{"id":96906,"date":"2021-07-16T06:55:54","date_gmt":"2021-07-16T11:55:54","guid":{"rendered":"https:\/\/PERSIAN-HERITAGE.COM\/?p=96906"},"modified":"2021-07-16T06:55:54","modified_gmt":"2021-07-16T11:55:54","slug":"auto-draft-618","status":"publish","type":"post","link":"https:\/\/PERSIAN-HERITAGE.COM\/en\/2021\/07\/16\/auto-draft-618\/","title":{"rendered":"Iranian Hackers Target US Military, Defense Companies"},"content":{"rendered":"<p><img loading=\"lazy\" decoding=\"async\" class=\"size-medium wp-image-96907 alignleft\" src=\"https:\/\/PERSIAN-HERITAGE.COM\/wp-content\/uploads\/2021\/07\/Iran-Flag-1-300x200.jpg\" alt=\"\" width=\"300\" height=\"200\" srcset=\"https:\/\/PERSIAN-HERITAGE.COM\/wp-content\/uploads\/2021\/07\/Iran-Flag-1-300x200.jpg 300w, https:\/\/PERSIAN-HERITAGE.COM\/wp-content\/uploads\/2021\/07\/Iran-Flag-1-150x100.jpg 150w, https:\/\/PERSIAN-HERITAGE.COM\/wp-content\/uploads\/2021\/07\/Iran-Flag-1.jpg 600w, https:\/\/PERSIAN-HERITAGE.COM\/wp-content\/uploads\/2021\/07\/Iran-Flag-1-24x16.jpg 24w, https:\/\/PERSIAN-HERITAGE.COM\/wp-content\/uploads\/2021\/07\/Iran-Flag-1-36x24.jpg 36w, https:\/\/PERSIAN-HERITAGE.COM\/wp-content\/uploads\/2021\/07\/Iran-Flag-1-48x32.jpg 48w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/>VOA \u2014 Iran appears to be intensifying its effort to exploit U.S. and Western targets in cyberspace, running a campaign aimed at manipulating American military personnel and defense companies on social media.<\/p>\n<p>Tehran&#8217;s latest campaign, orchestrated on Facebook by a group known as Tortoiseshell, used a series of sophisticated, fake online personas to make contact with U.S. servicemembers and employees of major defense companies in order to infect their computers with malware and extract information.<\/p>\n<p>&#8220;This activity had the hallmarks of a well-resourced and persistent operation, while relying on relatively strong operational security measures to hide who&#8217;s behind it,&#8221; Facebook said Thursday in a blog post, calling it part of a &#8220;much broader cross-platform cyber espionage operation.&#8221;<\/p>\n<p>Personas used<\/p>\n<p>Employees of defense companies in the U.K. and other European countries were also targeted.<\/p>\n<p>&#8220;These accounts often posed as recruiters and employees of defense and aerospace companies from the countries their targets were in,&#8221; Facebook said. &#8220;Other personas claimed to work in hospitality, medicine, journalism, NGOs and airlines.&#8221;<\/p>\n<p>And the hackers were in no hurry.<\/p>\n<p>&#8220;Our investigation found that this group invested significant time into their social engineering efforts across the internet, in some cases engaging with their targets for months,&#8221; Facebook said. &#8220;They leveraged various collaboration and messaging platforms to move conversations off-platform and send malware to their targets.&#8221;<\/p>\n<p>Facebook said it has notified users who appeared to have been targeted, took down the fake accounts and blocked the malicious domains from being shared.<br \/>\nFILE &#8211; In this Aug. 11, 2019, file photo an iPhone displays a Facebook page in New Orleans. Facebook says hackers in China\u2026<br \/>\nFILE &#8211; An iPhone displays a Facebook page, Aug. 11, 2019.<\/p>\n<p>The social media company said it was able to trace the activity to Iran, in part because of the distinctive malware, known to have been developed by Mahak Rayan Afraz, a Tehran-based company with links to Iran&#8217;s Islamic Revolutionary Guard Corps.<\/p>\n<p>Mandiant Threat Intelligence, a private cybersecurity company, said Thursday that it agreed with Facebook&#8217;s assessment that Iran, and the IRGC in particular, was behind the campaign.<\/p>\n<p>Tortoiseshell &#8220;has historically targeted people and organizations affiliated with the U.S. military and information technology providers in the Middle East since at least 2018,&#8221; Mandiant Senior Principal Analyst Sarah Jones said in an email.