{"id":604561,"date":"2023-02-04T07:48:45","date_gmt":"2023-02-04T13:48:45","guid":{"rendered":"https:\/\/news.sellorbuyhomefast.com\/index.php\/2023\/02\/04\/microsoft-alleges-attacks-on-french-magazine-came-from-iranian-backed-group\/"},"modified":"2023-02-04T07:48:45","modified_gmt":"2023-02-04T13:48:45","slug":"microsoft-alleges-attacks-on-french-magazine-came-from-iranian-backed-group","status":"publish","type":"post","link":"https:\/\/newsycanuse.com\/index.php\/2023\/02\/04\/microsoft-alleges-attacks-on-french-magazine-came-from-iranian-backed-group\/","title":{"rendered":"Microsoft alleges attacks on French magazine came from Iranian-backed group"},"content":{"rendered":"<div>\n<h4>\n      INFLUENCE CAMPAIGN    \u2014<br \/>\n<\/h4>\n<h2 itemprop=\"description\">Leaked personal data of Charlie Hebdo customers puts them at risk from extremists.<\/h2>\n<section>\n<p itemprop=\"author creator\" itemscope itemtype=\"http:\/\/schema.org\/Person\">\n      <a itemprop=\"url\" href=\"https:\/\/arstechnica.com\/author\/dan-goodin\/\" rel=\"author\"><span itemprop=\"name\">Dan Goodin<\/span><\/a><br \/>\n    &#8211;  <time data-time=\"1675458623\" datetime=\"2023-02-03T21:10:23+00:00\">Feb 3, 2023 9:10 pm UTC<\/time>\n<\/p>\n<\/section><\/div>\n<div itemprop=\"articleBody\">\n<figure>\n  <img decoding=\"async\" src=\"https:\/\/cdn.arstechnica.net\/wp-content\/uploads\/2023\/02\/iranian-flag-800x522.jpg\" alt=\"Microsoft alleges attacks on French magazine came from Iranian-backed group\"><figcaption><\/figcaption><\/figure>\n<p>Microsoft said on Friday that an Iranian nation-state group already sanctioned by the US government was behind an attack last month that targeted the satirical French magazine Charlie Hebdo and thousands of its readers.<\/p>\n<p>The attack came to light on January 4, when a previously unknown group calling itself Holy Souls took to the Internet to claim it had <a href=\"https:\/\/web.archive.org\/web\/20230109230105\/https:\/\/breached.vc\/Thread-Personal-information-of-230000-customers-of-charliehebdo-fr\">obtained a Charlie Hebdo database<\/a> that contained personal information for 230,000 of its customers. The post said the database was available for sale at the price of 20 BTC, or roughly $340,000 at the time. The group also released a sample of the data that included the full names, telephone numbers, and home and email addresses of people who had subscribed to, or purchased merchandise from, the publication. French media <a href=\"https:\/\/www.lemonde.fr\/lmdgft\/1\/NjE1NjkxNi1mZjNlZmMwMGQ1NGUyMWVlMTBmYzRmZjBjZjAzYjU2YzNkY2JkM2NlYjNhZjIwZTg2ZGIwMTJlYThjODA0OWE3?random=1150217085\">confirmed<\/a> the veracity of the leaked data.<\/p>\n<p>The release of the sample put the customers at risk of online targeting or physical violence by extremist groups, which have retaliated against Charlie Hebdo in recent years for its satirical treatment of matters pertaining to the Muslim religion and Islamic countries such as Iran. The retaliation included the 2015 shooting by two French Muslim terrorists and brothers at Charlie Hebdo offices that killed 12 and injured 11 others. To further gin up attention to the breached data, a flurry of fake personas\u2014one falsely claiming to be a Charlie Hebdo editor\u2014took to social media to discuss and publicize the leak.<\/p>\n<figure><a href=\"https:\/\/cdn.arstechnica.net\/wp-content\/uploads\/2023\/02\/hebdo1-1.jpg\" data-height=\"1218\" data-width=\"876\" alt=\"Twitter post purporting to come from impersonating a Charlie Hebdo editor.\"><img loading=\"lazy\" decoding=\"async\" alt=\"Twitter post purporting to come from impersonating a Charlie Hebdo editor.