Showing posts with label FBI. Show all posts
Showing posts with label FBI. Show all posts

Monday, October 2, 2017

Iranian Hacking Threat to USA if Nuclear Deal Collapses



Since the signing of the nuclear deal between the USA and Iran in 2015 (the Joint Comprehensive Plan of Action (JCPOA)), Iranian cyber attacks against the USA have dropped off. 

The U.S. and six partners began discussions with Iran in 2013 to lift some economic sanctions to limit Iranian nuclear developments, and since then Iranian hackers have largely reduced attacks against the U.S., focusing instead on industrial espionage and hitting rival Middle Eastern countries. However, with the threat by the U.S. President Donald Trump to walk away from the deal, there are fears that Iran will re-start cyber-attacks against the USA.

The cyber-security research company FireEye have produced a report which has identified an Iranian-government group that FireEye have called APT33 (APT means Advanced Persistent Threat, indicating state-involvement). APT33 has previously attacked using spear-phishing techniques to target companies involved in the petrochemical industry and in military and commercial aviation. Could APT33 or similar be ready to attack the U.S. if Trump quits the JCPOA?

A Short History of Iranian Cyber-attacks

  • 2010: It was suspected that the U.S. and Israel attacked Iran with the Stuxnet malware, damaging Iranian nuclear control equipment at the Natanz uranium enrichment plant.
  • 2011/2013: In possible response to Stuxnet, Iran used DDoS (Distributed Denial of Service) Operation Ababil attacks against over 45 major financial institutions. Seven members of the Iranian ITSec Team were subsequently indicted by the FBI for over 176 days of DDoS attacks against the U.S. and also the attack against the Bowman Dam.
  • 2012: APT33 attack the Saudi Aramco oil company using the Shamoon malware, destroying thousands of computers in that company.
  • 2015: After JCPOA, large-scale Iranian attacks against the U.S. dropped off, although this may also have been due to Iran's concerns with Syria and Yemen. Also, APT33 continued espionage attacks against the U.S., South Korea and Saudi. In 2015, many Iranian hacking forums and use of hacker handles disappeared, probably because Iran realized that they were under greater scrutiny. 
  • 2016/2017: APT33 attacked Saudi and U.S. aerospace companies, along with attacks against a South Korean petrochemical company. In May 2017, APT33 attacked a Saudi organization and a South Korean company using malicious spear-phishing emails attempting to target victims with job vacancies for a Saudi petrochemical company.

The FireEye APT33 Report

FireEye state that APT33 used an Iranian developed web-shell developed by the hacker Solevisibile to craft the spear-phishing emails to targets. The webshell (called ALFASHELL, ALFA TEaM Shell v2-Fake Mail), has the default sender email address of solevisible@gmail.com. It is not known if Solevisible is linked with APT33 or not.

APT33 used domain masquerading as the following companies: Boeing, Alsalam Aircraft Company, Northrop Grumman Aviation Arabia, and Vinnell Arabia. APT33 used the domains to target victims with spear-phishing emails.

FireEye identified the hacker xman_1365_x as being the developer of a backdoor used in APT33 malware. It appears that xman_1365_x was also a manager in the Barnamenevis Iranian programming & software engineering forum, and registered accounts in the Iranian Shabgard and Ashiyane forums. The hacker xman_1365_x is also linked with the Nasr Institute, which is similar to Iran’s cyber army and controlled by the Iranian government. The Nasr Institute appears to be linked to the 2011-2013 DDoS attacks on the financial industry (Operation Ababil).

Further indications that Iran is behind APT33

  • A malware dropper (known as StoneDrill) used by APT33 has Farsi language artifacts in it.
  • APT33’s targeting of organizations involved in aerospace and energy is aligned with with nation-state interests (not those of cyber-criminal groups), implying that APT33 is probably government sponsored.
  • Iranian working hours; APT33 worked at the time zone close to 04:30 hours ahead of UTC, which heavily indicates Iran. APT33 largely operated on days that correspond to the Iranian working week (Saturday to Wednesday). Iran is one of few countries that subscribes to a Saturday to Wednesday working week.
  • APT33 used popular Iranian hacker tools and DNS servers used by other suspected Iranian hackers. The publicly available backdoors & tools utilized by APT33 (including NANOCORE, NETWIRE, and ALFA Shell) are available on Iranian hacking websites, associated with Iranian hackers, and used by other suspected Iranian threat groups.

Thursday, August 10, 2017

Iranians Indicted by FBI for Credit Card Fraud and Computer Hacking


A superseding indictment was unsealed on August 8 2017 charging Iranian hackers Arash Amiri Abedian -31- and Danial Jeloudar -27- with:

  • Aggravated identity theft 
  • Wire fraud 
  • Criminal conspiracy relating to access device fraud,unauthorized access to, and theft of information from, computers, and threatening to damage a computer. 

In October 2007 Abedian and Jeloudar, living in Iran, conspired together to violate multiple U.S. criminal statutes. The indictment states they obtained stolen credit card numbers and related personal information by hacking, and used that information to defraud and extort money, goods and services from victims in the U.S. and elsewhere.



