Facebook Says Iranian Hackers Targeted US, Europe Defence Workers Using Fake Accounts

Facebook said Iran-based cyber espionage rings used fake accounts posing as company job recruiters to dupe targets.

Advertisement
By Reuters | Updated: 16 July 2021 10:58 IST
Highlights
  • The group made fictitious profiles across multiple social media platforms
  • LinkedIn said it had removed a number of accounts
  • Twitter was "actively investigating" the information in Facebook's report

Facebook said the group used email, messaging, and collaboration services to distribute the malware

Facebook said on Thursday it had taken down about 200 accounts run by a group of hackers in Iran as part of a cyber-spying operation that targeted mostly US military personnel and people working at defense and aerospace companies.

The social media giant said the group, dubbed 'Tortoiseshell' by security experts, used fake online personas to connect with targets, build trust sometimes over the course of several months and drive them onto other sites where they were tricked into clicking malicious links that would infect their devices with spying malware.

"This activity had the hallmarks of a well-resourced and persistent operation, while relying on relatively strong operational security measures to hide who's behind it," Facebook's investigations team said in a blog post.

Advertisement

The group, Facebook said, made fictitious profiles across multiple social media platforms to appear more credible, often posing as recruiters or employees of aerospace and defense companies. Microsoft-owned LinkedIn said it had removed a number of accounts and Twitter said it was "actively investigating" the information in Facebook's report.

Advertisement

Facebook said the group used email, messaging, and collaboration services to distribute the malware, including through malicious Microsoft Excel spreadsheets. A Microsoft spokesperson said in a statement it was aware of and tracking this actor and that it takes action when it detects malicious activity.

Alphabet's Google said it had detected and blocked phishing on Gmail and issued warnings to its users. Workplace messaging app Slack said it had acted to take down the hackers who used the site for social engineering and shut down all Workspaces that violated its rules.

Advertisement

The hackers also used tailored domains to attract its targets, Facebook said, including fake recruiting websites for defense companies, and it set up online infrastructure that spoofed a legitimate job search website for the US Department of Labor.

Facebook said the hackers mostly targeted people in the United States, as well as some in the United Kingdom and Europe, in a campaign running since mid-2020. It declined to name the companies whose employees were targeted but its head of cyber espionage Mike Dvilyanski said it was notifying the "fewer than 200 individuals" who were targeted.

Advertisement

The campaign appeared to show an expansion of the group's activity, which had previously been reported to concentrate mostly on the I.T. and other industries in the Middle East, Facebook said. The investigation found that a portion of the malware used by the group was developed by Mahak Rayan Afraz (MRA), an IT company based in Tehran with ties to the Islamic Revolutionary Guard Corps.

Reuters could not immediately locate contact information for Mahak Rayan Afraz and former employees of the firm did not immediately return messages sent via LinkedIn. Iran's mission to the United Nations in New York did not immediately respond to a request for comment.

MRA's alleged connection to Iranian state cyber espionage is not new. Last year cybersecurity company Recorded Future said MRA was one of several contractors suspected of serving the IRGC's elite Quds Force.

Iranian government spies - like other espionage services - have long been suspected of farming out their mission to a host of domestic contractors.

Facebook said it had blocked the malicious domains from being shared and Google said it had added the domains to its "blocklist."

© Thomson Reuters 2021


What is the best phone to buy right now? We discussed this on Orbital, the Gadgets 360 podcast. Orbital is available on Apple Podcasts, Google Podcasts, Spotify, Amazon Music and wherever you get your podcasts.
Affiliate links may be automatically generated - see our ethics statement for details.
 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Further reading: Facebook, hackers, cybersecurity
Advertisement

Related Stories

Popular Mobile Brands
  1. Samsung Galaxy S26+ Reportedly Listed for Sale Online Ahead of Launch
  2. Vivo X300 FE Reportedly Bags IMDA and TUV Certifications Ahead of Launch
  3. Anthropic's First Indian Office in Bengaluru Is Now Open
  4. Apple to Reportedly Launch Low-Cost MacBook in 'Playful Colors' in March
  5. Lava Bold N2 Will Be Launched in India on This Date: See Expected Specs
  6. Oppo K14x 5G With 6,500mAh Battery Goes on Sale in India: See Price, Offers
  1. Xiaomi 17, Xiaomi 17 Ultra Global Price Details, Launch Date and Colour Options Leaked
  2. X Building Smart 'Cashtags' to Let Users Check Cryptocurrency Prices in Real-Time
  3. Samsung Galaxy A27 5G Listing on IMEI Database Suggests a Galaxy A26 Successor Is on the Way
  4. Anthropic Inaugurates First Indian Office in Bengaluru, Starts Hiring Local Talent
  5. Apple Tipped to Adopt Samsung's Privacy Display Technology for MacBook Models by 2029
  6. Oppo Find X10 Series Tipped to Launch in H2 2026 With Built-In Magnets for Wireless Charging
  7. AMD and TCS to Co-Develop Helios AI Data Centre Architecture, Deliver 200MW Data Centre Blueprint
  8. Tecno Spark 50 4G Tipped to Launch Globally Soon; Design, Colourways, Key Features Leaked
  9. Lava Bold N2 India Launch Date Revealed; Will Be Exclusively Available via Amazon
  10. Government Green Lights Rs. 10,000 Crore Fund of Funds 2.0 Under the Startup India Mission
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.