Showing posts with label Ashiyane. Show all posts
Showing posts with label Ashiyane. Show all posts

Monday, October 2, 2017

Iranian Hacking Threat to USA if Nuclear Deal Collapses



Since the signing of the nuclear deal between the USA and Iran in 2015 (the Joint Comprehensive Plan of Action (JCPOA)), Iranian cyber attacks against the USA have dropped off. 

The U.S. and six partners began discussions with Iran in 2013 to lift some economic sanctions to limit Iranian nuclear developments, and since then Iranian hackers have largely reduced attacks against the U.S., focusing instead on industrial espionage and hitting rival Middle Eastern countries. However, with the threat by the U.S. President Donald Trump to walk away from the deal, there are fears that Iran will re-start cyber-attacks against the USA.

The cyber-security research company FireEye have produced a report which has identified an Iranian-government group that FireEye have called APT33 (APT means Advanced Persistent Threat, indicating state-involvement). APT33 has previously attacked using spear-phishing techniques to target companies involved in the petrochemical industry and in military and commercial aviation. Could APT33 or similar be ready to attack the U.S. if Trump quits the JCPOA?

A Short History of Iranian Cyber-attacks

  • 2010: It was suspected that the U.S. and Israel attacked Iran with the Stuxnet malware, damaging Iranian nuclear control equipment at the Natanz uranium enrichment plant.
  • 2011/2013: In possible response to Stuxnet, Iran used DDoS (Distributed Denial of Service) Operation Ababil attacks against over 45 major financial institutions. Seven members of the Iranian ITSec Team were subsequently indicted by the FBI for over 176 days of DDoS attacks against the U.S. and also the attack against the Bowman Dam.
  • 2012: APT33 attack the Saudi Aramco oil company using the Shamoon malware, destroying thousands of computers in that company.
  • 2015: After JCPOA, large-scale Iranian attacks against the U.S. dropped off, although this may also have been due to Iran's concerns with Syria and Yemen. Also, APT33 continued espionage attacks against the U.S., South Korea and Saudi. In 2015, many Iranian hacking forums and use of hacker handles disappeared, probably because Iran realized that they were under greater scrutiny. 
  • 2016/2017: APT33 attacked Saudi and U.S. aerospace companies, along with attacks against a South Korean petrochemical company. In May 2017, APT33 attacked a Saudi organization and a South Korean company using malicious spear-phishing emails attempting to target victims with job vacancies for a Saudi petrochemical company.

The FireEye APT33 Report

FireEye state that APT33 used an Iranian developed web-shell developed by the hacker Solevisibile to craft the spear-phishing emails to targets. The webshell (called ALFASHELL, ALFA TEaM Shell v2-Fake Mail), has the default sender email address of solevisible@gmail.com. It is not known if Solevisible is linked with APT33 or not.

APT33 used domain masquerading as the following companies: Boeing, Alsalam Aircraft Company, Northrop Grumman Aviation Arabia, and Vinnell Arabia. APT33 used the domains to target victims with spear-phishing emails.

FireEye identified the hacker xman_1365_x as being the developer of a backdoor used in APT33 malware. It appears that xman_1365_x was also a manager in the Barnamenevis Iranian programming & software engineering forum, and registered accounts in the Iranian Shabgard and Ashiyane forums. The hacker xman_1365_x is also linked with the Nasr Institute, which is similar to Iran’s cyber army and controlled by the Iranian government. The Nasr Institute appears to be linked to the 2011-2013 DDoS attacks on the financial industry (Operation Ababil).

Further indications that Iran is behind APT33

  • A malware dropper (known as StoneDrill) used by APT33 has Farsi language artifacts in it.
  • APT33’s targeting of organizations involved in aerospace and energy is aligned with with nation-state interests (not those of cyber-criminal groups), implying that APT33 is probably government sponsored.
  • Iranian working hours; APT33 worked at the time zone close to 04:30 hours ahead of UTC, which heavily indicates Iran. APT33 largely operated on days that correspond to the Iranian working week (Saturday to Wednesday). Iran is one of few countries that subscribes to a Saturday to Wednesday working week.
  • APT33 used popular Iranian hacker tools and DNS servers used by other suspected Iranian hackers. The publicly available backdoors & tools utilized by APT33 (including NANOCORE, NETWIRE, and ALFA Shell) are available on Iranian hacking websites, associated with Iranian hackers, and used by other suspected Iranian threat groups.

