A group of Iranian hackers, previously identified by U.S. intelligence for targeting both the Trump and Biden-Harris campaigns, was blocked by Meta after being linked to fake WhatsApp accounts. These hackers posed as tech support from companies like Google and Microsoft to target high-profile individuals in countries including the U.S., U.K., Israel, and Iran.
The scheme was exposed after users reported suspicious messages, leading Meta to connect it to APT42, known for phishing attacks aimed at stealing credentials. Although no evidence of hacked accounts was found, Meta shared its findings with law enforcement and tech companies out of caution.
This hacker group, also called UNC788 and Mint Sandstorm, had been previously associated with attacks on individuals in the Middle East, including military and human rights figures, as well as academics and politicians globally. U.S. intelligence linked the group to efforts to disrupt the presidential election, and Google confirmed its ties to Iran's Revolutionary Guard.
Microsoft had also reported Iranian cyber activity linked to this year's election, and the FBI noted this hack as part of an ongoing increase in aggressive cyber actions by Iran. The U.S. intelligence community believes these efforts are aimed at fostering distrust in U.S. institutions and creating social discord, particularly around sensitive issues like the Israel-Gaza conflict through disinformation campaigns.
Post a Comment