Skip to main content

Facebook says Iranian hackers spied on US military personnel using fake accounts

The social media company said the hackers baited targets into clicking on malicious links that would infect their devices with malware.

Facebook logos
A computer screen displays logos associated with the social networking site Facebook, taken in Manchester, England, on March 22, 2018. — OLI SCARFF/AFP via Getty Images

A group of Iranian hackers used fake Facebook accounts to target US military personnel, as well as defense and aerospace workers, the social media company said Thursday. 

The hacking group, known as Tortoiseshell, used Facebook and other social media platforms to engage with targets before infecting their devices with malware for espionage purposes. According to Facebook, a fake account would “contact its targets, build trust and trick them into clicking on malicious links.”

Facebook said it has removed "fewer than 200” fraudulent accounts linked to the operation, which often claimed to be recruiters or employees of various defense and aerospace companies. Others said they worked in hospitality, medicine, journalism, nongovernmental organizations or the airline industry.

Their tactics included setting up fake recruiting websites and spoofing a US Department of Labor job portal. They also gave their targets links to malicious Microsoft Excel spreadsheets.

SUBSCRIBER EXCLUSIVE

Continue reading this exclusive analysis

Original reporting and analysis unavailable elsewhere. Subscribe to AL-MONITOR to read this story and access everything we publish