Social Engineering in the Name of Iran’s Islamic Revolution – Algemeiner
i24 News Iran continues to significantly develop its cyber capabilities for a variety of purposes. Only recently it was reported that Tehran had sought to attack Boston Childrens Hospital an attempt that the director of the Federal Bureau of Investigation called one of the most despicable he had ever seen. This incident is another indication of Irans boldness in operating cyber tools.
But the majority of Iranian cyberactivity is focused on social engineering for obtaining intelligence information. Tehran has been expanding its use as a tool, mainly through numerous inquiries to various experts on Iran. Iranian intelligence is attempting to obtain their information and assessments, and even trying to lure some to attend international conferences to recruit or kidnap them.
One of the authors of this article was recently contacted via email by someone claiming to be a leading journalist. When the email was met without a response, the same journalist called the author personally multiple times asking to schedule a test interview, with the phone number appearing registered from the country in which that media outlet was located.
Further investigation revealed this to likely be a phishing attempt by Charming Kitten, which is an advanced persistent threat actor linked to the Iranian government. There are lessons to be learned from this episode, namely the sloppiness in tradecraftthrough persistence and unaffiliated, personal email addresses of Iranian cyberwarriors. The fact that the Iranian operatives followed up after an email with phone calls demonstrates the aggressiveness with which the Islamic Republic is deploying these tools.
To uncover the Iranian pattern of action, we will focus in this article on the ways Iran uses social engineering tools and their unique characteristics to help possible targets identify that they are under Iranian attack. In general, most of the actions being carried out by Tehran are very amateurish and easy to identify, provided those who are subjects of interest to the Iranian government are aware of its tactics.
The use of social engineering tools has greatly expanded in recent years, mainly due to the difficulty of obtaining information from social media platforms in light of heightened awareness and actions taken by these networks aimed at protecting the privacy of their users.
Social engineering has thus become a kind of offensive WEBINT (Web Intelligence) tool that allows for receiving a lot of information about the relevant user.
The central principle when it comes to social engineering is trust. That is, the target will feel safe enough to provide details to the applicant (in this case Iranian intelligence). Iran also understands this principle very well, and therefore it seems that its operatives are working around the clock on these strategies.
If in the past Iran used assets that it established for dedicated operations which were for the most part very easy to identify, today the Iranian trend is to steal the identities of real people and to weaponize them.
That is, they are using the real names of people to approach their targets using emails that are very close to the real name of the stolen identity. This is usually a respectable approach made by a high-ranking expert (to persuade the target to work with him) during which there is an offer for a potential target to collaborate, whether it is via an interview, writing a joint article, or appearing at some conference. This modus operandi can be seen in a recent cyberoperation targeting Israels former Foreign Minister Tzipi Livni, where an Iranian hacker posed as an Israeli military official asking her to use her email password to open a document, which would compromise her account.
Most often the goal is to get valuable information from the target and assessments about how he sees the situation in Iran. The same researcher is often showered with praise and seduced by an original idea that often goes against Iran, such as how to destroy Iran from within.
The approach usually is signed under the name of the same person without his phone number (for fear that the target will call the same person and understand that he was tricked). But as one of the authors recently experienced, Iran-linked operatives are now even leaving phone numbers.
Those who are at the receiving end of such Iranian entreaties should take the following steps: doubt any email they receive regarding possible collaboration, especially when emails are sent from a users private address (e.g., via Gmail) and not the institutional domain; doubly verify that the sender is real through other social media platforms or by calling his/her employer; never provide personal details or open links you receive from this source; and be cautious in the information you make accessible about yourself on social media platforms.
Contrary to popular belief, most of Irans successful cyberattacks were not because of its technological capabilities, but because of the very extensive use it makes of social engineering tools. Today there are good technical solutions that can protect companies and people from hacking in the cyber dimension. However, it is very difficult to influence the human factor with these approaches, especially when the email seems credible, the offer to cooperate is so flattering, and it corresponds with the subjects desire to demonstrate the knowledge he has and share it with others.
This makes the human factor the weakest link in the chain. This is not a new pattern of action, but there has been an acceleration in its use. The higher the awareness of the relevant parties, the more difficult it will be for Iran in its intelligence missions.
