Showing posts with label iran. Show all posts
Showing posts with label iran. Show all posts

Thursday, March 31, 2022

Australia PROMISE to retaliate to any cyber attack from Iran! 😲


Australia WILL RETALIATE to any cyber attack from Iran! 

Earlier this week it was reported that defense minister of Australia Peter Dutton stated that any cyber attack that originates from Iranian regime will be responded to by Australia "by an equal measure" 😮

Peter Dutton also says that officials in Australia are monitoring malicious cyber activity on a daily basis. And even though Australia has not been targeted for a month Peter Dutton is concerned that Australia could become collateral damage in a cyber war between other countries. He give example of instances were Microsoft is hacked like they were last week by Lapsus$. Hacks like this also will affect Australian government and innocent Australian people too. He also says that Australia would anticipate hacks from regimes like Iran ahead of time. 



Microsoft was hacked by Lapsus$ last week

Australia works very closely with the United States and the UK and have just opened up a new cyber security center in Australia capital of Canberra to monitor malicious cyber threats. 

Cyber war is changing especially with Russian invasion of Ukraine. And cyber attacks can cause so much damage such as loss of money or business collapse and at the worst injury or loss of life to people.😢

Iran has been publicly named by Australia since 2017 as a country that has launched malicious cyber activities against Australia and Australia will continue to publicly attribute Iran and expose attacks made by them to deter the threat. Iranian regime needs to change its ways!! 😤 

Friday, March 11, 2022

Increase of Iranian cyber attacks on India! Deployment of deadly ransomware in schools!

Local media in India report that cyber attacks from Iran are on the rise. Local media reports indicate that schools and banks as well as government departments such as the police force and defense agencies have been severely targeted. This new wave of cyber attacks has been reported mainly in Kerala and New Delhi as well as in areas such as Bihar and West Bengal.

The Ministry of Home Affairs in India has said that experts are being pressured to accept the requests as a result of the ransomware attack because they are afraid of data being put on  dark web if they do not pay. This type of attack is called Lock and Leak attacks and is very popular with cyber criminals in the Iranian regime.

This follows a public warning that Google issued in 2021 at the CharmingKitten AKA APT35, and I wrote a blog about it here. In that warning, Google said CharmingKitten was using phishing tools to collect data from innocent victims.


Google advisory of CharmingKitten in 2021 

India has always been accustomed to cyber threats from Pakistan and China, but now Iran has to intervene again illegally in another country! When will it stop ??? 😤😤

Saturday, March 5, 2022

Iranian hacking group MuddyWater runs new cyber attack campaign in shadows of Russia invasion of Ukraine

 


Khamenei Loves War and Terror! 

Russia Invasion of Ukraine have now entered a full scale cyber war 😢. Hacktivist group Anonymous have retaliated taking out several key communication tools of Russia but it has been reported by Hacker News and Several Other News outlets that Iran has now come to the aid of its ally Russia with State-backed Hacking group MuddyWater now increasing it's activity 😡

In a joint US and UK Release multiple security agencies has put out a warning on MuddyWater saying they are targeting government industries and small private business including those in critical infrastructure and healthcare! 



Manually Generated Telegram Beacon 


The MuddyWater Hacking group steals data like passwords and online accesses which is then passed to disgusting regime controlling Iran and its allies including Russia. They use tools such as manually generated Beacon to harvest data of Telegram like one above. 



 

        MuddyWater runs under Iran's Ministry of Intelligence (MOIS)

The US Cybersecurity and Infrastructure Security Agency (CISA) in there report said MuddyWater is under the control of the Iranian Ministry of Intelligence and Security agency otherwise known as MOIS. Iran is a staunch Russia ally and needs support of Russia  especially now its increasing its nuclear program with JCPOA talks stalling. 

Khamenei has not denounced the Russian military operation in Ukraine and has suggested the root cause of the war was the “mafia regime” of the US and the polices of Western powers.