\" src=\"https:\/\/cdn.arstechnica.net\/wp-content\/uploads\/2023\/02\/hebdo1-1-640x890.jpg\" width=\"640\" height=\"890\" ><\/a><figcaption>\n<p><a href=\"https:\/\/cdn.arstechnica.net\/wp-content\/uploads\/2023\/02\/hebdo1-1.jpg\" data-height=\"1218\" data-width=\"876\">Enlarge<\/a> <span>\/<\/span> Twitter post purporting to come from impersonating a Charlie Hebdo editor.<\/p>\n<p>Microsoft<\/p>\n<\/figcaption><\/figure>\n<p>On Friday, Clint Watts, the general manager of Microsoft\u2019s Digital Threat Analysis Center, <a href=\"https:\/\/blogs.microsoft.com\/on-the-issues\/2023\/02\/03\/dtac-charlie-hebdo-hack-iran-neptunium\/\">wrote<\/a>:<\/p>\n<blockquote>\n<p>We believe this attack is a response by the Iranian government to a cartoon contest conducted by Charlie Hebdo. One month before Holy Souls conducted its attack, the magazine announced it would be holding an international competition for cartoons \u201cridiculing\u201d Iranian Supreme Leader Ali Khamenei. The issue featuring the winning cartoons was to be published in early January, timed to coincide with the eighth anniversary of an attack by two al-Qa\u2019ida in the Arabian Peninsula (AQAP)-inspired assailants on the magazine\u2019s offices.<\/p>\n<\/blockquote>\n<p>The tactics, techniques, and procedures of the influence campaign led Microsoft researchers to conclude it was the work of Emennet Pasargad, an Iranian group that has long been monitored and targeted by the US government. The FBI <a href=\"https:\/\/www.ic3.gov\/Media\/News\/2022\/221020.pdf\">said<\/a> in January 2022 that Emennet Pasargad was behind \u201ca multi-faceted campaign to interfere in the 2020 US presidential election.\u201d<\/p>\n<p>Participants in the operation obtained confidential US voter information from at least one state election website, sent threatening emails designed to intimidate voters, and published a video airing disinformation concerning non-existent voting vulnerabilities. The group also claimed affiliation with the neo-fascist group Proud Boys to further intimidate voters.<\/p>\n<p>Last October, the FBI <a href=\"https:\/\/www.ic3.gov\/Media\/News\/2022\/221020.pdf\">said<\/a> that Emennet Pasargad targeted groups in Israel with \u201ccyber-enabled information operations that included an initial intrusion, theft, and subsequent leak of data, followed by amplification through social media and online forums, and in some cases the deployment of destructive encryption malware.\u201d<\/p>\n<p>The US Treasury in 2021 <a href=\"https:\/\/home.treasury.gov\/news\/press-releases\/jy0494\">placed sanctions<\/a> on Emennet Pasargad and six Iranian nationals who are members, citing their attempts \u201cto sow discord and undermine voters\u2019 faith in the US electoral process.\u201d<\/p>\n<p>Friday\u2019s post said Microsoft had \u201chigh confidence\u201d that the group, which the company refers to as Neptunium, was behind the Charlie Hebdo influence campaign. The assessment was based on elements including:<\/p>\n<blockquote>\n<ul>\n<li aria-level=\"1\">A hacktivist persona claiming credit for the cyberattack<\/li>\n<li aria-level=\"1\">Claims of a successful website defacement<\/li>\n<li aria-level=\"1\">Leaking of private data online<\/li>\n<li aria-level=\"1\">The use of inauthentic social media \u201csockpuppet\u201d personas\u2014social media accounts using fictitious or stolen identities to obfuscate the account\u2019s real owner for the purpose of deception\u2014claiming to be from the country that the hack targeted to promote the cyberattack using language with errors obvious to native speakers<\/li>\n<li aria-level=\"1\">Impersonation of authoritative sources<\/li>\n<li aria-level=\"1\">Contacting news meida organizations<\/li>\n<\/ul>\n<\/blockquote>\n<figure><a href=\"https:\/\/cdn.arstechnica.net\/wp-content\/uploads\/2023\/02\/hebdo2.jpg\" data-height=\"812\" data-width=\"960\" alt=\"Attribution matrix Microsoft used to arrive at its assessment.