. Infinix Smart 20 Launched in India With MediaTek Helio G81 Ultimate SoC, Slim 7.7mm Profile: Price, Features
  6. Infinix Hot 70 Pro India Launch Timeline Leaked; Could Feature Dimensity 7100 Chip, 6,000mAh Battery
  7. Bitcoin Rebounds Above $62,000 as Buyers Return at Lower Prices Despite ETF Outflow Concerns
  8. Samsung Galaxy S26 FE WPC Database Listing Reveals Design, Qi2 Wireless Charging Support
  9. Apple's Foldable iPhone Seen in New Images of Dummy Units That Reveal Design
  10. Samsung Galaxy S27 Pro Leak Hints at Display Size, Tipped to Launch With 5,000mAh Battery
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.