Iran Operated Fake Human-Resources Firm to Root Out Unfriendly Spies, Researchers Say

FILE PHOTO: Figurines with computers are seen in front of USA and Iran flags in this illustration taken, September 10, 2022. REUTERS/Dado Ruvic/Illustration/File Photo
FILE PHOTO: Figurines with computers are seen in front of USA and Iran flags in this illustration taken, September 10, 2022. REUTERS/Dado Ruvic/Illustration/File Photo
TT

Iran Operated Fake Human-Resources Firm to Root Out Unfriendly Spies, Researchers Say

FILE PHOTO: Figurines with computers are seen in front of USA and Iran flags in this illustration taken, September 10, 2022. REUTERS/Dado Ruvic/Illustration/File Photo
FILE PHOTO: Figurines with computers are seen in front of USA and Iran flags in this illustration taken, September 10, 2022. REUTERS/Dado Ruvic/Illustration/File Photo

An Iranian hacking group ran a fake professional recruiting business to lure national security officials across Iran, Syria and Lebanon into a cyber espionage trap, according to new research by US cybersecurity firm Mandiant, a division of Alphabet's Google Cloud.
Researchers said the hackers are loosely connected to a group known as APT42 or Charming Kitten, which was recently accused of hacking the US presidential campaign of Republican candidate Donald Trump. APT42 is widely attributed to an intelligence division of the Iranian Revolutionary Guard, an expansive military organization based in Tehran. The FBI has said it is investigating APT42’s ongoing efforts to interfere in the 2024 US election, Reuters reported.
The mission uncovered by Mandiant dates back to at least 2017 and was active until recently. At different times, the Iranians made their operation appear as if it was controlled by Israelis. Analysts say the likely purpose of the impersonation was to identify individuals in the Middle East who were willing to sell secrets to Israel and other Western governments. It targeted military and intelligence staff associated with Iran’s allies in the region.
“The data collected by this campaign may support the Iranian intelligence apparatus in pinpointing individuals who are interested in collaborating with Iran’s perceived adversarial countries,” the Mandiant report said. “The collected data may be leveraged to uncover human intelligence (HUMINT) operations conducted against Iran and to persecute any Iranians suspected to be involved in these operations.”
Iran's mission to the United Nations did not immediately respond to a request for comment.
Mandiant found that the digital spies used a network of websites impersonating human resources companies to manipulate Farsi-speaking targets. The bogus firms were named VIP Human Solutions, also known as VIP Recruitment, Optima HR and Kandovan HR, among others. They leveraged dozens of inauthentic online profiles on Telegram, Twitter, YouTube and social media platform Virasty, which is popular in Iran, to promote the front companies. Nearly all the associated internet accounts have since been removed.
“VIP Recruitment, a center for recruiting respected military personnel into the army, security services and intelligence from Syria and Hezbollah, Lebanon,” said a statement on one of the websites. “Join us to help each other impact the world. Our duty is to protect your privacy.”
The hackers cast a wide net by using various social media platforms to disseminate links about their fake HR scheme. It is unclear how many targets ultimately fell for the ruse. The collected data, which included addresses, contact details and other resume-related data, could still be exploited in the future, Mandiant said.



CIA Official: Suspects in Foiled Plot to Attack Taylor Swift Shows Aimed to Kill 'Tens Of Thousands'

Security officers stand outside Wembley Stadium ahead of a Taylor Swift concert, following the cancellation of three Taylor Swift concerts in Vienna because of a planned attack, in London, Britain, August 15, 2024.  REUTERS/Toby Melville
Security officers stand outside Wembley Stadium ahead of a Taylor Swift concert, following the cancellation of three Taylor Swift concerts in Vienna because of a planned attack, in London, Britain, August 15, 2024. REUTERS/Toby Melville
TT

CIA Official: Suspects in Foiled Plot to Attack Taylor Swift Shows Aimed to Kill 'Tens Of Thousands'

Security officers stand outside Wembley Stadium ahead of a Taylor Swift concert, following the cancellation of three Taylor Swift concerts in Vienna because of a planned attack, in London, Britain, August 15, 2024.  REUTERS/Toby Melville
Security officers stand outside Wembley Stadium ahead of a Taylor Swift concert, following the cancellation of three Taylor Swift concerts in Vienna because of a planned attack, in London, Britain, August 15, 2024. REUTERS/Toby Melville

The suspects in the foiled plot to attack Taylor Swift concerts in Vienna earlier this month sought to kill “tens of thousands” of fans before the CIA discovered intelligence that disrupted the planning and led to arrests, the agency's deputy director said.
The CIA notified Austrian authorities of the scheme, which allegedly included links to the ISIS group. The intelligence and subsequent arrests ultimately led to the cancellation of three sold-out Eras Tour shows, devastating fans who had traveled across the globe to see Swift in concert.
CIA Deputy Director David Cohen addressed the failed plot during the annual Intelligence and National Security Summit, held this week in Maryland, The Associated Press said.
“They were plotting to kill a huge number — tens of thousands of people at this concert, including I am sure many Americans — and were quite advanced in this," Cohen said Wednesday. “The Austrians were able to make those arrests because the agency and our partners in the intelligence community provided them information about what this ISIS-connected group was planning to do.”
Austrian officials said the main suspect, a 19-year-old Austrian man, was inspired by the ISIS group. He allegedly planned to attack outside the stadium, where upwards of 30,000 fans were expected to gather, with knives or homemade explosives. Another 65,000 fans were likely to be inside the venue. Investigators discovered chemical substances and technical devices during a raid of the suspect's home.
The 19-year-old’s lawyer has said the allegations were “overacting at its best,” and contended Austrian authorities were “presenting this exaggeratedly” in order to get new surveillance powers.
Swift broke her silence about the cancellations last week after her London shows had concluded.
“Having our Vienna shows canceled was devastating,” she wrote in a statement posted to Instagram. “The reason for the cancellations filled me with a new sense of fear, and a tremendous amount of guilt because so many people had planned on coming to those shows.”
She thanked authorities — “thanks to them, we were grieving concerts and not lives,” she wrote — and said she waited to speak until the European leg of her Eras Tour concluded to prioritize safety.
“Let me be very clear: I am not going to speak about something publicly if I think doing so might provoke those who would want to harm the fans who come to my shows,” she wrote.
Concert organizer Barracuda Music said it canceled the three-night Vienna run that would have begun Aug. 8 because the arrests made in connection to the conspiracy were too close to showtime.
The main suspect and a 17-year-old were taken into custody on Aug. 6, the day before the cancellations were announced. A third suspect, 18, was arrested Aug. 8.
The shows in London, the next stop after Vienna, came on the heels of a stabbing at a Swift-themed dance class that left three little girls dead in the UK In a statement issued after the Southport attack, Swift said she was “just completely in shock” and “at a complete loss for how to ever convey my sympathies to these families.” News outlets reported that Swift met with some of the survivors backstage in London.
The Vienna plot also drew comparisons to a 2017 attack by a suicide bomber at an Ariana Grande concert in Manchester, England, that killed 22 people. The bomb detonated at the end of Grande’s concert as thousands of young fans were leaving, becoming the deadliest extremist attack in the United Kingdom in recent years.
Cohen on Wednesday praised the CIA's work in preventing the planned violence, saying that other counterterrorism “successes” in foiling plots typically go unheralded.
“I can tell you within my agency, and I'm sure in others, there were people who thought that was a really good day for Langley,” he said, referring to the CIA headquarters. “And not just the Swifties in my workforce.”
The record-smashing tour is on hiatus until the fall.