On Friday, Meta Platforms joined Microsoft, Google, and OpenAI in exposing the activities of an Iranian state-sponsored threat actor. This actor, using a set of WhatsApp accounts, attempted to target individuals in Israel, Palestine, Iran, the U.K., and the U.S.
Meta revealed that the activity cluster originated from Iran and appeared to focus on political and diplomatic officials, as well as other public figures. Some of these targets were associated with the administrations of President Biden and former President Trump.
Meta attributed this malicious activity to a nation-state actor tracked as APT42, also known by aliases such as Charming Kitten, Damselfly, Mint Sandstorm (formerly Phosphorus), TA453, and Yellow Garuda. This group is believed to be linked to Iran's Islamic Revolutionary Guard Corps (IRGC).
APT42 is known for using sophisticated social engineering techniques to spear-phish targets of interest, deploying malware, and stealing credentials. Just this week, Proofpoint disclosed that APT42 targeted a prominent Jewish figure, attempting to infect their device with malware named AnvilEcho.
According to Meta, this "small cluster" of WhatsApp accounts posed as technical support for well-known companies like AOL, Google, Yahoo, and Microsoft. However, Meta believes these efforts were ultimately unsuccessful. The identified accounts have since been blocked.
"We have not seen evidence that their accounts were compromised," said Meta, the parent company of Facebook, Instagram, and WhatsApp. "We have encouraged those who reported to us to take steps to ensure their online accounts are safe across the internet."
This development aligns with the U.S. government's formal accusation against Iran of trying to undermine U.S. elections, sow division among the American public, and erode trust in the electoral process through the spread of propaganda and the gathering of political intelligence.