Social Engineering in the Name of Iran’s Islamic Revolution – Algemeiner
i24 News Iran continues to significantly develop its cyber capabilities for a variety of purposes. Only recently it was reported that Tehran had sought to attack Boston Childrens Hospital an attempt that the director of the Federal Bureau of Investigation called one of the most despicable he had ever seen. This incident is another indication of Irans boldness in operating cyber tools.
But the majority of Iranian cyberactivity is focused on social engineering for obtaining intelligence information. Tehran has been expanding its use as a tool, mainly through numerous inquiries to various experts on Iran. Iranian intelligence is attempting to obtain their information and assessments, and even trying to lure some to attend international conferences to recruit or kidnap them.
One of the authors of this article was recently contacted via email by someone claiming to be a leading journalist. When the email was met without a response, the same journalist called the author personally multiple times asking to schedule a test interview, with the phone number appearing registered from the country in which that media outlet was located.
Further investigation revealed this to likely be a phishing attempt by Charming Kitten, which is an advanced persistent threat actor linked to the Iranian government. There are lessons to be learned from this episode, namely the sloppiness in tradecraftthrough persistence and unaffiliated, personal email addresses of Iranian cyberwarriors. The fact that the Iranian operatives followed up after an email with phone calls demonstrates the aggressiveness with which the Islamic Republic is deploying these tools.
To uncover the Iranian pattern of action, we will focus in this article on the ways Iran uses social engineering tools and their unique characteristics to help possible targets identify that they are under Iranian attack. In general, most of the actions being carried out by Tehran are very amateurish and easy to identify, provided those who are subjects of interest to the Iranian government are aware of its tactics.
The use of social engineering tools has greatly expanded in recent years, mainly due to the difficulty of obtaining information from social media platforms in light of heightened awareness and actions taken by these networks aimed at protecting the privacy of their users.
Social engineering has thus become a kind of offensive WEBINT (Web Intelligence) tool that allows for receiving a lot of information about the relevant user.
The central principle when it comes to social engineering is trust. That is, the target will feel safe enough to provide details to the applicant (in this case Iranian intelligence). Iran also understands this principle very well, and therefore it seems that its operatives are working around the clock on these strategies.
If in the past Iran used assets that it established for dedicated operations which were for the most part very easy to identify, today the Iranian trend is to steal the identities of real people and to weaponize them.
That is, they are using the real names of people to approach their targets using emails that are very close to the real name of the stolen identity. This is usually a respectable approach made by a high-ranking expert (to persuade the target to work with him) during which there is an offer for a potential target to collaborate, whether it is via an interview, writing a joint article, or appearing at some conference. This modus operandi can be seen in a recent cyberoperation targeting Israels former Foreign Minister Tzipi Livni, where an Iranian hacker posed as an Israeli military official asking her to use her email password to open a document, which would compromise her account.
Most often the goal is to get valuable information from the target and assessments about how he sees the situation in Iran. The same researcher is often showered with praise and seduced by an original idea that often goes against Iran, such as how to destroy Iran from within.
The approach usually is signed under the name of the same person without his phone number (for fear that the target will call the same person and understand that he was tricked). But as one of the authors recently experienced, Iran-linked operatives are now even leaving phone numbers.
Those who are at the receiving end of such Iranian entreaties should take the following steps: doubt any email they receive regarding possible collaboration, especially when emails are sent from a users private address (e.g., via Gmail) and not the institutional domain; doubly verify that the sender is real through other social media platforms or by calling his/her employer; never provide personal details or open links you receive from this source; and be cautious in the information you make accessible about yourself on social media platforms.
Contrary to popular belief, most of Irans successful cyberattacks were not because of its technological capabilities, but because of the very extensive use it makes of social engineering tools. Today there are good technical solutions that can protect companies and people from hacking in the cyber dimension. However, it is very difficult to influence the human factor with these approaches, especially when the email seems credible, the offer to cooperate is so flattering, and it corresponds with the subjects desire to demonstrate the knowledge he has and share it with others.
