An indictment for nine Iranians was unsealed on March 23 2018. They each stand accused of a variety of crimes relating to cyber-attacks conducted on universities, government agencies, and private organisations around the globe. 31 terabytes of data was stolen - that is a lot of data! The nine suspects are all affiliated with Mabna, the group responsible for the HBO hacking (in which Game of Thrones episodes were leaked), which led to the indictment of Mesri for his involvement in the hacking and attempts to extort US$6 million. It has been revealed that the cyber-assault used customized phishing emails that were sent under the disguise of academics at other institutions. The emails contained links to academic papers that directed the victim to a malicious domain masquerading as a university web page, prompting the victim to give away his log-in details.
Among the victims were government agencies and private companies, but the primary target was universities, with around 8000 professors falling victims. So, unlike the targets identified in previous indictments, we now appear to be seeing a diversification of the type and location of the target. Furthermore, the attack was indiscriminate with regards to academic discipline. Whilst the economic value of the data should not be given disregarded (the indictment makes the cost of the stolen research to USE institutions as US$3.4 billion), the financial loss is only one implication. The concept of targeting innovation, ideas and information, acquired through years of research effort, is new and frightening. The attacks demonstrate the need for academic institutions, to improve their cyber-security, both in terms of the awareness and implementation. It is worrying that the attacks reached beyond the usual suspects of the US and Israel; universities in 22 different counties, including many in Europe, and also China, were victims. Among the non-academic targets was the Unite Nations Children's Fund, demonstrating the callous and indiscriminate way in which the Iranian cyber machine selects victims.
Whilst considered innocent until proven guilty in a court of law, presumably investigators must be pretty convinced of guilt to name these individuals in the indictment. These men will join those previously indicted by the FBI for cyber-criminals, in not being able to leave Iran without fear of arrest. This limitation of freedom will surely deter some of those considering a 'career' in hacking, and slow recruitment to the Iranian cyber-army.
Who is backing Mabna? The indictment reveals that spear-phising email attacks were then conducted on behalf of the Islamic Revolutionary Guard Corps (IRGC) of Iran. But were there other governmental bodies involved? This is a persistent question which resurfaces with each attack. Given their close association, it seems likely that there is some level of co-ordination between the IRGC and other government offices, like those within the Iranian Ministry of Foreign Affairs, when planning the cyber-attacks. Will this public condemnation deter Iran form undertaking further attacks on university, or will the stat simply distance themselves form cyber criminals?
Showing posts with label cyber crime. Show all posts
Showing posts with label cyber crime. Show all posts
Wednesday, April 4, 2018
A cyber-attack on ideas: Mabna behind latest frightening global phising campaign that targets intellectual property, with allegations of state-sponsorship.
Labels:
computer hacking,
cyber crime,
cyber warfare,
cyber-attack,
cybercrime,
Europe,
human rights,
iran,
iran cyber,
Iranian,
phishing,
spear-phishing,
USA
Thursday, October 9, 2014
Iranian cyber criminals target PayPal users with phishing attack
PayPal users were targets of a phishing attack in late 2014.This attack involved the perpetrators sending out spam emails that directed unsuspecting members of the public to follow a link that would take them through to web pages that looked similar to PayPal pages and when they were there customers personal details were collected.
A known Iranian cyber criminal who was involved in setting up the attack, first registered a number of web domains, one of which is http://com-paypal-verification.com:2222/ that they used to host phishing sites. The false domains are designed to look like official PayPal money services sites and login screens that will then collect login details, passwords and credit card numbers.
This is a type of credential harvesting attack which is an example of serious cyber crime.
This attack captures account usernames and passwords and then gives them access to the PayPal account. It is best, to hover your mouse over a link or tap and hold it on a mobile device to see its destination. If you do click on such a link then one or more of the following points could happen:
- You will be directed to a spoof website that collects your personal data (as in the Iranian credential-harvesting attack above)
- Install spyware on your system (it can monitor your actions using a keylogger to steal passwords and or credit card numbers you type online)
- Malware could be installed on your computer that could disable it
How to tell a fake PayPal site:
- If it does not include the paypal.com domain then it is not legitimate
- Only enter password on paypal.com site which starts with https
- URLs:
- If the alleged PayPal domain contains @ sign then it is fake
- Only paypal.com domain is legitimate (it could redirect to your country); examples of fake URLs are www.paypalsecure.com; www.secure-paypal.com; or in the case of Iranian attack http://com-paypal-verification.com
Labels:
credential harvesting,
cyber crime,
cyber criminal,
fake website,
iran,
Iranian,
keylogger,
malware,
PayPal,
phishing,
spam,
spoof website,
spyware
Thursday, April 24, 2014
Iran Calls for Broader International Cooperation in Campaign Against Cyber Crimes
Head of Iran Cyber Police (FATA) General Seyed Kamal Hadianfar asked for collective efforts by all world states to prevent the spread of cyber crimes throughout the globe.
General
Hadianfar said in meeting with the representative of the UN Office on
Drugs and Crime (UNODC) to Tehran Leik Boonwaat on Wednesday:
"effective international cooperation is an important and
determining factor in prosecuting and confronting cyber crimes."
Boonwaat
for his part, vowed that the UNODC will seriously pursue campaign
against cyber crimes in Iran.
Iran
hosted a conference and a regional workshop on international
cooperation and campaign against cyber crimes on August 13-14.
Eight
regional countries, representatives of Interpol, UNODC and Iran Cyber
Police chief took part in the conference
The
conference and the workshop were held to strengthen international
cooperation on prosecuting cyber crimes and reinforce cyber space
police forces of the neighboring countries.
In
October 2013 Iran's Deputy Police Chief Brigadier General Ahmad Reza
Radan said that the country's Cyber Police unit has greatly improved
its infrastructures and is able to discover and detect over 60% of
cyber related crimes.
Radan
said: "Right now, the Iranian Law Enforcement Police have made
eye-catching progress in the field of cyber infrastructures".
On
January 23, 2011 Iran Cyber Police started its work to prevent
espionage and sabotage activities through the internet.
Labels:
cyber,
cyber crime,
FATA,
Interpol,
iran,
iran cyber police,
UNODC
Subscribe to:
Posts (Atom)
-
Since my last post in October, there has been no confirmation of which group was behind the cyber-attack on Westminster, or the role of the ...
-
It's back! It appears that the Shamoon malware aka "Shamoon 2" is targeting Saudi computers. Back in 2012, malware known a...
-
Are Iranian hackers involved in using the " Mamba " ransomware (or possibly be behind the ransomware)? It seems unclear but an...
-
Reuters has reported that Binance the worlds largest cryptocurrency market is helping Iran avoid US sanctions because of very weak identity ...
-
Mohammad-Ali Movahedi Kermani: not liking the Internet In the latest desperate attempt to subvert the freedom of Iranian expression, the...
-
Emen Net Pasargad Iranian Hacker Group The FBI recently announced that Emen net Pasargad an Iranian hacker group that successfully posed as...
-
Censorship comes in many forms and most recently that includes at the barrel of a gun. I speak of course of the murder in Istanbul of Mas...
-
Cisco Talos reports that the Iranian-backed hacking group MuddyWater AKA MERCURY AKA Static Kitten has been caught on another hacking campai...




