Also available in Persian — نسخه فارسی EN فا
🔴 Breaking ❓ Unknown

New Trick of Iranian Government Hackers: Offering 'Dream Jobs' to Western Users

Jul 16, 2026 July 16, 2026 3 min read 📰 VOA Persian
📋 Key Takeaway

Iranian government-linked hackers are using fake job offers to infiltrate and steal sensitive data from key officials in allied countries. The attacks have targeted industries in Israel, the UAE, Turkey, India, and Albania, and are linked to the IRGC. This escalation in cyber threats, especially ahead of the U.S. elections, raises concerns about national security and foreign influence.

🔍 Quick Context Guide
💡 Bottom Line: Iranian cyber operations are evolving and pose significant risks to Western interests.

👥 Key Players

TA 455 ACTOR
Hacking group
"Hacking group 'TA 455,' identified as responsible for these operations."
Islamic Revolutionary Guard Corps (IRGC) (سپاه پاسداران انقلاب اسلامی) LINKED_TO
Military unit
"Hacking group 'TA 455' is reported to be linked to the Islamic Revolutionary Guard Corps (IRGC)."
Donald Trump (دونالد ترامپ) TARGET
Former U.S. President
"Attackers stole information from Donald Trump's campaign headquarters."
ClearSky QUOTED
Cybersecurity firm
"The Tel Aviv-based cybersecurity firm 'ClearSky' states that these attacks..."
Mandiant QUOTED
Cybersecurity firm
"According to a report published in February 2023 by the cybersecurity firm 'Mandiant,'..."
Canada (کانادا) QUOTED
Government body
"Canada's warning about the cyber threat from the Islamic Republic."

⚡ Actions

TA 455 ATTACK key officials in U.S. allied countries
"These attacks, dubbed 'Iranian Dream Job,' target the aerospace, aviation, and defense industries."
Confidence: 90%
TA 455 STEAL sensitive data from victims
"Distributing malware among victims that allows them access to systems and the theft of sensitive data."
Confidence: 90%
hacking group linked to the Islamic Republic PUBLISH stolen materials related to Trump's campaign
"Stolen materials related to Trump's campaign were published by a hacking group linked to the Islamic Republic."
Confidence: 90%

📰 What Happened

Iranian hackers target Western officials with fake job offers to steal sensitive data.

  • TA 455 attack key officials in U.S. allied countries
  • TA 455 steal sensitive data from victims
  • hacking group linked to the Islamic Republic publish stolen materials related to Trump's campaign

💡 Why It Matters

🇮🇷 For Iran: Because it enhances Iran's cyber capabilities and influence.
🌍 Regional: Because it increases tensions between Iran and U.S. allies.
🌐 International: Because it poses a threat to Western political stability and security.

📚 Background

Iranian cyber operations are evolving and pose significant risks to Western interests.

📝 Key Evidence

"Distributing malware among victims that allows them access to systems and the theft of sensitive data."
→ This proves the method of attack used by the hacking group.
"Stolen materials related to Trump's campaign were published by a hacking group linked to the Islamic Republic."
→ This proves the targeting of political entities.
📡 Source: INTERNATIONAL
📊 Confidence: 80%
VOA Persian is generally considered a reliable source for news on Iran.

Newsweek reported, citing a cybersecurity company in Israel, that individuals linked to the Iranian government are hacking the accounts of key officials in U.S. allied countries by offering fake jobs. The Tel Aviv-based cybersecurity firm 'ClearSky' states that these attacks, dubbed 'Iranian Dream Job,' target the aerospace, aviation, and defense industries of countries including Israel, the United Arab Emirates, Turkey, India, and Albania. Since at least last October, hackers have posed as recruiters for fake companies on LinkedIn, distributing malware among victims that allows them access to systems and the theft of sensitive data. The hacking group 'TA 455,' identified as responsible for these operations, is reported to be linked to the Islamic Revolutionary Guard Corps (IRGC). According to a report published in February 2023 by the cybersecurity firm 'Mandiant,' the information collected by this group is 'related to Iran's strategic interests and may be used for espionage operations or targeting.' This hacking method has previously been used by North Korean hackers in connection with cryptocurrencies, and 'ClearSky' suspects that the Iranian group either 'deliberately imitates North Korean tactics and tools' to conceal their actions and deflect blame or that 'North Korea has shared its attack methods and tools with Iran.' Cyber threats from Tehran and Pyongyang have escalated, especially before the U.S. presidential elections, with reports of attempts to hack the accounts of current and former U.S. officials, media members, NGOs, and individuals linked to U.S. political campaigns. In May, attackers stole information from Donald Trump's campaign headquarters. Reuters reported on November 4, ahead of the presidential election on November 14, that stolen materials related to Trump's campaign were published by a hacking group linked to the Islamic Republic, which, after failing to release the stolen materials in mainstream media, found other sites for publication. Initially, they contacted media outlets such as Politico, The Washington Post, and The New York Times, claiming to have internal information from Trump's campaign that could raise new allegations against the Republican candidate in the U.S. election. In recent weeks, hackers began sending Trump's campaign emails to a Democratic political group, which published a collection of materials on its website named 'American Muckrakers' and shared it with several independent journalists, at least one of whom posted the materials on the 'Substack' platform. These materials contained correspondence from Trump's campaign with advisors and other supporters, addressing a wide range of topics. The hacking of the Telegram channel of two Israeli journalists and the publication of images of Hitler and Khamenei in it, Canada's warning about the cyber threat from the Islamic Republic, China, and Russia, and Western security agencies' warnings about the access of Iranian cyber agents to infrastructure networks indicate an increase in collaboration between 'cybercriminals' and the governments of Iran, Russia, and China against the U.S. and its allies.

🌐

Translated from the original and edited for English readers. View original source →

Translation confidence: 85%

📰 Related Coverage

⚖️ Independent Platform — Artesh.com is not affiliated with any government, military, or political organization. Editorial Policy →