ZeroHour
CyberScooppublished ()ingested @timstarks

Iranian spies tried hacking US military personnel by posing as job recruiters on Facebook

criticalExploit / PoC exploited in the wildimportance 60
Full article834 words · extracted from cyberscoop.com · click to collapse
Skip to main content

Get our latest cybersecurity news first on Google.

Click here!

Facebook said it took down the campaign from the hackers known as Tortoiseshell.

Facebook takedown
Stickers bearing the Facebook logo at the F8 developers conference in San Jose, California, on April 30, 2019. (REUTERS / Stephen Lam)

Facebook said on Thursday it upended Iranian government-backed hackers who targeted U.S. military personnel and defense companies on its platform before trying to move conversations elsewhere to infect victims with malware.

In a blog post, Facebook linked the campaign to a group known alternately as Tortoiseshell or Imperial Kitten, which primarily had focused on Middle East targets before. This time, they were mainly preoccupied with the United States.

“In an apparent expansion of malicious activity to other regions and industries, our investigation found them targeting military personnel and companies in the defense and aerospace industries primarily in the US, and to a lesser extent in the UK and Europe,” wrote Mike Dvilyanski, Facebook’s head of cyberespionage investigations, and David Agranovich, director of threat disruption.

As part of a social engineering effort, the hackers posed via fake online personas as defense and aerospace industry recruiters, or claimed to work in hospitality, journalism, medicine or for non-governmental organizations.

The social media giant said it removed the offending accounts, blocked the sharing of malicious domains, notified potential victims and shared threat information with others in its industry.

Those blocked domains included fake recruiting websites, a spoofed U.S. Department of Labor job site and several that used the Trump family name, a fact that stood out to cybersecurity firm Mandiant.

“The existence of Trump related domains is notable, though we have no evidence that these domains were operationalized or used to target anyone affiliated with the Trump family or properties,” said Sarah Jones, senior principal analyst for Mandiant Threat Intelligence. “Domains such as these could suggest social engineering associated with US political topics.”

Besides the names Imperial Kitten and Tortoiseshell, the organization also is sometimes labeled Charming Kitten or APT35. FireEye has dubbed this particular activity UNC1833, and says it has a history of going after U.S. information technology targets working in the Middle East.

“Overlaps often reflect the fluid movement of Iranian personnel between companies and organizations supporting Iran’s offensive cyber program,” said Jones.

While Tortoiseshell is usually associated with cyberespionage that scours the Middle East, including a lengthy effort that first surfaced in 2019, the group’s spying sometimes has bled over into targeting U.S. military veterans before.

More Scoops

Smoke rises as Israel targets the notorious Evin Prison in north of Tehran, Iran, on June 23, 2025. Evin prison has been known as the place where Iran imprisons mostly political activists, dissidents and journalists. Media reports say that administrative building and the hospital of Evin prison have been damaged, and a number of families of inmates and prison staff have been killed and wounded. (Photo by Nikan / Middle East Images via AFP)

Iranian hackers were more coordinated, aligned during Israel conflict than it seemed

SecurityScorecard and the Middle East Institute said in separate reports this week that Iranian hacker operations during the 12-day conflict exhibited clear strategic intent.

A picture taken from the plain of Khiam shows a man waving an Iranian flag as smoke rises from burning dry grass, following skirmishes between Lebanese youths and Israeli soldiers, at a rally to mark the 23rd anniversary of Israel’s withdrawal from Lebanon, on May 25, 2023. (Photo by MAHMOUD ZAYYAT/AFP via Getty Images)

Iran hacking group impersonates defense firms, hostage campaigners

Researchers at the cybersecurity firm Proofpoint attributed a cyberattack on a “close affiliate” of former National Security Adviser John Bolton, seen here in Washington in August 2022, to an Iranian hacking group known as TA453. (Photo by Anna Moneymaker/Getty Images)

Iranian hacking group expands focus to US politicians, critical infrastructure, researchers find

Latest Podcasts

Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/facebook-tortoiseshell-iran-military/