Showing posts with label china. Show all posts
Showing posts with label china. Show all posts
Wednesday, November 25, 2015
Iranian Hackers Attack State Dept. via Social Media Accounts
Iran launched sophisticated computer espionages leading to a series of cyberattacks against US State Department officials over the past month.
It is possible that cyberespionage is becoming the tool of seeking the type of influence that Iranian hardliners hoped that that country's nuclear program will eventually provide.
According to diplomatic and law enforcement officials who are familiar with the investigation Iranian hackers over the past month identified individual State Department officials who focus on Iran and the Middle East and broke into their email and social media accounts. The State Department became aware of the compromises when Facebook told the victims that the state-sponsored hackers compromised their accounts.
Iran’s cyberskills are not yet equal to those of Russia or China but the attack against the State Department by using the social media accounts of young government employees to gain access to their friends across the administration is a focus that was not seen before.
Iranians have been less destructive than they could be, but they are getting far more aggressive in cyberespionage, which they know is less likely it will prompt a response from the United States.
Iranian hackers have been responsible for a series of powerful attacks against American banks that took their websites offline as well as a destructive attack on Saudi Aramco, the world’s largest oil producer, that replaced data on employee machines with an image of a burning American flag. American government officials also blame Iran for a similarly destructive attack at RasGas, the Qatari natural gas giant,and for an attack on Sands Casino in Las Vegas, where a large number of computers were destroyed.
Last year Iranians began using cyberattacks for espionage rather than for destruction and disruption. From May 2014 Iranian hackers were targeting Iranian dissidents and later policy makers,senior military personnel and defense contractors in the United States, England and Israel.
The attacks were basic “spear phishing” attempts, in which attackers tried to lure their victims to click on a malicious link, in this case by impersonating members of the news media.
Iranian hackers were successful in more than a quarter of their attempts. The number of such attacks reached its climax in May just ahead of the nuclear talks in Vienna in July and reached more than 1,500 attempts.
In the months before the talks, Iran’s hackers began probing critical infrastructure networks in what appeared reconnaissance for cyberattacks with the objective of causing physical damage but in June and July as American and Iranian negotiators gathered in Vienna to agree a deal on Iran’s nuclear program, attacks against targets in the United States stopped. Instead of this, Iran started targeting victims in Israel as well as members of Daesh in July as the militant group began expanding territory across Iraq.
Then in August just two weeks after the nuclear accord was reached, the trickle of cyberattacks against the group’s usual targets resumed against included 1600 individuals from scholars, scientists, chief executives and ministry officials to education institutes, journalists and human rights activists. If facebook last month had not decided to use a new alert system to notify users when facebook's security team believed state-sponsored hackers had hijacked their accounts, and US State Department officials began to see a troubling new message pop up on their facebook accounts, it is possible that the victims didn't learn of the compromises.
Labels:
american banks,
china,
cyber,
Daesh,
England,
espionage,
Facebook,
hackers,
iran,
Israel,
las vegas,
nuclear,
Qatar,
RasGas,
russia,
Sands,
Saudi Aramco,
spear-phishing,
state department,
USA
Wednesday, June 10, 2015
Duqu 2.0: ‘Almost Invisible’ Cyber Espionage Tool Targeted Russian Co., Linked to Iran Nuclear Talks
A Russian
cyber security company says that it has discovered a
highly-technical, “almost invisible” cyber espionage tool that
targeted the company’s own servers and other systems around the
world, including some linked to the controversial Iranian nuclear
negotiations.
Kaspersky
Labs which is based in Moscow announced that the discovery of the
worm,
called Duqu
2.0,
which the company said it found this spring after the worm had
penetrated through its system for “months.”
Kaspersky
claims that after discovering the worm, started its investigation to
find out other victims of the attack and found that some of the
“infections are linked to the P5+1 events and venues related to
negotiations with Iran
about a nuclear deal.”
The
Wall Street Journal was the first news agency to publish the news
about Duqu 2.0. According to the Wall Street, computers at
three luxury European hotels where negotiations had been held were
among the worm’s victims.
