Social Engineering in the Name of Iran’s Islamic Revolution – Algemeiner
i24 News Iran continues to significantly develop its cyber capabilities for a variety of purposes. Only recently it was reported that Tehran had sought to attack Boston Childrens Hospital an attempt that the director of the Federal Bureau of Investigation called one of the most despicable he had ever seen. This incident is another indication of Irans boldness in operating cyber tools.
But the majority of Iranian cyberactivity is focused on social engineering for obtaining intelligence information. Tehran has been expanding its use as a tool, mainly through numerous inquiries to various experts on Iran. Iranian intelligence is attempting to obtain their information and assessments, and even trying to lure some to attend international conferences to recruit or kidnap them.
One of the authors of this article was recently contacted via email by someone claiming to be a leading journalist. When the email was met without a response, the same journalist called the author personally multiple times asking to schedule a test interview, with the phone number appearing registered from the country in which that media outlet was located.
Further investigation revealed this to likely be a phishing attempt by Charming Kitten, which is an advanced persistent threat actor linked to the Iranian government. There are lessons to be learned from this episode, namely the sloppiness in tradecraftthrough persistence and unaffiliated, personal email addresses of Iranian cyberwarriors. The fact that the Iranian operatives followed up after an email with phone calls demonstrates the aggressiveness with which the Islamic Republic is deploying these tools.
To uncover the Iranian pattern of action, we will focus in this article on the ways Iran uses social engineering tools and their unique characteristics to help possible targets identify that they are under Iranian attack. In general, most of the actions being carried out by Tehran are very amateurish and easy to identify, provided those who are subjects of interest to the Iranian government are aware of its tactics.
The use of social engineering tools has greatly expanded in recent years, mainly due to the difficulty of obtaining information from social media platforms in light of heightened awareness and actions taken by these networks aimed at protecting the privacy of their users.
Social engineering has thus become a kind of offensive WEBINT (Web Intelligence) tool that allows for receiving a lot of information about the relevant user.
The central principle when it comes to social engineering is trust. That is, the target will feel safe enough to provide details to the applicant (in this case Iranian intelligence). Iran also understands this principle very well, and therefore it seems that its operatives are working around the clock on these strategies.
If in the past Iran used assets that it established for dedicated operations which were for the most part very easy to identify, today the Iranian trend is to steal the identities of real people and to weaponize them.
That is, they are using the real names of people to approach their targets using emails that are very close to the real name of the stolen identity. This is usually a respectable approach made by a high-ranking expert (to persuade the target to work with him) during which there is an offer for a potential target to collaborate, whether it is via an interview, writing a joint article, or appearing at some conference. This modus operandi can be seen in a recent cyberoperation targeting Israels former Foreign Minister Tzipi Livni, where an Iranian hacker posed as an Israeli military official asking her to use her email password to open a document, which would compromise her account.
Most often the goal is to get valuable information from the target and assessments about how he sees the situation in Iran. The same researcher is often showered with praise and seduced by an original idea that often goes against Iran, such as how to destroy Iran from within.
The approach usually is signed under the name of the same person without his phone number (for fear that the target will call the same person and understand that he was tricked). But as one of the authors recently experienced, Iran-linked operatives are now even leaving phone numbers.
Those who are at the receiving end of such Iranian entreaties should take the following steps: doubt any email they receive regarding possible collaboration, especially when emails are sent from a users private address (e.g., via Gmail) and not the institutional domain; doubly verify that the sender is real through other social media platforms or by calling his/her employer; never provide personal details or open links you receive from this source; and be cautious in the information you make accessible about yourself on social media platforms.
Contrary to popular belief, most of Irans successful cyberattacks were not because of its technological capabilities, but because of the very extensive use it makes of social engineering tools. Today there are good technical solutions that can protect companies and people from hacking in the cyber dimension. However, it is very difficult to influence the human factor with these approaches, especially when the email seems credible, the offer to cooperate is so flattering, and it corresponds with the subjects desire to demonstrate the knowledge he has and share it with others.
