NZ Herald
  • Home
  • Latest news
  • Video
  • New Zealand
  • Sport
  • World
  • Business
  • Entertainment
  • Podcasts
  • Quizzes
  • Opinion
  • Lifestyle
  • Travel
  • Viva
  • Weather forecasts

Subscriptions

  • Herald Premium
  • Viva Premium
  • The Listener
  • BusinessDesk

Sections

  • Latest news
  • New Zealand
    • All New Zealand
    • Crime
    • Politics
    • Education
    • Open Justice
    • Scam Update
    • The Great NZ Road Trip
  • On The Up
  • World
    • All World
    • Australia
    • Asia
    • UK
    • United States
    • Middle East
    • Europe
    • Pacific
  • Business
    • All Business
    • MarketsSharesCurrencyCommoditiesStock TakesCrypto
    • Markets with Madison
    • Media Insider
    • Business analysis
    • Personal financeKiwiSaverInterest ratesTaxInvestment
    • EconomyInflationGDPOfficial cash rateEmployment
    • Small business
    • Business reportsMood of the BoardroomProject AucklandSustainable business and financeCapital markets reportAgribusiness reportInfrastructure reportDynamic business
    • Deloitte Top 200 Awards
    • CompaniesAged CareAgribusinessAirlinesBanking and financeConstructionEnergyFreight and logisticsHealthcareManufacturingMedia and MarketingRetailTelecommunicationsTourism
  • Opinion
    • All Opinion
    • Analysis
    • Editorials
    • Business analysis
    • Premium opinion
    • Letters to the editor
  • Sport
    • All Sport
    • OlympicsParalympics
    • RugbySuper RugbyNPCAll BlacksBlack FernsRugby sevensSchool rugby
    • CricketBlack CapsWhite Ferns
    • Racing
    • NetballSilver Ferns
    • LeagueWarriorsNRL
    • FootballWellington PhoenixAuckland FCAll WhitesFootball FernsEnglish Premier League
    • GolfNZ Open
    • MotorsportFormula 1
    • Boxing
    • UFC
    • BasketballNBABreakersTall BlacksTall Ferns
    • Tennis
    • Cycling
    • Athletics
    • SailingAmerica's CupSailGP
    • Rowing
  • Lifestyle
    • All Lifestyle
    • Viva - Food, fashion & beauty
    • Society Insider
    • Royals
    • Sex & relationships
    • Food & drinkRecipesRecipe collectionsRestaurant reviewsRestaurant bookings
    • Health & wellbeing
    • Fashion & beauty
    • Pets & animals
    • The Selection - Shop the trendsShop fashionShop beautyShop entertainmentShop giftsShop home & living
    • Milford's Investing Place
  • Entertainment
    • All Entertainment
    • TV
    • MoviesMovie reviews
    • MusicMusic reviews
    • BooksBook reviews
    • Culture
    • ReviewsBook reviewsMovie reviewsMusic reviewsRestaurant reviews
  • Travel
    • All Travel
    • News
    • New ZealandNorthlandAucklandWellingtonCanterburyOtago / QueenstownNelson-TasmanBest NZ beaches
    • International travelAustraliaPacific IslandsEuropeUKUSAAfricaAsia
    • Rail holidays
    • Cruise holidays
    • Ski holidays
    • Luxury travel
    • Adventure travel
  • Kāhu Māori news
  • Environment
    • All Environment
    • Our Green Future
  • Talanoa Pacific news
  • Property
    • All Property
    • Property Insider
    • Interest rates tracker
    • Residential property listings
    • Commercial property listings
  • Health
  • Technology
    • All Technology
    • AI
    • Social media
  • Rural
    • All Rural
    • Dairy farming
    • Sheep & beef farming
    • Horticulture
    • Animal health
    • Rural business
    • Rural life
    • Rural technology
    • Opinion
    • Audio & podcasts
  • Weather forecasts
    • All Weather forecasts
    • Kaitaia
    • Whangārei
    • Dargaville
    • Auckland
    • Thames
    • Tauranga
    • Hamilton
    • Whakatāne
    • Rotorua
    • Tokoroa
    • Te Kuiti
    • Taumaranui
    • Taupō
    • Gisborne
    • New Plymouth
    • Napier
    • Hastings
    • Dannevirke
    • Whanganui
    • Palmerston North
    • Levin
    • Paraparaumu
    • Masterton
    • Wellington
    • Motueka
    • Nelson
    • Blenheim
    • Westport
    • Reefton
    • Kaikōura
    • Greymouth
    • Hokitika
    • Christchurch
    • Ashburton
    • Timaru
    • Wānaka
    • Oamaru
    • Queenstown
    • Dunedin
    • Gore
    • Invercargill
  • Meet the journalists
  • Promotions & competitions
  • OneRoof property listings
  • Driven car news

