Politics
Facebook says group of Iranian-based ‘Tortoiseshell’ hackers used 200 fake accounts to target US military with spyware
FACEBOOK said a group of Iranian-based “Tortoiseshell” hackers used 200 fake accounts to target US military with spyware.
The social media giant announced that it had removed the accounts, which were also targeting people who work at defense and aerospace companies, on Thursday.
Facebook said 200 fake accounts that were targeting US military personnel were removed
Getty – ContributorThe hackers would lure people off of Facebook with malicious links[/caption]
The hackers, dubbed “Tortoiseshall” by security experts, would use the fake accounts to connect with their targets and build trust over the course of months before driving people onto other sites that contained malicious links.
Once the targets clicked the links, their devices would be infected with spying malware.
Facebook‘s investigations team said the operation was “well-sourced and persistent” and relied on “relatively strong operational security measures to hide who’s behind it.”
The operation involved four phases and began with thorough research to find targets, Mike Dvilyanksi, Facebook head of cyber espionage investigations, told CBS News.
“We saw a big investment in this phase,” he said. “There’s a large research component that goes into that type of targeting.”
The next phase involved creating fake personas across multiple social media accounts to appear more realistic, Dvilyanski said.
He said that the malware the hackers would install “was target-tailored to understand the type of software that the device was running and the networks that it was connected to, to presumably assist in future targeting efforts for the attackers.”
Facebook had reportedly been tracking Tortoiseshell’s activity since mid-2020.
The hackers would apparently often pose as recruiters or employees of aerospace or defense companies.
Most read in News
Facebook said the hackers mostly targeted people in the US, though some in the UK and Europe were targeted as well.
The social media giant did not name the companies whose employees were targeted but said the people who were targeted were being notified.
The company said “fewer than 200 individuals” were targeted.
GettyFacebook said fewer than 200 people were targeted[/caption]