In a broad sense, there is a need to increase information sharing between the social networks and state intelligence agencies. This cooperation in the Iranian context can help block those profiles. The phenomenon cannot be prevented, but it can certainly be reduced considerably. Awareness of Iranian behavior in the cyber realm is the best way to counter their practices.
Excerpt from:
Social Engineering in the Name of Iran's Islamic Revolution - Algemeiner
- Iran Rial Tanks to Record Low as US Sanctions and Inflation Bite - Bloomberg.com - December 18th, 2025 [December 18th, 2025]
- Top Iran Stories of 2025: A Year of Renewed Maximum Pressure - Kharon - December 18th, 2025 [December 18th, 2025]
- 'I hope there wont be a war, Iran will come to its senses': Mike Huckabee on Israel, war and diplomacy - Ynetnews - December 18th, 2025 [December 18th, 2025]
- Iran: Narges Mohammadi, several other human rights defenders arbitrarily arrested in massive crackdown - World Organisation Against Torture | OMCT - December 18th, 2025 [December 18th, 2025]
- Araqchi Highlights Benefits Of Iran-Russia Cooperation In Countering Sanctions - Eurasia Review - December 18th, 2025 [December 18th, 2025]
- How Internet Censorship Impacts the Womens Rights Movement in Iran: Insights from OONI Data and Activist Interviews - Open Observatory of Network... - December 18th, 2025 [December 18th, 2025]
- U.S. TREASURY RAMPS UP ON IRAN'S SHADOW FLEET: SANCTIONS HIT 29 VESSELS TO STARVE NUCLEAR AMBITIONS The US Treasury's OFAC just dropped fresh... - December 18th, 2025 [December 18th, 2025]
- Building on our Strategic Partnership Treaty, Iran and Russia's foreign ministries have agreed on a three-year roadmap to regularize and elevate our... - December 18th, 2025 [December 18th, 2025]
- Trump security strategy gives short shrift to Iran threat, expert says - - December 18th, 2025 [December 18th, 2025]
- What Has Iran Gained from BRICS? - The National Interest - December 18th, 2025 [December 18th, 2025]
- US imposes sanctions on vessels linked to Iran, Treasury website says By Reuters - Investing.com - December 18th, 2025 [December 18th, 2025]
- Israel, Iran to expand military use of AI - Shafaq News - - December 18th, 2025 [December 18th, 2025]
- India's Mohun Bagan suspended, fined over $100,000 for refusing to visit Iran - Reuters - December 18th, 2025 [December 18th, 2025]
- Exclusive: Iran open to resuming nuclear talks with the US but wont shift its conditions, supreme leaders adviser says - CNN - November 20th, 2025 [November 20th, 2025]
- Iran cancels new nuclear inspections it agreed to after bombing campaign - The Washington Post - November 20th, 2025 [November 20th, 2025]
- Iran releases Marshall Islands-flagged tanker and crew it seized last week - AP News - November 20th, 2025 [November 20th, 2025]
- Iran Releases Tanker It Seized From the Strait of Hormuz - The New York Times - November 20th, 2025 [November 20th, 2025]
- IAEA votes to urge Iran to provide information about nuclear material - Euronews.com - November 20th, 2025 [November 20th, 2025]
- UN committee adopts resolution criticizing Iran rights record - - November 20th, 2025 [November 20th, 2025]
- Europeans want to revive Iran nuclear diplomacy with Iran, says France - Reuters - November 20th, 2025 [November 20th, 2025]
- US Treasury hits Iran's shadow oil trade with sweeping sanctions - - November 20th, 2025 [November 20th, 2025]
- Iran asks Saudi Crown Prince to press U.S. to review nuclear talks - Foundation for Defense of Democracies - November 20th, 2025 [November 20th, 2025]
- US, European nations urge Iran to cooperate with UN nuclear watchdog - The Times of Israel - November 20th, 2025 [November 20th, 2025]
- Iran's foreign minister says the nation is no longer enriching uranium at any site in the country - NPR - November 20th, 2025 [November 20th, 2025]
- UN nuclear watchdog demands full cooperation from Iran on sites bombed in 12-day war - The Times of Israel - November 20th, 2025 [November 20th, 2025]
- Beersheba resident indicted on charges of spying for Iran during military service - The Times of Israel - November 20th, 2025 [November 20th, 2025]
- Israeli soldier indicted for sharing sensitive intel with Iran - thecradle.co - November 20th, 2025 [November 20th, 2025]
- UN Nuclear Watchdog Board Urges Iran to Allow Inspections - IranWire - November 20th, 2025 [November 20th, 2025]
- UN atomic agency demands Iran provide full information about its nuclear stockpile - AP News - November 20th, 2025 [November 20th, 2025]
- Iran: No IAEA access to bombed nuclear sites without agreement - Israel National News - November 20th, 2025 [November 20th, 2025]
- Iran: No IAEA access to bombed nuclear sites without a concrete deal - The Times of Israel - November 20th, 2025 [November 20th, 2025]
- Iran releases Marshall Islands-flagged tanker, gives no reason for detention - The Times of Israel - November 20th, 2025 [November 20th, 2025]
- Araghchi: Iran more prepared than ever to deter Israeli aggression - PressTV - November 20th, 2025 [November 20th, 2025]
- New IAEA Resolution Restores Oversight, Adds No New Obligations for Iran - WANA News Agency - November 20th, 2025 [November 20th, 2025]
- Disable the SIM, disable the citizen: Iran's new, silent crackdown | Iran International - - November 20th, 2025 [November 20th, 2025]
- Iran climb one spot to 20th in FIFA Ranking - Tehran Times - November 20th, 2025 [November 20th, 2025]
- Sanctioning Entities That Have Traded In Iran's Petroleum - Mirage News - November 20th, 2025 [November 20th, 2025]
- New IAEA resolution disrupting cooperation: Iran FM - New Age BD - November 20th, 2025 [November 20th, 2025]
- Iran's Pezeshkian says Tehran seeks peace, but will not bow to coercion - Reuters - November 7th, 2025 [November 7th, 2025]
- IAEA chief says Iran still capable of building nuclear weapons | Iran International - - November 7th, 2025 [November 7th, 2025]
- Cultural Genocide and the Kurdish Struggle in Iran - Genocide Watch - November 7th, 2025 [November 7th, 2025]
- Iran Fears Gen-Z: Why the Regime Is Ratcheting Up Propaganda - National Council of Resistance of Iran - NCRI - November 7th, 2025 [November 7th, 2025]
- Iran plotted to kill Israeli ambassador to Mexico, US and Israeli officials say - The Times of Israel - November 7th, 2025 [November 7th, 2025]
- Iran planned to kill Israeli envoy to Mexico this year - JNS.org - November 7th, 2025 [November 7th, 2025]
- Iran: Protest in Ahvaz Following Shocking Self-Immolation of 20-Year-Old Ahmad Baldi - National Council of Resistance of Iran - NCRI - November 7th, 2025 [November 7th, 2025]
- Iran says open to negotiation but will not give up nuclear - The Jerusalem Post - November 7th, 2025 [November 7th, 2025]
- Marginalization of the Baloch in Iran - Genocide Watch - November 7th, 2025 [November 7th, 2025]
- Pezeshkian: Iran seeks peace, but wont give up its nuclear and missile programs - The Times of Israel - November 7th, 2025 [November 7th, 2025]
- Jewish Iranian-American sentenced to prison in Iran for visiting Israel 13 years ago - Jewish Telegraphic Agency - November 7th, 2025 [November 7th, 2025]
- Iran News in Brief November 7, 2025 - National Council of Resistance of Iran - NCRI - November 7th, 2025 [November 7th, 2025]
- After its drone success, Iran's next breakout hit could come from the sea - Tehran Times - November 7th, 2025 [November 7th, 2025]
- Surviving 903 Days of Torture and Sexual Assault by Iran-Backed Shia Militias - IranWire - November 7th, 2025 [November 7th, 2025]