Puzzles & Quizzes

  • Puzzles
    • All Puzzles
    • Sudoku
    • Code Cracker
    • Crosswords
    • Cryptic crossword
    • Wordsearch
  • Quizzes
    • All Quizzes
    • Morning quiz
    • Afternoon quiz
    • Sports quiz

Regions

  • Northland
    • All Northland
    • Far North
    • Kaitaia
    • Kerikeri
    • Kaikohe
    • Bay of Islands
    • Whangarei
    • Dargaville
    • Kaipara
    • Mangawhai
  • Auckland
  • Waikato
    • All Waikato
    • Hamilton
    • Coromandel & Hauraki
    • Matamata & Piako
    • Cambridge
    • Te Awamutu
    • Tokoroa & South Waikato
    • Taupō & Tūrangi
  • Bay of Plenty
    • All Bay of Plenty
    • Katikati
    • Tauranga
    • Mount Maunganui
    • Pāpāmoa
    • Te Puke
    • Whakatāne
  • Rotorua
  • Hawke's Bay
    • All Hawke's Bay
    • Napier
    • Hastings
    • Havelock North
    • Central Hawke's Bay
    • Wairoa
  • Taranaki
    • All Taranaki
    • Stratford
    • New Plymouth
    • Hāwera
  • Manawatū - Whanganui
    • All Manawatū - Whanganui
    • Whanganui
    • Palmerston North
    • Manawatū
    • Tararua
    • Horowhenua
  • Wellington
    • All Wellington
    • Kapiti
    • Wairarapa
    • Upper Hutt
    • Lower Hutt
  • Nelson & Tasman
    • All Nelson & Tasman
    • Motueka
    • Nelson
    • Tasman
  • Marlborough
  • West Coast
  • Canterbury
    • All Canterbury
    • Kaikōura
    • Christchurch
    • Ashburton
    • Timaru
  • Otago
    • All Otago
    • Oamaru
    • Dunedin
    • Balclutha
    • Alexandra
    • Queenstown
    • Wanaka
  • Southland
    • All Southland
    • Invercargill
    • Gore
    • Stewart Island
  • Gisborne

Media

  • Video
    • All Video
    • NZ news video
    • Business news video
    • Politics news video
    • Sport video
    • World news video
    • Lifestyle video
    • Entertainment video
    • Travel video
    • Markets with Madison
    • Kea Kids news
  • Podcasts
    • All Podcasts
    • The Front Page
    • On the Tiles
    • Ask me Anything
    • The Little Things
    • Cooking the Books
  • Cartoons
  • Photo galleries
  • Today's Paper - E-editions
  • Photo sales
  • Classifieds

NZME Network

  • Advertise with NZME
  • OneRoof
  • Driven Car Guide
  • BusinessDesk
  • Newstalk ZB
  • What the Actual
  • Sunlive
  • ZM
  • The Hits
  • Coast
  • Radio Hauraki
  • The Alternative Commentary Collective
  • Gold
  • Flava
  • iHeart Radio
  • Hokonui
  • Radio Wanaka
  • iHeartCountry New Zealand
  • Restaurant Hub
  • NZME Events

SubscribeSign In
Advertisement
Advertise with NZME.
Home / Business

Cyber spies use fake profile as a 'honey pot' to trap male workers

news.com.au
28 Jul, 2017 02:05 AM4 mins to read

Subscribe to listen

Access to Herald Premium articles require a Premium subscription. Subscribe now to listen.
Already a subscriber?  Sign in here

Listening to articles is free for open-access content—explore other articles or learn more about text-to-speech.
‌
Save

    Share this article

Mia Ash is a fake persona used to target people in a hacker scam using stolen images.

