Showing posts with label Islamic Republic. Show all posts
Showing posts with label Islamic Republic. Show all posts

Wednesday, November 24, 2021

Mahan Air Cyberattack - Exposing dirty secrets of IRGC QF and Further Technical Analysis

Hello friends 🙏 As I promised I continued my research on Mahan Air cyber attack and collected technical analysis for all of you.

It turned out that the hacker group responsible for this cyberattack Hooshyarane Vatan had succeeded in accessing Mahan air systems due to the fact that all sensitive information was not encrypted. It was also revealed that Mahan Airs IT department had actually identified the hackers on the network and had not yet been able to remove them. How bad are the security measures in Mahan Air ???? 😳😳


Hacktivist group responsible for Mahan Air Hack - Hooshyarane Vatan

The first revelation that came out of this cyber attack was evidence that multiple passengers called MR Hamrah Hamrah had boarded flights more than 70000 times on Iranian flights to Syria !! All are booked using the same travel agency called Utab Gasht. Utab Gasht seems to be a legitimate company but it turned out that they regularly transfer funds to a company called Hamrah or Hamrah SYR. Hamrah Company was rarely mentioned by Mahan Air employees, but a number of employees accidently leaked this information and wrote letters to the esteemed CEO of the company Mr. Golparast. Mr. Golparast is an exposed officer of the IRGC and the owner of Qeshm Fars Company which is a front for IRGC!! Mahan air is making dirty deals with IRGC officers !! Incredible! 🤯🤯



Leaked Letter 

Further analysis of this cyber attack also reveals numerous receipts for charter flights fully booked by the Hamrah company along with hundreds of illegal passengers traveling between Tehran, Damascus and Beruit. This evidence as well as further evidence indicating that passenger load exceeds limits over hundreds of kilograms shows that Mahan Air is actively facilitating the IRGCs QF activities and arms deals in Syria and Hezbollah in Lebanon. There is also a big difference with passengers who board flights and who are registered in the flight system. More than 400 passengers are lost every month under this name. Who knows what other dangerous personnel and cargo the Islamic Revolutionary Guard Corps carries on these flights alongside innocent civilians on flights? Absolutely embarrassing!! 😡



Leaked Invoice for hidden chartered flights 

It was also revealed that all these flights are booked with only 15 phone numbers and also certain people with special privilege are mentioned to board Mahan Air flights. Most likely these are QF IRGC officials. These are listed below:



Phone Numbers and Names used for IRGC QF flight bookings at Mahan Air 


After the technical analysis of this cyber attack it is revealed that Mahan Air has sold its soul to the IRGC and QF. How can Mahan Air do this to the Iranian people? A catastrophe could easily have happened when all these covert and evil deals and trips were completed. The Hamrah company are accompanying Utab Gasht and Qeshm Fars as front companies of the IRGC and its sinister motives and Mahan Air is in bed with them. disgusting! Friends, please do not travel with this airline anymore 🙏🙏

Thursday, November 11, 2021

Who is DEV-0343??

It has been reported by the Microsoft Intelligence center that malicious password spray attacks which first occurred in July have been attributed to Iranian cybercriminals codenamed DEV-0343, according to the Microsoft Information center.

The term password spray usually refers to a brutal attack in which a cybercriminal uses the same password on multiple accounts, with the goal of locking the account with repeated attempts to gain unauthorized access.

DEV-0343 seeks to target more than 250 Office 365 tenants associated with US, Israeli and EU defense companies, as well as ports and shipping companies in the Persian Gulf. However less than 20 tenants have been successfully hacked.


DEV-0343 

These attacks were simulated by DEV-0343 using an emulated Firefox browser and rotated through IPs hosted on a TOR proxy network. This attempt to remain anonymous did not work, because after analyzing the lifestyle and geographical targeting of known Iranian cybercriminals, it became clear that this was the work of this vicious and intrusive regime. At 7:30 a.m. and 8:30 p.m. Iranian time the group targets hundreds of accounts at a time, praying for just one account for weak cyber security measures.