This makes the human factor the weakest link in the chain. This is not a new pattern of action, but there has been an acceleration in its use. The higher the awareness of the relevant parties, the more difficult it will be for Iran in its intelligence missions.
In a broad sense, there is a need to increase information sharing between the social networks and state intelligence agencies. This cooperation in the Iranian context can help block those profiles. The phenomenon cannot be prevented, but it can certainly be reduced considerably. Awareness of Iranian behavior in the cyber realm is the best way to counter their practices.
Excerpt from:
Social Engineering in the Name of Iran's Islamic Revolution - Algemeiner
- 2 IDF reservists, one of them in Iron Dome unit, arrested on suspicion of spying for Iran - The Times of Israel - January 27th, 2025 [January 27th, 2025]
- On GPS: Is Iran weaker than ever? - CNN - January 27th, 2025 [January 27th, 2025]
- Bolton: there is no question in my mind Iran may take action against me - MSNBC - January 27th, 2025 [January 27th, 2025]
- Is Iran inching closer to recognizing Taliban rule in Afghanistan? - Amwaj.media - January 27th, 2025 [January 27th, 2025]
- Online gold platforms thrive in Iran as economic pressures mount - - January 27th, 2025 [January 27th, 2025]
- Who is John Ratcliffe, the Iran hawk heading the CIA? - - January 27th, 2025 [January 27th, 2025]
- Iran says weighing Trump factor, insists on nuclear talks only | Iran International - - January 27th, 2025 [January 27th, 2025]
- 2 IDF reservists, one of them from Iron Dome unit, arrested on suspicion of spying for Iran - The Times of Israel - January 27th, 2025 [January 27th, 2025]
- Iran's judiciary denies release of convicted tycoon Babak Zanjani - - January 27th, 2025 [January 27th, 2025]
- Israel boosts F-16s with $80M upgrades amid rising tensions with Iran - The Jerusalem Post - January 27th, 2025 [January 27th, 2025]
- US ties crucial for Iraq, separate from relations with Iran, says Iraqi FM - Kurdistan24 - January 27th, 2025 [January 27th, 2025]
- Trump urged to rethink nixing security for US ex-officials under threat from Iran - The Times of Israel - January 27th, 2025 [January 27th, 2025]
- Iraq Is a Key Test of Trump's Willingness to Counter Iran - Business Insider - January 27th, 2025 [January 27th, 2025]
- In Iran, One-Third of Patients Refrain from Purchasing Medication - Iran Focus - January 27th, 2025 [January 27th, 2025]
- Iran News: Iranian Arms Smuggling to Hezbollah Disrupted Amid Growing Tensions in Syria - National Council of Resistance of Iran (NCRI) - January 27th, 2025 [January 27th, 2025]
- BCFIF Calls on UK to Act Against Imminent Executions of Political Prisoners in Iran - Iran News Update - January 27th, 2025 [January 27th, 2025]
- Trump Revokes Security Detail for Pompeo and Others, Despite Threats From Iran - The New York Times - January 26th, 2025 [January 26th, 2025]
- How Iran Lost Before It Lost: The Roll Back of Its Gray Zone Strategy - War On The Rocks - January 26th, 2025 [January 26th, 2025]
- Iran's foreign minister meets the Taliban in the first visit to Kabul in 8 years - ABC News - January 26th, 2025 [January 26th, 2025]
- Iran Review - 48th Session of Universal Periodic Review - Welcome to the United Nations - January 26th, 2025 [January 26th, 2025]
- New Russia-Iran Treaty Reveals the Limits of Their Partnership - Carnegie Endowment for International Peace - January 26th, 2025 [January 26th, 2025]
- How quickly could Iran build its first nuclear weapon? Look at China - Bulletin of the Atomic Scientists - January 26th, 2025 [January 26th, 2025]
- Mastermind of Iran's US influence effort appointed head of ministry think tank - - January 26th, 2025 [January 26th, 2025]
- Iran is 'pressing the gas pedal' on uranium enrichment, IAEA chief says - Reuters - January 26th, 2025 [January 26th, 2025]
- Trump said set to appoint Steve Witkoff to manage Iran nuclear file - The Times of Israel - January 26th, 2025 [January 26th, 2025]
- Donald Trump ("Abu Ivanka") and the Gulf States Vs. Iran - The Globalist - January 26th, 2025 [January 26th, 2025]
- Trump to appoint Steve Witkoff as Iran envoy: Report - Anadolu Agency | English - January 26th, 2025 [January 26th, 2025]
- Trump says Iran deal would be 'really nice', bucks hawks - The New Arab - January 26th, 2025 [January 26th, 2025]
- Trump says he hopes not to have to support Israeli attack on Iran - - January 24th, 2025 [January 24th, 2025]
- Trump: Would be nice to solve problems with Iran without Israeli strikes - The Times of Israel - January 24th, 2025 [January 24th, 2025]
- From Iran to European nations: What does the world expect from Trump? - Israel Hayom - January 24th, 2025 [January 24th, 2025]
- The Farda Briefing: Iran Talks Tough But Signals Openness For Negotiations With U.S. - Radio Free Europe / Radio Liberty - January 24th, 2025 [January 24th, 2025]
- What a Secretary of State Rubio means for the Middle East: Getting tougher on Iran and tighter with allies - Atlantic Council - January 24th, 2025 [January 24th, 2025]
- Trump revokes protections for former Secretary of State Pompeo and top aide threatened by Iran - The Associated Press - January 24th, 2025 [January 24th, 2025]
- UN chief Guterres calls on Iran to renounce nuclear weapons - Reuters - January 24th, 2025 [January 24th, 2025]
- Davos- Iran's Zarif says he hopes Trump will choose 'rationality' - Reuters - January 24th, 2025 [January 24th, 2025]
- Conscience Held Captive: The State of Religious Minorities in Iran - IranWire | - January 24th, 2025 [January 24th, 2025]
- Trump will seek snapback of UN sanctions on Iran, Rubio says - - January 24th, 2025 [January 24th, 2025]
- Trump says hes hopeful Iran deal can be reached without Israeli military strike on nuclear program - All Israel News - January 24th, 2025 [January 24th, 2025]
- Trump has few good options to prevent Iran from building a nuclear bomb - The Conversation - January 24th, 2025 [January 24th, 2025]
- Italian journalist detained in Iran says she expected to be held longer and praises Musk's role - The Associated Press - January 24th, 2025 [January 24th, 2025]
- Why Russia and Iran signed a new 'strategic partnership' - Le Monde - January 24th, 2025 [January 24th, 2025]
- Iran and Russia deepen cyber ties with new agreement - The Record from Recorded Future News - January 24th, 2025 [January 24th, 2025]
- Saudi FM says Trump presidency doesnt raise risk of Iran-Israel war - The Times of Israel - January 24th, 2025 [January 24th, 2025]
- Over 1,000 tons of missile fuel chemicals head for Iran from China report - The Jerusalem Post - January 24th, 2025 [January 24th, 2025]
- Iran says it hopes Trump will take realistic approach, show respect to Mideast - The Times of Israel - January 24th, 2025 [January 24th, 2025]
- Trump ends Secret Service protection for John Bolton as Iran threat persists - WBAL TV Baltimore - January 24th, 2025 [January 24th, 2025]
- How Iran Lost Before It Lost - RealClearWorld - January 24th, 2025 [January 24th, 2025]
- The alliance of outcasts: Closer ties between Russia and Iran bring benefits and new enemies for both nations - The Insider - January 24th, 2025 [January 24th, 2025]
- Trump revokes security detail for Mike Pompeo, years after Iran threatened to kill the then-secretary of State - New York Post - January 24th, 2025 [January 24th, 2025]
- Trumps Iran Policy Puts Focus on $30 Billion-a-Year Oil Revenue - Bloomberg - January 24th, 2025 [January 24th, 2025]