Mia Ash is a fake persona used to target people in a hacker scam using stolen images.

By Dana McCauley

Mia Ash is young, attractive and popular, with hundreds of social media connections.

She shares your favourite hobbies, so when she adds you, you're flattered and a little bit excited.

After exchanging messages on LinkedIn, you're happy to continue the conversation on Facebook and WhatsApp.

Mia Ash is a fake profile containing stolen images used by foreign hackers to lure unsuspecting men with access to sensitive data.
Mia Ash is a fake profile containing stolen images used by foreign hackers to lure unsuspecting men with access to sensitive data.
Advertisement
Advertise with NZME.
Advertisement
Advertise with NZME.

There's just one problem: Mia Ash does not exist.

You've been communicating with a mirage, and you're about to fall into the hands of a team of hackers believed to be acting on behalf of a hostile foreign government.

Online "honey pot" attackers like Mia Ash represent a new front in a global espionage, with hackers targeting strategically important companies through their weakest line of defence: their hapless employees.

That's according to cyber security expert Allison Wikoff from SecureWorks, whose counter threat unit has been fighting what has been dubbed the Cobalt Gypsy spy campaign.

Advertisement
Advertise with NZME.

Mia Ash is a sophisticated fake persona that the unit has identified as an agent of a hacker group called Cobalt Gypsy aka OilRig, which is understood to be backed by the Iranian Government.

With highly detailed social media profiles portraying her as a young English photographer, the group used real images believed to be stolen from an innocent woman in Romania.

Look out for stock images and watermarked (stolen) photographs used to create social media profiles.
Look out for stock images and watermarked (stolen) photographs used to create social media profiles.

The scam targeted mid-level staff at Middle Eastern telecommunication, technology, aerospace and oil and gas companies with access to sensitive parts of their company's IT operations.

Mia Ash introduced herself as a wedding and portrait photographer reaching out to people around the world, saying she wanted to "learn more about your country".

Discover more

Lifestyle

Woman hilariously recreates celeb Instagrams

30 Jul 01:33 AM

One worker fell for Mia Ash's charm, striking up a friendship that lasted several weeks before the true nature of the situation was revealed when the hackers sent him a malware-infected email disguised as a "photography survey".

The man, an amateur photographer who connected with the young woman believing they had a shared interest, unsuspectingly opened the attachment.

Ms Wikoff said the aim was to steal login IDs and passwords when the document, once opened, would unleash a type of malware called PupyRAT, giving the hackers access to the organisation's computer systems.

"They're really interested in information that aligns with the Iranian government's objectives," she told news.com.au.

The amount of detail in the Mia Ash profile made it appear like a real person.
The amount of detail in the Mia Ash profile made it appear like a real person.

"SecureWorks firmly believes the Cobalt Gypsy group is associated with Iranian government-directed cyber operations, and that this Mia Ash campaign has been designed to obtain the high- level network credentials of male employees of specific target organisations in Israel, Saudi Arabia, India, US and Iraq."

Luckily, the photography buff's computer was protected by anti-malware software and the hackers did not succeed.

Advertisement
Advertise with NZME.

While Mia Ash had not been caught targeting Australians, Ms Wikoff said, the method of attack could be employed anywhere in the world by foreign government hacker spies - with the risk to Australia coming from China, Indonesia and Russia.

In January, the vulnerability of Australia's government and corporate spheres to foreign cyber spies was highlighted by the massive global data break affecting Yahoo.

Social Services Minister Christian Porter, shadow treasurer Chris Bowen and Liberal senator Cory Bernardi were among 3000 users affected by the breach, prompting Prime Minister Malcolm Turnbull to order a cyber security investigation.

Ms Wikoff and her team spent two months observing "Mia Ash" interact with her victims online, only to disappear without a trace when she was exposed.

At least one worker targeted by the hackers behind "Mia Ash" fell for the scam.
At least one worker targeted by the hackers behind "Mia Ash" fell for the scam.

