Researchers tracking the activities of advanced hacking groups (APTs) originating from China, North Korea, Iran and Turkey say that journalists and organizations media. Hackers either masquerade as journalists or attack media organizations because they can gain access to important information that could help expand a cyberespionage.

Proofpoint analysts have been closely monitoring these activities for the past year (from 2021 to 2022) and recently published a report on several APT groups impersonating or targeting journalists.
See also: App Store: 84 scammy apps secretly charge iPhone users
A hacking group said to be linked to China and known as “Zirconium” (TA412) has been confirmed to be targeting American journalists since early 2021. The hackers sent emails containing trackers that alerted when the messages.
This simple trick also allowed the attackers to obtain the target's public IP address from which they could gather more information, such as the victim's location and Internet (ISP).
Since February 2022, the Chinese group Zirconium has launched new campaigns targeting journalists, focusing primarily on those reporting on the Russia-Ukraine.
In April 2022, Proofpoint observed another Chinese APT group tracked as TA459, which targeted journalists with files that, upon opening, installed a copy of the Chinoxy malware on victims’ devices. According to researchers, the group targeted media outlets interested in foreign policy in Afghanistan.
See also: Play Store: Android malware with over 3 million installations
Additionally, North Korean hackers (TA404 group) were identified targeting media organization personnel in spring 2022, using fake job postings as a lure.
Finally, Turkish threat actors known as TA482 are conducting campaigns aimed at collecting credentials and stealing journalists' social media accounts.

Hackers impersonate journalists
However, not all hackers are interested in compromising accounts belonging to journalists. Some impersonate well-known journalists to directly reach other targets.
Proofpoint has seen this tactic primarily from Iranian groups, such as TA453 (also known as Charming Kitten), which sent emails to academics and other experts in the Middle East, posing as journalists.
Another example is the TA456 (also known as Tortoiseshell), which sends emails with purported newsletters from the Guardian or Fox news, hoping to deliver malware to the victim's device.
See also: Amazon admitted to providing Ring videos to authorities without owners' knowledge
Proofpoint researchers are placing particular emphasis on the activity of Iranian hackers TA457, who, between September 2021 and March 2022, launched media targeting campaigns every two to three weeks.
Journalists and media organizations in general will always be a favorite target for hackers. Media organizations and employees are open to the public, so they can become victims of social engineering and other hacking tactics aimed at gaining access to important information.
Source: www.bleepingcomputer.com