Friday, January 15, 2016

The Top Iranian Lammers, I mean, Hackers?



This is interesting. According to this website the best Iranian hackers are as follows. Do you agree? Vote now!
Looking at the comments on the site and what I know you can conclude the following:

* Most are lammers
* They can do defacements...but that is all
* Many are kids
* Some are even girls!
* Some are not even Iranian!

Is this the best that Iran can produce at the moment? If so, then #fail


However:

* YoSeF HaCkeR is well respected
* Black_N3T is from the Shishe Digital Security Team
* Behrouz Kamalian founded Ashiyane Digital Security Team
* wild.soldier is well respected
* MilaD Ramus owns the SaeQeH Security Team
* Ali Morshedloo is member of Iran Security Team
* Mr.PERSIA is owner of Emperor team
* Mr. Rahgozar is member of irsec team
* MR.F@RDIN owns Emperor Security Team
* Action Spider and Ashiyane were behind a hack against NASA in 2012
* Offensive is owner of Attacker Security Team
* Explo!ter is owner of the Emperor team
* amin3enator is a member of Iran-cyber team
* K!nG_4l!R3Z4 is a member of Pars team
* Crash (of Ashiyane) is meant to be a master of social engineering
* T3rY4K (Pars team)

The list:


1) YoSeF HaCkeR
2) Shadmehr
3) Mosi Pro
4) Ali Morshedloo
5) Kamran Nemati Harikandei (Kamranpcs)
6) Saeed0511
7) Black_N3T
8) Behrouz Kamalian
9) MR.khashi
10) Alireza Khodatalab
11) Black Ice (Ali Abasi)
12) Shahrooz
13) Negar Bayat
14) wild.soldier
15) Mr-SaSHa
16) Sourena
17) MilaD Ramus
18) B14ckc0d3r
19) Mr.PERSIA
20) JJHACKER
21) Arsan
22) ϻoנι☇ѕтнєηɨc
23) Trend_X
24) Farzad Terojan
25) KaMraN Injector
26) F4RY4R_RED
27) Mr. Rahgozar
28) greendel
29) Majid NT
30) Rocket Boy (Sina)
31) moji_rider
32) Saeed210
33) Peyman Poya (Toy Boy)
34) Iliya Norton
35) A75s6M
36) Mohsen NJ
37) Mohammad_Reza007
38) MR.F@RDIN
39) [A]мɪя [Ӈ]օƨᴇιɴ
40) Mr. Hossein
41) MR.M@J!d
42) Mohsen Ds
43) SoltanBahman
44) Mr.GHARIB3H
45) Arash Cyber
46) kos nane
47) mr.karkas
48) Action Spider
49) BADBOY17
50) [M]sey-[N]ofozi
51) optimus-hacker
52) b-yakhi
53) MR-545H4
54) XTAM4
55) Ali Plus
56) Rooter
57) Offensive
58) MR.ART@N
59) Masoud Invisible
60) Hidden Dagger
61) Explo!ter
62) Cair3x
63) NAVIDLIV
64) Dr.3vil
65) Mr. Saeed Mafiya
66) D3s!6n37
67) Pouya Eblis
68) H4M3D F.B.I
69) R.IG
70) Benyamin Payande
71) Amirkalantar
72) Sheytan Azzam
73) mr.vahshat
74) samara
75) Ali Attacker
76) sik
77) kir
78) W@0.5wE
79) Hacker Kord
80) Hacker Kord (again)
81) hamedhacker
82) CraZyl3oy
83) Hacker maro
84) M4hdi
85) Javadnadna
86) Devilmohammad
87) KSSM
88) bl4ck_rem0v3r
89) h4m1d
90) Mohammad-nofozi
91) BaBaK.Blackhat
92) S.R.B
93) amin3enator
94) Pi.hack
95) aghdas
96) Smartx
97) Keivan 98
98) Elenor
99) Mr.khofashe.siyah
100) SH4Y4N
101) 4L1R3Z4
102) sina_lizard
103) Mr.V!rus
104) Omid Generall
105) amin78
106) B.T
107) Majid Kurd
108) Hacker111
109) SHA13AH
110) Mr.GraY HaT
111) Amirosein
112) Reza-Atoom
113) MrVICI
114) se7en boy
115) Dr. Virangar (Sayyed Mohammad Ali Hosseini)
116) Black Storm
117) Kiram Dahan Sina Lizard
118) XX-Alibala-XX
119) JOK3R
120) K!nG_4l!R3Z4
121) Ho3!en-Mojazat
122) Crash from Ashiyane
123) Hossein Asgari
124) Soltegar
125) ZartoshT
126) T3rY4K
127) Coloner
128) Modiret
129) Amir00Army
130) Mr. 3im
131) Pershian-Joker
132) Shiva Shadow
133) Sarina Wolf
134) xSecurity
135) Mr. Defacer
136) H0553|N7
137) pasha_jabaar
138) mr.zero0
139) siyahi
140) mr.moien
141) bl4ck_v!per
142) ali-demon
143) ALI D.NAP

