Facebook captures Iranian spies to capture U.S. military targets

[ad_1]

If you are a U.S. military members who have become friendly Facebook The news of private sector recruiters in the past few months has shown promising prospects for the aerospace or defense contractor industry, but Facebook may have some bad news.

On Thursday, the social media giant revealed that it has been tracked and at least partially disrupted the long-running Iranian Hackers using Facebook accounts to impersonate recruiters, before sending malware-infected files to U.S. targets or tricking them into submitting sensitive credentials to phishing sites, lure them with convincing social engineering programs. Facebook stated that hackers also pretend to work in the hotel or medical industry, journalism, non-governmental organizations or airlines, and sometimes use personal data on several different social media platforms to engage with targets for months. Unlike some previous social media phishing cases funded by the Iranian state of Iran’s neighbors, this latest campaign seems to be mainly aimed at Americans, and to a lesser extent, victims in Britain and Europe.

Facebook stated that as a result of the investigation, it has removed “less than 200” false personal data from its platform and notified roughly the same number of Facebook users that hackers have targeted them. “Our investigation found that Facebook is part of a broader espionage campaign that targets people with phishing, social engineering, spoofing sites, and malicious domains across multiple social media platforms, emails, and collaboration sites. “Facebook threatened to interrupt director David Agranovich (David Agranovich), said in a conference call with the media on Thursday.

Facebook has identified the hacker behind the social engineering activity as an organization known as “Tortoiseshell”, believed to be working on behalf of the Iranian government. This organization has some loose connections and similarities with other well-known Iranian organizations known as APT34 or Helix Kitten and APT35 or Charming Kitten, which were first exposed in 2019.At the time, the security company Symantec Hacker found The IT supplier in Saudi Arabia was compromised in an apparent supply chain attack aimed at infecting the company’s customers with a piece of malware called Syskit. Facebook found the same malware used in this latest hacking campaign, but the infection technology has a broader scope, targeting the United States and other Western countries, not the Middle East.

According to security company Mandiant, Tortoiseshell seems to have chosen social engineering rather than supply chain attacks from the beginning, and started phishing on social media as early as 2018. John Hultquist, vice president of threat intelligence at Mandiant, said that this includes not just Facebook. “Starting from some of the earliest actions, they made up for very simple technical methods with very complex social media plans. This is an area that Iran is very good at,” Hultquist said.

In 2019, Cisco’s Talos Security Department discovered Tortoiseshell Run a fake veterans website called Hire Military Heroes, Designed to trick victims into installing desktop applications containing malware on their PCs. Craig Williams, director of the Talos Intelligence Organization, said that fake websites and the wider activities uncovered by Facebook both show how military personnel trying to find work in the private sector can become mature targets for spies. “The problem we face is that the transition of veterans to the business world is a huge industry,” Williams said. “Bad people can find people who make mistakes, they will click on things they shouldn’t do, and they will be attracted by certain proposals.”

Facebook warned that the organization also deceived the U.S. Department of Labor website; the company provided a list of fake domain names of the organization posing as news media sites, YouTube and LiveLeak versions, and many URLs related to the Trump family and the Trump Organization Different variants.

[ad_2]

Source link