Iranian spies tried hacking US military personnel by posing as job recruiters on Facebook
Full article834 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
Facebook said it took down the campaign from the hackers known as Tortoiseshell.
Facebook said on Thursday it upended Iranian government-backed hackers who targeted U.S. military personnel and defense companies on its platform before trying to move conversations elsewhere to infect victims with malware.
In a blog post, Facebook linked the campaign to a group known alternately as Tortoiseshell or Imperial Kitten, which primarily had focused on Middle East targets before. This time, they were mainly preoccupied with the United States.
“In an apparent expansion of malicious activity to other regions and industries, our investigation found them targeting military personnel and companies in the defense and aerospace industries primarily in the US, and to a lesser extent in the UK and Europe,” wrote Mike Dvilyanski, Facebook’s head of cyberespionage investigations, and David Agranovich, director of threat disruption.
As part of a social engineering effort, the hackers posed via fake online personas as defense and aerospace industry recruiters, or claimed to work in hospitality, journalism, medicine or for non-governmental organizations.
The social media giant said it removed the offending accounts, blocked the sharing of malicious domains, notified potential victims and shared threat information with others in its industry.
Those blocked domains included fake recruiting websites, a spoofed U.S. Department of Labor job site and several that used the Trump family name, a fact that stood out to cybersecurity firm Mandiant.
“The existence of Trump related domains is notable, though we have no evidence that these domains were operationalized or used to target anyone affiliated with the Trump family or properties,” said Sarah Jones, senior principal analyst for Mandiant Threat Intelligence. “Domains such as these could suggest social engineering associated with US political topics.”
Besides the names Imperial Kitten and Tortoiseshell, the organization also is sometimes labeled Charming Kitten or APT35. FireEye has dubbed this particular activity UNC1833, and says it has a history of going after U.S. information technology targets working in the Middle East.
“Overlaps often reflect the fluid movement of Iranian personnel between companies and organizations supporting Iran’s offensive cyber program,” said Jones.
While Tortoiseshell is usually associated with cyberespionage that scours the Middle East, including a lengthy effort that first surfaced in 2019, the group’s spying sometimes has bled over into targeting U.S. military veterans before.
More Scoops
Iranian hackers were more coordinated, aligned during Israel conflict than it seemed
SecurityScorecard and the Middle East Institute said in separate reports this week that Iranian hacker operations during the 12-day conflict exhibited clear strategic intent.
Iran hacking group impersonates defense firms, hostage campaigners
Iranian hacking group expands focus to US politicians, critical infrastructure, researchers find
Latest Podcasts
Government
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
Feds accuse China of ‘systematic’ distillation of U.S. AI models
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
The G7 tells industry to hurry up and prep for post-quantum encryption
Technology
Threats
Chinese espionage groups swarm to exploit triple-link chain of zero-days
Microsoft discloses two actively exploited zero-days among 974 vulnerabilities
Russian national extradited to US for alleged involvement in bank-account takeover scheme
Attackers exploit zero-days in consistently besieged SonicWall product
Policy
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/facebook-tortoiseshell-iran-military/