Tuesday, December 22, 2015

Ashiyane Security Team: agent of the Iranian regime


Ashiyane Security Group (officially Ashiyane Information and Communication Technology Company) is one of the oldest cyber security group in Iran (since around 2002).
Ashiyane started with the aim of teaching users and network administrators as well as improving the security level of the computer networks.
During the mass protest against the presidential election in 2009, Iran tried to control the protests in cyber space and since then Ashiyane Security Team trying to do so via hacking and identifying cyber activists which implied that Ashiyane cooperated with the Iranian Revolutionary Guards Corps (IRGC) and other security units leading many to believe that the “Iranian Cyber Army” group is actually also the Ashiyane group.

Before 2009 protests, Ashiyane was involved in activity for the state e.g. in response to the publication of cartoons depicting the Prophet Muhammad in Danish newspapers, over 1000 American, British and French websites were hacked by Ashiyane. News of Ashiyane activities was highly published by some news agencies such as Fars, IRNA and the newspapers such as Iran, Javan and Keyhan and was named as “Iran’s victories in cyber space”.

After changing the home page of this website, Ashiyane mostly displays a political message on the main page so that Behrouz Kamalian (team founder) said in an interview with Fars News Agency about this activity: “In response to the inhumane actions of the terrorism sponsors, headed by US and Britain, the new way of confronting is raised.”

Kamalian has also been quoted deflecting rumors about Ashiyane cooperating with the Islamic Republic Security System, “Ashiyane has also officially worked to improve the security of web sites and intranets and has served many governmental organizations, military and private companies. Unfortunately it has been announced that Ashiyane Group is affiliated to the government by many of the opposition websites with Iran’s government. I have said in my other interviews that our team is an independent group and is not affiliated with any other military or governmental organizations. We act spontaneously based on our bias and when we see a country insults our religion or our nationality, so we display our objection through penetrating into their sites and it does not mean that we have been ordered to do so. If Ashiyane was an affiliated group, it wouldn’t be able to easily interview with the media, and this freedom is a sign of our independency.”

Kamalian contradicted himself by also saying: “We get orders to hack different sites both from legal persons and individuals, but this is not part of our ordinary project and we reject many of these orders. We have never accepted to hack an internal websites to gain money. But there are websites that had insulted Quran and our religion. In these occasions we would also like to penetrate into these sites."

Kamalian has also announced about the corporation of Ashiyane with Department of IRGC Cyber Defense: “We corporate with military organizations in the field of counselling and improving the security, but it is never in the way that we get order to work on their behalf.”

He created Alborz Hackers Group which was among the first groups of Iranian hackers in 2001 and met Mahdi Mirzaei there; this meeting caused the creation of a new group called Ashiyane Group in 2002.

This team started its activity by hacking the university’s websites in the country such as University of Science and Industry (Elm & Sanaat) and Amir Kabir University.

Hacking the Iranian sites would quickly lead the Ashiyane Group to get fame among those interested in Informatics Science and many security companies (in network and internet field) invited them to cooperate.

Increasing economic activities of the group tend Kamalian to decide about registration the Ashiyane Group as an official and legal company and after the registration, in addition to providing network and servers’ security, consulting services and selling security softwares, also hold hacking, cracking and network and server and also security training.

The project of hacking a Persian website called "Balatarin" was one of the Ashiyane’s activities that raised the most negative reactions; Ashiyane declared the project with the cooperation of Virtual Jihad Group affiliated with Basij of Students, but after the negative reactions toward it Bahman Kamalian denied any involvement in the hacking.