CISA Report : https://www.cisa.gov/uscert/ncas/alerts/aa22-055a


End these evil dictatorships! We want Peace!#StandWithUkraine 



Wednesday, January 5, 2022

Iranian hackers Shia Eagle hack Jerusalem Post and Maariv Online on anniversary of Soleimani's death. ⚰️

On Monday it was revealed that the Israeli newspapers Jerusalem Post and Maariv Online had been hacked and hacked exactly two years since Soleimani's death. Both newspaper websites with defaced with a threatening image claiming revenge for Soleimani's death. This image shows the Dimona nuclear base in Israel being destroyed by a rocket fired from a hand very similar to Soleimani's.


        Image that was displayed on hacked websites after attack

No hacker group inside Iran has officially claimed responsibility for the attack, but a Twitter account called @shiaeagle posted several tweets at the time of the attack that strongly claimed responsibility. Twitter has since blocked the account.



                Shia Eagle twitter account which is now banned 

It is clear that in 2022 this cyber war between Israel and Iran has no sign of stopping.😢 This cyber attack could also be a statement by this corrupt Iranian regime that its nuclear program is being implemented at 100 percent and could be used as another negotiating tactic in the JCPOA Vienna talks. very sad!!!! 😭

Thursday, December 30, 2021

JCPOA Negotiations: How Iranian regime delegation in Vienna are leading world partners down a path of deceit and delay 🤬🤬🤬


JCPOA Vienna Talks (Image credit: Foreign Brief) 

Private talks in Vienna between Iran and Western powers aimed at reviving nuclear deal reached in 2015 have been going on for some time but there have been reports of numerous differences between the two sides. E3 diplomats say Iranian regime delegation unwilling to negotiate genuinely and as Iran's deceptive regime continues to stockpile uranium E3 diplomats warn that the nuclear deal will become a hollow shell in the not-too-distant future.

Iran's response to these allegations is as usual a deceptive and deviant response saying that diplomacy is a two-way street that goes so far as to accuse Western powers of playing the blame game. But the reality is very different as usual. Leaked notes from these talks indicate that the Iranian regime wants all sanctions to be lifted by the United States regardless of whether the sanctions were imposed because of  nuclear deal. 🤦‍♂️🤦‍♂️

It is clear that this delegation and by proxy this evil regime of mullahs have no interest in negotiating with the Western powers in this regard. They continue to delay and deceive their partners into thinking that an agreement can be reached while behind scenes they continue to stockpile uranium for nuclear weapons. this is so BAD! Western powers must be ready to withdraw from these negotiations and take further measures to eliminate this regime.

The innocent people of Iran suffer every day because they fail to act 😭😭

Wednesday, December 22, 2021

Charming Kitten AKA APT35 activity up rapidly in 2021: Google Issue public warning

 



It has been reported that the servant group of this corrupt Iranian regime called the Charming Kitten also known as APT35 has steadily increased its cyber attacks this year and increased the complexity of its cyber attacks. Google has now issued a public warning against the group.

Charming Kitten became famous in 2020 for phishing the accounts of US White House staff in the run-up to the 2020 US presidential election and they continued their evil ways in 2021. They Withdraw credentials from a British university called SOAS using a phishing kit and deploying a piece of spyware in mobile app stores that pretend to be VPNs. They also used telegram sendMessage API to find out the IP addresses and whereabouts of victims who clicked on their phishing links, as well as pretending to be staff members at Think20 conventions in Munich and here at home in Italy sending malicious phishing links to innocent victims.

Google have issues public warning of State-Sponsored cyber attacks 

It is worrying trend that Google feels that the threat posed by Charming Kitten is strong enough to issue a public announcement because they feel that the complexity of attacks from this horrific group is increasing. When will this corrupt regime stop trying to turn the lives of others into hell ??? 😡😡



Wednesday, November 24, 2021

Mahan Air Cyberattack - Exposing dirty secrets of IRGC QF and Further Technical Analysis

Hello friends 🙏 As I promised I continued my research on Mahan Air cyber attack and collected technical analysis for all of you.

