logo

Operation Lonely Guy: Iranians Use Cute Girl Profile to Cultivate, Compromise Targets in Middle East

ID: 1af2aecd-a188-5fff-a530-e333936bd165

STIX ID: report--1af2aecd-a188-5fff-a530-e333936bd165

Feed Name: Security Ledger

Threat Score
85/100

Date Published: 2017-07-27

Date Updated: 2026-04-26

Author: Paul Roberts

...
...

Dell Secureworks CTU reported a 2017 spear-phishing campaign by the APT group COBALT GYPSY that used a fake social-media persona "Mia Ash" across LinkedIn and Facebook to befriend employees in MENA oil, gas, telecom, government, defense and finance sectors, delivering PupyRAT via malicious Word macros and PowerShell loaders to harvest credentials and gain persistent access, with links to prior destructive operations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.