Showing posts with label Sharif University. Show all posts
Showing posts with label Sharif University. Show all posts

Tuesday, August 15, 2017

IRGC and the Risks of Iranian Malware Development

IRGC

Recent articles have shown that the Iranian State has used computer malware Shamoon and linked malware StoneDrill and NewsBeef to damage others. Instead of glorifying Iran, the exposing of such activity by well-known companies like Kaspersky Lab, discussion on the Iranian Exploit Database (IEDB) forum and articles on the Iran Cyber News Agency (ICNA) site has damaged its reputation.


IEDB

Iranian Cyber News Agency (ICNA)

Despite trying to hide their identities, simple investigations have revelaed the identities of those who are involved within the IRGC at the Imam Hossein University (IHU).


Imam Hossein University (IHU)


This is supposed to be a seat of learning, but it seems that the education of students is for purposes other than knowledge. The IRGC officers who pose as professors and academics, have put their hands in the hand of their masters. We have seen the State has turned against its own with controls on the Internet. Are students there helping to suffocate the true Iranian voice?

Instead of serving the people of Iran, students can apply to trade-off their military service, by doing 'project' work. The IRGC claim to offer a trade-off to students to exchange time spent on projects for a reduction of their military commitment. The IHU offered sites for students to do this. What sort of exchange do students actually receive? Months of hard work for a few days respite? Military service should be exactly this: to protect the people of Iran, not hiding away working on developing malware that has only served to show us in a bad light internationally, and does not benefit the State.

It is far from unknown for the IRGC to make money from their work, and some of this malware development may be to extort money from victims to gain finances for their own personal 'projects'. The ill-gotten gains will not be shared with the authors.

There are other Universities - University of Tehran, Iran University of Science and Technology, and Sharif University of Technology, that are not so closely linked to the State, where studies can be conducted without the shadow that hangs over the Imam Hossein University.

Already, there are people being sought by foreign nations for arrest because of their work for the State against others. Last year with the ITSec Team and again this year, with other actors Ajily and Rezakhah that the Americans have indicted those involved in malware attacks. With the publication of the recent articles we are sure that the concentration of the West will be even more closely focused on Iran. This work is linked back to the IHU, so how long will it be before others are exposed?

The risks of working for the Iranian State

It may be in the future that Iranians will be freer to travel and work overseas; already we see that Russia is keen to allow visa-free travel to Iranians. If those involved with this malware work are identified, they will be denied the opportunities this would bring them and their families. Travelling overseas, individuals would be at risk of being diverted to an airport in a country with an extradition agreement with the U.S. Students could then be arrested and then sent to face the justice of the U.S. courts. They must realize that they are jeopardizing their futures...

Not only is it their futures at stake; President Rouhani has worked hard to lift sanctions on Iran. Can it be that the IRGC will use students to bring down a new round of punishment for all citizens?

CNN has recently suggested that Iranian cyber actors are using LinkedIn to target U.S. nationals. The U.S. will not stand idly by as we know from the past. Only last month, new sanctions were put in place by the U.S. congress.

The selfish actions of a few will affect the many. If blame is sought from within, will the IRGC shoulder the responsibility, or will they suggest that students had acted on their own and leave them to face the resulting severe penalties and national shame?




Thursday, April 23, 2015

Project "Pistachio Harvest"


Months of research in Iranian networks is uncovering at least 16000 systems controlled by Iran outside borders and 2000 of these were infected machines of businesses in the US, Israel and other countries.

Many of the Internet Protocol addresses (IPs) of those machines are hosting .ir websites, domains that are used as platforms for attacks. According to the company, in many cases visitors to those sites are later infected with malware, software designed specifically for surveillance and to obtain valuable data from target organisations.

Most targets are in the US although attacks have also hit including UK, Israel, Germany and Canada. Various US and European hosting companies also have been abused. Cloud and hosting services of industry giants like Amazon and GoDaddy are used to launch the attacks.

Norse believes previous research into Iranian activity may included false assumptions about the actors involved as Iran has been able at creating disinformation and used more than 5000 fake social networking profiles to trick viewers to following tracks to nobody and nowhere.

iSight released a report and claimed that these fake profiles were used to spy on military leaders and political staff across the world.

Norse set up fake systems that appeared to belong to businesses and critical infrastructure providers that was attractive to attackers. The organization collected data of subsequent attacks and traced a large number to Iran. Norse also used "millions of sensors dropped all over the world" and analysis tools for tracing.

Turkey and Iran collaborate on cyber issues and is reported that Turkey in exchange for oil and other goods helped Iran circumvent US and European sanctions that were implemented in response to that country's nuclear programs.

Rival security research firm CrowdStrike says that it tracks four different Iranian groups that it calls Kittens. Each Kitten is separate from the other and has its own modus operandi and target list. Finally there is Cutting Kitten.

Role of Iran’s Universities

Islamic Republic of Iran has other ways in encour aging IT entrepreneurs follow its commands. For example the role of government in Iran’s university system is enormous. The regime invested large amounts in building IT and other scientific infrastructure at the top educational institutions including Sharif Univer sity of Technology, Shahid Beheshti University and IRGC linked Malek Ashtar University and in return can direct research in ways to pursue regime objectives.

The development of Iran’s nuclear weapons program after 2003 is an example for understand ing the evolution of the relationship between gov ernment, security services and universities in IT. When Supreme Leader Khamenei ordered stop to Iran’s state nuclear weapons research program after the US invasion to Iraq in 2003 and his lieutenants built a new structure that spread rel evant research through the university system.

The scale and effects of this effort are visible but assessing the level of awareness and or willingness of all the univer sity participants in it is not easy and Iran’s IT sector works in a similar fashion. Government and secu rity institutions collaborate with universities in research to achieve government aims and make faculties and students components of regime strategic efforts. Students after graduation find themselves in a network of associations and research projects that mostly also supports regime priorities, whether they know or not.

The Islamic Republic also uses incentives created by mandatory military service to encourage aspiring young programmers to support state security efforts directly. At least one scientist involved in research related to development of nuclear weapons writes in his resume that he was exempted from com pulsory military service in exchange for work on a project deemed useful to the armed forces. This pro gram of exemption was developed in 2007.

Therefore Iran’s leaders have carefully and consciously built national IT, education and corporate infrastruc tures that produce excellently educated developers with incentives to pursue government objectives and not use skills against the government. They have involved Iran’s security organs especially the IRGC, through these structures in ways to allow the regime uses these IT and hacking capabilities with plausible deniability. In addition they have built an internet infrastructure designed to hide the sources of malicious activity and give the government the ability to monitor, regulate and control citizens access to the internet in extremely detailed ways.

Full details of the Norse Project Pistachio Harvest report are found here: www.pistachioharvest.com/#/dashboard