That’s a new one: Iranian hackers pretend to be a modelling agency to try and steal user details


- Unit 42 found a website spoofing a known German modelling agency
- The site carries obfuscated JavaScript which exfiltrates system information
- In the future, it could host malware or steal login credentials
Iranian hackers were found spoofing a German modelling agency in an attempt to gather more information about their targets’ devices.
This is according to a new report from Palo Alto Networks’ Unit 42, which also claims that full functionality of the campaign, which could include malware delivery or credential harvesting, has not yet been achieved.
Unit 42 says that while monitoring infrastructure they believe are likely tied to Iranian threat actors, the researchers found the domain “Megamodelstudio[.]com”. After browsing through the site a little, they determined it was a spoofed version of megamodelagency.com, a legitimate modelling agency based in Hamburg, Germany.
Selective targeting
The two websites are seemingly identical, but there are a few key differences. The malicious one, for example, carries an obfuscated JavaScript designed to capture detailed visitor information.
Unit 42 says the script grabs information about browser languages and plugins, screen resolution information, as well as timestamps, which allow the attackers to track a visitor’s location and environment.
The script also reveals the user’s local and public IP address, leverages canvas fingerprinting, and uses SHA-256 to produce a device-unique hash. Finally, it structures the collected data as JSON and delivers it to the endpoint /ads/track via a POST request.
“The likely goal of the code is to enable selective targeting by determining sufficient device- and network-specific details about visitors,” Unit 42 said.
Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!
“This naming convention suggests an attempt to disguise the collection as benign advertising traffic rather than storing and processing potential target fingerprints.”
Another key difference is that among profile pages of different models, one is fake. That page is currently not operational, but Unit 42 speculates it could be used in the future for more destructive attacks, dropping malware or stealing login credentials.
The researchers concluded, “with high confidence”, that the Iranians are behind the attack. They’re somewhat less confident about the exact group behind it, speculating that it might have been the work of Agent Serpens, also known as Charming Kitten, or APT35.
You might also like
Unit 42 found a website spoofing a known German modelling agency The site carries obfuscated JavaScript which exfiltrates system information In the future, it could host malware or steal login credentials Iranian hackers were found spoofing a German modelling agency in an attempt to gather more information about their targets’…
Recent Posts
- That’s a new one: Iranian hackers pretend to be a modelling agency to try and steal user details
- The Sonos Ace have hit their best price to date ahead of Father’s Day
- Google Drive’s new Gemini features include video analysis at last – but be wary of possible security risks
- Apple WWDC 2025: What we expect including new iOS software updates, macOS, AI and more
- macOS Tahoe rumored to follow Sequoia – here’s 3 things to expect from Apple’s next desktop OS
Archives
- June 2025
- May 2025
- April 2025
- March 2025
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023
- May 2023
- April 2023
- March 2023
- February 2023
- January 2023
- December 2022
- November 2022
- October 2022
- September 2022
- August 2022
- July 2022
- June 2022
- May 2022
- April 2022
- March 2022
- February 2022
- January 2022
- December 2021
- November 2021
- October 2021
- September 2021
- August 2021
- July 2021
- June 2021
- May 2021
- April 2021
- March 2021
- February 2021
- January 2021
- December 2020
- November 2020
- October 2020
- September 2020
- August 2020
- July 2020
- June 2020
- May 2020
- April 2020
- March 2020
- February 2020
- January 2020
- December 2019
- November 2019
- September 2018
- October 2017
- December 2011
- August 2010