Chillingly, she said, half of the fake persona's social media contacts appeared to be real photographers chosen to bolster its legitimacy, while the other half were made up of "potential victims".

Mia Ash's profile appeared to have been set up after a campaign of traditional "phishing" emails targeting the company's employees had failed, she said.

Advertisement
Advertise with NZME.

Organisations were increasingly shutting down such attempts by educating staff on how to spot a fake email address, with savvy workers much less likely to click on malicious links or attachments.

"So they are using other ways to get into the organisation," Ms Wikoff said.

She said hackers spent weeks building trust with victims before launching their attack by sending a document made to look legitimate and relevant to their discussions.

"We train employees to recognise and report phishing emails, but do we talk to people about this sort of social engineering? With LinkedIn and Facebook, the employer can't control what is going on, but it's about how to train people to detect this sort of thing."

Ms Wikoff said warning signs included profiles that used stock images or photographs bearing watermarks, indicating that they may belong to someone else.

And she recommended having "end point protection" software in place to ensure that, if staff unwittingly fell for a profile like Mia Ash, the malware would not get through - even if the employee clicked and opened the malicious email.

Advertisement
Advertise with NZME.
Save

    Share this article

Latest from Business

Premium
Media Insider

From the heartbreak of losing her husband at just 48, a couple's enduring media legacy

09 May 05:00 PM
Premium
Opinion

Fran O'Sullivan: Political games hinder vital superannuation reform

09 May 05:00 PM
Premium
Opinion

Mary Holm: Is there are pot of gold waiting for those who invest in non-bank deposits?

09 May 05:00 PM

“Not an invisible footprint”: Why technology supply chains need optimising

sponsored
Advertisement
Advertise with NZME.

Latest from Business

Premium
From the heartbreak of losing her husband at just 48, a couple's enduring media legacy

From the heartbreak of losing her husband at just 48, a couple's enduring media legacy

09 May 05:00 PM

'It allows me to focus on myself and the kids and figure out life without Allan.'

Premium
Fran O'Sullivan: Political games hinder vital superannuation reform

Fran O'Sullivan: Political games hinder vital superannuation reform

09 May 05:00 PM
Premium
Mary Holm: Is there are pot of gold waiting for those who invest in non-bank deposits?

Mary Holm: Is there are pot of gold waiting for those who invest in non-bank deposits?

09 May 05:00 PM
Premium
Noise ban, off-limit interviews: TVNZ's rules as RNZ moves in; Ad agencies take aim at global merger

Noise ban, off-limit interviews: TVNZ's rules as RNZ moves in; Ad agencies take aim at global merger

09 May 10:58 AM
Deposit scheme reduces risk, boosts trust – General Finance
sponsored

Deposit scheme reduces risk, boosts trust – General Finance

NZ Herald
  • About NZ Herald
  • Meet the journalists
  • Newsletters
  • Classifieds
  • Help & support
  • Contact us
  • House rules
  • Privacy Policy
  • Terms of use
  • Competition terms & conditions
  • Our use of AI
Subscriber Services
  • NZ Herald e-editions
  • Daily puzzles & quizzes
  • Manage your digital subscription
  • Manage your print subscription
  • Subscribe to the NZ Herald newspaper
  • Subscribe to Herald Premium
  • Gift a subscription
  • Subscriber FAQs
  • Subscription terms & conditions
  • Promotions and subscriber benefits
NZME Network
  • The New Zealand Herald
  • The Northland Age
  • The Northern Advocate
  • Waikato Herald
  • Bay of Plenty Times
  • Rotorua Daily Post
  • Hawke's Bay Today
  • Whanganui Chronicle
  • Viva
  • NZ Listener
  • What the Actual
  • Newstalk ZB
  • BusinessDesk
  • OneRoof
  • Driven CarGuide
  • iHeart Radio
  • Restaurant Hub
NZME
  • About NZME
  • NZME careers
  • Advertise with NZME
  • Digital self-service advertising
  • Book your classified ad
  • Photo sales
  • NZME Events
  • © Copyright 2025 NZME Publishing Limited
TOP