Iran-linked hackers used fake Atlantic Council-affiliated persona to target human rights researchers
Full article1,197 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
A persona dubbed Sara Shokouhi recycled photos of a Russian psychologist and tarot card reader to pose as a Middle East-focused researcher
On the face of it, the Twitter profile of a person calling herself Sara Shokouhi looks like any other earnest Middle East-focused researcher. Her tweets are a litany of retweets of various voices protesting the Iranian government. Her bio claims she’s completed a PhD from Northwestern State University of Louisiana. At the top of her profile, the person calling herself Sara Shokouhi peers into the camera with her hands folded over a stack of books.
In reality, Shokouhi is a persona manufactured by Iranian-linked hackers to target a number of different Iran-focused researchers, according to a report released Thursday by Secureworks. The woman in her photos is in fact a Russia-based psychologist and tarot card reader.
In recent weeks, the hackers — who are believed to be part of a group tracked by Secureworks as COBALT ILLUSION but also known as Charming Kitten, APT42 or Phosphorus — have used the Shokouhi persona to reach out to legitimate researchers asking if they were interested in contributing to an upcoming Atlantic Council report together with a researcher who possesses a genuine Atlantic Council affiliation.
The genuine Atlantic Council researcher, Holly Dagres, tweeted on Feb. 23 that the claims that she was working together with Shokouhi were “a lie” and that she was “sure this is some kind of phishing.” The next day, Nariman Gharib, a U.K.-based Iranian opposition activist and independent cyber espionage investigator, warned his 13,100 subscribers on Telegram about the account. Shortly after that, the Computer Emergency Response Team in Farsi — a group of security researchers focused on cybersecurity threats related to Iran — issued another warning:
— Certfa | سرتفا (@certfalab) February 24, 2023⚠️ Beware of fake accounts of Iranian state backed hackers on Twitter. They usually send phishing links via DM and you must not click on these links under any circumstances.
user_id: 1581246833887698944 pic.twitter.com/uv3mvOvh91
It’s not clear if this particular persona’s efforts resulted in any successful phishing attacks. The Twitter account, created in October 2022, remains active. An Instagram account associated with the name is unavailable.
To build credibility with the researchers it aims to target, the persona has in recent weeks tweeted a variety of messages that align with ongoing anti-government in Iran. “To appear sympathetic to the protestors’ interests and demands, the account owner has posted cynical content such as images of dead children, physical abuse suffered by protesters, anti-Iranian government commentary, and anti-Iranian symbolism,” Secureworks researchers write.
The incident isn’t Dagres first run-in with Charming Kitten. In a 2020 Washington Post op-ed, she described a “relentless and sophisticated” effort by the same Iranian hackers to spearphish her.
According to Secureworks, the hacking group is suspected of operating on behalf of the Intelligence Organization of the Islamic Revolutionary Guard Corps. The cybersecurity firm Proofpoint reported in December that the group had quietly added “outlier” targets to its portfolio over the last two years, including U.S. politicians, medical researchers and even a realtor involved in the sale of multiple homes near the headquarters of U.S. Central Command in Tampa, Fla.
The Computer Emergency Response Team in Farsi published a report in September 2022 detailing similar spear phishing campaigns by the same hacking group. “Charming Kitten actors have targeted individuals, academics, journalists, activists, think tankers, institutes, organizations, military and government sectors in the United States, European, and Middle Eastern countries since as early as 2014,” the report notes.
As part of their operations, the hackers use fictitious personas or pose as real people using compromised email or social media accounts to build rapport with targets before sending them malicious links to documents or online meeting sites. The CERTFA report notes that the hacking group has previously impersonated at least one Atlantic Council nonresident fellow, Hagar Hajjar.
The Atlantic Council declined to comment.
Twitter did not return a request for comment. Owner Elon Musk’s deep layoffs at the company have severely impacted the company’s ability to respond to issues of trolling and state-backed disinformation, as the BBC reported this week.
More Scoops
Iranian hackers were more coordinated, aligned during Israel conflict than it seemed
SecurityScorecard and the Middle East Institute said in separate reports this week that Iranian hacker operations during the 12-day conflict exhibited clear strategic intent.
Iranian hackers impersonate journalists in social engineering campaign
Iranian hacking group expands focus to US politicians, critical infrastructure, researchers find
Phishing scheme targeting Mideast researchers uses ‘herd mentality’ approach to dupe victims
Google researchers expose Iranian hackers’ tool to steal emails from Gmail, Yahoo and Outlook
Chinese hackers targeted U.S. political reporters just ahead of Jan. 6 attack, researchers say
Analysis of well-known Iranian hacking group points to more purely financial attacks
Latest Podcasts
Government
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
The G7 tells industry to hurry up and prep for post-quantum encryption
Jail time for Maine child in 764 marks turning point in federal law enforcement
Technology
Threats
Chinese espionage groups swarm to exploit triple-link chain of zero-days
Microsoft discloses two actively exploited zero-days among 974 vulnerabilities
Russian national extradited to US for alleged involvement in bank-account takeover scheme
Attackers exploit zero-days in consistently besieged SonicWall product
Policy
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
Election official says Tina Peters would be consultant, won’t have access to election systems
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/iran-linked-hackers-used-fake-atlantic-council-persona-to-target-human-rights-researchers/