This makes the human factor the weakest link in the chain. This is not a new pattern of action, but there has been an acceleration in its use. The higher the awareness of the relevant parties, the more difficult it will be for Iran in its intelligence missions.
In a broad sense, there is a need to increase information sharing between the social networks and state intelligence agencies. This cooperation in the Iranian context can help block those profiles. The phenomenon cannot be prevented, but it can certainly be reduced considerably. Awareness of Iranian behavior in the cyber realm is the best way to counter their practices.
Excerpt from:
Social Engineering in the Name of Iran's Islamic Revolution - Algemeiner
- Israel and Iran Seemed on the Brink of a Bigger War. Whats Holding Them Back? - The New York Times - November 24th, 2024 [November 24th, 2024]
- Iran's Air1Air reprimanded over flight suspension - ch-aviation - November 24th, 2024 [November 24th, 2024]
- Pop icon Googoosh is a voice for women in Iran - DW (English) - November 24th, 2024 [November 24th, 2024]
- Israel kills wanted Hezbollah commander behind the establishment of Iraqs Iran-backed militias - Long War Journal - November 24th, 2024 [November 24th, 2024]
- Iran Braces for Trump Reset With Economy Buckling From Sanctions - Bloomberg - November 24th, 2024 [November 24th, 2024]
- Iran to hold nuclear talks with Britain, France, Germany on Nov. 29 - Kyodo News Plus - November 24th, 2024 [November 24th, 2024]
- Iran says it immediately activated new, advanced centrifuges after IAEA censure - The Times of Israel - November 24th, 2024 [November 24th, 2024]
- Iran preparing to respond to Israel's Oct. 26 attack - Khamenei's aide - - November 24th, 2024 [November 24th, 2024]
- United Nations nuclear agency again condemns Iran for failing to fully cooperate - NPR - November 24th, 2024 [November 24th, 2024]
- Iran is preparing to respond to Israel adviser to Supreme Leader Khamenei - The Times of Israel - November 24th, 2024 [November 24th, 2024]
- Iran says it is activating new centrifuges after being condemned by UN nuclear watchdog - CNN - November 24th, 2024 [November 24th, 2024]
- Iran to "substantially increase" uranium enrichment capacity over IAEA rebuke led by U.S. and allies - CBS News - November 24th, 2024 [November 24th, 2024]
- Iran defies international pressure, increasing its stockpile of near weapons-grade uranium, UN says - The Associated Press - November 24th, 2024 [November 24th, 2024]
- Iran offers to cap sensitive uranium stock as IAEA resolution looms - Reuters - November 24th, 2024 [November 24th, 2024]
- Iran has ambitions in Western Sahara. Trump can contain them by bolstering ties with Morocco. - Atlantic Council - November 24th, 2024 [November 24th, 2024]
- Israeli rabbi kidnapped in UAE, sparking fears of Iran's involvement - - November 24th, 2024 [November 24th, 2024]
- Iran's President calls on Pope Francis to use influence to stop war in Middle East - Reuters - November 24th, 2024 [November 24th, 2024]
- American-Israeli families sue Iran, Hamas and Hezbollah in federal court - Middle East Eye - November 24th, 2024 [November 24th, 2024]
- Norwegian guard at US Embassy in Oslo arrested over allegations of spying for Russia and Iran - CNN - November 24th, 2024 [November 24th, 2024]
- Iran categorically rejects allegations of involvement in murder of Abu Dhabi rabbi - The Times of Israel - November 24th, 2024 [November 24th, 2024]
- Iran: EU widens restrictive measures in view of Iran support of the Russian war of aggression against Ukraine and lists one individual and four... - November 24th, 2024 [November 24th, 2024]
- Student Charged With Spying on US Embassy for Russia, Iran - Newsweek - November 24th, 2024 [November 24th, 2024]
- Russia sends Yemeni mercenaries to fight in Ukraine after they were tricked into signing up for war by Iran-backed Houthis: report - New York Post - November 24th, 2024 [November 24th, 2024]
