Showing posts with label hackers. Show all posts
Showing posts with label hackers. Show all posts

Friday, March 16, 2018

Are large scale human casualties inevitable in state sponsored cyber war?



The attack on the Saudi Petrochemical Company in August represents a terrifying escalation in cyber wars. The machinery was the primary target, but human casualties would have been almost certain. Whether human death was the intention or just an accepted consequence is not known, but doesn't really matter - the attackers would have been aware that large scale casualties were likely and still went ahead with the attack.

Worryingly, the complexity of the malware indicates a level of resourcing that suggests the attacks were state sponsored. Although the culprit has not yet been confirmed by investigators, the open hostility between Iran and Saudi Arabia and the step change in the intensity of hostile cyber activity, make the Iranians an obvious candidate.

The malware (which has been named Trisis) compromised machinery that is common in other nuclear and oil companies throughout the world - this demonstrates the potentially global destruction that can be rapidly released by a single well planned cyber attack.

Where do we go from here? For now we can be thankful that the attacked failed and was detected. But if the bug that caused the malware to fail has been fixed, are all industrial systems sitting on a ticking time bomb with human casualties inevitable collateral damage? Attribution will be difficult, but if a government such as Iran are behind these attacks, then their consideration towards human life is very worrying. These are scary times.






Tuesday, January 9, 2018

Mesri remains silent; where next for exposed Iranian hackers?

Just over a month ago, the US announced the indictment of Behzad Mesri (Skote Vahshat) who has been indicted by the FBI for computer fraud, extortion, and identity theft. 


Image result for mesri iran hbo

It seems that Mesri is a member of Turk Black Hat Iranian hacking group, which is responsible for defacing hundreds of websites, and most famously, the hacking of HBO's computer servers. As expected, we have heard nothing from Mesri himself.

Silence, in such cases, means that the accused is unable to justify their actions; was he doing it for someone else? Was it for money or ideology? The fate of exposed hackers in Iran is unlikely to be good. 

As noted in the US indictment, Mesri will be unable to travel abroad and presumably for this reason, there will not be so many opportunities for employment in the future. Whether staying silent is Meri's own decision, or whether he was obeying orders form higher up the command chain, is not known. Although the cybersecurity consulting and intelligence company Clearsky have recently reported evidence linking Mesri to the Iranian hacking group Charming Kitten, it is still unclear if this group and other Iranian hacking groups are working for the Iranian government.

Tuesday, December 19, 2017

The web is no safe house when it comes to protesting about violation of human rights in Iran:

Last month the UN General Assembly once again condemned Iran for its continuing and systematic violations of human rights. Sunday 10 December was United Nations Day of Human Rights and was marked by protests such as those involving Iranians who live in Paris, which highlighted the terrible human rights record of the Islamic Regime.




The regime of the clerics is swift to identify and crush any such activities within Iran, but this anti-human rights sentiment appears now to have spread to the web; the Clearsky report indicates human right activities have been specifically isolated and targeted by the Charming Kitten hackers. Are the hackers acting upon direct orders from the regime or are they acting for themselves because they support the regime's views on human rights?

Sunday, October 15, 2017

UK Parliament Hacked By Iran



The United Kingdom (UK) Parliament appears to have been hacked by Iran. The cyber-attack on 23 June 2017 was a brute-force attack against 9000 email accounts including the UK Prime Minister Theresa May and in total between 30 to 90 members of Parliament.

The UK Times newspaper which broke the story, said that it was Iran’s first significant act of cyber-warfare on the UK and underlines its emergence as one of the world’s biggest cyber powers and that Iran is highly capable of such attacks.

The decision to publish the information now is interesting, coming after the US President Donald Trump's intent to withdraw from the JCPOA (Joint Comprehensive Plan of Action) against Iran, which could threaten to re-instate sanctions against Iran. The UK, France and Germany do not agree with the USA on the matter. Without complete agreement, perhaps Iran will not suffer from any new sanctions against it, as it appears that Iran has not violated any of the sanctions.


Iranian regime attack or amateur hackers?

