Showing posts with label Kaspersky. Show all posts
Showing posts with label Kaspersky. Show all posts

Tuesday, August 15, 2017

IRGC and the Risks of Iranian Malware Development

IRGC

Recent articles have shown that the Iranian State has used computer malware Shamoon and linked malware StoneDrill and NewsBeef to damage others. Instead of glorifying Iran, the exposing of such activity by well-known companies like Kaspersky Lab, discussion on the Iranian Exploit Database (IEDB) forum and articles on the Iran Cyber News Agency (ICNA) site has damaged its reputation.


IEDB

Iranian Cyber News Agency (ICNA)

Despite trying to hide their identities, simple investigations have revelaed the identities of those who are involved within the IRGC at the Imam Hossein University (IHU).


Imam Hossein University (IHU)


This is supposed to be a seat of learning, but it seems that the education of students is for purposes other than knowledge. The IRGC officers who pose as professors and academics, have put their hands in the hand of their masters. We have seen the State has turned against its own with controls on the Internet. Are students there helping to suffocate the true Iranian voice?

Instead of serving the people of Iran, students can apply to trade-off their military service, by doing 'project' work. The IRGC claim to offer a trade-off to students to exchange time spent on projects for a reduction of their military commitment. The IHU offered sites for students to do this. What sort of exchange do students actually receive? Months of hard work for a few days respite? Military service should be exactly this: to protect the people of Iran, not hiding away working on developing malware that has only served to show us in a bad light internationally, and does not benefit the State.

It is far from unknown for the IRGC to make money from their work, and some of this malware development may be to extort money from victims to gain finances for their own personal 'projects'. The ill-gotten gains will not be shared with the authors.

There are other Universities - University of Tehran, Iran University of Science and Technology, and Sharif University of Technology, that are not so closely linked to the State, where studies can be conducted without the shadow that hangs over the Imam Hossein University.

Already, there are people being sought by foreign nations for arrest because of their work for the State against others. Last year with the ITSec Team and again this year, with other actors Ajily and Rezakhah that the Americans have indicted those involved in malware attacks. With the publication of the recent articles we are sure that the concentration of the West will be even more closely focused on Iran. This work is linked back to the IHU, so how long will it be before others are exposed?

The risks of working for the Iranian State

It may be in the future that Iranians will be freer to travel and work overseas; already we see that Russia is keen to allow visa-free travel to Iranians. If those involved with this malware work are identified, they will be denied the opportunities this would bring them and their families. Travelling overseas, individuals would be at risk of being diverted to an airport in a country with an extradition agreement with the U.S. Students could then be arrested and then sent to face the justice of the U.S. courts. They must realize that they are jeopardizing their futures...

Not only is it their futures at stake; President Rouhani has worked hard to lift sanctions on Iran. Can it be that the IRGC will use students to bring down a new round of punishment for all citizens?

CNN has recently suggested that Iranian cyber actors are using LinkedIn to target U.S. nationals. The U.S. will not stand idly by as we know from the past. Only last month, new sanctions were put in place by the U.S. congress.

The selfish actions of a few will affect the many. If blame is sought from within, will the IRGC shoulder the responsibility, or will they suggest that students had acted on their own and leave them to face the resulting severe penalties and national shame?




Wednesday, June 10, 2015

Duqu 2.0: ‘Almost Invisible’ Cyber Espionage Tool Targeted Russian Co., Linked to Iran Nuclear Talks

 

A Russian cyber security company says that it has discovered a highly-technical, “almost invisible” cyber espionage tool that targeted the company’s own servers and other systems around the world, including some linked to the controversial Iranian nuclear negotiations.
Kaspersky Labs which is based in Moscow announced that the discovery of the worm, called Duqu 2.0, which the company said it found this spring after the worm had penetrated through its system for “months.”



Kaspersky claims that after discovering the worm, started its investigation to find out other victims of the attack and found that some of the “infections are linked to the P5+1 events and venues related to negotiations with Iran about a nuclear deal.”
The Wall Street Journal was the first news agency to publish the news about Duqu 2.0. According to the Wall Street, computers at three luxury European hotels where negotiations had been held were among the worm’s victims.

Eugene Kaspersky said that the company cannot say definitely who is behind the attack, but he believes that due to its sophistication and technical links to previous next-generation computer worms, the attack is most possibly been carried out by a government.

Kaspersky said that the name of the Duqu 2.0 was chosen for this worm because it appeared to be an upgraded version of the Duqu worm which was another highly-sophisticated espionage tool discovered in 2011.
Kaspersky said, We can’t prove attribution because they’re going through proxy servers. “There are technical attributions we can read from the code. This attack is a relative, it’s a new generation of the Duqu attack, most probably made by the same people, or they shared the source code with others.”
Symantec which is a large cyber security company in America agreed that Duqu 2.0 is a evolution of the original threat that was created by the same group of attackers.



Symantec also reported Duqu 2.0 appears to have targeted European and North African telecom operators and a South East Asian electronic equipment manufacturer. Symantec had reported in 2012 that the Duqu threat had not been eliminated and that a new version of the worm had been discovered then.

Duqu and Duqu 2.0 is closely linked to Stuxnet, which is a revolutionary cyber-weapon that was believed to have physically damaged an Iranian nuclear facility and that was suspected to be a result of the joint US-Israeli top secret operation’s. 

 

When the original Duqu was discovered in 2011, Symantec reported that it “shares large number of codes with Stuxnet” and the same suspicions were raise about whether the attackers were the same or if source code had been shared.

Wall Street Journal in its report today said that Duqu 2.0 was “commonly believed to be used by Israeli spies.”
But according to Kaspersky Labs, Duqu 2.0 code also included a number of “false flag” clues to hide/mislead who was behind it. One was a mention in the code of a nickname for a Chinese military officer who was one of five indicted by the U.S. in an extraordinary move by the Department of Justice against Chinese cyber espionage. Another report mentioned a prolific Romanian hacker.

Kaspersky claims that such false flags are relatively easy to spot, especially when the attacker is very careful not to make any other mistakes,”