Friends please protect yourself from this criminal group 🙏. Enable 2FA authentication on all your accounts, block all incoming traffic from anonymous services, and make sure all of your Microsoft Exchange access policies are up to date.

When will this regime stop interfering with the rest of the world while the Iranian people are starving? While Internet blackouts occur regularly? How can the Iranian government continue to claim its lack of money while supporting criminal acts like this? 😡


Follow me on Twitter and Instagram: @_0x7c3

#cybercrime #cybersecurity #cybercrime #DEV0343 #PasswordSpray #cyber #attack #Office365 #Microsoft  

Thursday, March 24, 2016

Powerful Iran? Iranian Twitter Bots #FAIL


The Iranians appear to be engaged in a strange soft-war propaganda campaign projecting to a Western audience using the hashtag, "Powerful_Iran" (#powerful_iran)

Multiple fake Twitter accounts have been publishing content from accounts with English names and profile photographs of Hollywood celebrities. The tweets have photographs of Iranian military equipment and cover a range of countries, media outlets, political slogans and other issues.

All of the tweeted photos have a logo of a dove with a rifle on its back showing the Iranian flag. They also include a caption using the "Powerful Iran" hashtag in English, Arabic and Persian.  Many of the tweets have images which vainly state that, "Islamic Republic of Iran is an international power" If you say so...




Here are some of the obviously fake Twitter accounts (seems that these 16 accounts are sending most of the tweets):

@daniel_mathew12 (created:12/15/2015)
@coreenwright3 (created: 12/26/2015)
@brianrauscher3 (created: 12/15/2015)
@harrisonangela5 (created: 12/15/2015)
@Williams2070 (created: 12/27/2015)
@daisybailey01 (created: 12/27/2015)
@EthelBell2016 (created: 12/26/2015)
@charlesmeyer201 (created: 12/26/2015)
@agustinarobbin1 (created: 12/27/2015)
@thomasanaya3 (created: 12/26/2015)
@Halina1321 (created: 12/13/2015)
@Peggy_Seitz (created: 12/26/2015)
@stefan_witcher (created: 12/26/2015)
@TillieMedeiros (created: 12/26/2015)
@shahab945 (created: 08/05/2015)
@pablofisher1990 (created: 12/22/2015)

The profiles are fake because:
  1. They have clearly mostly been created around the same time.
  2. They replay the same content between profiles.
  3. They don't tweet about much else!
  4. They have a lot of followers & tweets in a short time.
  5. They use images of celebrities, obviously!

Similarities to Letter4u

Last year, the hashtag "Letter4u" was used by many bot-like accounts following the release of an open letter by Iran's supreme leader addressed to Western youth and the "Powerful_Iran" shows similarities to that campaign: "Letter4u" was also launched by an army of bots using photos of celebrities and also used a similar range of random hashtags. The themes of the tweets coincides with the predictable goals of the Iranian state, that is to destroy Israel and shut down traffic in the Persian Gulf, suggestions that Israel and Saudi Arabia are working together, & that Iran is a major global military country.

While it's not entirely clear who is behind the "Powerful_Iran" campaign, but it gained traction following the nuclear agreement between the West & Iran.

#FAIL

John Little, author of Blogs of War states that, "...the campaign is a miserable failure. Almost all of the tweets have gone unnoticed and have no retweets or favourites. The few interactions that I can find also appear to be faked by other bots".   

Links

You can follow the Twitter & Telegram accounts for: @powerful_iran

Sunday, July 5, 2015

Iran claims to stop Dino Malware attack



Iran confirms that spy malware called Dino is targeting sensitive centers inside the country since one and half years ago.

Masoud Biglarian, head of the Computer Emergency Response Team Coordination Center (CERTCC), said that after malware was discovered the CERTCC which is subset of the Information and Communication Technology (ICT) sent a secret report to the countrys officials about the issue.