It turned out that the hacker group responsible for this cyberattack Hooshyarane Vatan had succeeded in accessing Mahan air systems due to the fact that all sensitive information was not encrypted. It was also revealed that Mahan Airs IT department had actually identified the hackers on the network and had not yet been able to remove them. How bad are the security measures in Mahan Air ???? 😳😳


Hacktivist group responsible for Mahan Air Hack - Hooshyarane Vatan

The first revelation that came out of this cyber attack was evidence that multiple passengers called MR Hamrah Hamrah had boarded flights more than 70000 times on Iranian flights to Syria !! All are booked using the same travel agency called Utab Gasht. Utab Gasht seems to be a legitimate company but it turned out that they regularly transfer funds to a company called Hamrah or Hamrah SYR. Hamrah Company was rarely mentioned by Mahan Air employees, but a number of employees accidently leaked this information and wrote letters to the esteemed CEO of the company Mr. Golparast. Mr. Golparast is an exposed officer of the IRGC and the owner of Qeshm Fars Company which is a front for IRGC!! Mahan air is making dirty deals with IRGC officers !! Incredible! 🤯🤯



Leaked Letter 

Further analysis of this cyber attack also reveals numerous receipts for charter flights fully booked by the Hamrah company along with hundreds of illegal passengers traveling between Tehran, Damascus and Beruit. This evidence as well as further evidence indicating that passenger load exceeds limits over hundreds of kilograms shows that Mahan Air is actively facilitating the IRGCs QF activities and arms deals in Syria and Hezbollah in Lebanon. There is also a big difference with passengers who board flights and who are registered in the flight system. More than 400 passengers are lost every month under this name. Who knows what other dangerous personnel and cargo the Islamic Revolutionary Guard Corps carries on these flights alongside innocent civilians on flights? Absolutely embarrassing!! 😡



Leaked Invoice for hidden chartered flights 

It was also revealed that all these flights are booked with only 15 phone numbers and also certain people with special privilege are mentioned to board Mahan Air flights. Most likely these are QF IRGC officials. These are listed below:



Phone Numbers and Names used for IRGC QF flight bookings at Mahan Air 


After the technical analysis of this cyber attack it is revealed that Mahan Air has sold its soul to the IRGC and QF. How can Mahan Air do this to the Iranian people? A catastrophe could easily have happened when all these covert and evil deals and trips were completed. The Hamrah company are accompanying Utab Gasht and Qeshm Fars as front companies of the IRGC and its sinister motives and Mahan Air is in bed with them. disgusting! Friends, please do not travel with this airline anymore 🙏🙏

Wednesday, November 17, 2021

Lyceum is back! Targeting ISPs and other strategic targets 😡

Reports this week indicate that the notorious Iranian hacker group Lyceum has returned to chaos and this time mainly attacking Internet service providers and telecom companies in Morocco, Saudi Arabia, Israel and other companies in the wider Middle East including the African Ministry of foreign Affairs

The Lyceum group which was first discovered in 2017 and also known as Hexene has been identified as responsible for a number of cyberattacks in July and October 2021 according to information from Accenture Cyber ​​Threat (ACTI) and Prevailion's Adversarial counterintelligence groups (PACT). The main focus of the Lyceum Group is the implementation of computer network penetration events on a number of strategic target that are appropriate for the Iranian regime. It also now appears that they are expanding their reach to other targets even including places that are friendly to the Iran such as Tunisia.

                        Lyceum: Puppets of Regime!   

The hacker group appears to have stop used its famous Danbot .NET scripts and Powershell scripts to gain unauthorized access to the systems, and is now using a number of new technical techniques to do its evil work. Like the Base64-encoded Powershell scripts and new backdoors written in C++ which are new types of malware called James and Kevin. The group also relies on DNS tunneling which is an intrusion method for using DNS as a secret communication channel which is allowing the group to execute HTTP (S) commands using malicious C2 functionality. More scrutiny of source code also shows that Lyceum is also upgrading its backdoors to stay ahead of defense systems.

Lyceum is evil and guilty perpetrators of Iranian regime and seems to have continue committing ugly acts against other countries in the region regardless of whether they are friends or not. Please friends protect yourself against these types of attacks 🙏 by monitoring DNS traffic and being aware of suspicious domains and report them to threat information platforms.