Between 2011 and 2016, Abedian used malicious software (malware) to capture the credit card and other personal information of individuals who had transacted with various websites. Abedian used that information to commit identity theft and get goods and services by fraud, and, on some occasions, Abedian transmitted the stolen information to Jeloudar. On 21 February 2012, Abedian sent Jeloudar approximately 30,000 names and numbers, which he said were unauthorized credit card numbers and associated information. 
Around March 2012 and April 2012, Jeloudar ordered and obtained various equipment, servers, and internet hosting services from a provider in South Carolina using stolen credit card numbers and other personal identifiers.

Arash Amiri Abedian

Danial Jeloudar
In January 2017, Jeloudar contacted a Californian online merchant and threatened to disclose its customers’ credit card numbers and other related information previously obtained by hacking the merchant‘s website, unless it made a Bitcoin payment to Jeloudar. Jeloudar also threatened to disclose to the company’s customers that their private information had been compromised and launched a denial-of-service attack (DoS) on the company’s website.

References

U.S. Department of Justice indictment link
FBI Wanted poster for Arash Amiri Abedian link
FBI Wanted poster for Danial Jeloudar link

Tuesday, July 18, 2017

FBI Indicts Iranian Hackers



The U.S. FBI -Federal Bureau of Investigation- has announced the indictments of two Iranian hackers.

The hackers are Mohammed Reza Rezakhah -aged 39- and Mohammed Saeed Ajily -aged 35-. They have both been charged with the following:

  • Criminal conspiracy relating to computer fraud and abuse
  • Unauthorized access to and theft of information from computers
  • Wire fraud
  • Exporting a defense article without a license, and
  • Violating sanctions against Iran 
Arrow Tech: Vermont Software Company

Rezakhah and Ajily have been charged for activity starting in around 2007, where they and a third hacker, Nima Golestaneh -who has already pleaded guilty-, hacked into computers in order to obtain software which they would then sell and redistribute in Iran and elsewhere outside the U.S. It appears that Golestaneh worked with Rezakhah, in supplying servers for Rezakhah to conduct illegal activities.

Ajily tasked Rezakhah and other hackers with stealing or unlawfully cracking particular pieces of software. Rezakhah then hacked into victim networks to steal the software they wanted & once they got the software, Ajily marketed and sold the software through various companies and associates to Iranian entities, including universities, military and government entities, specifically noting that such sales were in contravention of U.S. export controls and sanctions. The Universities and company included: Malek Ashtar Defense University, Tehran University, Sharif Technical University, Khvajeh Nasir University, and Shiraz Electro Optic Industry. Rezakhah worked with Golestaneh, selling their "cracked" solution to the Arrow Tech software -they formed a company called "Dongle Labs", which sold a crack to the software that normally requires a hardware "dongle" for the software to work-.

In addition to payment, Ajily received certificates of appreciation for his work from several of the Iranian government and military entities. This implies that Ajily and Rezakhah could be working for the Iranian state?

In October 2012, Rezakhah hacked a Vermont-based engineering consulting and software design company -Arrow Tech-. Arrow Tech's primary product was PRODAS -Projectile Rocket Ordnance Design and Analysis System-; software that provides aerodynamics analysis and design for projectiles -from bullets to GPS guided artillery shells-. This software is designated as a “defense article” on the U.S. Munitions List of the International Traffic in Arms Regulations -ITAR-, meaning it cannot be exported from the U.S. without a license from the U.S. Department of State. Ajily marketed the same software as one of the products he could offer to his Iranian clients.

What does this mean for the hackers?

The court issued arrest warrants for both defendants, which means that if either Rezakhah or Ajily wanted to travel outside of Iran, they would be arrested. This means they are now effectively prisoners inside Iran. No doubt, their activities have brought great shame upon Iran, themselves and their families. Such illegal activities may not help their career chances inside Iran either...

It would appear that the FBI is getting tough on Iranian hackers who may work for or have links to supporting the Iranian state in such illegal activities. The indictment can be read in full here.


Tuesday, December 2, 2014

North Korea Prime Suspect in Hacking Attack Against Sony Pictures


According to the Wall Street Journal, hackers who took Sony Pictures Entertainment’s computer systems offline used tools which were very similar to those used last year in an attack on South Korean television stations and ATMs. The similarity reinforces a suspicion among some investigators, which include Sony, the FBI and a team from the security company FireEye Inc., that North Korea played a role in the breach. 
 
Sony Pictures is investigating if the North Korean regime was behind a massive hack attack on the studio computer network. Email was damaged and four movies were leaked.

The website Re/code reported that Sony and its security consultants are exploring the possibility that hackers based in China targeted studio computers in retaliation for the upcoming release of the film  The Interview.  In this film, Seth Rogen and James Franco play journalists who arrange an interview with North Korean leader Kim Jong-Un, and the CIA then ask them to assassinate him.

On Friday a North Korean government website called "The Interview" an "evil act of provocation" that deserved "stern punishment." Reportedly North Korea has organized a team of approximately 3,000 hackers to promote the Kim regime.