Security News > 2021 > July > Facebook: Iranian Hackers Target Military, Aerospace Entities in the US

Recent activity that Facebook associated with the group focused on military personnel, defense organizations, and aerospace entities primarily in the United States and, to a lesser extent, the U.K. and Europe, showing an escalation of the group's cyberespionage activities.
Today, Facebook revealed that it took action against similar attacks from the Iranian hacking group, which leveraged its online platform to lure victims into downloading malware.
The activity observed bfy Facebook was part of a wider, cross-platform cyber espionage operation that leveraged the social media platform for social engineering rather than direct malware delivery.
The hackers were posing as recruiters and employees of defense and aerospace companies, as journalists, or as employees of NGOs and organizations in hospitality, medicine, and airline industries.
The hackers also deployed multiple domains tailored to specific targets in the aerospace and defense industries, including recruiting portals, a website that spoofed a legitimate US Department of Labor job search site, and domains that spoofed major e-mail providers and URL-shortening services.
One of the malware used by the group is believed to have been developed by Tehran-based IT company Mahak Rayan Afraz, which appears to be tied to the Islamic Revolutionary Guard Corps, Facebook also notes.
News URL
Related news
- Russian hackers attack Western military mission using malicious drive (source)
- Iranian Hackers Maintain 2-Year Access to Middle East CNI via VPN Flaws and Malware (source)
- Luna Moth extortion hackers pose as IT help desks to breach US firms (source)
- Hackers behind UK retail attacks now targeting US companies (source)
- Chinese hackers breach US local governments using Cityworks zero-day (source)