Facebook and Instagram Used by Advanced Persistent Threats (APTs) to Target South Asia

Recent reports have revealed that three advanced persistent threat (APT) groups have used Facebook and Instagram to target individuals located in South Asia as part of their cyber espionage efforts. These APTs have relied heavily on social engineering tactics to trick people into clicking on malicious links, downloading malware, and sharing personal information over the internet. This article will discuss each of these APTs and their specific tactics in more detail.

Fictitious personas on Facebook and Instagram

The three different threat actors, who leveraged hundreds of elaborate fictitious personas on Facebook and Instagram, are believed to be disparate groups. Each of them relied heavily on social engineering to trick people into clicking on malicious links, downloading malware or sharing personal information across the internet.

One of these groups is a Pakistan-based APT that relied on a network of 120 accounts on Facebook and Instagram, as well as rogue apps and websites, to infect military personnel in India and the Pakistan Air Force with GravityRAT under the guise of cloud storage and entertainment apps. The use of low-sophistication malware with reduced capabilities was noted during this cyber espionage attempt.

Another threat actor that caught Meta’s attention is an India-based APT dubbed Patchwork. This group took advantage of malicious apps uploaded to the Play Store to harvest data from victims in Pakistan, India, Bangladesh, Sri Lanka, Tibet, and China. Meta reported that it purged 50 accounts on Facebook and Instagram linked to this APT.

Disrupting Adversarial Networks

Meta has disrupted six adversarial networks engaged in “coordinated inauthentic behavior” on multiple social media platforms including Twitter, Telegram, YouTube, Medium, TikTok, Blogspot, Reddit, and WordPress. Two of these networks originated from China and operated dozens of fraudulent accounts, pages, and groups across Facebook and Instagram, targeting users in India, Tibet, Taiwan, Japan, and the Uyghur community. Chinese APTs have been notorious for their espionage attempts and are regularly the focus of cybersecurity experts.

The network from Iran singled out Israel, Bahrain, and France, corroborating an earlier assessment from Microsoft about Iran’s involvement in the hacking of the French satirical magazine Charlie Hebdo in January 2023. Redmond has linked 24 Iranian APT operations to the Iranian government in 2022, primarily targeting Israel and the US. Redmond has named these APTs as Moses Staff, Homeland Justice, Abraham’s Ax, Holy Souls, and DarkBit. Seventeen of these operations have taken place since June 2022.

Implications for cybersecurity

The use of social media platforms like Facebook and Instagram, which have a massive user base, could be a significant threat to the cybersecurity of individuals and governments in South Asia and beyond. Furthermore, the prevalence of low-sophistication malware that can cause significant harm to critical infrastructure could result in severe consequences.

Cybersecurity experts have called for greater efforts toward advanced threat detection and protection. Organizations must be vigilant and proactive in their approach to cybersecurity with a focus on identifying and stopping advanced threats before they cause damage.

Facebook and Instagram may be widely used by individuals and governments worldwide, but they are not immune to cyber espionage attempts by bad actors. The recent reports on APTs using these platforms to target South Asia are a reminder that cybersecurity has become an ever-more vital priority for nations and organizations as their digital dependence grows. To prevent cyber threats from causing significant damage, proactive steps must be taken to identify and prevent them.

Explore more

Xiaomi Redmi Note 17 5G Debuts With Massive 8,000mAh Battery

Dominic Jainy joins us today to discuss the bold strategy behind Xiaomi’s latest release in the Indian market. As an expert in mobile technology and hardware architecture, Jainy offers a unique perspective on why a manufacturer would choose to prioritize raw endurance over traditional performance metrics. Today, we delve into the technical nuances of the Redmi Note 17 5G and

The Authority Gap Undermines Workplace Wellbeing

The current corporate landscape has become increasingly saturated with holistic wellness programs that promise to alleviate the heavy burden of modern productivity, yet deep-seated disparities in how professional authority is perceived continue to sabotage these efforts for female employees. While mental health apps and meditation workshops are common features of the 2026 workplace, they fail to address the underlying psychological

How Will Mirendil and Google Cloud Automate AI Research?

Dominic Jainy stands at the forefront of the modern technological landscape, possessing a deep mastery of artificial intelligence and machine learning architectures. With a career dedicated to exploring how blockchain and high-performance computing can reshape industrial workflows, he offers a unique perspective on the strategic moves made by elite AI labs. As the industry grapples with a massive surge in

What Challenges Will Continue to Shape Customer Experience?

The volatile intersection of shifting consumer expectations and internal operational rigidities creates a landscape where even the most resilient organizations must constantly reassess their core service delivery models to remain competitive. Today, the difficulties faced by faith-based groups—ranging from funding limitations and complex organizational structures to leadership development and staffing concerns—reflect the exact hurdles encountered by customer-facing enterprises. This shared

Why Is Women-Only Leadership Training Still Essential?

The persistent imbalance of gender representation in executive suites suggests that traditional methods of professional advancement are fundamentally misaligned with the lived experiences of many employees. While many organizations advocate for equality by providing identical resources to all staff, this approach often ignores the structural barriers that affect individuals differently based on their gender. To understand this, one might consider