- Did We Do Enough? Airmen Heed Lessons from Their Air Victory over Iran - Air & Space Forces Magazine - November 24th, 2024 [November 24th, 2024]
- Guard at U.S. Embassy in Norway Accused of Spying for Russia and Iran - The New York Times - November 24th, 2024 [November 24th, 2024]
- Is Iran's Khamenei signaling readiness for new deal as Trump threat looms large? - Al-Monitor - November 24th, 2024 [November 24th, 2024]
- Iran signals willingness to halt stockpile expansion, Grossi says - World Nuclear News - November 24th, 2024 [November 24th, 2024]
- Iran set to launch advanced centrifuges after IAEA censure for noncooperation - The Times of Israel - November 24th, 2024 [November 24th, 2024]
- The winds of change are blowing in Iran - The Spectator - November 24th, 2024 [November 24th, 2024]
- Iran says German-Iranian died before execution was reported - BBC.com - November 5th, 2024 [November 5th, 2024]
- Iran is now dangerously vulnerable to the consequences of another attack on Israel - Business Insider - November 5th, 2024 [November 5th, 2024]
- Federal agencies say Russia and Iran are ramping up influence campaigns targeting US voters - The Associated Press - November 5th, 2024 [November 5th, 2024]
- Three sentenced to death in Iran over killing of top nuclear scientist - Al Jazeera English - November 5th, 2024 [November 5th, 2024]
- Russia launches Soyuz rocket with dozens of satellites, including two from Iran - Reuters - November 5th, 2024 [November 5th, 2024]
- Full-scale war in Middle East involving Israel and Iran likely, say most Europeans in poll - The Guardian - November 5th, 2024 [November 5th, 2024]
- Iran executes a Jewish citizen convicted of murder following a dispute over money - ABC News - November 5th, 2024 [November 5th, 2024]
- US says Iranian-American held in Iran as tensions high following Israeli attack on country - The Associated Press - November 5th, 2024 [November 5th, 2024]
- An Iranian-American journalist is believed to be held by Iran as tensions remain high after an Israeli attack, US says - ABC News - November 5th, 2024 [November 5th, 2024]
- Iran Issues Fresh Threats Against Israel, U.S. - Foundation for Defense of Democracies - November 5th, 2024 [November 5th, 2024]
- Iran arrests female university student who stripped to her underwear in protest over dress code enforcement - CBS News - November 5th, 2024 [November 5th, 2024]
- Oil prices settle up slightly on Iran worries, but prices down for week - Reuters - November 5th, 2024 [November 5th, 2024]
- Two members of Iran's Revolutionary Guards killed in helicopter crash - FRANCE 24 English - November 5th, 2024 [November 5th, 2024]
- Iran wants to hold region hostage with retaliation op - analysis - The Jerusalem Post - November 5th, 2024 [November 5th, 2024]
- Iran slams destabilizing presence as US sends B-52 bombers to region - The Times of Israel - November 5th, 2024 [November 5th, 2024]
- Woman strips off clothes at Iran university in apparent protest, reports say - Reuters - November 5th, 2024 [November 5th, 2024]
- Iran says two French detainees held in good conditions - Reuters - November 5th, 2024 [November 5th, 2024]
- Reformist clerics imply Iran should back two-state solution for Israel and Palestine - The Guardian - November 5th, 2024 [November 5th, 2024]
- Iran to use bigger warheads in attack on Israel - JNS.org - November 5th, 2024 [November 5th, 2024]
- Will Iran Withdraw from the Nuclear Non-Proliferation Treaty? - War On The Rocks - November 5th, 2024 [November 5th, 2024]
- From Iran to Turkey, how the Middle East is bracing for US elections - Al-Monitor - November 5th, 2024 [November 5th, 2024]
- Iran Rejects Nuclear Weapons but Will 'Defend Itself by All Means' - Newsweek - November 5th, 2024 [November 5th, 2024]
- Iran vows strong and complex attack against Israel in retaliation for strikes - New York Post - November 5th, 2024 [November 5th, 2024]
