Phishing scheme targeting Mideast researchers uses 'herd mentality' approach to dupe victims
Full article1,147 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
The tactic linked to an Iranian group creates the impression the email activity is real by employing a phenomenon known as "social proof."
Hackers are using a clever new phishing technique to create email threads with multiple responses to trick potential victims into thinking bogus messages are legitimate.
The cybersecurity firm Proofpoint has identified the group deploying these so-called “multi-persona impersonation” emails as TA453. The company previously linked TA453 to Iran and says their activities overlap with other groups called Charming Kitten, Phosphorous and APT42.
Proofpoint said Tuesday that it noticed a recent uptick in these types of phishing emails in late June, when the attackers posing as a researcher in one email referenced another researcher who then replied to the thread.
The tactic is designed to create a stronger impression that the activity is real, the researchers said, by employing a psychological phenomenon known as “social proof.” Sometimes referred to as “herd mentality,” the idea is that people are more likely to engage if they see others doing it, too.
The research lands amid a flurry of developments related to other Iranian cyberattacks. Last week, for instance, cybersecurity firm Mandiant classified a range of Iranian-linked hacking activity dating back several years under one threat umbrella dubbed APT42. The same day, Albania announced it was severing diplomatic ties with Iran over a string of mid-July cyberattacks that targeted government systems there.
Both the U.S. and the British governments backed up the Albanians’ assessment of Iranian responsibility, and Washington took it a step further Friday by announcing sanctions on the Iranian Ministry of Intelligence and its leader.
Various Iranian-linked spear phishing schemes are known for building rapport with potential victims over long periods of time. Even within TA453, they noted, some campaigns “engage in benign conversations with targets for weeks before delivering malicious links,” while others tend “to immediately send a malicious link in the initial email.”
TA453, the researchers noted, has typically masqueraded as a journalist or policy-adjacent individual claiming to want to work with or collaborate on research in order to target victims. “Benign conversations that eventually lead to credential harvesting links are hallmarks of TA453 activity,” the researchers said.
But this latest evolution marks an interesting leveling up and increased resource load on the attackers’ side, said Sherrod DeGrippo, vice president of threat research and detection at Proofpoint.
“This is an intriguing technique because it requires more resources to be used per target — potentially burning more personas — and a coordinated approach among the various personalities in use by TA453,” DeGrippo said in a statement.
In one example, the hackers impersonated a researcher with the Foreign Policy Research Institute, a legitimate Philadelphia-based think tank focused on international policy. In the email the researcher referenced another researcher at the Pew Research Center, who was cc’d on the email.
A day after the initial email sent by the first researcher, the second researcher responded to the thread and told the unnamed victim that the two were “looking forward to hearing from you.”
In that case, no malicious documents were sent. But in another, the group employed the same tactic using an initial researcher and three additional hacker-controlled accounts, who were cc’d on the initial email. In that case, the victim initially responded to to the email and the initial researcher sent a Microsoft OneDrive link containing a Microsoft Word document.
After the victim didn’t respond to additional emails, one of the three additional “researchers” dropped the first researcher from the thread and tried to get the victim to download the document.
“All threat actors are in constant states of iterating their tools, tactics, and techniques (TTPs), advancing some while deprecating others,” the researchers said. Even with MPI, they wrote, a potential next step is attempting to send a blank email and then responding to that blank email while including multiple “friends” in the cc line as a possible attempt to bypass security detection.
“Researchers involved in international security, particularly those specializing in Middle Eastern
studies or nuclear security, should maintain a heightened sense of awareness when receiving
unsolicited emails,” the researchers said. “For example, experts that are approached by journalists should check the journalist’s website to see if the email address belongs to the journalist.”
More Scoops
Iranian hackers impersonate journalists in social engineering campaign
Members of a notorious Iranian hacking crew are using false personas to steal credentials and access victim cloud environments, per a new Mandiant report.
Iran-linked hackers used fake Atlantic Council-affiliated persona to target human rights researchers
Iranian hacking group expands focus to US politicians, critical infrastructure, researchers find
Sprawling, multi-year Iranian cyberespionage and surveillance group exposed in new report
Google researchers expose Iranian hackers’ tool to steal emails from Gmail, Yahoo and Outlook
Chinese hackers targeted U.S. political reporters just ahead of Jan. 6 attack, researchers say
Years of hacks against aviation, transportation industries tied to one group, researchers say
Latest Podcasts
Government
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
Feds accuse China of ‘systematic’ distillation of U.S. AI models
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
The G7 tells industry to hurry up and prep for post-quantum encryption
Technology
Threats
Microsoft discloses two actively exploited zero-days among 974 vulnerabilities
Russian national extradited to US for alleged involvement in bank-account takeover scheme
Attackers exploit zero-days in consistently besieged SonicWall product
Jail time for Maine child in 764 marks turning point in federal law enforcement
Policy
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
Election official says Tina Peters would be consultant, won’t have access to election systems
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/phishing-scheme-targeting-mideast-researchers/