ZeroHour
CyberScooppublished ()ingested @AJVicens

Phishing scheme targeting Mideast researchers uses 'herd mentality' approach to dupe victims

criticalPhishing & fraud exploited in the wildimportance 60
Full article1,147 words · extracted from cyberscoop.com · click to collapse
Skip to main content

Get our latest cybersecurity news first on Google.

Click here!

The tactic linked to an Iranian group creates the impression the email activity is real by employing a phenomenon known as "social proof."

Getty Images

Hackers are using a clever new phishing technique to create email threads with multiple responses to trick potential victims into thinking bogus messages are legitimate.

The cybersecurity firm Proofpoint has identified the group deploying these so-called “multi-persona impersonation” emails as TA453. The company previously linked TA453 to Iran and says their activities overlap with other groups called Charming Kitten, Phosphorous and APT42.

Proofpoint said Tuesday that it noticed a recent uptick in these types of phishing emails in late June, when the attackers posing as a researcher in one email referenced another researcher who then replied to the thread.

The tactic is designed to create a stronger impression that the activity is real, the researchers said, by employing a psychological phenomenon known as “social proof.” Sometimes referred to as “herd mentality,” the idea is that people are more likely to engage if they see others doing it, too.

The research lands amid a flurry of developments related to other Iranian cyberattacks. Last week, for instance, cybersecurity firm Mandiant classified a range of Iranian-linked hacking activity dating back several years under one threat umbrella dubbed APT42. The same day, Albania announced it was severing diplomatic ties with Iran over a string of mid-July cyberattacks that targeted government systems there.

Both the U.S. and the British governments backed up the Albanians’ assessment of Iranian responsibility, and Washington took it a step further Friday by announcing sanctions on the Iranian Ministry of Intelligence and its leader.

Various Iranian-linked spear phishing schemes are known for building rapport with potential victims over long periods of time. Even within TA453, they noted, some campaigns “engage in benign conversations with targets for weeks before delivering malicious links,” while others tend “to immediately send a malicious link in the initial email.”

TA453, the researchers noted, has typically masqueraded as a journalist or policy-adjacent individual claiming to want to work with or collaborate on research in order to target victims. “Benign conversations that eventually lead to credential harvesting links are hallmarks of TA453 activity,” the researchers said.

But this latest evolution marks an interesting leveling up and increased resource load on the attackers’ side, said Sherrod DeGrippo, vice president of threat research and detection at Proofpoint.

“This is an intriguing technique because it requires more resources to be used per target — potentially burning more personas — and a coordinated approach among the various personalities in use by TA453,” DeGrippo said in a statement.

In one example, the hackers impersonated a researcher with the Foreign Policy Research Institute, a legitimate Philadelphia-based think tank focused on international policy. In the email the researcher referenced another researcher at the Pew Research Center, who was cc’d on the email.

A day after the initial email sent by the first researcher, the second researcher responded to the thread and told the unnamed victim that the two were “looking forward to hearing from you.”

In that case, no malicious documents were sent. But in another, the group employed the same tactic using an initial researcher and three additional hacker-controlled accounts, who were cc’d on the initial email. In that case, the victim initially responded to to the email and the initial researcher sent a Microsoft OneDrive link containing a Microsoft Word document.

After the victim didn’t respond to additional emails, one of the three additional “researchers” dropped the first researcher from the thread and tried to get the victim to download the document.

“All threat actors are in constant states of iterating their tools, tactics, and techniques (TTPs), advancing some while deprecating others,” the researchers said. Even with MPI, they wrote, a potential next step is attempting to send a blank email and then responding to that blank email while including multiple “friends” in the cc line as a possible attempt to bypass security detection.

“Researchers involved in international security, particularly those specializing in Middle Eastern
studies or nuclear security, should maintain a heightened sense of awareness when receiving
unsolicited emails,” the researchers said. “For example, experts that are approached by journalists should check the journalist’s website to see if the email address belongs to the journalist.”

More Scoops

An Iranian flag is carried around the Azadi (Freedom) monument tower during the annual rally commemorating Iran’s 1979 Islamic Revolution in Tehran on Feb. 11, 2024. (Photo by Majid Saeedi/Getty Images)

Iranian hackers impersonate journalists in social engineering campaign 

Members of a notorious Iranian hacking crew are using false personas to steal credentials and access victim cloud environments, per a new Mandiant report.

Protests in Iran, which started with the death of 22-year-old Mahsa Amini after being detained on the grounds that she did not comply with the headscarf rules, continue at the Iranian consulate on October 31, 2022 in İstanbul, Turkey. (Omer Kuscu/ dia images via Getty Images)

Iran-linked hackers used fake Atlantic Council-affiliated persona to target human rights researchers

Researchers at the cybersecurity firm Proofpoint attributed a cyberattack on a “close affiliate” of former National Security Adviser John Bolton, seen here in Washington in August 2022, to an Iranian hacking group known as TA453. (Photo by Anna Moneymaker/Getty Images)

Iranian hacking group expands focus to US politicians, critical infrastructure, researchers find

Sprawling, multi-year Iranian cyberespionage and surveillance group exposed in new report

Google researchers expose Iranian hackers’ tool to steal emails from Gmail, Yahoo and Outlook

Chinese hackers targeted U.S. political reporters just ahead of Jan. 6 attack, researchers say

Years of hacks against aviation, transportation industries tied to one group, researchers say

Latest Podcasts

Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/phishing-scheme-targeting-mideast-researchers/