Iran-Based TG-2889 Uses Fake LinkedIn Network to Target Middle East Telecom and Defense
- Actor Motivations: Espionage,Exfiltration
- Attack Vectors: Honey Trap,Phishing,Spear Phishing
- Attack Complexity: Medium
- Threat Risk: High Impact/Low Probability
Threat Overview
In October 2015, Dell SecureWorks Counter Threat Unit (CTU) researchers uncovered a network of 25 fake LinkedIn profiles created by TG-2889, a suspected Iran-based threat group linked to Operation CLEAVER. The fake accounts were divided into two tiers: eight "Leader" personas with detailed professional histories, 500+ connections, and skills endorsements — purporting to work for companies including Teledyne Technologies, Northrop Grumman, Doosan, and Petrochemical Industries Co. — and 17 simpler "Supporter" personas designed solely to endorse the Leader accounts and artificially boost their credibility. Five Leader personas posed as recruitment consultants, providing a natural pretext to approach targets with job offers. CTU researchers identified 204 likely victims based on users who had endorsed the fake Leader profiles; a quarter worked in telecommunications (Middle Eastern and North African mobile operators featured heavily), with significant minorities in Middle Eastern governments and defense organizations. The threat actors also demonstrated a novel technique — replacing one persona's identity with another on the same LinkedIn account, inheriting the accumulated network and endorsements while refreshing the cover identity. Fake domains matching the impersonated companies (teledyne-jobs[.]com, doosan-job[.]com, northropgrumman[.]net) link TG-2889 to the Operation CLEAVER malware campaign documented by Cylance, which used fake job application portals to deliver malware. The group's geographic focus on Arab states in the MENA region is consistent with Iran-based threat actor targeting.
Detected Targets
| Type | Description | Confidence |
|---|---|---|
| Sector | Defense | Verified |
| Sector | Government Agencies and Services None | Verified |
| Sector | Manufacturing | Verified |
| Sector | Aerospace | Verified |
| Sector | Telecommunication None | Verified |
| Region | Algeria | High |
| Region | Bahrain | High |
| Region | Canada | High |
| Region | Egypt | High |
| Region | India | High |
| Region | Iran | High |
| Region | Israel | High |
| Region | Jordan | High |
| Region | Kuwait | High |
| Region | Qatar | High |
| Region | Saudi Arabia | High |
| Region | Sudan | High |
| Region | United Arab Emirates | High |
| Region | United Kingdom | High |
| Region | United States | High |
Extracted IOCs
- doosan-job[.]com
- northropgrumman[.]net
- teledyne-jobs[.]com
Tip: 3 related IOCs (0 IP, 3 domain, 0 URL, 0 email, 0 file hash) to this threat have been found.
FAQs
Frequently Asked Questions about TG-2889's Fake LinkedIn Network Operation
TG-2889, a suspected Iran-based threat group linked to the Operation CLEAVER campaign, built a network of 25 fake LinkedIn profiles designed to infiltrate the professional networks of employees at Middle Eastern telecom companies, defense contractors, and government organizations. The fake profiles fell into two types: eight highly developed "Leader" personas posing as recruitment consultants and engineers at major companies, and 17 simpler "Supporter" personas that existed purely to endorse the Leaders' skills and make them appear more credible. Dell SecureWorks Counter Threat Unit (CTU) researchers uncovered the operation and identified 204 real LinkedIn users who had already engaged with the fake profiles, making them likely targets for follow-on phishing or malware attacks.
The operation was conducted by TG-2889, tracked by Dell SecureWorks as a suspected Iran-based threat group. CTU researchers linked TG-2889 to the activity documented in Cylance's December 2014 Operation CLEAVER report — both groups used identical fake company domains (teledyne-jobs[.]com, doosan-job[.]com, northropgrumman[.]net) and impersonated the same companies. Operation CLEAVER was attributed to Iran-based threat actors. TG-2889's geographic focus on Arab states in the Middle East and North Africa is consistent with the targeting behavior of Iran-aligned groups.
The LinkedIn network was the reconnaissance and trust-building phase. Once connected with targets, TG-2889 likely followed up with spearphishing links or malicious files — tactics consistent with Operation CLEAVER, where fake job application portals delivered malware disguised as résumé submission tools. The goal was intelligence collection and network access: telecom companies hold valuable subscriber data and network infrastructure access, while defense contractors and government employees hold sensitive information relevant to Iran's geopolitical interests.
CTU researchers identified 204 likely targets by analyzing real LinkedIn users who had endorsed the fake Leader profiles — meaning they had already accepted connection requests from TG-2889's fake personas. A quarter of those 204 people worked in telecommunications, with Middle Eastern and North African mobile phone operators featuring heavily. A significant portion also worked in Middle Eastern governments and defense organizations across the Middle East and South Asia. The broader geographic targeting spread across 18 countries including Saudi Arabia, the UAE, Qatar, Kuwait, Jordan, Egypt, Israel, and others.
The primary targets were employees at Middle Eastern and North African telecommunications companies — particularly mobile phone operators — along with people working in Middle Eastern governments and regional and South Asian defense organizations. Telecom employees are attractive targets because their organizations control communications infrastructure and subscriber data. Defense and government employees hold sensitive national security and policy information. All of these sectors represent high-value intelligence targets for a state-aligned Iranian actor.
TG-2889 built a layered fake identity network on LinkedIn. The high-quality Leader personas used stolen photos, fabricated employment histories copied from real job postings, and claimed to work at well-known defense and industrial companies like Teledyne and Northrop Grumman. Five of the Leaders posed as recruitment consultants — giving them a credible reason to reach out to strangers. The Supporter personas then endorsed the Leaders' skills, making the profiles appear more established and trustworthy. Once a target accepted a connection request from a Leader persona, TG-2889 could message them directly, potentially sending job offers with malicious links or attachments. The group also demonstrated a clever trick: replacing one fake persona's identity with another on the same LinkedIn account, so the new persona immediately inherited hundreds of connections and endorsements without starting from scratch.
Middle Eastern telecom operators are attractive targets because they control the communications infrastructure that governments, businesses, and citizens rely on — giving an adversary access to call records, subscriber data, and potentially the ability to monitor or disrupt communications. Defense contractors in the region hold sensitive information about weapons systems and regional security partnerships that are directly relevant to Iran's strategic calculations. Government employees are targeted for intelligence on policy decisions, diplomatic activities, and national security matters. All of these sectors represent information Iran would seek to monitor, given ongoing regional rivalries and geopolitical tensions.
Be skeptical of LinkedIn connection requests from recruiters at major defense or technology companies you don't have a prior relationship with — especially if the request comes out of nowhere. Before engaging with a LinkedIn recruiter, verify they are a real person by calling the company's main switchboard directly using contact details from the official company website, not from the LinkedIn profile. Do not click links or open attachments sent via LinkedIn messages from people you don't know personally. Limit what you share publicly on LinkedIn — project details, security clearances, technical roles, and organizational structure all help adversaries identify and target you. Organizations in telecom, defense, and government should monitor LinkedIn for fake profiles impersonating their brand and report them to LinkedIn. Security awareness training should specifically cover the risk of social engineering via professional networks, not just email.