Iran hunts down double agents with fake recruiting sites, Mandiant reckons
ID: b7733225-2fc8-5dd5-9eff-8faf99cfd3fe
STIX ID: report--b7733225-2fc8-5dd5-9eff-8faf99cfd3fe
Feed Name: The Register (Security)
Threat Score
Mandiant reported a government-backed Iranian operation (active from at least 2017 through March 2024) that used over 35 fake Israeli-themed recruiting websites and social accounts to lure Farsi speakers into submitting names, birth dates, contact details, addresses, and professional histories; the harvested data could be used for identification, targeting, or physical harm, and the activity is attributed with high confidence to Iranian actors with a weak overlap to APT42.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
