Iran operated fake human-resources firm to root out unfriendly spies, researchers say

By Christopher Bing

(Reuters) - An Iranian hacking group ran a fake professional recruiting business to lure national security officials across Iran, Syria and Lebanon into a cyber espionage trap, according to new research by U.S. cybersecurity firm Mandiant, a division of Alphabet (NASDAQ:GOOGL )'s Google Cloud. 

Researchers said the hackers are loosely connected to a group known as APT42 or Charming Kitten, which was recently accused of hacking the U.S. presidential campaign of Republican candidate Donald Trump. APT42 is widely attributed to an intelligence division of the Iranian Revolutionary Guard, an expansive military organization based in Tehran. The FBI has said it is investigating APT42’s ongoing efforts to interfere in the 2024 U.S. election. 

The mission uncovered by Mandiant dates back to at least 2017 and was active until recently. At different times, the Iranians made their operation appear as if it was controlled by Israelis. Analysts say the likely purpose of the impersonation was to identify individuals in the Middle East who were willing to sell secrets to Israel and other Western governments. It targeted military and intelligence staff associated with Iran’s allies in the region. 

“The data collected by this campaign may support the Iranian intelligence apparatus in pinpointing individuals who are interested in collaborating with Iran’s perceived adversarial countries,” the Mandiant report said. “The collected data may be leveraged to uncover human intelligence (HUMINT) operations conducted against Iran and to persecute any Iranians suspected to be involved in these operations.”

Iran's mission to the United Nations did not immediately respond to a request for comment. 

Mandiant found that the digital spies used a network of websites impersonating human resources  companies to manipulate Farsi-speaking targets. The bogus firms were named VIP Human Solutions, also known as VIP Recruitment, Optima HR and Kandovan HR, among others. They leveraged dozens of inauthentic online profiles on Telegram, Twitter, YouTube and social media platform Virasty, which is popular in Iran, to promote the front companies. Nearly all the associated internet accounts have since been removed. 



“VIP Recruitment, a center for recruiting respected military personnel into the army, security services and intelligence from Syria and Hezbollah, Lebanon,” said a statement on one of the websites. “Join us to help each other impact the world. Our duty is to protect your privacy.” 

The hackers cast a wide net by using various social media platforms to disseminate links about their fake HR scheme. It is unclear how many targets ultimately fell for the ruse. The collected data, which included addresses, contact details and other resume-related data, could still be exploited in the future, Mandiant said. 

Source: Investing.com

Останні публікації
Oklo target nearly doubled at Wedbush on AI-driven demand for nuclear energy
24.01.2025 - 18:00
Crypto markets lose steam after Trump's first policy move
24.01.2025 - 18:00
Combination of Google's TPU-DeepMind units may be worth $700 bn - DA Davidson
24.01.2025 - 18:00
British American Tobacco, Altria shares rise after menthol ban proposal dropped
24.01.2025 - 18:00
Morocco stocks higher at close of trade; Moroccan All Shares up 0.34%
24.01.2025 - 18:00
Commerzbank says no talks with UniCredit until specific proposal made
24.01.2025 - 18:00
Venture Global aims for $64 billion valuation at debut in test for energy IPOs
24.01.2025 - 18:00
Intuitive Machines stock surges on NASA contract award
24.01.2025 - 18:00
International Paper's $7.2 billion acquisition of DS Smith gets EU approval
24.01.2025 - 18:00
Short-term stock optimism soars among retail investors, AAII survey shows
24.01.2025 - 18:00
Venture Global shares likely to open up to 6% above IPO price
24.01.2025 - 18:00
Intuitive Surgical, American Express Stir Friday's Market Cap Stock Movers
24.01.2025 - 18:00
BMW joins Chinese EV makers in filing EU court challenge to tariffs
24.01.2025 - 18:00
Turkey stocks lower at close of trade; BIST 100 down 0.08%
24.01.2025 - 18:00
Diageo stock jumps on possible Guinness sale
24.01.2025 - 18:00

© Analytic DC. All Rights Reserved.

new
Аналіз ринку Як вплине завтра звіт NFP на курс долара США?