Meta deep-sixes WhatsApp accounts tied to Iranian hacking group
Full article580 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
The tech giant believes it is another instance of Iranian hackers attempting to meddle in U.S. politics and the upcoming presidential election.
Meta security teams blocked “a small cluster” of WhatsApp accounts associated with APT42, an Iranian government-backed group accused by U.S. officials of hacking into the Trump campaign’s email accounts, the company said Friday.
According to a blog post from Meta, the Iranian-linked accounts were “likely” for social engineering purposes, with the actors posing as tech support for companies like AOL, Google, Yahoo and Microsoft. Impersonating IT support employees is a tactic that has at times proven to be successful in helping malicious cyber groups steal high-value credentials for major businesses and organizations, but in this case, intended victims flagged the activity using WhatsApp’s reporting tools.
The accounts targeted individuals in Israel, Palestine, Iran, the United States and the United Kingdom, in what Meta believes is another instance of Iranian hackers attempting to meddle in U.S. politics and the upcoming presidential election.
“This effort appeared to have focused on political and diplomatic officials, and other public figures, including some associated with administrations of President Biden and former President Trump,” the company wrote.
Meta could only say it found no evidence of compromised accounts and its information “suggests” the attempts were unsuccessful.
Meta’s actions follow a flurry of recent reporting that accuses Iran’s government of attempting to interfere in the U.S. presidential election. Earlier this month, Microsoft first reported that Iranian hackers attempted to use a former senior adviser’s compromised email account to spearphish a high-ranking presidential campaign official.
Google later reinforced those findings with its own research, saying it had observed Iranian actors linked to Iran’s Islamic Revolutionary Guard Corps attempting to pilfer credentials from people associated with the Trump and Biden campaigns.
Earlier this week, the Office of the Director of National Intelligence, the FBI and the Cybersecurity and Infrastructure Security Agency said that incident helped to lay the groundwork for a hack-and-leak effort by APT42 targeting the Trump campaign, vice presidential candidate JD Vance and campaign associates. Intelligence officials said Vice President Kamala Harris’ presidential campaign has also been targeted by Iranian hackers.
Latest Podcasts
Government
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
The G7 tells industry to hurry up and prep for post-quantum encryption
Jail time for Maine child in 764 marks turning point in federal law enforcement
Technology
Threats
Chinese espionage groups swarm to exploit triple-link chain of zero-days
Microsoft discloses two actively exploited zero-days among 974 vulnerabilities
Russian national extradited to US for alleged involvement in bank-account takeover scheme
Attackers exploit zero-days in consistently besieged SonicWall product
Policy
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/meta-iran-apt42-whatsapp-trump-campaign-hack/