\"><img loading=\"lazy\" decoding=\"async\" alt=\"Attribution matrix Microsoft used to arrive at its assessment.\" src=\"https:\/\/cdn.arstechnica.net\/wp-content\/uploads\/2023\/02\/hebdo2-640x541.jpg\" width=\"640\" height=\"541\" ><\/a><figcaption>\n<p><a href=\"https:\/\/cdn.arstechnica.net\/wp-content\/uploads\/2023\/02\/hebdo2.jpg\" data-height=\"812\" data-width=\"960\">Enlarge<\/a> <span>\/<\/span> Attribution matrix Microsoft used to arrive at its assessment.<\/p>\n<p>Microsoft<\/p>\n<\/figcaption><\/figure>\n<p>Microsoft said the January campaign used French-language sockpuppet social media accounts, many with low follower counts, to amplify the leak and \u201cdistribute antagonistic messaging.\u201d The accounts also posted criticisms of the cartoon competition aimed at Khamenei.<\/p>\n<p>\u201cCrucially, before there had been any substantial reporting on the purported cyberattack, these accounts posted identical screenshots of a defaced website that included the French-language message: \u2018Charlie Hebdo a \u00e9t\u00e9 pirat\u00e9\u2019 (\u2018Charlie Hebdo was hacked\u2019),\u201d Watts wrote.<\/p>\n<p>Shortly after that, at least two social media accounts\u2014one purporting to belong to a tech executive and the other to a Charlie Hebdo editor\u2014posted screenshots of the leaked customer data.<\/p>\n<p>The campaign Microsoft has documented is the latest reminder that social media is often manipulated by special interest groups\u2014some with deep pockets. People would do well to remember this manipulation and be careful to verify claims before spreading them further.<\/p>\n<\/p><\/div>\n<p><a href=\"https:\/\/arstechnica.com\/?p=1915010\" class=\"button purchase\" rel=\"nofollow noopener\" target=\"_blank\">Read More<\/a><br \/>\n Dan Goodin<\/p>\n","protected":false},"excerpt":{"rendered":"<p>INFLUENCE CAMPAIGN \u2014 Leaked personal data of Charlie Hebdo customers puts them at risk from extremists. Dan Goodin &#8211; Feb 3, 2023 9:10 pm UTC Microsoft said on Friday that an Iranian nation-state group already sanctioned by the US government was behind an attack last month that targeted the satirical French magazine Charlie Hebdo and<\/p>\n","protected":false},"author":1,"featured_media":604562,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[30403,78,46],"tags":[],"class_list":{"0":"post-604561","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-alleges","8":"category-microsoft","9":"category-technology"},"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/newsycanuse.com\/index.php\/wp-json\/wp\/v2\/posts\/604561","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/newsycanuse.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/newsycanuse.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/newsycanuse.com\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/newsycanuse.com\/index.php\/wp-json\/wp\/v2\/comments?post=604561"}],"version-history":[{"count":0,"href":"https:\/\/newsycanuse.com\/index.php\/wp-json\/wp\/v2\/posts\/604561\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/newsycanuse.com\/index.php\/wp-json\/wp\/v2\/media\/604562"}],"wp:attachment":[{"href":"https:\/\/newsycanuse.com\/index.php\/wp-json\/wp\/v2\/media?parent=604561"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/newsycanuse.com\/index.php\/wp-json\/wp\/v2\/categories?post=604561"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/newsycanuse.com\/index.php\/wp-json\/wp\/v2\/tags?post=604561"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}