In a sophisticated cyberespionage campaign, Iranian hackers have created a fake website pretending to belong to a legitimate German modeling agency, with the aim of gathering information and potentially targeting specific individuals.
See also: Iranian hackers target UAE aviation sector with Golang backdoor

The operation, revealed in early May 2025, involves advanced tracking techniques and visitor profiling, designed to selectively identify and compromise targets of interest, particularly individuals associated with Iranian dissident communities. The Iranian hackers precisely copied the website of Hamburg-based modeling agency Mega Model Agency , replicating its branding, layout, and content, to create a convincing scam.
However, this deceptive website copy contains disguised JavaScript code, which is activated upon visitor access and collects detailed information about potential targets, such as browser settings, screen resolution, IP addresses, and unique browsing “fingerprints.”
Palo Alto Networks researchers identified this operation as likely originating from a state-sponsored Iranian threat group, which is affiliated with Agent Serpens , also known as APT35 or Charming Kitten . The group has a history of targeting Iranian dissidents, journalists, and activists living abroad, with a particular focus on Germany.
See also: US and Israel warn about Iranian group Cotton Sandstorm
This campaign demonstrates a worrying development in social engineering, as cybercriminals created a completely fictitious model profile named “Shir Benzion” on the fake website. This profile replaces the information of an existing model and includes a currently inactive link to a “private album,” suggesting preparations for targeted phishing or malware distribution.

The technical sophistication of the operation lies in the carefully disguised JavaScript code embedded in the fake website. Upon analysis, the researchers found that the script performs multiple data collection simultaneously. Specifically, it detects browser languages and plugins, while also recording screen resolution to determine the visitor’s computing environment. Even more intrusively, the code exploits the WebRTC to reveal both the visitor’s local and public IP addresses, creating a complete identification profile.
The script then applies canvas fingerprinting techniques, generating SHA-256 to uniquely identify each device. The collected data is formatted in JSON format and sent to an endpoint posing as an advertising analytics service (/ads/track), revealing the perpetrators’ intent to mask their tracking activities behind seemingly legitimate web traffic.
See also: Iranian hackers sell access to critical infrastructure as brokers
The use of techniques such as canvas fingerprinting and WebRTC IP leakage are among the most sophisticated methods of cyber surveillance, as they allow attackers to bypass traditional anonymity measures, such as VPNs and private browsers. What makes such attacks particularly dangerous is the imitation of legitimate websites and the use of obfuscation techniques, which make them difficult to detect by traditional security tools.
Source: cybersecuritynews
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
