London's School of Oriental and African Studies. Courtesy: SOAS
London's School of Oriental and African Studies. Courtesy: SOAS
London's School of Oriental and African Studies. Courtesy: SOAS
London's School of Oriental and African Studies. Courtesy: SOAS

Iranian hackers posed as British-based academic in failed espionage effort


  • English
  • Arabic

An Iranian group masqueraded as a British-based academic during a cyber espionage campaign.

The group also compromised the website belonging to the School of Oriental and African Studies (SOAS), University of London, to try to steal information.

The operation, which did not affected SOAS data systems, was uncovered by cyber security company Proofpoint. They called it "SpoofedScholars" and said it showed an increase in threat sophistication.

The attackers, sometimes referred to as "Charming Kitten" and believed to be linked to the Iranian state, were also willing to engage in real-time conversations with their targets, who were mainly in the US and UK.

In early 2021, emails claiming to come from a "senior teaching and research fellow" at SOAS invited people to join an online conference called The US Security Challenges in the Middle East.

The emails, sent from a Gmail address, were not from the academic but an espionage group believed to be linked to the Iranian Islamic Revolutionary Guard Corps (IRGC).

Once a conversation was established, the target was sent a "registration link" hosted by a website that was compromised by the attackers.

It belonged to SOAS radio, an independent online radio station and production company based at SOAS.

This link then offered a means to log on using email providers Google, Yahoo, Microsoft, iCloud, Outlook, AOL, mail.ru, Email, and Facebook, which could then capture the passwords and usernames.

Stealing credentials is not new, but the use of a real website to do so is.

"It is highly unusual and more sophisticated for this group," said Sherrod DeGrippo, senior director, threat research and detection for Proofpoint.

The communications between the fake academic and the target could be lengthy to build trust before sending the registration link. In some cases, the sender asked to connect by phone with the recipients to discuss the invitation.

In one instance, the recipient asked for and received more detail by email, with the attackers then suggesting they connect by videoconference.

That cyber spies were trying to connect in real time with individuals by phones and videoconferencing to talk rather than just engaging by email was also unusual, suggesting confidence in their skills in English and in impersonation.

It was not clear if conversations took place.

The operation was highly focused, involving fewer than 10 target organisations, Proofpoint said. In some cases, there were multiple individuals inside those organisations.

They were primarily from three groups:

  • Senior think tank personnel working on the Middle East
  • Journalists focused on the region
  • Academics, including senior professors

It is thought likely that they were selected because they might have information on foreign policy of countries towards Iran, negotiations about Iran's nuclear programme, or information about Iranian dissidents.

This fits with earlier activity by the same espionage group, which Proofpoint called TA453.

"TA453's continued interest in these targets demonstrates an Iranian commitment to user cyber operations to collect intelligence in support of intelligence priorities," Ms DeGrippo said.

A few months after the initial campaign began in January, another SOAS academic's identity was used by the group to try to recruit for a webinar.

The group also seemed interested in mobile phone numbers, possibly to use to deliver malicious software or to use to against others.

SOAS said no personal information was obtained and its data systems were not affected.

It said the compromised radio website was separate from the official SOAS website and not part of any of its academic domains.

"Once we became aware of the dummy site earlier this year, we immediately remedied and reported the breach in the normal way. We have reviewed how this took place and taken steps to further improve protection of these sort of peripheral systems," the university said.

Proofpoint said it cannot be completely sure the IRGC was behind the campaign but the tactics, techniques and the targeting give it "high confidence" that it was responsible.

The company said it has worked with the authorities on victim notification but that TA453 was likely to continue to try to pass itself off as academics.

Proofpoint recommended that academics, journalists, and think tank scholars should verify the identity of anyone offering them opportunities, especially if approached online.

