ZeroHour
CyberScooppublished ()ingested @AJVicens

Iran-linked hackers used fake Atlantic Council-affiliated persona to target human rights researchers

criticalExploit / PoC exploited in the wildimportance 60
Full article1,197 words · extracted from cyberscoop.com · click to collapse
Skip to main content

Get our latest cybersecurity news first on Google.

Click here!

A persona dubbed Sara Shokouhi recycled photos of a Russian psychologist and tarot card reader to pose as a Middle East-focused researcher

Protests in Iran, which started with the death of 22-year-old Mahsa Amini after being detained on the grounds that she did not comply with the headscarf rules, continue at the Iranian consulate on October 31, 2022 in İstanbul, Turkey. (Omer Kuscu/ dia images via Getty Images)

On the face of it, the Twitter profile of a person calling herself Sara Shokouhi looks like any other earnest Middle East-focused researcher. Her tweets are a litany of retweets of various voices protesting the Iranian government. Her bio claims she’s completed a PhD from Northwestern State University of Louisiana. At the top of her profile, the person calling herself Sara Shokouhi peers into the camera with her hands folded over a stack of books.

In reality, Shokouhi is a persona manufactured by Iranian-linked hackers to target a number of different Iran-focused researchers, according to a report released Thursday by Secureworks. The woman in her photos is in fact a Russia-based psychologist and tarot card reader.

In recent weeks, the hackers — who are believed to be part of a group tracked by Secureworks as COBALT ILLUSION but also known as Charming Kitten, APT42 or Phosphorus — have used the Shokouhi persona to reach out to legitimate researchers asking if they were interested in contributing to an upcoming Atlantic Council report together with a researcher who possesses a genuine Atlantic Council affiliation.

The genuine Atlantic Council researcher, Holly Dagres, tweeted on Feb. 23 that the claims that she was working together with Shokouhi were “a lie” and that she was “sure this is some kind of phishing.” The next day, Nariman Gharib, a U.K.-based Iranian opposition activist and independent cyber espionage investigator, warned his 13,100 subscribers on Telegram about the account. Shortly after that, the Computer Emergency Response Team in Farsi — a group of security researchers focused on cybersecurity threats related to Iran — issued another warning:

⚠️ Beware of fake accounts of Iranian state backed hackers on Twitter. They usually send phishing links via DM and you must not click on these links under any circumstances.

user_id: 1581246833887698944 pic.twitter.com/uv3mvOvh91

— Certfa | سرتفا (@certfalab) February 24, 2023

It’s not clear if this particular persona’s efforts resulted in any successful phishing attacks. The Twitter account, created in October 2022, remains active. An Instagram account associated with the name is unavailable.

To build credibility with the researchers it aims to target, the persona has in recent weeks tweeted a variety of messages that align with ongoing anti-government in Iran. “To appear sympathetic to the protestors’ interests and demands, the account owner has posted cynical content such as images of dead children, physical abuse suffered by protesters, anti-Iranian government commentary, and anti-Iranian symbolism,” Secureworks researchers write.

The incident isn’t Dagres first run-in with Charming Kitten. In a 2020 Washington Post op-ed, she described a “relentless and sophisticated” effort by the same Iranian hackers to spearphish her.

According to Secureworks, the hacking group is suspected of operating on behalf of the Intelligence Organization of the Islamic Revolutionary Guard Corps. The cybersecurity firm Proofpoint reported in December that the group had quietly added “outlier” targets to its portfolio over the last two years, including U.S. politicians, medical researchers and even a realtor involved in the sale of multiple homes near the headquarters of U.S. Central Command in Tampa, Fla.

The Computer Emergency Response Team in Farsi published a report in September 2022 detailing similar spear phishing campaigns by the same hacking group. “Charming Kitten actors have targeted individuals, academics, journalists, activists, think tankers, institutes, organizations, military and government sectors in the United States, European, and Middle Eastern countries since as early as 2014,” the report notes.

As part of their operations, the hackers use fictitious personas or pose as real people using compromised email or social media accounts to build rapport with targets before sending them malicious links to documents or online meeting sites. The CERTFA report notes that the hacking group has previously impersonated at least one Atlantic Council nonresident fellow, Hagar Hajjar.

The Atlantic Council declined to comment.

Twitter did not return a request for comment. Owner Elon Musk’s deep layoffs at the company have severely impacted the company’s ability to respond to issues of trolling and state-backed disinformation, as the BBC reported this week.

More Scoops

Smoke rises as Israel targets the notorious Evin Prison in north of Tehran, Iran, on June 23, 2025. Evin prison has been known as the place where Iran imprisons mostly political activists, dissidents and journalists. Media reports say that administrative building and the hospital of Evin prison have been damaged, and a number of families of inmates and prison staff have been killed and wounded. (Photo by Nikan / Middle East Images via AFP)

Iranian hackers were more coordinated, aligned during Israel conflict than it seemed

SecurityScorecard and the Middle East Institute said in separate reports this week that Iranian hacker operations during the 12-day conflict exhibited clear strategic intent.

An Iranian flag is carried around the Azadi (Freedom) monument tower during the annual rally commemorating Iran’s 1979 Islamic Revolution in Tehran on Feb. 11, 2024. (Photo by Majid Saeedi/Getty Images)

Iranian hackers impersonate journalists in social engineering campaign 

Researchers at the cybersecurity firm Proofpoint attributed a cyberattack on a “close affiliate” of former National Security Adviser John Bolton, seen here in Washington in August 2022, to an Iranian hacking group known as TA453. (Photo by Anna Moneymaker/Getty Images)

Iranian hacking group expands focus to US politicians, critical infrastructure, researchers find

Phishing scheme targeting Mideast researchers uses ‘herd mentality’ approach to dupe victims

Google researchers expose Iranian hackers’ tool to steal emails from Gmail, Yahoo and Outlook

Chinese hackers targeted U.S. political reporters just ahead of Jan. 6 attack, researchers say

Analysis of well-known Iranian hacking group points to more purely financial attacks

Latest Podcasts

Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/iran-linked-hackers-used-fake-atlantic-council-persona-to-target-human-rights-researchers/