Article Details

Scrape Timestamp (UTC): 2024-08-24 07:00:43.724

Source: https://thehackernews.com/2024/08/meta-exposes-iranian-hacker-group.html

Original Article Text

Click to Toggle View

Meta Exposes Iranian Hacker Group Targeting Global Political Figures on WhatsApp. Meta Platforms on Friday became the latest company after Microsoft, Google, and OpenAI to expose the activities of an Iranian state-sponsored threat actor, who it said used a set of WhatsApp accounts that attempted to target individuals in Israel, Palestine, Iran, the U.K., and the U.S. The activity cluster, which originated from Iran, "appeared to have focused on political and diplomatic officials, and other public figures, including some associated with administrations of President Biden and former President Trump," Meta said. The social media giant attributed it to a nation-state actor tracked as APT42, which is also known as Charming Kitten, Damselfly, Mint Sandstorm (formerly Phosphorus), TA453, and Yellow Garuda. It's assessed to be linked to Iran's Islamic Revolutionary Guard Corps (IRGC). The adversarial collective is well-known for its use of sophisticated social engineering lures to spear-phish targets of interest with malware and steal their credentials. Earlier this week, Proofpoint revealed that the threat actor targeted a prominent Jewish figure to infect their machine with malware called AnvilEcho. Meta said the "small cluster" of WhatsApp accounts masqueraded as technical support for AOL, Google, Yahoo, and Microsoft, although the efforts are believed to be unsuccessful. The accounts have since been blocked. "We have not seen evidence that their accounts were compromised," the parent company of Facebook, Instagram, and WhatsApp said. "We have encouraged those who reported to us to take steps to ensure their online accounts are safe across the internet." The development comes as the U.S. government formally accused Iran of attempting to undermine U.S. elections, stoke divisive opinion among the American public, and erode confidence in the electoral process by amplifying propaganda and gathering political intelligence.

Daily Brief Summary

NATION STATE ACTIVITY // Meta Unveils Iranian Hackers Targeting Global Politics via WhatsApp

Meta Platforms identified efforts by Iranian state-backed hackers using WhatsApp to target political and diplomatic figures globally.

The offensive, attributed to APT42 also known as Charming Kitten and other aliases, focused on individuals affiliated with both current and former U.S. administrations.

The group, linked to Iran’s Islamic Revolutionary Guard Corps, employs sophisticated social engineering and malware for spying.

Earlier incidents revealed by Proofpoint involved the same group using malware called AnvilEcho to target prominent Jewish figures.

The hackers impersonated technical support for major tech firms like AOL and Microsoft to facilitate their attacks, though no account compromises have been confirmed.

Meta has taken action by blocking the implicated WhatsApp accounts and advising targeted users on strengthening their online security.

The exposure aligns with U.S. official accusations against Iran for attempting to disrupt the American electoral process and societal cohesion through misinformation and intelligence gathering.