Facebook Says Iranian Hackers Targeted US, Europe Defence Workers Using Fake Accounts

Facebook said Iran-based cyber espionage rings used fake accounts posing as company job recruiters to dupe targets.

Advertisement
By Reuters | Updated: 16 July 2021 10:58 IST
Highlights
  • The group made fictitious profiles across multiple social media platforms
  • LinkedIn said it had removed a number of accounts
  • Twitter was "actively investigating" the information in Facebook's report

Facebook said the group used email, messaging, and collaboration services to distribute the malware

Facebook said on Thursday it had taken down about 200 accounts run by a group of hackers in Iran as part of a cyber-spying operation that targeted mostly US military personnel and people working at defense and aerospace companies.

The social media giant said the group, dubbed 'Tortoiseshell' by security experts, used fake online personas to connect with targets, build trust sometimes over the course of several months and drive them onto other sites where they were tricked into clicking malicious links that would infect their devices with spying malware.

"This activity had the hallmarks of a well-resourced and persistent operation, while relying on relatively strong operational security measures to hide who's behind it," Facebook's investigations team said in a blog post.

Advertisement

The group, Facebook said, made fictitious profiles across multiple social media platforms to appear more credible, often posing as recruiters or employees of aerospace and defense companies. Microsoft-owned LinkedIn said it had removed a number of accounts and Twitter said it was "actively investigating" the information in Facebook's report.

Advertisement

Facebook said the group used email, messaging, and collaboration services to distribute the malware, including through malicious Microsoft Excel spreadsheets. A Microsoft spokesperson said in a statement it was aware of and tracking this actor and that it takes action when it detects malicious activity.

Alphabet's Google said it had detected and blocked phishing on Gmail and issued warnings to its users. Workplace messaging app Slack said it had acted to take down the hackers who used the site for social engineering and shut down all Workspaces that violated its rules.

Advertisement

The hackers also used tailored domains to attract its targets, Facebook said, including fake recruiting websites for defense companies, and it set up online infrastructure that spoofed a legitimate job search website for the US Department of Labor.

Facebook said the hackers mostly targeted people in the United States, as well as some in the United Kingdom and Europe, in a campaign running since mid-2020. It declined to name the companies whose employees were targeted but its head of cyber espionage Mike Dvilyanski said it was notifying the "fewer than 200 individuals" who were targeted.

Advertisement

The campaign appeared to show an expansion of the group's activity, which had previously been reported to concentrate mostly on the I.T. and other industries in the Middle East, Facebook said. The investigation found that a portion of the malware used by the group was developed by Mahak Rayan Afraz (MRA), an IT company based in Tehran with ties to the Islamic Revolutionary Guard Corps.

Reuters could not immediately locate contact information for Mahak Rayan Afraz and former employees of the firm did not immediately return messages sent via LinkedIn. Iran's mission to the United Nations in New York did not immediately respond to a request for comment.

MRA's alleged connection to Iranian state cyber espionage is not new. Last year cybersecurity company Recorded Future said MRA was one of several contractors suspected of serving the IRGC's elite Quds Force.

Iranian government spies - like other espionage services - have long been suspected of farming out their mission to a host of domestic contractors.

Facebook said it had blocked the malicious domains from being shared and Google said it had added the domains to its "blocklist."

© Thomson Reuters 2021


What is the best phone to buy right now? We discussed this on Orbital, the Gadgets 360 podcast. Orbital is available on Apple Podcasts, Google Podcasts, Spotify, Amazon Music and wherever you get your podcasts.
Affiliate links may be automatically generated - see our ethics statement for details.
 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Further reading: Facebook, hackers, cybersecurity
Advertisement

Related Stories

Popular Mobile Brands
  1. Realme 16 Pro+ 5G Confirmed to Launch With This Snapdragon Chipset
  2. Vijay Sales Announces Apple Days Sale With Offers on These Apple Products
  3. Foxconn's Manufacturing Expansion in India Is Straight Out of Its China Playbook
  4. Here's How Much the Oppo Reno 15 Pro Mini Might Cost in India
  5. Why the Samsung Galaxy S26 Series Might Launch at a Higher Price in 2026
  6. Vivo X300 Ultra Surfaces on Certification Website Ahead of 2026 Launch
  7. Fusion Reactors Could Generate Axions, Offering a New Path to Detect Dark Matter
  8. Poco M8 5G Design Teased Ahead of India Launch: See Expected Specifications
  9. OnePlus Teases OnePlus Turbo 6 Series China Launch Date, Key Specs
  10. ISRO Plans Third Launch Pad at Sriharikota in Four Years to Support Heavier Satellites
  1. New Electrochemical Method Doubles Hydrogen Output While Cutting Energy Costs
  2. JWST Spots Most Distant Supernova Ever, From 730 Million Years After Big Bang
  3. ISRO Plans Third Launch Pad at Sriharikota in Four Years to Support Heavier Satellites
  4. ISS Microgravity Experiment Reveal How Particles Behave Without Gravity
  5. Fusion Reactors Could Generate Axions, Offering a New Path to Detect Dark Matter
  6. Meant For You (2025) Now Streaming Online: What You Need to Know About this Turkish Film
  7. Constable Kanakam Season 2 OTT Release Date: When and Where to Watch it Online?
  8. Americana (2025) Now Streaming on Prime Video: What To Know About This Darkly Comic Crime Thriller
  9. Motorola Signature India Launch Date Announced; Company Teases Design, Fabric Finish
  10. Foxconn’s Manufacturing Expansion in India Is Straight Out of Its China Playbook
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.