Advertisement
Facebook
WorldMiddle East

Facebook: Iran-based hackers used social media site to target US military personnel

  • Facebook said it had taken down about 200 accounts run by a group of hackers in Iran as part of a cyber-spying operation that targeted US military personnel
  • Facebook said the group used fake online personas to connect with targets, and drive them onto sites where they were tricked into clicking malicious links

Reading Time:2 minutes
Why you can trust SCMP
Facebook said on Thursday it has disrupted an Iran-based espionage operation targeting defence and aerospace workers in Europe and the United States. Photo: AFP
Reuters

Facebook said on Thursday it had taken down about 200 accounts run by a group of hackers in Iran as part of a cyber-spying operation that targeted mostly US military personnel and people working at defence and aerospace companies.

The social media giant said the group, dubbed “Tortoiseshell” by security experts, used fake online personas to connect with targets, build trust sometimes over the course of several months and drive them onto other sites where they were tricked into clicking malicious links that would infect their devices with spying malware.

“This activity had the hallmarks of a well-resourced and persistent operation, while relying on relatively strong operational security measures to hide who’s behind it,” Facebook’s investigations team said in a blog post.

Advertisement

The group, Facebook said, made fictitious profiles across multiple social media platforms to appear more credible, often posing as recruiters or employees of aerospace and defence companies. Microsoft-owned LinkedIn said it had removed a number of accounts and Twitter said it was “actively investigating” the information in Facebook’s report.

07:30

Why China is tightening control over cybersecurity

Why China is tightening control over cybersecurity

Facebook said the group used email, messaging and collaboration services to distribute the malware, including through malicious Microsoft Excel spreadsheets. A Microsoft spokesman said in a statement it was aware of and tracking this actor and that it takes action when it detects malicious activity.

Advertisement

Alphabet Inc’s said it had detected and blocked phishing on Gmail and issued warnings to its users. Workplace messaging app Slack Technologies Inc said it had acted to take down the hackers who used the site for social engineering and shut down all Workspaces that violated its rules.

Advertisement
Select Voice
Choose your listening speed
Get through articles 2x faster
1.25x
250 WPM
Slow
Average
Fast
1.25x