HomeSecurityIranian hackers pose as German Model Agency

Iranian hackers pose as German modeling agency

In a sophisticated cyberespionage campaign, Iranian hackers have created a fake website pretending to belong to a legitimate German modeling agency, with the aim of gathering information and potentially targeting specific individuals.

See also: Iranian hackers target UAE aviation sector with Golang backdoor

Iranian hackers Modeling Agency

The operation, revealed in early May 2025, involves advanced tracking techniques and visitor profiling, designed to selectively identify and compromise targets of interest, particularly individuals associated with Iranian dissident communities. The Iranian hackers precisely copied the website of Hamburg-based modeling agency Mega Model Agency , replicating its branding, layout, and content, to create a convincing scam.

However, this deceptive website copy contains disguised JavaScript code, which is activated upon visitor access and collects detailed information about potential targets, such as browser settings, screen resolution, IP addresses, and unique browsing “fingerprints.”

Palo Alto Networks researchers identified this operation as likely originating from a state-sponsored Iranian threat group, which is affiliated with Agent Serpens , also known as APT35 or Charming Kitten . The group has a history of targeting Iranian dissidents, journalists, and activists living abroad, with a particular focus on Germany.

See also: US and Israel warn about Iranian group Cotton Sandstorm

This campaign demonstrates a worrying development in social engineering, as cybercriminals created a completely fictitious model profile named “Shir Benzion” on the fake website. This profile replaces the information of an existing model and includes a currently inactive link to a “private album,” suggesting preparations for targeted phishing or malware distribution.

Iranian hackers pose as German modeling agency
Iranian hackers pose as German modeling agency

The technical sophistication of the operation lies in the carefully disguised JavaScript code embedded in the fake website. Upon analysis, the researchers found that the script performs multiple data collection simultaneously. Specifically, it detects browser languages ​​and plugins, while also recording screen resolution to determine the visitor’s computing environment. Even more intrusively, the code exploits the WebRTC to reveal both the visitor’s local and public IP addresses, creating a complete identification profile.

The script then applies canvas fingerprinting techniques, generating SHA-256 to uniquely identify each device. The collected data is formatted in JSON format and sent to an endpoint posing as an advertising analytics service (/ads/track), revealing the perpetrators’ intent to mask their tracking activities behind seemingly legitimate web traffic.

See also: Iranian hackers sell access to critical infrastructure as brokers

The use of techniques such as canvas fingerprinting and WebRTC IP leakage are among the most sophisticated methods of cyber surveillance, as they allow attackers to bypass traditional anonymity measures, such as VPNs and private browsers. What makes such attacks particularly dangerous is the imitation of legitimate websites and the use of obfuscation techniques, which make them difficult to detect by traditional security tools.

Source: cybersecuritynews

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS