“Shabak” Warns of Iranian Cyberattacks Targeting “Journalists and Media Personnel” - Sarmad

Israel’s General Security Service, known as Shin Bet, has warned of cyberattacks carried out by Iranian intelligence agencies, primarily targeting journalists and media professionals.
According to the warning, these attacks rely on a “spear-phishing” approach, with attackers contacting journalists via WhatsApp and Telegram using fake accounts impersonating individuals well-known to the victims, such as colleagues or reputable media outlets.
The operation begins with messages that appear personal and convincing, offering opportunities to participate in interviews or discussion panels, or inviting collaboration on specific topics. After building a degree of trust, journalists are asked to click on a link purportedly for joining a video conference, but which actually leads to a fraudulent page requesting login credentials for Google accounts, or contains malicious files that allow full control over the device.
Shin Bet noted that the primary objective of these operations is espionage and the collection of sensitive information regarding security and political developments, as well as attempts to access journalists’ sources, work materials, and private correspondence.
The warnings were not limited to journalists; they also extended to public figures, political activists, and government employees, indicating an expansion of the targeting scope.
The National Cyber Directorate has urged extreme caution, advising against clicking on any links received via unexpected messages, even if they appear to come from a trusted source. It also recommended enabling two-factor authentication on all major accounts, regularly reviewing login activity, and immediately reporting any suspicious attempts to the relevant authorities.