- Iran Arrests Baha'is in Wave of Raids Across Multiple Provinces - IranWire - November 7th, 2025 [November 7th, 2025]
- Trump says Iran has asked about lifting US sanctions - - November 7th, 2025 [November 7th, 2025]
- Iran unveils monument to ancient victory in show of post-war defiance - RFI - November 7th, 2025 [November 7th, 2025]
- Iran condemns Israels breach of truce and strikes on Lebanon - Tehran Times - November 7th, 2025 [November 7th, 2025]
- Iran: US Citizen Hekmati, 70, Sentenced to 4 Years Over Trip to Israel in 2012 - EA WorldView - November 7th, 2025 [November 7th, 2025]
- Iran submits three films to 1st Open Eurasian Film Award Diamond Butterfly - Tehran Times - November 7th, 2025 [November 7th, 2025]
- IDF reveals Hamas ties to Iran, UNRWA, Al Jazeera, stolen aid in collection of documents - The Jerusalem Post - November 7th, 2025 [November 7th, 2025]
- Iran unveils monument to ancient victory in show of post-war defiance - Homenewshere.com - November 7th, 2025 [November 7th, 2025]
- Iranian-American poets son arrested over Detroit terror plot | Iran International - - November 7th, 2025 [November 7th, 2025]
- Average age of first-time mothers in Iran continues to rise - Tehran Times - November 7th, 2025 [November 7th, 2025]
- Iran planned to assassinate Israel's ambassador to Mexico, but the attempt was thwarted - US official - - November 7th, 2025 [November 7th, 2025]
- Between Mediation and Advocacy: Omans Shifting Role in Gulf-Iran Relations - orfonline.org - November 7th, 2025 [November 7th, 2025]
- Not if they say we will bomb you: Pezeshkian says Iran seeks peace, but wont abandon nuke programme - WION - November 7th, 2025 [November 7th, 2025]
- Soroka to receive over $300 million to rebuild after Iran missile strike in June - The Times of Israel - November 3rd, 2025 [November 3rd, 2025]
- Iran: Human rights investigators alarmed by surge in repression and spike in executions following Israeli airstrikes - UN News - November 3rd, 2025 [November 3rd, 2025]
- Iran says wont dismantle missiles, ready for war with Israel - JNS.org - November 3rd, 2025 [November 3rd, 2025]
- Irans Ruling Class Turns on Itself as Crises Deepen - National Council of Resistance of Iran - NCRI - November 3rd, 2025 [November 3rd, 2025]
- Is this the end of Iran's Islamic Revolution? - The Jerusalem Post - November 3rd, 2025 [November 3rd, 2025]
- Dead Sea hotel worker charged with spying for Iran; was asked for intel on Ben Gvir - The Times of Israel - November 3rd, 2025 [November 3rd, 2025]
- Iran's Bitcoin Mining Industry: Inside the World's Fifth-Largest Operation Amid Sanctions and Energy Crisis - Brave New Coin - November 3rd, 2025 [November 3rd, 2025]
- Russian FM says no limits for military cooperation with Iran - Tehran Times - November 3rd, 2025 [November 3rd, 2025]
- Araghchi says Israel duped US on Iran threat, urges Trump to reverse course - - November 3rd, 2025 [November 3rd, 2025]
- Former Israeli Ambassador Warns That Iran, Russia, and China Are Expanding Terror Sleeper Cells Across the US - VINnews - November 3rd, 2025 [November 3rd, 2025]
- In the past 48 hours, the heinous lie that the unlawful Israeli and U.S. bombing of Iran was motivated by an imminent nuclear threat has been... - November 3rd, 2025 [November 3rd, 2025]
- Iran To Build 8 New Nuclear Plants With Russias Help - Eurasia Review - November 3rd, 2025 [November 3rd, 2025]
- At the heart of regional architecture, Iran is inevitable - Tehran Times - November 3rd, 2025 [November 3rd, 2025]
- Iran promises to rebuild bombed nuclear sites "with greater strength" after US strikes - Euromaidan Press - November 3rd, 2025 [November 3rd, 2025]
- We will not be set back: Pezeshkian vows Iran will rebuild its nuclear sites stronger than before - WION - November 3rd, 2025 [November 3rd, 2025]