/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

← → days · ↑ ↓ browse · Enter similar · o open

Facebook says it stopped a campaign by Iranian hackers, targeting about 200 defense and aerospace personnel, primarily from the US, using fake online personas

Hannah Murphy / Financial Times :

Financial Times Hannah Murphy

Context & Ripple Effects

Facebook's takedowns of Iran-linked networks have been running for years — from the 82 Pages and groups removed in October 2018 to the far larger 262 Pages, 356 accounts and 162 Instagram accounts tied to Iran in early 2019, many uncovered with information shared by Twitter. What changes now is the target profile: instead of broad influence operations aimed at publics in the US and UK, this campaign used fake personas to go after roughly 200 named defense and aerospace personnel.

That pivot matters because it moves platform security work from content moderation toward something closer to counterintelligence. The earlier discovery chain — FireEye flagging fake accounts after the DNC hack, then Twitter-to-Facebook intelligence sharing on the 2019 network — already built the muscle; individual-level espionage targeting tests whether it extends from pages to people.

First-order effects

  • About 200 defense and aerospace personnel, primarily in the US, were the direct targets of impersonation accounts designed to build trust with them — the immediate exposure is to their employers' networks, not public opinion.

Second-order effects

Third-order effects

  • If the pattern holds, state-aligned operators keep shifting from mass-page influence ops to persona-based targeting of specific professionals, pushing platforms further into an ongoing counterintelligence role they report on rather than fully control.

The trend: Platform takedowns are evolving from removing bulk influence-operation pages toward detecting individually targeted espionage personas aimed at government-adjacent professionals.

Discussion

  • @mdvily Mike D on x
    6/ Our team found that a portion of malware tooling used by this group was developed by an IT firm Mahak Rayan Afraz based in Tehran with ties to IRGC. More in our report this morning https://about.fb.com/...
  • @jseldin Jeff Seldin on x
    What, if anything, did the #Iran's #Tortoiseshell hackers get from US military personnel, defense companies? “For operational security purposes, US Cyber Command does not discuss operations, intelligence & cyber planning” a @US_CYBERCOM spokesperson tells @VOANews https://twitter…
  • @jseldin Jeff Seldin on x
    NEW: #Iran-based hackers known as “Tortoiseshell” targeted US military, defense companies in US, #Britain, #Europe per @Facebook “This group used various malicious tactics to identify its targets & infect their devices with malware to enable espionage” https://about.fb.com/...
  • @johnhultquist John Hultquist on x
    Good work from the team at Facebook hunting and disrupting Iranian intel ops on the platform. A good reminder that they don't always stick their region and they love social media. https://twitter.com/...
  • @ildannymoore Daniel Moore on x
    Great work from our folks working to counter espionage campaigns! https://twitter.com/...
  • @ericgarland Eric Garland on x
    Facebook: “Not only do we let Russia attack democracy, and Myanmar to commit genocide - fuck it - we also let the Iranian regime use our company to attack America even more!” Shut it down. https://www.reuters.com/...
  • @shanvav Shannon Vavra on x
    Iranian hackers posing as American job recruiters have been targeting nearly 200 American & European defense industry employees, in the latest job recruiter hacking campaign, @arawnsley reports. @thedailybeast https://www.thedailybeast.com/ ...
  • @davidagranovich David Agranovich on x
    1/ Today we shared our latest research into Tortoiseshell, an APT actor in Iran. Our investigative team found a significant expansion in this group's targeting towards the aerospace and defense sector primarily in the US, but also in the UK, and EU. https://about.fb.com/...
  • @mdvily Mike D on x
    1/ Today our team at Facebook announced a disruption of espionage activity from an Iranian hacking group known as Tortoiseshell. They targeted the aerospace & defense industry, primarily in the U.S. https://about.fb.com/... Thread 👇
  • @ngleicher Nathaniel Gleicher on x
    1/ Today we removed a cyber-espionage op that originated from Iran and targeted military personnel and individuals in the defense and aerospace industries primarily in the US, and some in the UK and Europe. https://about.fb.com/...
  • @mshannahmurphy Hannah Murphy on x
    Facebook says it has blocked a “sophisticated” online cyber espionage campaign conducted by hackers in Iran attempting to surveil 200 western military, defence & aerospace personnel via its platform Other platforms are investigating similar activity: https://www.ft.com/...