Facebook Says Iranian Hackers Targeted US, Europe Defence Workers Using Fake Accounts

Facebook said Iran-based cyber espionage rings used fake accounts posing as company job recruiters to dupe targets.

Advertisement
By Reuters | Updated: 16 July 2021 10:58 IST
Highlights
  • The group made fictitious profiles across multiple social media platforms
  • LinkedIn said it had removed a number of accounts
  • Twitter was "actively investigating" the information in Facebook's report

Facebook said the group used email, messaging, and collaboration services to distribute the malware

Facebook said on Thursday it had taken down about 200 accounts run by a group of hackers in Iran as part of a cyber-spying operation that targeted mostly US military personnel and people working at defense and aerospace companies.

The social media giant said the group, dubbed 'Tortoiseshell' by security experts, used fake online personas to connect with targets, build trust sometimes over the course of several months and drive them onto other sites where they were tricked into clicking malicious links that would infect their devices with spying malware.

"This activity had the hallmarks of a well-resourced and persistent operation, while relying on relatively strong operational security measures to hide who's behind it," Facebook's investigations team said in a blog post.

Advertisement

The group, Facebook said, made fictitious profiles across multiple social media platforms to appear more credible, often posing as recruiters or employees of aerospace and defense companies. Microsoft-owned LinkedIn said it had removed a number of accounts and Twitter said it was "actively investigating" the information in Facebook's report.

Advertisement

Facebook said the group used email, messaging, and collaboration services to distribute the malware, including through malicious Microsoft Excel spreadsheets. A Microsoft spokesperson said in a statement it was aware of and tracking this actor and that it takes action when it detects malicious activity.

Alphabet's Google said it had detected and blocked phishing on Gmail and issued warnings to its users. Workplace messaging app Slack said it had acted to take down the hackers who used the site for social engineering and shut down all Workspaces that violated its rules.

Advertisement

The hackers also used tailored domains to attract its targets, Facebook said, including fake recruiting websites for defense companies, and it set up online infrastructure that spoofed a legitimate job search website for the US Department of Labor.

Facebook said the hackers mostly targeted people in the United States, as well as some in the United Kingdom and Europe, in a campaign running since mid-2020. It declined to name the companies whose employees were targeted but its head of cyber espionage Mike Dvilyanski said it was notifying the "fewer than 200 individuals" who were targeted.

Advertisement

The campaign appeared to show an expansion of the group's activity, which had previously been reported to concentrate mostly on the I.T. and other industries in the Middle East, Facebook said. The investigation found that a portion of the malware used by the group was developed by Mahak Rayan Afraz (MRA), an IT company based in Tehran with ties to the Islamic Revolutionary Guard Corps.

Reuters could not immediately locate contact information for Mahak Rayan Afraz and former employees of the firm did not immediately return messages sent via LinkedIn. Iran's mission to the United Nations in New York did not immediately respond to a request for comment.

MRA's alleged connection to Iranian state cyber espionage is not new. Last year cybersecurity company Recorded Future said MRA was one of several contractors suspected of serving the IRGC's elite Quds Force.

Iranian government spies - like other espionage services - have long been suspected of farming out their mission to a host of domestic contractors.

Facebook said it had blocked the malicious domains from being shared and Google said it had added the domains to its "blocklist."

© Thomson Reuters 2021


What is the best phone to buy right now? We discussed this on Orbital, the Gadgets 360 podcast. Orbital is available on Apple Podcasts, Google Podcasts, Spotify, Amazon Music and wherever you get your podcasts.
Affiliate links may be automatically generated - see our ethics statement for details.
 

For the latest tech news and reviews, follow Gadgets 360 on X, Facebook, WhatsApp, Threads and Google News. For the latest videos on gadgets and tech, subscribe to our YouTube channel. If you want to know everything about top influencers, follow our in-house Who'sThat360 on Instagram and YouTube.

Further reading: Facebook, hackers, cybersecurity
Advertisement

Related Stories

Popular Mobile Brands
  1. These Samsung Phones Will Get Price Drops Ahead of Festive Season
  2. Amazon Great Indian Festival Sale 2025: Check Early Deals on Tablets
  3. These Companies Fired Over 10K Employees Between July and September 2025
  4. iOS 26's Liquid Glass Design Causes Optical Illusions, Users Claim
  5. Samsung Galaxy S24 Ultra Deal Revealed Ahead of Amazon GIF Sale
  6. Xiaomi Announces Offers on These Products Ahead of Amazon, Flipkart Sales
  1. Astronomers Reveal Sudden Explosion of Small Asteroid Over France
  2. Rare ‘Crescent Sunrise’ Solar Eclipse to Grace Skies Over Antarctica and New Zealand
  3. Sun Shows Signs of Rising Activity Following Decades of Weakening, Study Finds
  4. IMAP Space Weather Mission to Lift Off Soon, NASA Confirms Broadcast Plans
  5. Microsoft's Xbox Full-Screen Experience Leaks on Other Windows Handhelds Ahead of ROG Xbox Ally Debut
  6. Cellecor Comet CBS-05 Pro Bluetooth Speaker Launched in India: Price, Features
  7. Samsung Galaxy S24 Ultra, Galaxy S24 FE, Galaxy A55 5G and More to Go on Sale With Discounts During Festive Season
  8. Coinbase Urges US DOJ Action as SEC Mulls Dropping Lawsuit Against Crypto Exchange
  9. Vivo V60 Lite 4G Design, Specifications Leaked; Tipped to Launch With Snapdragon 685 SoC, 6,500mAh Battery
  10. Nothing Ear 3 Launched With Super Mic Feature, Up to 45dB Active Noise Cancellation: Price, Features
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.