Members


Except the name and the photo of the director of the group there isn’t complete information neither about identity and reality of Ashiyane Group nor about other certain photo of its members, although research has revealed the names & handles below:
 

  • Behrouz Kamalian (Director, handle: Behrouz_ice)
  • Nima Salehi (member/manager, handle: Q7X)
  • Mahdi Chinichi (member/manager, handle: Virangar)
  • Omid Norouzi (member/manager, handle: Sha2ow)
  • Farshid Sargheini (member/manager, handle: Azazel)
  • Hamid Norouzi (member/manager, handle: eychenz)
  • Iman Honarvar (member, handle: iman_taktaz)
  • Keyvan Sedaghati (member, handle: keivan)
  • Ali Seid Nejad (member, handle: Ali_Eagle)
  • Milad Bokharaei (member, handle: ®Maste)
  • Mohammad Tajik (member, handle: taghva)
  • Meghdad Mohammadi (member, handle: M3QD4D)
  • Erfan Zadpoor (member, handle: PrinceofHacking)
  • Mohammad Reza Dolati (member, handle: HIDDEN-HUNTER)
  • Kaveh Jasri (member, handle: root3r)
  • Navid Naghdi (member, handle: elvator)
  • Mohammad Hadi Nasiri (member, handle: unique2world) 
  • Amin Javid (member, handle: Gladiator)
  • Vahid Maani (member, handle: WAHID 2)
  • Sina Ahmadi Neshat (member, handle: Encoder)
  • Milad Mazaheri (member, handle: mmilad200)
  • Armin (member, handle: n3me3iz)
  • Mohammad Mohammadi (member, handle: Classic)
  • Mahdi K. (member, handle: r3d.z0nE)
  • Mohammad Reza (member, handle: iNJECTOR)
  • Mohammad Reza Ali Babaei (member, handle: mzhacker)
  • Ramin Baz Ghandi (member, handle: fr0nk)
  • Ashkan Hosseini (member, handle: Http://Askn)
  • Ali Hayati (member, handle: Zend)
  • Milad Jafari (member, handle: Milad-Bushehr)
  • Mehrab Akherati (member, handle: AliAkh)
  • Amir Hossein Tahmasebi (member, handle: __amir__)
  • Amin Bandali (member, handle: anti206)
  • Shahin Salak Tootonchi (member, handle: ruiner_blackhat)
  • Poorya Mohammadrezaei (member, handle: Hijacker)

Mission


Apart from the security and anti-security activities of Ashiyane, it has established its hosting company, believing about the provided services: “Communication and Information Company of Ashiyane has decided to enter the hosting field due to analyzing the present situation of web hosting in Iran and realizing the lack of security and knowledgeable people in this field; in order to gratify the shortage, Ashiyane Host Company is ready to present high quality and security services. 

Considering the strength of the Ashiyane’s security team in hacking and security, being aware of up-to-date methods of penetrating, having access to illegal hacker communities,as well as utilizing these methods, Ashiyane applies its knowledge in security and configuration of the servers so that the company is able to close the penetration ways one step ahead of others and bring satisfaction to the customers.

Despite the remarkable statement of Ashiyane about its ability, while earlier it was also claimed that Ashiyane had discovered the security hole in the Telegram software messenger and the news quickly found a wide reflection in the media close to the Islamic Republic, the website of Ashiyane Security Group was hacked on July 1, 2014 and there was a black page appeared written in English: “This site has been hacked by Iranian Black Hat hackers group:” when the site was visited.

Thursday, May 15, 2014

Operation Saffron Rose



Ajax Security Team which has been targeting both US defense companies as well as those in Iran is using popular anti-censorship tools to bypass internet censorship controls in the country.

This group which has its roots in popular Iranian hacker forums such as Ashiyane and Shabgard, has engaged in website defacements since 2010. However by 2014 this group is transitioned to malware-based espionage with use of methodology consistent with other advanced persistent threats in this region.

It is unclear if the Ajax Security Team operates in isolation or is part of a larger coordinated effort. We observed this group uses varied social engineering tactics to lure targets to infect themselves with malware. They use malware tools that do not appear to be publicly available. Although we did not see the use of to infect victims, members of the Ajax Security Team previously used exploit code in web site defacement operations.

The objectives of this group are consistent with Iran’s efforts to control political dissent and expand offensive cyber capabilities but we believe that members of the group may also be involved in traditional cybercrime. This indicates that there is a considerable gray area between the cyber espionage capabilities of Iran hacker groups and any direct Iranian government or military involvement.

Although the Ajax Security Team’s capabilities remain unclear, we believe that their current operations are somewhat successful. We assess that if these actors continued the current pace of their operations they will improve their capabilities in the mid-term.