<\/p>\n<p>Jones also said it was noteworthy that some of the fake domains associated with the Iranian campaign used the name of former U.S. President Donald Trump, including, &#8220;trumphotel[.]net&#8221;, &#8220;trumporganization[.]world&#8221;, and &#8220;trumporganizations[.]com&#8221;.<\/p>\n<p>&#8220;Domains such as these could suggest social engineering associated with U.S. political topics,&#8221; Jones said. &#8220;We have no evidence that these domains were operationalized or used to target anyone affiliated with the Trump family or properties.&#8221;<\/p>\n<p>Facebook, which discovered the hacking campaign, did not comment on whether Iran managed to steal any critical or sensitive data.<\/p>\n<p>U.S. military officials also declined to speak about what, if anything, the Iranian hackers were able to steal.<\/p>\n<p>&#8220;For operational security purposes, U.S. Cyber Command does not discuss operations, intelligence and cyber planning,&#8221; a spokesperson told VOA.<\/p>\n<p>&#8220;The threats posed by social media interactions are not unique to any particular social media platform and Department of Defense personnel must be cautious when engaging online,&#8221; the spokesperson added.<\/p>\n<p>&#8216;Significant threat&#8217;<\/p>\n<p>U.S. intelligence officials have been increasingly concerned about Iran&#8217;s growing capabilities and aggressiveness in cyberspace.<\/p>\n<p>In its annual Worldwide Threat Assessment, published in April, the Office of the Director of National Intelligence called Tehran &#8220;a significant threat to the security of U.S. and allied networks and data.&#8221;<\/p>\n<p>&#8220;We expect Tehran to focus on online covert influence, such as spreading disinformation about fake threats or compromised election infrastructure and recirculating anti-U.S. content,&#8221; the report said.<\/p>\n<p>The U.S. intelligence community, earlier this year, also accused Iran of meddling in the 2020 U.S. presidential election, carrying out a &#8220;multi-pronged covert influence campaign intended to undercut former President Trump&#8217;s reelection prospects.&#8221;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>VOA \u2014 Iran appears to be intensifying its effort to exploit U.S. and Western targets in cyberspace, running a campaign aimed at manipulating American military personnel and defense companies on social media. Tehran&#8217;s latest campaign, orchestrated on Facebook by a group known as Tortoiseshell, used a series of sophisticated, fake online personas to make contact [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":96907,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":"","_links_to":"","_links_to_target":""},"categories":[16],"tags":[],"class_list":["post-96906","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-recposts"],"translation":{"provider":"WPGlobus","version":"3.0.2","language":"en","enabled_languages":["fa","en"],"languages":{"fa":{"title":true,"content":false,"excerpt":false},"en":{"title":true,"content":true,"excerpt":false}}},"_links":{"self":[{"href":"https:\/\/PERSIAN-HERITAGE.COM\/en\/wp-json\/wp\/v2\/posts\/96906","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/PERSIAN-HERITAGE.COM\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/PERSIAN-HERITAGE.COM\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/PERSIAN-HERITAGE.COM\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/PERSIAN-HERITAGE.COM\/en\/wp-json\/wp\/v2\/comments?post=96906"}],"version-history":[{"count":2,"href":"https:\/\/PERSIAN-HERITAGE.COM\/en\/wp-json\/wp\/v2\/posts\/96906\/revisions"}],"predecessor-version":[{"id":96909,"href":"https:\/\/PERSIAN-HERITAGE.COM\/en\/wp-json\/wp\/v2\/posts\/96906\/revisions\/96909"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/PERSIAN-HERITAGE.COM\/en\/wp-json\/wp\/v2\/media\/96907"}],"wp:attachment":[{"href":"https:\/\/PERSIAN-HERITAGE.COM\/en\/wp-json\/wp\/v2\/media?parent=96906"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/PERSIAN-HERITAGE.COM\/en\/wp-json\/wp\/v2\/categories?post=96906"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/PERSIAN-HERITAGE.COM\/en\/wp-json\/wp\/v2\/tags?post=96906"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}