Will this regime ever stop committing ugly acts in the region?? 😡😡


#cybercrime #cybersecurity #cybercrime #NET #Powershell #cyber #attack #C++ #HTTP #HTTPS #Morocco #SaudiArabia #Tunisa #Israel #Iran #IranianRegime #corrupt #evil   

Friday, November 27, 2020

Corona Censorship



It is well known that Iran has not been truthful about Corona. The Iranian government has lied to the world about the deaths of Iranian people. The Iranian state say that 40,000 Iranian have perished but other sources say that this is actually 150,000. This is more than Italy! Why does the government try to cover this up?

This is the latest example of the Iranian governments control and censorship over Iranian people. It also shows how far the Iranian state will go to protect itself from scrutiny. What has the government done to stop Corona. Why has it taken so long to begin lockdown. And is it too late?

It is more important than ever that Iranians have access to the Internet. Iranians are the only people who know what is really going on. Corona has come at a time where Iran continues to control internet access and service providers. Ever since the November 2019 protests Iranian government has stepped up its attempts to censor the Iranian people and hide them from the world.

Last year I blogged about how to avoid Iranian censorship by using Tor to overcome government barriers. This is now more relevant and necessary because of Corona. Maybe in ten years we will know the truth about Corona. Until then the people must continue to document the truth.

Wednesday, September 5, 2018

Can you spot fake accounts? Iran continues to spread disinformation through fake news agencies and social media


Back in January I blogged about how Iran had followed the Chinese in the creation and use of fake social media accounts to further their political agenda. A report by FireEye shows that Iran continues to exploit social medial to promote its political interests and influence other unsuspecting users - fake news appears to be back on the agenda!

The report identifies 'Liberty Front Press' as a fake news agency created by the Iranians to further their political interests, along with a number of associated counterfeit social media accounts. The site promotes Senator Bernie Sanders whilst making anti-trump sentiments. Clearly the Iranians and Russians were not collaborating on this at least! It seems likely the Iranians were worried about Trump's negativity towards the JCPOA and thought Mr Sanders would be the safer option. That has not worked out so well for them.



Other fake news agencies and websites with an Iranian footprint include the 'Real Progressive Front', 'The British Left' and 'Instituto Manquehue'. All these sites go out of their way to state that they are 'completely' or 'genuinely independent', in an attempt to deceive the reader. All have similar political narratives; anti-Saudi, anti-Israeli, pro-Palestinian and pro-Iranian.

It appears the Social Media giants, like Facebook and Twitter, are finally trying to crack down on fake accounts. In the last week, it has emerged that YouTube has blocked 39 channels linked to the Iranian-state-run IRIB network and Facebook has announced the closing of 562 pages all linked to the Iranian regime.The regime, of course, denies all connection to the government.

Social media platforms have the difficult task of distinguishing fake from real accounts - but what identifies an account as suspicious? Whilst the algorithms used by the platforms are unknown, there are probably a number of contributing factors like low levels of original content (copying material from elsewhere), absence of personal photographs in profile pictures, accessing sites through a proxy, inflated number of followers or friends, and promotion of suspect websites. However, this is not easy and there will inevitably be collateral damage; I know a number of people who have had their real accounts shut down for unspecified 'suspicious' behavior. I am worried that banning customers that access platforms through a VPN will have a big impact on Iranian citizens trying to overcome the regime's access restrictions. I hope that in the future they can accurately separate real users who are drawing attention to important human rights issues, from the Iranian, Chinese or Russian (and probably a lot of other countries) actors who are abusing the right of free speech and circulating disinformation.


Wednesday, April 4, 2018

A cyber-attack on ideas: Mabna behind latest frightening global phising campaign that targets intellectual property, with allegations of state-sponsorship.

An indictment for nine Iranians was unsealed on March 23 2018. They each stand accused of a variety of crimes relating to cyber-attacks conducted on universities, government agencies, and private organisations around the globe. 31 terabytes of data was stolen - that is a lot of data! The nine suspects are all affiliated with Mabna, the group responsible for the HBO hacking (in which Game of Thrones episodes were leaked), which led to the indictment of Mesri for his involvement in the hacking and attempts to extort US$6 million. It has been revealed that the cyber-assault used customized phishing emails that were sent under the disguise of academics at other institutions. The emails contained links to academic papers that directed the victim to a malicious domain masquerading as a university web page, prompting the victim to give away his log-in details.