The attack, which was suspected of being originally from Russia, may have been carried out by amateur hackers. At the time of the attack in June, it was said that the attackers could only break into the email accounts of members of Parliament (MPs) which had simple, easy to hack passwords. As a security response at the time, MPs were unable to access their accounts and had to communicate using SMS texts instead. It now seems, however, that the regime may perhaps have after all been behind the attack?

Reasons for the attack

The reasons for the attack are unknown (or at least the British Intelligence services are not saying), but could be:
  • Exploratory activities: Iran may have been looking for UK data that Iran could then force the UK to make concessions with, or that could compromise the interests of the UK
  • Iran may have been looking for a trade advantage
  • More worryingly is the possibility that the IRGC (Iranian Revolutionary Guards Corps) may be seeking to undermine Iran's anti-nuclear proliferation deal in order to get it scrapped; Iran could then restart its nuclear weapons research.
The IRGC are at odds with President Hassan Rouhani, who they see as being too pro-West and the religious leader of the regime, Ayatollah Khamenei is linked with the IRGC, so there is an ongoing rift between the religious and political leadership of Iran, partly due to Rouhani slashing the IRGC's budget to restrict their economic activities.



An uncertain future

In my previous article, it is possible that Iran may seek to increase cyber-attacks against the USA if the US walked away from the JCPOA. Now that President Trump appears to be doing that, even if Germany, UK and France don't agree, we may see an increase in the cyber war from Iran against the West.

Monday, June 20, 2016

Iranian Hackers Attack Iranian Government Portals & Banks



The IRGC Organized Cyber Crime Investigation Center have reported that over 3,000 Iranian websites have been hacked by a group called the Mafia Hacking Team.

According to Tasnim news, IRGC Organized Cyber Crime Investigation Center spokesman Mostafa Alizadeh stated that, "The person who recently hacked state bodies' websites managed to access banks' data bases, including 3,000 pay slips... the person who introduced themselves as 'Mafia Hacking Team' in cyberspace and hacked websites of state bodies had identified well-known sites more than a year ago"



Alizadeh also added that, "This hacker tried to make these bodies realize that the security hole that exists in their portals but they did not pay any attention to this". In other words, Iran has been caught with her cyber-underwear exposed and is very red faced!

Mostafa Alizadeh stated that the attacker had also hacked various bank information, but did not publish the information (including 3,000 payslips) as the attacker "did not have criminal intentions", according to Alizadeh.
So it seems that Mafia Hacking Team are not black hat hackers but perhaps gray hat hackers?

The IRGC said that of the 3,000 websites attacked, 38 were Government sites, including the National Organization for Civil Registration (reported by the Iranian Young Journalists Club), Roads and Urban Development, Customs, Industries and Mines organizations. In addition, 370 University sites were also attacked.

Alizadeh was at least honest enough to admit that those "organizations do not use firewalls and lack enough experts for updating their security means". Not the best cyber security policy perhaps...

Thursday, June 16, 2016

Iranian Hackers Find Security Bug in Telegram



The Iranian Young Journalists Club (YJC) report that the popular messaging application Telegram has a security hole which has been exposed by Iranian white-hat hackers (ethical hackers). The vulnerability could cause smartphones to crash.

Telegram's security claims challenge anyone to try and undermine its security. Two Iranian hackers have discovered a security hole in Telegram, in which it is possible to send files much larger that the existing permitted limit (set at 4,096 bytes).

The Iranian hackers uploaded a video to prove their exploit. In the video, they say that there are two responses from a recipient's phone when Telegram messages larger than 4,096 bytes are sent. Firstly, the recipient's internet bandwidth is accordingly reduced in relation to the size of the message until it finishes and secondly, the receiving device runs out of memory and then the application crashes the smartphone.

The hackers stated that the sender does not need to be in your contacts so you may never know the true attacker if they are using an additional SIM card, for example.

Telegram is very popular with over 25 million users in Iran and its popularity is mainly due to many rival applications being subject to Iran's filtering restrictions.
Also, Iranians like Telegram because of the ability to create private or public "channels" and broadcast ideas through those.

However, can you really trust the encryption that Telegram uses, compared to applications like WhatsApp which use Signal standard end-to-end encryption? This article shows that maybe Iranians should think twice about using Telegram...

Friday, January 15, 2016

The Top Iranian Lammers, I mean, Hackers?



This is interesting. According to this website the best Iranian hackers are as follows. Do you agree? Vote now!
Looking at the comments on the site and what I know you can conclude the following:

* Most are lammers
* They can do defacements...but that is all
* Many are kids
* Some are even girls!
* Some are not even Iranian!

Is this the best that Iran can produce at the moment? If so, then #fail


However:

* YoSeF HaCkeR is well respected
* Black_N3T is from the Shishe Digital Security Team
* Behrouz Kamalian founded Ashiyane Digital Security Team
* wild.soldier is well respected
* MilaD Ramus owns the SaeQeH Security Team
* Ali Morshedloo is member of Iran Security Team
* Mr.PERSIA is owner of Emperor team
* Mr. Rahgozar is member of irsec team
* MR.F@RDIN owns Emperor Security Team
* Action Spider and Ashiyane were behind a hack against NASA in 2012
* Offensive is owner of Attacker Security Team
* Explo!ter is owner of the Emperor team
* amin3enator is a member of Iran-cyber team
* K!nG_4l!R3Z4 is a member of Pars team
* Crash (of Ashiyane) is meant to be a master of social engineering
* T3rY4K (Pars team)

The list:


1) YoSeF HaCkeR
2) Shadmehr
3) Mosi Pro
4) Ali Morshedloo
5) Kamran Nemati Harikandei (Kamranpcs)
6) Saeed0511
7) Black_N3T
8) Behrouz Kamalian
9) MR.khashi
10) Alireza Khodatalab
11) Black Ice (Ali Abasi)
12) Shahrooz
13) Negar Bayat
14) wild.soldier
15) Mr-SaSHa
16) Sourena
17) MilaD Ramus
18) B14ckc0d3r
19) Mr.PERSIA
20) JJHACKER
21) Arsan
22) ϻoנι☇ѕтнєηɨc
23) Trend_X
24) Farzad Terojan
25) KaMraN Injector
26) F4RY4R_RED
27) Mr. Rahgozar
28) greendel
29) Majid NT
30) Rocket Boy (Sina)
31) moji_rider
32) Saeed210
33) Peyman Poya (Toy Boy)
34) Iliya Norton
35) A75s6M
36) Mohsen NJ
37) Mohammad_Reza007
38) MR.F@RDIN
39) [A]мɪя [Ӈ]օƨᴇιɴ
40) Mr. Hossein
41) MR.M@J!d
42) Mohsen Ds
43) SoltanBahman
44) Mr.GHARIB3H
45) Arash Cyber
46) kos nane
47) mr.karkas
48) Action Spider
49) BADBOY17
50) [M]sey-[N]ofozi
51) optimus-hacker
52) b-yakhi
53) MR-545H4
54) XTAM4
55) Ali Plus
56) Rooter
57) Offensive
58) MR.ART@N
59) Masoud Invisible
60) Hidden Dagger
61) Explo!ter
62) Cair3x
63) NAVIDLIV
64) Dr.3vil
65) Mr. Saeed Mafiya
66) D3s!6n37
67) Pouya Eblis
68) H4M3D F.B.I
69) R.IG
70) Benyamin Payande
71) Amirkalantar
72) Sheytan Azzam
73) mr.vahshat
74) samara
75) Ali Attacker
76) sik
77) kir
78) W@0.5wE
79) Hacker Kord
80) Hacker Kord (again)
81) hamedhacker
82) CraZyl3oy
83) Hacker maro
84) M4hdi
85) Javadnadna
86) Devilmohammad
87) KSSM
88) bl4ck_rem0v3r
89) h4m1d
90) Mohammad-nofozi
91) BaBaK.Blackhat
92) S.R.B
93) amin3enator
94) Pi.hack
95) aghdas
96) Smartx
97) Keivan 98
98) Elenor
99) Mr.khofashe.siyah
100) SH4Y4N
101) 4L1R3Z4
102) sina_lizard
103) Mr.V!rus
104) Omid Generall
105) amin78
106) B.T
107) Majid Kurd
108) Hacker111
109) SHA13AH
110) Mr.GraY HaT
111) Amirosein
112) Reza-Atoom
113) MrVICI
114) se7en boy
115) Dr. Virangar (Sayyed Mohammad Ali Hosseini)
116) Black Storm
117) Kiram Dahan Sina Lizard
118) XX-Alibala-XX
119) JOK3R
120) K!nG_4l!R3Z4
121) Ho3!en-Mojazat
122) Crash from Ashiyane
123) Hossein Asgari
124) Soltegar
125) ZartoshT
126) T3rY4K
127) Coloner
128) Modiret
129) Amir00Army
130) Mr. 3im
131) Pershian-Joker
132) Shiva Shadow
133) Sarina Wolf
134) xSecurity
135) Mr. Defacer
136) H0553|N7
137) pasha_jabaar
138) mr.zero0
139) siyahi
140) mr.moien
141) bl4ck_v!per
142) ali-demon
143) ALI D.NAP

Wednesday, December 23, 2015

Iranian Hackers Hacked New York Dam in 2013



Iranian hackers attached the security of a dam outside of New York in 2013.
The hack of Bowman Avenue Dam near Rye Brook, New York, was not a sophisticated intrusion, but a test by Iranian hackers to see what they could access. The hackers got into the system through a cellular modem. The breach occurred during the same time that Iranian hackers were targeting US financial institutions.

The attackers were unable to get into the full dam system but could take control of the flood gates. Hackers can easily get into pieces of old critical infrastructure running on retro-fitted software that is connected to the Internet. More than 57000 industrial control systems (ICS) — more than any other country — that are largely unprotected on the Internet.


 
According to researchers at Shodan, a search engine that catalogs each machine online, the systems range from office air-conditioning units to major pipelines and electrical-control systems. Most of the critical infrastructure in the U.S. is privately owned, making it difficult for governments to harden the systems against attack.






Wednesday, November 25, 2015

Iranian Hackers Attack State Dept. via Social Media Accounts


Iran launched sophisticated computer espionages leading to a series of cyberattacks against US State Department officials over the past month.

It is possible that cyberespionage is becoming the tool of seeking the type of influence that Iranian hardliners hoped that that country's nuclear program will eventually provide.

According to diplomatic and law enforcement officials who are familiar with the investigation Iranian hackers over the past month identified individual State Department officials who focus on Iran and the Middle East and broke into their email and social media accounts. The State Department became aware of the compromises when Facebook told the victims that the state-sponsored hackers compromised their accounts.

Iran’s cyberskills are not yet equal to those of Russia or China but the attack against the State Department by using the social media accounts of young government employees to gain access to their friends across the administration is a focus that was not seen before.

Iranians have been less destructive than they could be, but they are getting far more aggressive in cyberespionage, which they know is less likely it will prompt a response from the United States.

Iranian hackers have been responsible for a series of powerful attacks against American banks that took their websites offline as well as a destructive attack on Saudi Aramco, the world’s largest oil producer, that replaced data on employee machines with an image of a burning American flag. American government officials also blame Iran for a similarly destructive attack at RasGas, the Qatari natural gas giant,and for an attack on Sands Casino in Las Vegas, where a large number of computers were destroyed.

Last year Iranians began using cyberattacks for espionage rather than for destruction and disruption. From May 2014 Iranian hackers were targeting Iranian dissidents and later policy makers,senior military personnel and defense contractors in the United States, England and Israel.

The attacks were basic “spear phishing” attempts, in which attackers tried to lure their victims to click on a malicious link, in this case by impersonating members of the news media.
Iranian hackers were successful in more than a quarter of their attempts. The number of such attacks reached its climax in May just ahead of the nuclear talks in Vienna in July and reached more than 1,500 attempts.

In the months before the talks, Iran’s hackers began probing critical infrastructure networks in what appeared reconnaissance for cyberattacks with the objective of causing physical damage but in June and July as American and Iranian negotiators gathered in Vienna to agree a deal on Iran’s nuclear program, attacks against targets in the United States stopped. Instead of this, Iran started targeting victims in Israel as well as members of Daesh in July as the militant group began expanding territory across Iraq.

Then in August just two weeks after the nuclear accord was reached, the trickle of cyberattacks against the group’s usual targets resumed against included 1600 individuals from scholars, scientists, chief executives and ministry officials to education institutes, journalists and human rights activists. If facebook last month had not decided to use a new alert system to notify users when facebook's security team believed state-sponsored hackers had hijacked their accounts, and US State Department officials began to see a troubling new message pop up on their facebook accounts, it is possible that the victims didn't learn of the compromises.

Monday, October 19, 2015

Iran’s Cyber Police Crackdown on Iranian Hackers




Iranian press has reported that the country's cyber police arrested 70 hackers.

According to Iranian Students News Agency (ISNA), the deputy commander of cyber police for legal and international affairs Colonel Hoseyn Ramezani, said that the cyber police carried out an operation from 10 August to 8 September 2015 to identify hackers and individuals who manage websites which provide hacking training and software.



Colonel Ramezani added that cyber police monitored more than 15000 websites and identified 104 violations. Additionally more than 70 hackers were identified and referred to the Judiciary.

It is possible that the cyber police exaggerates claims in an effort to use such propaganda to frighten the Iranian hacking community but time will tell.


Original ISNA Source

Thursday, May 14, 2015

Iran’s Cyberarmy: Is “Norse Company” as good as they think they are?



A report has been recently issued regarding Iran’s possible plans to carry out cyber attacks in USA. This report is really surprising not only because of the shocking claims but also the identity of the reporters. A Silicon Valley cyber security Company and a Washington think tank which has been one of the strong oppositions of the nuclear deal with Iran had issued this report. The report warns that if US removed the sanctions against Iran, the Iranian government will use the money to strengthen its Cyber warfare program.

However, it is interesting to know that before publication of the report, the Silicon Valley cyber security company has been sharing his information about Iran’s cyber warfare with US intelligence organisations. According to some US government officials, the information provided by the security company received negative reactions from the US officials that were trying to reach nuclear deal with Iran.



Based on this report, which was written by the cyber security company Norse in January of this year, Norse company claimed that it had data on “more than 500,000 attacks on Industrial Control systems over the last 24 months” referring to the computers that help to run electricity generation companies, hydroelectric facilities, and other critical infrastructure in the U.S.

Norse’s claim of half a million “attacks” is a very large number and they haven’t explained or shown any evidence in the document to prove their claim. They have just mentioned that more details are forthcoming in a report that the company will publish “later this year.” The bulletin also claims that Iran is targeting computer systems and Web sites inside the United States.

It seems that Norse company’s conclusions were based on the idea that Iran was behind malicious cyber activity just because the traffic was emanating from particular Internet protocol addresses located in Iran. But hackers routinely use IP addresses outside their own country to hide their true location.
Iranian cyber attacks against U.S. are not new: the cyber attack on the Sands casino company destroyed some of the company’s information assets and Iran was behind an attack on U.S. bank websites in 2012. However, the Norse document was making some of the most possible serious claims in cyber security accusing Iran as a country hostile to the U.S. targeting industrial control systems. 

 

Later, Norse appeared to remove its findings when its joint report was published in April and the claim of 500,000 attacks is nowhere to be found in that document. The findings also says that Iran specifically targeted Industrial Control Systems (ICS) in the United States 47 times during 2014. Yet again, the final report also doesn’t include that statement.
This report was intended to present a strategic view of Iran’s capabilities in cyberspace—which many U.S. officials have described as growing and dangerous and not to provide evidence for the U.S. to carry out some retaliatory action before any crime has taken place.
Kurt Stammberger, who is a senior deputy managing director at Norse, defended the report by saying that “briefing summaries [such as the bulletin] make theories that sometimes, at the end of the day, aren’t produced by the data”.

Norse’s critics say that it isn’t definitive enough to say that Iran was certainly trying to target industrial control systems. And it could make Iran look like more of a threat than it might actually be.

Even some of Norse’s critics have said that their ability to collect huge amounts of technical data is impressive and important. Although we don’t deny the company’s expertise but they are clearly not an expert on Iran.

Thursday, December 4, 2014

Operation Cleaver: Mass Hacking By Iranian State



Iranian hackers have been identified as the source of coordinated attacks against more than 50 targets in 16 countries, many of them corporate and government entities that manage critical energy, transportation and medical services.

According to Cylance, a security firm based in California in USA, over the course of two years Iranian hackers managed to steal confidential data from a long list of targets and in some cases infiltrated victims computer networks to such an extent that they could take over, manipulate or easily destroy data on those machines.

Cylance called the attacks “Operation Cleaver” because the word cleaver appeared often in the attackers malicious code.

The hackers used a set of tools that can spy and even shut down critical control systems and computer networks, and aimed them at targets in the United States, Canada, Israel, India, Qatar, Kuwait, Mexico, Pakistan, Saudi Arabia, Turkey, the United Arab Emirates, Germany, France, England, China and South Korea. 
 
Victims of the attacks include: US Marine Corps, a major airline, a medical university, an energy company that specializes in natural gas production, a car manufacturer, a major military installation and a large military contractor. The Islamic Republic also concentrated attacks on oil and gas industries and universities in the United States, India, Israel and South Korea and managed to steal pictures, passports and specific identifying information for students and faculty. 
 
Cylance said it also collected worrying evidence of attacks on transport networks, including airlines and airports in South Korea, Saudi Arabia and Pakistan. Researchers said they found evidence that hackers gained complete remote access to airport gates and security control systems, “potentially allowing them to spoof gate credentials.”


Tuesday, December 2, 2014

North Korea Prime Suspect in Hacking Attack Against Sony Pictures


According to the Wall Street Journal, hackers who took Sony Pictures Entertainment’s computer systems offline used tools which were very similar to those used last year in an attack on South Korean television stations and ATMs. The similarity reinforces a suspicion among some investigators, which include Sony, the FBI and a team from the security company FireEye Inc., that North Korea played a role in the breach. 
 
Sony Pictures is investigating if the North Korean regime was behind a massive hack attack on the studio computer network. Email was damaged and four movies were leaked.

The website Re/code reported that Sony and its security consultants are exploring the possibility that hackers based in China targeted studio computers in retaliation for the upcoming release of the film  The Interview.  In this film, Seth Rogen and James Franco play journalists who arrange an interview with North Korean leader Kim Jong-Un, and the CIA then ask them to assassinate him.

On Friday a North Korean government website called "The Interview" an "evil act of provocation" that deserved "stern punishment." Reportedly North Korea has organized a team of approximately 3,000 hackers to promote the Kim regime.

Sunday, November 23, 2014

Iran Cyber Attack Feared Soon



Fears are growing that Iran will release cyber warfare on US companies if negotiators fail to reach a nuclear deal by Monday that would require Iran limits its nuclear program.
Cyber-attacks from Tehran dropped after the US, Iran and other countries agreed an interim nuclear deal in 2013, but if discussions in Vienna failed before a November. 24 deadline, observers expect a new series of attacks.

American financial companies, oil and gas companies and water filtration systems could be among the targeted companies. 
 
The US has not yet faced the full force of Iran’s rapidly developing cyber capabilities. Iran initially increased its cyber efforts in 2010 and launched a barrage of simplistic attacks on the US financial sector in 2012. Detecting such relatively harmless attacks was easy.  

Over the last two years, Iran has formed a Supreme Council of Cyberspace that meets once a month and includes President Hassan Rouhani.

Iranian officials also strengthened cybersecurity research partnerships with Russia and Iran has gone from a nascent to a burgeoning cyber power.

Security company FireEye described that one popular Iranian hacking group went from website defacements in 2010 to “malware-based espionage” in just four years.

It is reported that Iranian hackers attacked oil giant Saudi Aramco, the world’s most valuable company, and deleted the contents of 30,000 computers. The same virus also hit Qatar-based liquid petroleum gas firm RasGas.

While the US is bombarded with cyber attacks, it has never been the subject of a large-scale destructive attack. So far Tehran’s hackers are mostly suspected of probing around US infrastructure networks to understand their designs.

But if the nuclear talks fell apart that could change. And this time an Iranian attack could be more advanced.