HomeSecurityIranian hackers impersonate journalists and attract victims via WhatsApp - LinkedIn

Iranian hackers impersonate journalists and lure victims via WhatsApp – LinkedIn

Iranian hackers are posing as journalists to recruit targets via LinkedIn and make calls via WhatsApp to gain their trust, before sharing links to phishing pages and files infected with malware. When the target clicks on the links or downloads the files, a type of malware infects device .


The attacks appear to have taken place in July and August of this year, according to Israeli cybersecurity firm ClearSky, which published a report detailing the campaign. The hackers involved are believed to be members of the Iranian group CharmingKitten, also known as APT35, NewsBeef, Newscaster and Ajax.

Iranian hackers

Ohad Zaidenberg, a cybersecurity analyst at ClearSky, said the campaign, whose activity was recently observed, targets journalists covering Iranian affairs, academics, and human rights activists. Zaidenberg noted that the hackers first contacted the victims through LinkedIn messages, where they posed as Persian-speaking journalists working for German broadcaster Deutsche Welle and Israeli magazine Jewish Journal.


After luring their targets, the Iranian hackers would attempt to set up a WhatsApp call with them and discuss Iran-related cases in order to gain their trust. After this call, the potential victims would receive a link to a compromised domain , which would either have a phishing page or a ZIP file containing malware, through which they could steal the credentials .

LinkedIn attacks

Zaidenberg also said that the recent Iranian hacking operation is a continuation of attacks carried out in late 2019 and early 2020, when the same hackers again posed as journalists, supposedly working for the Wall Street Journal, to attract targets. However, in previous attacks, the Iranian hackers only used email and SMS to contact victims, but never called their targets.

Iranian hackers-attacks


Additionally, Zaidenberg pointed out in the ClearSky report that this TTP [technique, tactic, procedure] is unusual and poses a risk of attackers spoofing their identity, unlike emails. He added that if attackers have successfully overcome the phone “barrier,” they can gain more trust from the victim, compared to an email message.

WhatsApp attacks

Finally, Zaidenberg explained that the tactic used by Iranian hackers via WhatsApp and LinkedIn was not similar to their original tactic. It is a tactic that North Korean have been using for years, which includes setting up fake job interviews on Skype to hack Chile's ATM network and creating fake interviews via phone or WhatsApp calls with employees working at various defense companies.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS