Showing posts with label cyber crime. Show all posts
Showing posts with label cyber crime. Show all posts

Wednesday, April 4, 2018

A cyber-attack on ideas: Mabna behind latest frightening global phising campaign that targets intellectual property, with allegations of state-sponsorship.

An indictment for nine Iranians was unsealed on March 23 2018. They each stand accused of a variety of crimes relating to cyber-attacks conducted on universities, government agencies, and private organisations around the globe. 31 terabytes of data was stolen - that is a lot of data! The nine suspects are all affiliated with Mabna, the group responsible for the HBO hacking (in which Game of Thrones episodes were leaked), which led to the indictment of Mesri for his involvement in the hacking and attempts to extort US$6 million. It has been revealed that the cyber-assault used customized phishing emails that were sent under the disguise of academics at other institutions. The emails contained links to academic papers that directed the victim to a malicious domain masquerading as a university web page, prompting the victim to give away his log-in details.

Among the victims were government agencies and private companies, but the primary target was universities, with around 8000 professors falling victims. So, unlike the targets identified in previous indictments, we now appear to be seeing a diversification of the type and location of the target. Furthermore, the attack was indiscriminate with regards to academic discipline. Whilst the economic value of the data should not be given disregarded (the indictment makes the cost of the stolen research to USE institutions as US$3.4 billion), the financial loss is only one implication. The concept of targeting innovation, ideas and information, acquired through years of research effort, is new and frightening. The attacks demonstrate the need for academic institutions, to improve their cyber-security, both in terms of the awareness and implementation. It is worrying that the attacks reached beyond the usual suspects of the US and Israel; universities in 22 different counties, including many in Europe, and also China, were victims. Among the non-academic targets was the Unite Nations Children's Fund, demonstrating the callous and indiscriminate way in which the Iranian cyber machine selects victims.

Whilst considered innocent until proven guilty in a court of law, presumably investigators must be pretty convinced of guilt to name these individuals in the indictment. These men will join those previously indicted by the FBI for cyber-criminals, in not being able to leave Iran without fear of arrest. This limitation of freedom will surely deter some of those considering a 'career' in hacking, and slow recruitment to the Iranian cyber-army.

Who is backing Mabna? The indictment reveals that spear-phising email attacks were then conducted on behalf of the Islamic Revolutionary Guard Corps (IRGC) of Iran. But were there other governmental bodies involved? This is a persistent question which resurfaces with each attack. Given their close association, it seems likely that there is some level of co-ordination between the IRGC and other government offices, like those within the Iranian Ministry of Foreign Affairs, when planning the cyber-attacks. Will this public condemnation deter Iran form undertaking further attacks on university, or will the stat simply distance themselves form cyber criminals?

Thursday, October 9, 2014

Iranian cyber criminals target PayPal users with phishing attack



PayPal users were targets of a phishing attack in late 2014.This attack involved the perpetrators sending out spam emails that directed unsuspecting members of the public to follow a link that would take them through to web pages that looked similar to PayPal pages and when they were there customers personal details were collected.


A known Iranian cyber criminal who was involved in setting up the attack, first registered a number of web domains, one of which is http://com-paypal-verification.com:2222/ that they used to host phishing sites. The false domains are designed to look like official PayPal money services sites and login screens that will then collect login details, passwords and credit card numbers.
This is a type of credential harvesting attack which is an example of serious cyber crime.

This attack captures account usernames and passwords and then gives them access to the PayPal account. It is best, to hover your mouse over a link or tap and hold it on a mobile device to see its destination. If you do click on such a link then one or more of the following points could happen:

  1. You will be directed to a spoof website that collects your personal data (as in the Iranian credential-harvesting attack above) 
  2. Install spyware on your system (it can monitor your actions using a keylogger to steal passwords and or credit card numbers you type online)
  3. Malware could be installed on your computer that could disable it

How to tell a fake PayPal site:
  • If it does not include the paypal.com domain then it is not legitimate
  • Only enter password on paypal.com site which starts with https
  • URLs:
    • If the alleged PayPal domain contains @ sign then it is fake
    • Only paypal.com domain is legitimate (it could redirect to your country); examples of fake URLs are www.paypalsecure.com; www.secure-paypal.com; or in the case of Iranian attack http://com-paypal-verification.com

Thursday, April 24, 2014

Iran Calls for Broader International Cooperation in Campaign Against Cyber Crimes


Head of Iran Cyber Police (FATA) General Seyed Kamal Hadianfar asked for collective efforts by all world states to prevent the spread of cyber crimes throughout the globe.

General Hadianfar said in meeting with the representative of the UN Office on Drugs and Crime (UNODC) to Tehran Leik Boonwaat on Wednesday: "effective international cooperation is an important and determining factor in prosecuting and confronting cyber crimes."
 
Boonwaat for his part, vowed that the UNODC will seriously pursue campaign against cyber crimes in Iran.

Iran hosted a conference and a regional workshop on international cooperation and campaign against cyber crimes on August 13-14.

Eight regional countries, representatives of Interpol, UNODC and Iran Cyber Police chief took part in the conference

The conference and the workshop were held to strengthen international cooperation on prosecuting cyber crimes and reinforce cyber space police forces of the neighboring countries.

In October 2013 Iran's Deputy Police Chief Brigadier General Ahmad Reza Radan said that the country's Cyber Police unit has greatly improved its infrastructures and is able to discover and detect over 60% of cyber related crimes.

Radan said: "Right now, the Iranian Law Enforcement Police have made eye-catching progress in the field of cyber infrastructures".

On January 23, 2011 Iran Cyber Police started its work to prevent espionage and sabotage activities through the internet.