According to Irans Mehr news agency Biglarian said: «We took appropriate measures to prevent damage to the strategic centers of the country by Dino».

He also said that Dino is a type of Spyware such as Stuxnet that is designed for specific purposes and launches targeted attacks.

He rejected claims that the malware infected some sensitive centers inside the country.

Last week some western media outlets reported that Dino malware which searches for specific data and steals it has infected some organizations inside Iran.

Security firm ESET researchers in Bratislava, Slovakia identified the sophisticated Dino Trojan that attacked Iranian and Syrian targets in 2013 and it is rumor that the group is a secret part of the French Intelligence service.


Dino was supposedly created by the so-called Animal Farm Group which also created other Trojans like Bunny, Casper and Babar. Casper malwares claim to fame is that it was involved in a large scale attack on computer systems in Syria last autumn.

ESET claims that Dinos main goal seems to be the exfiltration of files from its targets.

Large scale cyber attacks on Iranian facilities started in 2010 after the US and Israel reportedly tried to disrupt the operation of Irans nuclear facilities through a worm that later became known as Stuxnet.

US intelligence officials revealed in June 2013 that the Stuxnet malware was not only designed to disrupt the Irans nuclear program but also was part of a wider campaign directed from Israel that included assassination of the countrys nuclear scientists.

Stuxnet is the first discovered worm that spies on industrial systems and reprograms them. It is written specifically to attack SCADA systems that are used to control and monitor industrial processes.

In September 2013 the Islamic Republic of Iran said that the computer worm Stuxnet infected 30 000 IP addresses in Iran but it denied reports that the cyber worm had damaged computer systems at the countrys nuclear power plants.

Thursday, October 30, 2014

Iranian Government Spying in Social Networking Sites



No one can deny that these days millions of Iranians rely on Facebook. The high number of Facebook users in Iran, which is estimated to be anywhere between four million and five million people, makes this a social phenomena. Young Iranians are denied the most basic freedoms even in their private lives and without social liberties,what these users reflect on their Facebook pages is in effect how they would like to live.

Iranians use social networking sites among other things for political discussion, more open posting and publication of works of art and literature, the announcement of events that cannot be publicized on domestic newspapers and to find kindred spirits or like-minded people. But is it possible for Iranians appear in any arena without Islamic Republic officials cracking down on them?

In June 2014 three Ahvazi citizens were sentenced to three years in jail for creating certain Facebook pages, membership on Facebook carried a one-year sentence. Some people are arrested for crimes against morality and public decency on Facebook. In July 2014, a Revolutionary Court sentenced eight people to 127 years imprisonment in total for being active Facebook users. In another instance the Malayer Security chief announced the sentencing of 22 Facebook users, and this is a another long story.
Ali MirAhmadi, the deputy head of Iran Cyber Police has said: “The main objective of Iran’s Cyber Police is to promote cyber security through continuous observation and monitoring of cyber space. I advise all users to comply with the laws and regulations and avoid any form of offence within cyber space because the police have complete knowledge of it.”

In most cases as soon as someone is arrested for using Facebook, the Cyber Police regards him as either a spy, prostitute, enemy abettor or guilty of crimes against morals and public decency. The offences are considered to be proven in advance.

A lawyer says that judges often have no expertise in cyber technology and adds: “Judges have no expertise in computer technology and so everything goes back to the reports from the ministry of intelligence or the Cyber Police. The judge accepts these reports as expert opinions. Therefore, it is impossible to prove otherwise.”

An IT expert says the problem is that when an Iranian enters the World Wide Web, he must follow the model of use that suits his circumstances in Iran. “In our country, the internet and social networking sites are a venue for political activity. The government views this political activity as propaganda against the regime. Therefore, cyber space is under close scrutiny by the government.” The IT specialist goes on to conclude that for this reason, internet users in Iran must maintain different security criteria for themselves when they use the internet as opposed to people outside of Iran.