Eugene
Kaspersky said that the company cannot say definitely who is behind
the attack, but he believes that due to its sophistication and
technical links to previous next-generation computer worms, the
attack is most possibly been carried out by a government.
Kaspersky
said that the name of the Duqu 2.0 was chosen for this worm because
it appeared to be an upgraded version of the Duqu
worm which was another highly-sophisticated espionage tool discovered
in 2011.
Kaspersky
said, We can’t prove attribution because they’re going through
proxy servers. “There are technical attributions we can read from
the code. This attack is a relative, it’s a new generation of the
Duqu attack, most probably made by the same people, or they shared
the source code with others.”
Symantec
which is a large cyber security company in America agreed that Duqu
2.0 is a evolution of the original threat that was created by the
same group of attackers.
Symantec
also reported Duqu 2.0 appears to have targeted European and North
African telecom operators and a South East Asian electronic equipment
manufacturer. Symantec had reported in 2012 that the Duqu threat had
not been eliminated and that a new version of the worm had been
discovered then.
Duqu
and Duqu 2.0 is closely linked to Stuxnet,
which is a revolutionary cyber-weapon that was believed to have
physically damaged an Iranian nuclear facility and that was suspected
to be a result of the joint US-Israeli top secret operation’s.
When
the original Duqu was discovered in 2011, Symantec reported that it
“shares large number of codes with Stuxnet” and the same
suspicions were raise about whether the attackers were the same or if
source code had been shared.
Wall
Street Journal in its report today said that Duqu 2.0 was “commonly
believed to be used by Israeli spies.”
But according
to Kaspersky Labs, Duqu 2.0 code also included a number of “false
flag” clues to hide/mislead who was behind it. One was a mention in
the code of a nickname for a Chinese military officer who was one of
five indicted by the U.S. in an extraordinary move by the Department
of Justice against Chinese cyber espionage. Another report mentioned
a prolific Romanian hacker.
Kaspersky
claims that such false flags are relatively easy to spot, especially
when the attacker is very careful not to make any other mistakes,”
Thursday, December 4, 2014
Operation Cleaver: Mass Hacking By Iranian State
Iranian
hackers have been identified as the source of coordinated attacks
against more than 50 targets in 16 countries, many of them corporate
and government entities that manage critical energy, transportation
and medical services.
According
to Cylance, a security firm based in California in USA, over the
course of two years Iranian hackers managed to steal confidential
data from a long list of targets and in some cases infiltrated
victims computer networks to such an extent that they could take
over, manipulate or easily destroy data on those machines.
Cylance
called the attacks “Operation Cleaver” because the word cleaver
appeared often in the attackers malicious code.
The
hackers used a set of tools that can spy and even shut down critical
control systems and computer networks, and aimed them at targets in
the United States, Canada, Israel, India, Qatar, Kuwait, Mexico,
Pakistan, Saudi Arabia, Turkey, the United Arab Emirates, Germany,
France, England, China and South Korea.
Victims
of the attacks include: US Marine Corps, a major airline, a medical
university, an energy company that specializes in natural gas
production, a car manufacturer, a major military installation and a
large military contractor. The Islamic Republic also concentrated
attacks on oil and gas industries and universities in the United
States, India, Israel and South Korea and managed to steal pictures,
passports and specific identifying information for students and
faculty.
Cylance
said it also collected worrying evidence of attacks on transport
networks, including airlines and airports in South Korea, Saudi
Arabia and Pakistan. Researchers said they found evidence that
hackers gained complete remote access to airport gates and security
control systems, “potentially allowing them to spoof gate
credentials.”
