Wednesday Jun 18, 2025
NEWSLETTER
www.israelhayom.com
  • Home
  • Iran War
  • News
    • Gaza War
    • US Election Coverage
    • Middle East
    • Cyber & Internet
    • Business & Finance
  • Opinions
  • Jewish World
    • Archaeology
    • Antisemitism
  • Lifestyle
    • Food
    • Travel
    • Fashion
    • Culture
  • Magazine
    • Feature
    • Analysis
    • Explainer
  • In Memoriam
www.israelhayom.com
  • Home
  • Iran War
  • News
    • Gaza War
    • US Election Coverage
    • Middle East
    • Cyber & Internet
    • Business & Finance
  • Opinions
  • Jewish World
    • Archaeology
    • Antisemitism
  • Lifestyle
    • Food
    • Travel
    • Fashion
    • Culture
  • Magazine
    • Feature
    • Analysis
    • Explainer
  • In Memoriam
www.israelhayom.com
Home Science & Technology Cyber & Internet Social Media

Facebook says Iranian hackers used site to spy on US troops

Facebook investigation finds hackers used malware developed by company with ties to Revolutionary Guards. Activity had "hallmarks of a well-resourced, persistent operation," social media giant says.

by  Reuters and ILH Staff
Published on  07-16-2021 12:30
Last modified: 07-16-2021 12:42
Facebook says Iranian hackers used site to spy on US troopsReuters / Dado Ruvic

Facebook has taken down about 200 accounts that targeted mostly US military personnel | File photo: Reuters / Dado Ruvic

Share on FacebookShare on Twitter

Facebook said on Thursday it had taken down about 200 accounts run by a group of hackers in Iran as part of a cyber-spying operation that targeted mostly US military personnel and people working at defense and aerospace companies.

Follow Israel Hayom on Facebook and Twitter

The social media giant said the group, dubbed 'Tortoiseshell' by security experts, used fake online personas to connect with targets, build trust sometimes over the course of several months, and drive them onto other sites where they were tricked into clicking malicious links that infected their devices with malware.

"This activity had the hallmarks of a well-resourced and persistent operation while relying on relatively strong operational security measures to hide who's behind it," Facebook's investigations team said in a blog post.

The group, Facebook said, made fictitious profiles across multiple social media platforms to appear more credible, often posing as recruiters or employees of aerospace and defense companies. Microsoft-owned LinkedIn said it had removed a number of accounts, and Twitter said it was "actively investigating" the information in Facebook's report.

Facebook said the group used email, messaging, and collaboration services to distribute the malware, including through malicious Microsoft Excel spreadsheets. A Microsoft spokesperson said in a statement it was aware of and tracking the actor and that it takes action when it detects malicious activity.

Alphabet Inc's Google said it had detected and blocked phishing on Gmail and issued warnings to its users. Workplace messaging app Slack Technologies Inc said it had acted to take down the hackers who used the site for social engineering and shut down all Workspaces that violated its rules.

The hackers also used tailored domains to attract its targets, Facebook said, including fake recruiting websites for defense companies, and set up online infrastructure that spoofed a legitimate job search website for the US Department of Labor.

Facebook said the hackers mostly targeted people in the United States, as well as some in the United Kingdom and Europe, in a campaign running since mid-2020. It declined to name the companies whose employees were targeted, but its head of cyber espionage, Mike Dvilyanski, said it was notifying the "fewer than 200 individuals" who were targeted.

The campaign appeared to show an expansion of the group's activity, which had previously been reported to concentrate mostly on IT and other industries in the Middle East, according to Facebook. The investigation found that a portion of the malware used by the group was developed by Mahak Rayan Afraz, a Tehran-based IT company with ties to the Islamic Revolutionary Guard Corps.

Reuters could not immediately locate contact information for Mahak Rayan Afraz, and former employees of the firm did not immediately return messages sent via LinkedIn. Iran's mission to the United Nations in New York did not immediately respond to a request for comment.

MRA's alleged connection to Iranian state cyber espionage is not new. Last year, cybersecurity company Recorded Future said MRA was one of several contractors suspected of serving the IRGC's elite Quds Force.

Iranian government spies have long been suspected of farming out their mission to a host of domestic contractors.

Facebook said it had blocked the malicious domains from being shared and Google said it had added the domains to its "blocklist."

Subscribe to Israel Hayom's daily newsletter and never miss our top stories!

Tags: cybersecurityFacebookhackersIrantwitter

Related Posts

Who's with Israel, who's with Iran?Annegret Hilse/Reuters

Who's with Israel, who's with Iran?

by ILH Staff

Israel's image in the world has tanked during the Gaza war, but how is Western and global public opinion responding...

Which river, which sea: Pro-Palestinian activist confuses Rafah with EilatAP

Which river, which sea: Pro-Palestinian activist confuses Rafah with Eilat

by Neta Bar

South African activist Hasina Kathrada arrested in Egypt during Gaza march,, publishes route map revealing stunning geographic errors.

Erin Molan parts ways with Sky News Australia as network cancels her showMark Metcalfe/Getty Images

'Entire world should be incredibly grateful' – Australian journalist's message from Israel

by Tal Mizrahi

"The enemy of terrorism and Iran's Islamic regime is not just Israel, it's the entire Western world," Erin Molan tells...

Menu

Analysis 

Archaeology

Blogpost

Business & Finance

Culture

Exclusive

Explainer

Environment

 

Features

Health

In Brief

Jewish World

Judea and Samaria

Lifestyle

Cyber & Internet

Sports

 

Diplomacy 

Iran & The Gulf

Gaza Strip

Politics

Shopping

Terms of use

Privacy Policy

Submissions

Contact Us

About Us

The first issue of Israel Hayom appeared on July 30, 2007. Israel Hayom was founded on the belief that the Israeli public deserves better, more balanced and more accurate journalism. Journalism that speaks, not shouts. Journalism of a different kind. And free of charge.

All rights reserved to Israel Hayom

Hosted by sPD.co.il

  • Home
  • Iran War
  • News
    • Gaza War
    • US Election Coverage
    • Middle East
    • Cyber & Internet
    • Business & Finance
    • Sports
  • Opinions
  • Jewish World
    • Archaeology
    • Antisemitism
  • Lifestyle
    • Food
    • Travel
    • Fashion
    • Culture
  • Magazine
    • Feature
    • Analysis
    • Explainer
    • Environment & Wildlife
    • Health & Wellness
  • In Memoriam
  • Subscribe to Newsletter
  • Submit your opinion
  • Terms and conditions

All rights reserved to Israel Hayom

Hosted by sPD.co.il

Newsletter

[contact-form-7 id=”508379″ html_id=”isrh_form_Newsletter_en” title=”newsletter_subscribe”]

  • Home
  • Iran War
  • News
    • Gaza War
    • US Election Coverage
    • Middle East
    • Cyber & Internet
    • Business & Finance
    • Sports
  • Opinions
  • Jewish World
    • Archaeology
    • Antisemitism
  • Lifestyle
    • Food
    • Travel
    • Fashion
    • Culture
  • Magazine
    • Feature
    • Analysis
    • Explainer
    • Environment & Wildlife
    • Health & Wellness
  • In Memoriam
  • Subscribe to Newsletter
  • Submit your opinion
  • Terms and conditions

All rights reserved to Israel Hayom

Hosted by sPD.co.il