HomeSecurityIranian hackers pose as academics to steal passwords

Iranian hackers pose as academics to steal passwords

Iranian hackers pose as academics in new phishing campaign.

Iranian academic hackers
Iranian hackers pose as academics to steal passwords

Iranian hackers have carried out phishing attacks, posing as academics from a UK university. Their aim was to steal passwords of Middle East experts from universities, think tanks and the media.

See also: Iranians use fake Instagram accounts to attract and harm Israelis

Security researchers at Proofpoint dubbed the campaign Operation SpoofedScholars. Iranian hackers attempted to collect victims' passwords with fake pages that supposedly invited them to speak at a webinar on Middle East-related topics.

Proofpoint researchers have linked the phishing campaign to an Iranian-based APT group known as TA453, Charming Kitten , and Phosphorus. The group is said to be working on behalf of the Islamic Revolutionary Guard Corps (IRGC), a branch of the Iranian armed forces.

The attackers used Gmail addresses that resembled emails from academics at the School of Oriental and African Studies (SOAS) at the University of London.

Iranian hackers pose as academics to steal passwords

The attackers sent messages to the victims, inviting them to an online conference on “US Security Challenges in the Middle East.” The emails also said that telephone contact was possible for more details, which is quite unusual.

Useful information: Phishing: Without training, one in three falls victim to an attack

Finally, the attackers sent a personalized “registration link,” leading to a supposed SOAS webinar platform.

In reality, a legitimate site belonging to SOAS Radio, University of London, was used, but it had been compromised by hackers. Victims were invited to log in to the platform via an email address. Depending on the email provider, there were different links.

The options included: Google, Yahoo, Microsoft, iCloud, Facebook and more. If the user clicked on a link, they were taken to a spoofed version of the email provider's login page. From there, Iranian hackers could steal the victims' usernames and passwords.

Researchers are convinced that the campaign is linked to Iran.

“The connection is based on similarities to previous TA453 campaigns. TA453 often uses free email providers to impersonate individuals familiar with their targets (to increase the likelihood of a successful breach),” said Sherrod DeGrippo, a Proofpoint executive.

See also: Kaseya: Warns of phishing campaign promoting fake security updates

academic phishing

Researchers say Iranian hackers are posing as academics and stealing credentials for future phishing attacks.

It is not known whether the attackers were able to steal any information. The compromised site has been removed from SOAS, however.

“As soon as we became aware of the compromised site, we immediately fixed it and reported the breach. We have reviewed how this happened and have taken steps to further improve the protection of these systems,” a SOAS spokesperson said.

Source: ZDNet

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS