Showing posts with label defacement. Show all posts
Showing posts with label defacement. Show all posts
Monday, August 10, 2015
Iranian Dark Coders Hacking Team: Everywhere and Anywhere but not Harmless
A presentation at American security conference BlackHat USA in Las Vegas, has said that Iran appears to be actively seeking for critical national infrastructure systems connected to the Internet to exploit them.
At BlackHat USA Trend Micro researchers Kyle Wilhoit and Stephen Hilt revealed how their honeypot version of a Vedeer-Root Guardian AST gas gauge monitoring system (nickname «Gaspot») apparently fooled some Iranian hackers.
The Iranian hacking group Iranian Dark Coders, so called IDC-Team, modified the names of two pumps situated in Jordan. The IDC-Team which is best known for defacements and malware distribution, renamed two different tank names in the systems, one as «H4CK3D by IDC-TEAM» and other as «AHAAD Was Here».
IDC-Team
This is not a new thing. As a Google search will show IDC-Team has been hacking websites for a long time. According to their Facebook page the team started in 2012 and have grown since then in to a team with many members on its forum talking about hacks and bugs and computer security.
Over the last year IDC-Team have submitted more than 950 website defacements of targets all over the world. Many of these defacements are government sites (gov.pl, gov.co, gov.in) or companies with famous products (Jeep). This shows that the team have hacking skills that are enough advanced to damage to secure websites.
Why do they hack?
Despite the amount of hacks by IDC-Team and who they hack it is clear their agenda is little more than publicity. Their defacements are advertisements for their community and the individuals involved and they are not messages of hate and violence.
IDC-Team is everywhere and goes anywhere as Trend Micro revealed. However they appear to be looking for recognition as computer security experts and not hacktivists.
Labels:
Blackhat USA,
defacement,
Gaspot,
hacktivists,
honeypot,
IDCT,
iran,
Iranian Dark Coders Team,
Jeep,
Jordan,
malware,
security experts,
Trend Micro
Sunday, November 23, 2014
Iran Cyber Attack Feared Soon
Fears
are growing that Iran will release cyber warfare on US companies if
negotiators fail to reach a nuclear deal by Monday that would require
Iran limits its nuclear program.
Cyber-attacks
from Tehran dropped after the US, Iran and other countries agreed an
interim nuclear deal in 2013, but if discussions in Vienna failed
before a November. 24 deadline, observers expect a new series of
attacks.
American
financial companies, oil and gas companies and water filtration
systems could be among the targeted companies.
The
US has not yet faced the full force of Iran’s rapidly developing
cyber capabilities. Iran initially increased its cyber efforts in
2010 and launched a barrage of simplistic attacks on the US financial
sector in 2012. Detecting such relatively harmless attacks was easy.
Over
the last two years, Iran has formed a Supreme Council of Cyberspace
that meets once a month and includes President Hassan Rouhani.
Iranian
officials also strengthened cybersecurity research partnerships with
Russia and Iran has gone from a nascent to a burgeoning cyber power.
Security
company FireEye described that one popular Iranian hacking group went
from website defacements in 2010 to “malware-based espionage” in
just four years.
It
is reported that Iranian hackers attacked oil giant Saudi Aramco, the
world’s most valuable company, and deleted the contents of 30,000
computers. The same virus also hit Qatar-based liquid petroleum gas
firm RasGas.
While
the US is bombarded with cyber attacks, it has never been the subject
of a large-scale destructive attack. So far Tehran’s hackers are
mostly suspected of probing around US infrastructure networks to
understand their designs.
But
if the nuclear talks fell apart that could change. And this time an
Iranian attack could be more advanced.
Labels:
cyber warfare,
cyber-attack,
defacement,
FireEye,
hackers,
Hassan Rouhani,
infrastructure,
iran,
malware,
nuclear,
Qatar,
RasGas,
Saudi Aramco,
Supreme Council of Cyberspace,
Tehran,
Vienna
Thursday, May 15, 2014
Operation Saffron Rose
Ajax
Security Team
which has been targeting both US defense companies as well as those
in Iran is using popular anti-censorship tools to bypass internet
censorship controls in the country.
This
group which has its roots in popular Iranian hacker forums such as
Ashiyane
and Shabgard,
has engaged in website defacements since 2010. However by 2014 this
group is transitioned to malware-based espionage with use of
methodology consistent with other advanced persistent threats in this
region.
It
is unclear if the Ajax Security Team operates in isolation or is part
of a larger coordinated effort. We observed this group uses varied
social engineering tactics to lure targets to infect themselves with
malware. They use malware tools that do not appear to be publicly
available. Although we did not see the use of to infect victims,
members of the Ajax Security Team previously used exploit code in web
site defacement operations.
The
objectives of this group are consistent with Iran’s efforts to
control political dissent and expand offensive cyber capabilities but
we believe that members of the group may also be involved in
traditional cybercrime. This indicates that there is a considerable
gray area between the cyber espionage capabilities of Iran hacker
groups and any direct Iranian government or military involvement.
Although
the Ajax Security Team’s capabilities remain unclear, we believe
that their current operations are somewhat successful. We assess that
if these actors continued the current pace of their operations they
will improve their capabilities in the mid-term.
Labels:
Ajax Security Team,
anti-censorship,
Ashiyane,
cybercrime,
defacement,
hacker,
iran,
malware,
Shabgard,
social engineering,
US
Subscribe to:
Posts (Atom)
-
Since my last post in October, there has been no confirmation of which group was behind the cyber-attack on Westminster, or the role of the ...
-
It's back! It appears that the Shamoon malware aka "Shamoon 2" is targeting Saudi computers. Back in 2012, malware known a...
-
Are Iranian hackers involved in using the " Mamba " ransomware (or possibly be behind the ransomware)? It seems unclear but an...
-
Reuters has reported that Binance the worlds largest cryptocurrency market is helping Iran avoid US sanctions because of very weak identity ...
-
Mohammad-Ali Movahedi Kermani: not liking the Internet In the latest desperate attempt to subvert the freedom of Iranian expression, the...
-
Emen Net Pasargad Iranian Hacker Group The FBI recently announced that Emen net Pasargad an Iranian hacker group that successfully posed as...
-
Censorship comes in many forms and most recently that includes at the barrel of a gun. I speak of course of the murder in Istanbul of Mas...
-
Cisco Talos reports that the Iranian-backed hacking group MuddyWater AKA MERCURY AKA Static Kitten has been caught on another hacking campai...



