Facebook said it disrupted the Iran-linked threat actor Tortoiseshell after identifying a broad cyberespionage campaign that used fake personas, spoofed recruiting and job-search sites, and malicious domains impersonating trusted brands to target victims primarily in the United States. The operation focused on military personnel and organizations in the defense and aerospace sectors, with additional targeting in the UK and Europe, and relied on long-term social engineering, phishing, credential theft, and malware delivery through off-platform lures.
Reporting tied the activity to earlier Tortoiseshell operations, including a fake veteran hiring website used to host malware and probable supply-chain attacks against IT providers in Saudi Arabia. Facebook said the group deployed custom tools including the Windows malware Syskit, reconnaissance utilities, keyloggers, and malicious Excel files, including a variant that hid reconnaissance output inside a spreadsheet. The company removed attacker accounts, blocked malicious domains, notified targeted users, and said some malware development was linked to Tehran-based IT firm Mahak Rayan Afraz, which it assessed has ties to the IRGC.

TTPs, infrastructure, and targeting history in one profile.
6 events from the most recent confirmed update back to the earliest known activity.
Facebook revealed a previously unreported malicious Excel-embedded tool variant used by Tortoiseshell that stored system reconnaissance output in a hidden area of the spreadsheet. The company said the behavior resembled Cisco's previously identified Liderc reconnaissance tooling.
In the same investigation, Facebook assessed that part of Tortoiseshell's malware development was outsourced to Tehran-based IT company Mahak Rayan Afraz, which it said has ties to the IRGC. Facebook also noted links between some current and former MRA executives and U.S.-sanctioned companies.
Facebook said it disrupted an Iran-linked cyberespionage operation by Tortoiseshell that primarily targeted U.S. military personnel and defense and aerospace organizations, with additional targeting in the UK and Europe. Facebook removed the actors' accounts, blocked malicious domains, notified targeted users, and shared indicators with industry peers.
Proofpoint reported that TA456, overlapping with Tortoiseshell, used the fake persona “Marcella Flores” to build trust with an employee at a small subsidiary of an aerospace defense contractor and in early June 2021 sent a OneDrive link delivering a malicious Excel macro document. The document dropped the VBS-based LEMPO implant, which Proofpoint assessed as an updated Liderc variant used for reconnaissance and data exfiltration.
Cisco Talos reported that Tortoiseshell created a fake veteran hiring website as part of its malware delivery and social-engineering activity. The operation used spoofed employment-themed infrastructure to lure targets.
Symantec published research that Tortoiseshell targeted IT providers in Saudi Arabia in probable supply-chain attacks. The reporting identified a distinct campaign focus on regional service providers as an intrusion vector.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 197 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
4 references tracked. Mallory keeps watching after this page renders.
proofpoint.com
Open sourceabout.fb.com
Open sourceblog.talosintelligence.com
Open sourcesymantec-enterprise-blogs.security.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.