Facebook: Iran-based Hackers Used Site to Target US Military Personnel

A man types on a computer keyboard in front of the displayed cyber code in this illustration picture taken on March 1, 2017. REUTERS/Kacper Pempel/Illustration
A man types on a computer keyboard in front of the displayed cyber code in this illustration picture taken on March 1, 2017. REUTERS/Kacper Pempel/Illustration
TT

Facebook: Iran-based Hackers Used Site to Target US Military Personnel

A man types on a computer keyboard in front of the displayed cyber code in this illustration picture taken on March 1, 2017. REUTERS/Kacper Pempel/Illustration
A man types on a computer keyboard in front of the displayed cyber code in this illustration picture taken on March 1, 2017. REUTERS/Kacper Pempel/Illustration

Facebook said on Thursday it had taken down about 200 accounts run by a group of hackers in Iran as part of a cyber-spying operation that targeted mostly US military personnel and people working at defense and aerospace companies.

The social media giant said the group, dubbed 'Tortoiseshell' by security experts, used fake online personas to connect with targets, build trust sometimes over the course of several months and drive them onto other sites where they were tricked into clicking malicious links that would infect their devices with spying malware.

"This activity had the hallmarks of a well-resourced and persistent operation, while relying on relatively strong operational security measures to hide who's behind it," Facebook's investigations team said in a blog post, according to Reuters.

The group, Facebook said, made fictitious profiles across multiple social media platforms to appear more credible, often posing as recruiters or employees of aerospace and defense companies.

Microsoft-owned LinkedIn said it had removed a number of accounts and Twitter said it was "actively investigating" the information in Facebook's report.

Facebook said the group used email, messaging and collaboration services to distribute the malware, including through malicious Microsoft Excel spreadsheets.

A Microsoft spokesperson said in a statement it was aware of and tracking this actor and that it takes action when it detects malicious activity.

Alphabet Inc said it had detected and blocked phishing on Gmail and issued warnings to its users. Workplace messaging app Slack Technologies Inc said it had acted to take down the hackers who used the site for social engineering and shut down all Workspaces that violated its rules.

The hackers also used tailored domains to attract its targets, Facebook said, including fake recruiting websites for defense companies, and it set up online infrastructure that spoofed a legitimate job search website for the US Department of Labor.

Facebook said the hackers mostly targeted people in the United States, as well as some in the United Kingdom and Europe.

Facebook declined to name the companies whose employees were targeted but said it was notifying the individuals targeted.

The campaign appeared to show an expansion of the group's activity, which had previously been reported to concentrate mostly on the I.T. and other industries in the Middle East, Facebook said.

The investigation found that a portion of the malware used by the group was developed by Mahak Rayan Afraz (MRA), an I.T. company based in Tehran with ties to the Revolutionary Guard Corps.



Cuba Left Reeling after Hurricane Ravages Island

A man rides a bicycle along a flooded street after the passage of Hurricane Rafael in Batabano, Mayabeque province, Cuba, on November 7, 2024. (Photo by Yamil LAGE / AFP)
A man rides a bicycle along a flooded street after the passage of Hurricane Rafael in Batabano, Mayabeque province, Cuba, on November 7, 2024. (Photo by Yamil LAGE / AFP)
TT

Cuba Left Reeling after Hurricane Ravages Island

A man rides a bicycle along a flooded street after the passage of Hurricane Rafael in Batabano, Mayabeque province, Cuba, on November 7, 2024. (Photo by Yamil LAGE / AFP)
A man rides a bicycle along a flooded street after the passage of Hurricane Rafael in Batabano, Mayabeque province, Cuba, on November 7, 2024. (Photo by Yamil LAGE / AFP)

Cuba was left reeling Thursday after a fierce Category 3 hurricane ripped across the island, knocking out the country’s power grid, downing trees and damaging infrastructure. No fatalities were immediately reported.
Hurricane Rafael crossed a western portion of Cuba on Wednesday evening about 75 kilometers west of Havana.
Some 50,000 people took shelter in Havana, with thousands more doing the same in regions south and just west of the capital since they lived in flood zones or in flimsy homes. The main road from Havana to the southern coastal city of Batabanó was strewn with dozens of utility poles and wires.
Lázaro Guerra, electricity director for the Ministry of Energy and Mines, said power had been partially restored in the island’s western region and that generation units were powering back up. But he warned that restoring power would be slow-going as crews took safety precautions.
As Rafael plowed across Cuba on Wednesday evening it slowed to a Category 2 hurricane as it chugged into the Gulf of Mexico before heading toward Mexico, according to the National Hurricane Center in Miami.
Late Thursday morning, the hurricane was located about 200 miles (320 kilometers) west-northwest of Havana. It had maximum sustained winds of 100 mph (345 kph) and was moving west-northwest at 9 mph (15 kph).
Earlier in the week, Rafael brushed past Jamaica and battered the Cayman Islands, downing trees and power lines and unleashing heavy flooding in some areas.
Authorities in Jamaica are searching for a couple last seen inside a car that was swept away by floodwaters, police told Radio Jamaica News.
Thousands of customers in Jamaica and Little Cayman remained without power as crews worked to restore electricity after the storm.
Rafael was expected to keep weakening as it spins over open waters and heads toward northern Mexico, although the hurricane center warned there was “above average uncertainty” in the storm's future track.
Meanwhile, many Cubans were left picking up the pieces from Wednesday night, after a rocky few weeks in the Caribbean nation. In October, the island was hit by a one-two punch. First, it was hit by island-wide blackouts stretching on for days, a product of the island’s energy crisis. Shortly after, it was slapped by powerful hurricane that struck the eastern part of the island and killed at least six people.
The disasters have stoked discontent already simmering in Cuba amid an ongoing economic crisis, which has pushed many to migrate from Cuba.
Classes and public transport were suspended on parts of the island and authorities canceled flights in and out of Havana and Varadero. Thousands of people in the west of the island had been evacuated as a preventative measure.
Rafael is the 17th named storm of the season.