- Iran unveils new underground naval base amid tension with US and Israel - Reuters - January 24th, 2025 [January 24th, 2025]
- Iran pushing for better ties with Azerbaijan: Why and how? - analysis - The Jerusalem Post - January 24th, 2025 [January 24th, 2025]
- Trump fires his former Iran envoy Brian Hook on first day | Iran International - - January 24th, 2025 [January 24th, 2025]
- Interpreting the 20-year military pact between Russia & Iran - Responsible Statecraft - January 24th, 2025 [January 24th, 2025]
- Russia and Iran have a troubled history despite their current alliance - The Associated Press - January 24th, 2025 [January 24th, 2025]
- Trump: 'It Would Be Really Nice' if Iran Issues Could Be Worked Out Without Israeli Strikes on Nuclear Sites - Haaretz - January 24th, 2025 [January 24th, 2025]
- Trump to appoint Mideast envoy Witkoff to handle the Iran portfolio - Ynetnews - January 24th, 2025 [January 24th, 2025]
- Musk Said to Have Intervened to Help Free Italian Jailed in Iran - The New York Times - January 19th, 2025 [January 19th, 2025]
- Iran calls pending Gaza deal a defeat for Israel, as leaders worldwide welcome pact - The Times of Israel - January 19th, 2025 [January 19th, 2025]
- Russia and Iran sign cooperation treaty days before Trump's inauguration - Euronews - January 19th, 2025 [January 19th, 2025]
- Putin and Iran's president sign 20-year treaty, strengthening ties - CBS News - January 19th, 2025 [January 19th, 2025]
- Making Iran Choose Between the Bomb and Bankruptcy - The Washington Institute - January 19th, 2025 [January 19th, 2025]
- Iran unveils underground naval base as it seeks to counter Israeli threat - Sky News - January 19th, 2025 [January 19th, 2025]
- Russia's Strategic Treaty With Iran May Have Nuclear Angle - Newsweek - January 13th, 2025 [January 13th, 2025]
- Russia and Iran to sign partnership treaty this week - POLITICO Europe - January 13th, 2025 [January 13th, 2025]
- Iran, already on the defensive, braces for second Trump term - The Washington Post - January 13th, 2025 [January 13th, 2025]
- Russia says Iran's president will visit this week and sign a partnership pact with Putin - ABC News - January 13th, 2025 [January 13th, 2025]
- Reform is Happening in Iran and Assads Fall Could Accelerate It - Stimson Center - January 13th, 2025 [January 13th, 2025]
- Iran welcomes return of national held in Italy in spat involving the US - Al Jazeera English - January 13th, 2025 [January 13th, 2025]
- Iran holding war games as it faces Israel tensions, Trump's return - Reuters - January 13th, 2025 [January 13th, 2025]
- Iran, European powers hold third round of nuclear talks in Geneva - - January 13th, 2025 [January 13th, 2025]
- Will Iran build a nuclear bomb while Trump is in power in the US? - Al Jazeera English - January 13th, 2025 [January 13th, 2025]
- Iran nuclear talks resume ahead of Trump's return: What's at stake? - Perspective - FRANCE 24 English - January 13th, 2025 [January 13th, 2025]
- Iran Gets Major Drone Boost Amid Growing Tensions With Israel - Newsweek - January 13th, 2025 [January 13th, 2025]
- Frenchman held in Iran since 2022 reveals identity in audio message - FRANCE 24 English - January 13th, 2025 [January 13th, 2025]
- Trump Urged to Reapply Maximum Pressure on Iran in New Strategic Blueprint - BTW21 - January 13th, 2025 [January 13th, 2025]
- Iran expands military drills to two more nuclear sites in countrys west and center - The Times of Israel - January 13th, 2025 [January 13th, 2025]
- Germany welcomes release of German-Iranian rights activist from prison in Iran and her return home - Yahoo! Voices - January 13th, 2025 [January 13th, 2025]
- Opinion | Iran is weak, and should be ready to negotiate - The Washington Post - January 13th, 2025 [January 13th, 2025]