News

Iranian Hackers Stole Charlie Hebdo Database

Microsoft analysts have said that a group of Iranian government hackers called Neptunium is behind the hacking campaign against the French satirical magazine Charlie Hebdo.

Recall that we also wrote that Iranian hackers disguised themselves as an aerobics instructor, and also that the US Department of Justice accuses three Iranian hackers of hacking aerospace companies.

The media also reported that Iranian hackers attack VPN-servers to install backdoors.

Last month, the group said it had stolen the personal information of 200,000 Charlie Hebdo subscribers by gaining access to the publication’s internal database.

In January 2023, someone using the name Holy Souls put Charlie Hebdo subscriber information up for sale, valuing the dump at 20 BTC (roughly $340,000 at the time). Then the French media Le Monde confirmed the authenticity of the information that fell into the hands of hackers.

The published samples included names, phone numbers, addresses, email addresses, and more. Holy Souls advertised the stolen data on YouTube, on several hacker forums, and actively posted about the leak on social media.

According to Microsoft, the attack and the data breach followed the magazine’s decision to hold a cartoon contest in which readers were asked to submit drawings mocking Iran’s supreme leader, Ali Khamenei. The issue with the winning cartoons was supposed to be published in early January, timed to coincide with the eighth anniversary of the terrorist attack and attack on the publication’s office.

Iranian Foreign Minister Hossein Amir Abdollahian sharply criticized the competition, calling it “insulting and impolite action directed against the religious and political-spiritual authorities” of the country. He added that it was Charlie Hebdo’s actions that would not be “left unanswered”. In addition, the Iranian Foreign Ministry demanded a meeting with the French ambassador and also closed the French Research Institute in Iran.

As Microsoft researchers now write, the attack on the magazine is linked to the Iranian government because it matches attributes seen in other attacks by Iranian hackers. “Coincidences” even include the tactics used by hacktivists, who eventually claimed responsibility for the hack and leakage of personal data. According to experts, Holy Souls is the Iranian hack band Neptunium, also known as Emennet Pasargad.

The campaign targeting Charlie Hebdo used dozens of francophone sockpuppet accounts to amplify its campaign and spread antagonistic messages. On January 4, accounts, many of which were very recent and had few followers, began tweeting criticism of the Khamenei cartoons. Crucially, even before reports of the cyberattack surfaced, these accounts posted identical screenshots of the site’s defacement, with a message in French that Charlie Hebdo had been hacked (Charlie Hebdo a été piraté).the researchers say.

In addition, two fake social media accounts purporting to belong to the French CTO and editor of Charlie Hebdo also posted similar screenshots until they were banned.

Later, the same set of accounts were used to ridicule France and spread jokes that “French cybersecurity experts should be Charlie’s next cartoon characters.”
User Review
0 (0 votes)
Comments Rating 0 (0 reviews)
Daniel Zimmermann

Daniel Zimmermann has been writing on security and malware subjects for many years and has been working in the security industry for over 10 years. Daniel was educated at the Saarland University in Saarbrücken, Germany and currently lives in New York.

Recent Posts

Remove Pbmsoultions pop-up ads (Virus Removal Guide)

Pbmsoultions.com is a domain that tries to trick you into clik to its browser notifications…

1 day ago

Remove Prizestash pop-up ads (Virus Removal Guide)

Prizestash.com is a site that tries to trick you into subscribing to its browser notifications…

1 day ago

Remove Verifiedbreaking pop-up ads (Virus Removal Guide)

Verifiedbreaking.com is a domain that tries to force you into subscribing to its browser notifications…

1 day ago

Remove Themoneyminutes pop-up ads (Virus Removal Guide)

Themoneyminutes.com is a domain that tries to force you into subscribing to its browser notifications…

1 day ago

Remove News-xcidizi pop-up ads (Virus Removal Guide)

News-xcidizi.com is a domain that tries to trick you into clik to its browser notifications…

1 day ago

Remove Everytraffic-flow pop-up ads (Virus Removal Guide)

Everytraffic-flow.com is a domain that tries to trick you into subscribing to its browser notifications…

1 day ago