US%20federal%20gun%20reform%20since%20Sandy%20Hook
%3Cp%3E-%20April%2017%2C%202013%3A%20A%20bipartisan-drafted%20bill%20to%20expand%20background%20checks%20and%20ban%20assault%20weapons%20fails%20in%20the%20Senate.%3C%2Fp%3E%0A%3Cp%3E-%20July%202015%3A%20Bill%20to%20require%20background%20checks%20for%20all%20gun%20sales%20is%20introduced%20in%20House%20of%20Representatives.%20It%20is%20not%20brought%20to%20a%20vote.%3C%2Fp%3E%0A%3Cp%3E-%20June%2012%2C%202016%3A%20Orlando%20shooting.%20Barack%20Obama%20calls%20on%20Congress%20to%20renew%20law%20prohibiting%20sale%20of%20assault-style%20weapons%20and%20high-capacity%20magazines.%3C%2Fp%3E%0A%3Cp%3E-%20October%201%2C%202017%3A%20Las%20Vegas%20shooting.%20US%20lawmakers%20call%20for%20banning%20bump-fire%20stocks%2C%20and%20some%20renew%20call%20for%20assault%20weapons%20ban.%3C%2Fp%3E%0A%3Cp%3E-%20February%2014%2C%202018%3A%20Seventeen%20pupils%20are%20killed%20and%2017%20are%20wounded%20during%20a%20mass%20shooting%20in%20Parkland%2C%20Florida.%3C%2Fp%3E%0A%3Cp%3E-%20December%2018%2C%202018%3A%20Donald%20Trump%20announces%20a%20ban%20on%20bump-fire%20stocks.%3C%2Fp%3E%0A%3Cp%3E-%20August%202019%3A%20US%20House%20passes%20law%20expanding%20background%20checks.%20It%20is%20not%20brought%20to%20a%20vote%20in%20the%20Senate.%3C%2Fp%3E%0A%3Cp%3E-%20April%2011%2C%202022%3A%20Joe%20Biden%20announces%20measures%20to%20crack%20down%20on%20hard-to-trace%20'ghost%20guns'.%3C%2Fp%3E%0A%3Cp%3E-%20May%2024%2C%202022%3A%20Nineteen%20children%20and%20two%20teachers%20are%20killed%20at%20an%20elementary%20school%20in%20Uvalde%2C%20Texas.%3C%2Fp%3E%0A%3Cp%3E-%20June%2025%2C%202022%3A%20Joe%20Biden%20signs%20into%20law%20the%20first%20federal%20gun-control%20bill%20in%20decades.%3C%2Fp%3E%0A
THE BIO

Born: Mukalla, Yemen, 1979

Education: UAE University, Al Ain

Family: Married with two daughters: Asayel, 7, and Sara, 6

Favourite piece of music: Horse Dance by Naseer Shamma

Favourite book: Science and geology

Favourite place to travel to: Washington DC

Best advice you’ve ever been given: If you have a dream, you have to believe it, then you will see it.

Joker: Folie a Deux

Starring: Joaquin Phoenix, Lady Gaga, Brendan Gleeson

Director: Todd Phillips 

Rating: 2/5

What is safeguarding?

“Safeguarding, not just in sport, but in all walks of life, is making sure that policies are put in place that make sure your child is safe; when they attend a football club, a tennis club, that there are welfare officers at clubs who are qualified to a standard to make sure your child is safe in that environment,” Derek Bell explains.

Company%20profile
%3Cp%3EName%3A%20Cashew%0D%3Cbr%3EStarted%3A%202020%0D%3Cbr%3EFounders%3A%20Ibtissam%20Ouassif%20and%20Ammar%20Afif%0D%3Cbr%3EBased%3A%20Dubai%2C%20UAE%0D%3Cbr%3EIndustry%3A%20FinTech%0D%3Cbr%3EFunding%20size%3A%20%2410m%0D%3Cbr%3EInvestors%3A%20Mashreq%2C%20others%0D%3C%2Fp%3E%0A
Sole survivors
  • Cecelia Crocker was on board Northwest Airlines Flight 255 in 1987 when it crashed in Detroit, killing 154 people, including her parents and brother. The plane had hit a light pole on take off
  • George Lamson Jr, from Minnesota, was on a Galaxy Airlines flight that crashed in Reno in 1985, killing 68 people. His entire seat was launched out of the plane
  • Bahia Bakari, then 12, survived when a Yemenia Airways flight crashed near the Comoros in 2009, killing 152. She was found clinging to wreckage after floating in the ocean for 13 hours.
  • Jim Polehinke was the co-pilot and sole survivor of a 2006 Comair flight that crashed in Lexington, Kentucky, killing 49.
ADCC AFC Women’s Champions League Group A fixtures

October 3: v Wuhan Jiangda Women’s FC
October 6: v Hyundai Steel Red Angels Women’s FC
October 9: v Sabah FA

Classification from Tour de France after Stage 17

1. Chris Froome (Britain / Team Sky) 73:27:26"

2. Rigoberto Uran (Colombia / Cannondale-Drapac) 27"

3. Romain Bardet (France / AG2R La Mondiale)

4. Fabio Aru (Italy / Astana Pro Team) 53"

5. Mikel Landa (Spain / Team Sky) 1:24"

Updated: July 27, 2021, 7:11 AM`