---
title: "Russian, Iranian hackers pose as journalists in e-mails, UK says"
description: "British cybersecurity officials are warning that hacking groups linked to Russia and Iran are duping people into clicking malicious links by impersonating journalists and experts."
type: "NewsArticle"
publisher: "Daily Maverick"
site: "https://www.dailymaverick.co.za"
section: "Business Maverick"
author: "Bloomberg"
author_url: "https://www.dailymaverick.co.za/author/bloomberg/"
canonical_url: "https://www.dailymaverick.co.za/article/2023-01-26-russian-iranian-hackers-pose-as-journalists-in-e-mails-uk-says/"
published: "2023-01-26T06:04:02"
updated: "2023-01-26T06:06:43"
lang: "en-ZA"
word_count: 240
---

# Russian, Iranian hackers pose as journalists in e-mails, UK says

> British cybersecurity officials are warning that hacking groups linked to Russia and Iran are duping people into clicking malicious links by impersonating journalists and experts.

By Bloomberg · Published 26 January 2023, 08:04 SAST · Updated 26 January 2023, 08:06 SAST

## Key points
- The UK's National Cyber Security Centre (NCSC) has warned of two separate but similar hacking campaigns by Russian and Iranian groups targeting people in academia, defence, media, government, activists and NGOs. The Russian hackers, known as Seaborgium or Cold River, are linked to the website that published private emails from the former head of MI6. The Iranian hackers have previously targeted officials at the World Health Organisation. They use tactics like studying their targets' interests and creating fake social media profiles to lure victims into sending supposed conference invitations. NCSC urged organisations and individuals to follow their mitigation advice to protect themselves online.
- Russian and Iranian hackers are targeting people in academia, defence, the media, government and NGOs.
- Google researchers have linked the Russian hackers to a website that published private emails from the former head of MI6.
- The Iranian hackers have previously targeted officials at the World Health Organisation and Middle Eastern scholars.
- The hackers study their targets’ interests and create fake social media profiles to trick them into clicking malicious links. BM/DM

## Content

The hackers, who have similar goals but are said to be working separately, have sought to steal emails from people working in academia, defence, the media and government, as well as from activists and non-governmental organisations, according to an advisory released on Thursday by the UK’s [National Cyber Security Centre](https://www.ncsc.gov.uk/).

“These campaigns by threat actors based in Russia and Iran continue to ruthlessly pursue their targets in an attempt to steal online credentials and compromise potentially sensitive systems,” said Paul Chichester, the centre’s director of operations. “We strongly encourage organisations and individuals to remain vigilant to potential approaches and follow the mitigation advice in the advisory to protect themselves online.”

The Russian hackers, known as “Seaborgium” or “Cold River”, were [linked](https://blog.google/threat-analysis-group/continued-cyber-activity-in-eastern-europe-observed-by-tag/) by researchers from Google in May to a website that had published private emails from the former head of the UK’s MI6 intelligence agency. The group also last year targeted scientists at three nuclear research laboratories in the US, [according](https://www.reuters.com/world/europe/russian-hackers-targeted-us-nuclear-scientists-2023-01-06/) to Reuters.

The Iranian hackers, also sometimes called “TA453” or “Charming Kitten”, have previously been [observed](https://www.bloomberg.com/news/articles/2020-05-07/hackers-target-who-by-posing-as-think-tank-broadcaster) targeting officials at the World Health Organisation and scholars who specialise in Middle Eastern issues.

The hackers study their targets’ interests and identify their real-world social or professional contacts, according to the UK’s cyber security centre. They have also created fake social media or networking profiles and tricked their victims by sending supposed conference or event invitations, according to the centre. **BM/DM**
