Facebook says Iranian hackers used its platform to target U.S. military

The social media giant noted that targeting group Tortoiseshell has a history of attacking information technology industry in the Middle East.

July 16, 2021 05:58 pm | Updated 05:58 pm IST

Facebook says Iranian hackers used its platform to target U.S. military.

Facebook says Iranian hackers used its platform to target U.S. military.

Facebook said on Thursday it disrupted an online cyber espionage campaign conducted by a group of Iranian hackers that targeted U.S. military personnel and companies in defense and aerospace industries.

(Subscribe to our Today's Cache newsletter for a quick snapshot of top 5 tech stories. Click here to subscribe for free.)

The social media giant noted that targeting group Tortoiseshell has a history of attacking information technology industry in the Middle East.

In a blog post, the company explained that its platform was one of the elements of the much broader cross-platform cyber espionage operation.

“This activity had the hallmarks of a well-resourced and persistent operation, while relying on relatively strong operational security measures to hide who’s behind it,” Facebook said.

Tortoiseshell deployed fake profile to connect with targets, build trust and trick them into clicking on malicious links. To make profiles appear credible, hackers created accounts across multiple social media platforms.

While most fictitious accounts posed as recruiters and employees of defense and aerospace companies, others claimed to work in hospitality, medicine, journalism, NGOs and airline. They also set up online infrastructure that mimicked US Department of Labour job search site. Besides, they spoofed domains of major email providers and copied URL-shortening services.

“These domains appeared to have been used for stealing login credentials to the victims’ online accounts (e.g. corporate and personal email, collaboration tools, social media),” Facebook said.

Facebook also found that the group engaged with their targets for months and leveraged the social media platform to move conversation off-platform and send malware to their targets.

Facebook’s analysis found that a portion of the malware was developed by Mahak Rayan Afraz (MRA), an IT company in Tehran with ties to the Islamic Revolutionary Guard Corps (IRGC). IRGC is the branch of Iranian military responsible for the country’s cyber operations.

0 / 0
Sign in to unlock member-only benefits!
  • Access 10 free stories every month
  • Save stories to read later
  • Access to comment on every story
  • Sign-up/manage your newsletter subscriptions with a single click
  • Get notified by email for early access to discounts & offers on our products
Sign in

Comments

Comments have to be in English, and in full sentences. They cannot be abusive or personal. Please abide by our community guidelines for posting your comments.

We have migrated to a new commenting platform. If you are already a registered user of The Hindu and logged in, you may continue to engage with our articles. If you do not have an account please register and login to post comments. Users can access their older comments by logging into their accounts on Vuukle.