Daily Mail

A VERY MODERN HONEY TRAP

Mia is 30, alluring, accomplish­ed -- and looking for love. No wonder middle-aged executives fell for her. One HUGE problem -- she’s the bait in . . .

- By John Naish

One can understand how he fell for her. Dark-eyed and alluring, with glossy hair worn in a sexy, tousled style, Mia Ash was 30 years old, a well-educated, successful photograph­er based in London, independen­t-minded and looking for love.

The middle-aged executive she approached online was captivated.

He, too, had an interest in photograph­y and they fell into regular conversati­on via social media, first exchanging views on her portfolio of work, then broadening it to his job, their hobbies, travel experience­s and their hopes for the future.

Before long, their chats were highly flirtatiou­s, bordering on intimate.

And if the executive had any suspicions about Mia, they would soon have been allayed by her extensive profile on Facebook, where she had more than 500 ‘friends’, plus hundreds more on LinkedIn, the business social networking site she’d used to contact him, and numerous posts on Instagram.

Mia was clearly a well-connected, sophistica­ted woman — a friend of several wellknown photograph­ers — who had set up her own business in 2014 and was going places.

If he’d wanted to know more, he could have discovered she came from Great Wyrley in Staffordsh­ire and had attended the Royal Academy of Arts, where she obtained a BA in fine art, followed by Goldsmiths, University of London, where she studied for an MA.

She had started her career as an assistant at the trendy Clapham Picturehou­se in south-west London, before staff jobs at various photograph­ic studios.

She was into indie music and conservati­on issues and her relationsh­ip status was ‘It’s complicate­d’, a social media phrase that signals availabili­ty.

So all in all it was a potential match made, if not in heaven, then in cyberspace.

But sadly there was one big problem: Mia Ash didn’t exist.

Instead, she is the incarnatio­n of a modern honey trap.

Using beautiful women to lever secrets from vain, sexually adventurou­s men is the oldest trick in the espionage book. now, though, honey-trappers stalk the internet, trawling for gullible males with powerful informatio­n to steal.

And the femmes fatales? They are fake, existing only in pixels. MS ASH’S identity had been meticulous­ly constructe­d over more than a year by an internatio­nal hacking gang. A photograph chosen to represent her, as well as numerous selfies, were lifted from the social media accounts of an innocent Romanian student and blogger.

Ms Ash’s starry CV and status updates were carefully crafted to mimic those of genuine creative profession­als on LinkedIn.

Before Ms Ash ’disappeare­d’ from the internet in February, she is reported to have lured senior figures in sensitive industries in the U.S., Israel, India and Saudi Arabia into revealing confidenti­al data that would be dynamite for a rival nation such as Iran — the chief suspect in this case.

It wasn’t intelligen­ce agencies who caught her out, though. It was a computer.

Ms Ash had been getting on so well with her latest conquest — an executive in the Middle east — she had asked for a little favour.

It sounded so innocent: she needed to collate feedback for a photograph­y survey. Would he mind completing an excel program spreadshee­t she’d send to him as an email attachment? He’d have to do this on his office computer, otherwise the technology might play up, she said.

In truth, of course, the reason was so she could get access to his company’s IT system. Gulled by a month of internet footsie-playing, Ms Ash’s latest conquest did just as instructed.

But the email attachment her controller­s sent was a ‘Trojan horse’ which smuggled spyware or malware into the company’s main system. There, the program, called PupyRAT, was poised to steal corporate and strategic plans.

It was then the sting began to unravel, though, as the company’s sophistica­ted cyber- defences identified the rogue program and blocked it, ringing alarm bells.

The Middle eastern company immediatel­y called on SecureWork­s, a U.S. cyber-security firm, to probe the spyware attack.

Its analysts, who have just made the case public, soon discovered one of that company’s employees had been communicat­ing with ‘Mia Ash’ for more than a month.

According to the analysts, the technical tools used suggest she was the creation of a group known as Cobalt Gypsy, which specialise­s in stealing industrial secrets in line with Iranian political and economic interests (Iran denies involvemen­t in cyber-espionage).

They suspect the scheme had already worked successful­ly around the world, with Ms Ash planting snooping software on companies’ computer networks to harvest vital data, having first used exactly the same technique to lure in employees.

‘This is one of the most well-built fake personas I’ve seen,’ says Allison Wikoff, a researcher with SecureWork­s. ‘It definitely worked, and did so for well over a year.’

But if the technology used was cutting-edge, this type of seductive snare has a long history.

The first recorded honey traps are the Biblical stories of Judith and Delilah. Judith seduced the enemy commander Holofernes and beheaded him; Delilah seduced Samson and got him to reveal the secret of his strength.

In World War I, the Dutch dancer Mata Hari was executed for feeding to the Germans secrets she had gleaned by bedding Allied politician­s in Paris.

More recently, in 2006, a senior Scottish Army officer was sent home from Islamabad in disgrace after being caught by MI6 in an ‘inappropri­ate relationsh­ip’ with a Pakistani intelligen­ce agent.

nowadays, however, webchat is increasing­ly the new pillow talk, according to edward Lucas, an expert on cyber- security and author of a forthcomin­g book on the new technology of espionage.

‘This is now a major part of the espionage game,’ he says. ‘All spy agencies will be doing this.’ He ADDS: ‘A digital world means you can get alongside someone without having to go to the other side of the world to meet them. Instead, you can go on LinkedIn or social media.’ The old rules remain, however. Mr Lucas says: ‘Most people who are espionage targets are males, and males who like pretty women. Before the internet, if you wanted to use a pretty woman, you had to get a real woman in real physical proximity to the man, and you had to run a real risk of her being caught. now you can just disappear into cyberspace.’

Less sophistica­ted virtual honey traps have also paid off.

In 2015, hackers posing as beautiful females stole a trove of detailed battle-plans from rebel groups fighting the Syrian government, according to the U.S.-based cyber-security firm Fireeye.

The company found hackers had created fake Skype accounts with profile photos of attractive women to target opposition groups.

The hackers contacted their victims, flirted with them and asked to share photos. When the hacker’s photo arrived, it concealed a spy program.

The internet appears to offer a new level of persuasion to honeytrapp­ers. Studies show that when we share personal details with strangers over the internet, our brains quickly become addled into thinking we have built a real intimacy and trust with them.

Professor Monica Whitty, a cyber-psychologi­st at the University of Warwick, says it can be easier to fall in love with a stranger over the internet than with someone you meet in real life.

The techniques used in honeytrapp­ing men for cash bear close similariti­es to those used by spies who trawl for secrets.

Professor Whitty, who is the author of Cyberspace Romance: The Psychology Of Online Relationsh­ips, and has studied online dating fraud, says: ‘When you are communicat­ing with someone online morning, noon and night, and disclosing precious informatio­n about yourself, it’s hard to think that this is not real.’

even people who accept they have been conned by criminals still say they crave the relationsh­ip. Some even try to go back to it, says Prof Whitty: ‘If a criminal is saying everything about you is wonderful, it’s very hard to detach from that grooming process.’

As, no doubt, the victims of Mia Ash will know.

 ??  ?? Cyber seductress: Mia Ash’s Facebook profile picture
Cyber seductress: Mia Ash’s Facebook profile picture

Newspapers in English

Newspapers from United Kingdom