- US said to warn Iran it wont be able to restrain Israel if Tehran attacks again - The Times of Israel - November 5th, 2024 [November 5th, 2024]
- The Houthis couldn't have built their most dangerous weapons without help from Iran and others, UN experts find - Business Insider - November 5th, 2024 [November 5th, 2024]
- Iran detains woman who stripped to her underwear at university in apparent protest - ABC News - November 4th, 2024 [November 4th, 2024]
- Iran executes Jewish Iranian man after settlement aimed at saving him was rejected - The Times of Israel - November 4th, 2024 [November 4th, 2024]
- Israel says it conducted a ground raid in Syria and seized a Syrian citizen connected to Iran - PBS NewsHour - November 4th, 2024 [November 4th, 2024]
- Iran said planning to use more powerful weapons in next attack on Israel - The Times of Israel - November 4th, 2024 [November 4th, 2024]
- The Longer Iran Waits to Attack Israel, the More Risks It Takes - Haaretz - November 4th, 2024 [November 4th, 2024]
- Iran's enemies will receive crushing response - Khamenei - BBC.com - November 4th, 2024 [November 4th, 2024]
- Iran fears Trump win would bring Israeli strikes on nuclear sites, Western sanctions - The Times of Israel - November 4th, 2024 [November 4th, 2024]
- Israel says it carried out ground raid into Syria, seizing a Syrian citizen connected to Iran - The Associated Press - November 4th, 2024 [November 4th, 2024]
- Israel Iran war Live Updates: IDF says it eliminated Hezbollah commander Abu Ali Rida - The Times of India - November 4th, 2024 [November 4th, 2024]
- Iran plans strong and complex attack on Israel as Khamenei vows 'harsh retaliation' | What we know so far | Today News - Mint - November 4th, 2024 [November 4th, 2024]
- 'Orders to come from Iran': Iraqi militias pose growing risk to Israel - expert - The Jerusalem Post - November 4th, 2024 [November 4th, 2024]
- Iraq trying to reel in Iran-backed groups to prevent confrontation with Israel - The Times of Israel - November 4th, 2024 [November 4th, 2024]
- Iran warns of 'crushing response' following Israeli airstrikes as Pentagon announces plans to bolster US presence in the Middle East - Business... - November 4th, 2024 [November 4th, 2024]
- Khamenei aide warns Iran may review nuclear doctrine if facing existential threat - The Times of Israel - November 4th, 2024 [November 4th, 2024]
- Iran Is Freaked: The Air Force Is Sending B-52 Bombers Much Closer - The National Interest Online - November 4th, 2024 [November 4th, 2024]
- Israel at War Day 394 | Report: Iran's Army Will Participate in 'Strong and Complex' Attack on Israel - Haaretz - November 4th, 2024 [November 4th, 2024]
- Iran says airspace remains open - The Jerusalem Post - November 4th, 2024 [November 4th, 2024]
- UN experts say Houthis exploited Gaza war to boost regional status, aided by Iran - The Times of Israel - November 4th, 2024 [November 4th, 2024]
- Netanyahu tells U.S. that Israel will strike Iranian military, not nuclear or oil, targets, officials say - The Washington Post - October 16th, 2024 [October 16th, 2024]
- Opinion | Its Time for America to Get Real With Iran and Israel - The New York Times - October 16th, 2024 [October 16th, 2024]
- Iran says it will respond decisively if Israel attacks, asks UN to intervene - The Times of Israel - October 16th, 2024 [October 16th, 2024]
- US warns Iran to stop plotting against Trump, says US official - Reuters - October 16th, 2024 [October 16th, 2024]
- Iran working to control oil spill off Kharg Island, says IRNA - Reuters - October 16th, 2024 [October 16th, 2024]
- Israel said to decide on targets it could strike in Iran: Now a matter of time - The Times of Israel - October 16th, 2024 [October 16th, 2024]
- Israel will respond to Iran based on national interest - Netanyahu - BBC.com - October 16th, 2024 [October 16th, 2024]
- Israel Tells U.S. It Will Limit Its Expected Strike on Iran to Military Targets, Officials Say - The New York Times - October 16th, 2024 [October 16th, 2024]