See
here for full report:
http://www.cylance.com/assets/Cleaver/Cylance_Operation_Cleaver_Report.pdf
Labels:
Canada,
china,
Cylance,
England,
France,
Germany,
hackers,
India,
Iranian,
Israel,
Kuwait,
Mexico,
Operation Cleaver,
Pakistan,
Qatar,
Saudi Arabia,
South Korea,
Turkey,
UAE,
USA
Tuesday, December 2, 2014
North Korea Prime Suspect in Hacking Attack Against Sony Pictures
According
to the Wall Street Journal, hackers who took Sony Pictures
Entertainment’s computer systems offline used tools which were very
similar to those used last year in an attack on South Korean
television stations and ATMs. The similarity reinforces a suspicion
among some investigators, which include Sony, the FBI and a team from
the security company FireEye Inc., that North Korea played a role in
the breach.
Sony
Pictures is investigating if the North Korean regime was behind a
massive hack attack on the studio computer network. Email was damaged
and four movies were leaked.
The
website Re/code reported that Sony and its security consultants are
exploring the possibility that hackers based in China targeted studio
computers in retaliation for the upcoming release of the film
The
Interview.
In this film, Seth Rogen and James Franco play journalists who
arrange an interview with North Korean leader Kim Jong-Un, and the
CIA then ask them to assassinate him.
On
Friday a North Korean government website called "The Interview"
an "evil act of provocation" that deserved "stern
punishment." Reportedly North Korea has organized a team of
approximately 3,000 hackers to promote the Kim regime.
Labels:
china,
CIA,
FBI,
FireEye,
hackers,
Kim Jong-Un,
North Korea,
regime,
Sony,
South Korea,
The Interview,
Wall Street Journal
Saturday, April 12, 2014
Iran: The World's Worst Cyber-Terrorists – For Now
Iran became a major cyber terror threat to the US in the last 12 months and targeted several US government agencies but with regard to the Iranian lack of skills in this area it means that for now it has not been possible that Iran causes significant damage. Iran is more than five years behind countries like China, the US and Russia in terms of cyber capabilities but with the right resources that gap could be removed quickly especially considering Iran is the historical enemy of the US.
Security company Mandiant in its latest report describes Iran's development from cyber-obscurity to becoming a credible but unsophisticated threat. Mandiant is the same company which last year revealed the extent that Chinese government funded cyber espionage was carried out. In the company's report M Trends 2014 it is written that “threat actors” based in Iran "pose an ever-increasing threat due to Iran's historical hostility towards US business and government interests."
The report reveals that it observed "threat actors" based in Iran who target the networks of several US government agencies. In the report it is written that "Employees at a US state government office discovered evidence that someone had accessed multiple systems within their network without authorization. An internal IT department investigation found indications of data theft and unauthorized use of privileged credentials."
The security company said that the data that these actors steal "lacked a discernible focus or demonstrated intent". This suggests that the purpose of the attack is more likely "reconnaissance of the potential target's networks." Attacks that originate in Iran, are on a very low level of technical skill and those carrying out the attacking use off-the-shelf tools which are relatively easy to defend. Mandiant says that the victim detects 75% of all attacks from Iran.
Subscribe to:
Posts (Atom)
-
Since my last post in October, there has been no confirmation of which group was behind the cyber-attack on Westminster, or the role of the ...
-
It's back! It appears that the Shamoon malware aka "Shamoon 2" is targeting Saudi computers. Back in 2012, malware known a...
-
Are Iranian hackers involved in using the " Mamba " ransomware (or possibly be behind the ransomware)? It seems unclear but an...
-
Reuters has reported that Binance the worlds largest cryptocurrency market is helping Iran avoid US sanctions because of very weak identity ...
-
Mohammad-Ali Movahedi Kermani: not liking the Internet In the latest desperate attempt to subvert the freedom of Iranian expression, the...
-
Emen Net Pasargad Iranian Hacker Group The FBI recently announced that Emen net Pasargad an Iranian hacker group that successfully posed as...
-
Censorship comes in many forms and most recently that includes at the barrel of a gun. I speak of course of the murder in Istanbul of Mas...
-
Cisco Talos reports that the Iranian-backed hacking group MuddyWater AKA MERCURY AKA Static Kitten has been caught on another hacking campai...







