APT42 Iranian Hackers Target WhatsApp Users

Facebook’s security team recently intervened to shut down a series of WhatsApp accounts that were masquerading as tech support representatives from major companies, following user reports of suspicious activity.

This nefarious effort, originating from Iran, was aimed at individuals in Israel, Palestine, Iran, the United States, and the UK. It primarily targeted political figures, diplomats, and notable public personalities, including those connected to both President Biden’s and former President Trump’s administrations. The source of these activities was traced back to APT42, also known as UNC788 or Mint Sandstorm, an Iranian cyber group notorious for its extensive phishing campaigns.

APT42’s previous operations have involved targeting a wide range of individuals in the Middle East, including Saudi military personnel, dissidents, human rights activists from Israel and Iran, and politicians, as well as US-based academics, activists, and journalists focusing on Iran.

The fraudulent WhatsApp accounts pretended to be technical support from AOL, Google, Yahoo, and Microsoft. Many recipients of these misleading messages reported them to WhatsApp, allowing the platform to investigate and connect the incidents to APT42.

Although there is no evidence that the targeted WhatsApp accounts were actually breached, Facebook has advised those who encountered these suspicious accounts to bolster their online security.

In light of the increased risks surrounding the upcoming US election, Facebook has briefed law enforcement and presidential campaigns about the threat. The company remains vigilant, analyzing industry trends, internal data, and user feedback to swiftly address any further malicious activities.

Public figures, journalists, political candidates, and campaign teams are urged to stay alert, utilize privacy and security features, avoid engaging with unknown contacts, and report any suspicious interactions.

In response to such threats, Facebook takes proactive measures to disable malicious accounts, prevent their domains from spreading on the platform, and notify individuals who may have been targeted by these actors.

More Articles & Posts