Among the victims were government agencies and private companies, but the primary target was universities, with around 8000 professors falling victims. So, unlike the targets identified in previous indictments, we now appear to be seeing a diversification of the type and location of the target. Furthermore, the attack was indiscriminate with regards to academic discipline. Whilst the economic value of the data should not be given disregarded (the indictment makes the cost of the stolen research to USE institutions as US$3.4 billion), the financial loss is only one implication. The concept of targeting innovation, ideas and information, acquired through years of research effort, is new and frightening. The attacks demonstrate the need for academic institutions, to improve their cyber-security, both in terms of the awareness and implementation. It is worrying that the attacks reached beyond the usual suspects of the US and Israel; universities in 22 different counties, including many in Europe, and also China, were victims. Among the non-academic targets was the Unite Nations Children's Fund, demonstrating the callous and indiscriminate way in which the Iranian cyber machine selects victims.

Whilst considered innocent until proven guilty in a court of law, presumably investigators must be pretty convinced of guilt to name these individuals in the indictment. These men will join those previously indicted by the FBI for cyber-criminals, in not being able to leave Iran without fear of arrest. This limitation of freedom will surely deter some of those considering a 'career' in hacking, and slow recruitment to the Iranian cyber-army.

Who is backing Mabna? The indictment reveals that spear-phising email attacks were then conducted on behalf of the Islamic Revolutionary Guard Corps (IRGC) of Iran. But were there other governmental bodies involved? This is a persistent question which resurfaces with each attack. Given their close association, it seems likely that there is some level of co-ordination between the IRGC and other government offices, like those within the Iranian Ministry of Foreign Affairs, when planning the cyber-attacks. Will this public condemnation deter Iran form undertaking further attacks on university, or will the stat simply distance themselves form cyber criminals?

Friday, March 16, 2018

Are large scale human casualties inevitable in state sponsored cyber war?



The attack on the Saudi Petrochemical Company in August represents a terrifying escalation in cyber wars. The machinery was the primary target, but human casualties would have been almost certain. Whether human death was the intention or just an accepted consequence is not known, but doesn't really matter - the attackers would have been aware that large scale casualties were likely and still went ahead with the attack.

Worryingly, the complexity of the malware indicates a level of resourcing that suggests the attacks were state sponsored. Although the culprit has not yet been confirmed by investigators, the open hostility between Iran and Saudi Arabia and the step change in the intensity of hostile cyber activity, make the Iranians an obvious candidate.

The malware (which has been named Trisis) compromised machinery that is common in other nuclear and oil companies throughout the world - this demonstrates the potentially global destruction that can be rapidly released by a single well planned cyber attack.

Where do we go from here? For now we can be thankful that the attacked failed and was detected. But if the bug that caused the malware to fail has been fixed, are all industrial systems sitting on a ticking time bomb with human casualties inevitable collateral damage? Attribution will be difficult, but if a government such as Iran are behind these attacks, then their consideration towards human life is very worrying. These are scary times.






Tuesday, January 9, 2018

Mesri remains silent; where next for exposed Iranian hackers?

Just over a month ago, the US announced the indictment of Behzad Mesri (Skote Vahshat) who has been indicted by the FBI for computer fraud, extortion, and identity theft. 


Image result for mesri iran hbo

It seems that Mesri is a member of Turk Black Hat Iranian hacking group, which is responsible for defacing hundreds of websites, and most famously, the hacking of HBO's computer servers. As expected, we have heard nothing from Mesri himself.

Silence, in such cases, means that the accused is unable to justify their actions; was he doing it for someone else? Was it for money or ideology? The fate of exposed hackers in Iran is unlikely to be good. 

As noted in the US indictment, Mesri will be unable to travel abroad and presumably for this reason, there will not be so many opportunities for employment in the future. Whether staying silent is Meri's own decision, or whether he was obeying orders form higher up the command chain, is not known. Although the cybersecurity consulting and intelligence company Clearsky have recently reported evidence linking Mesri to the Iranian hacking group Charming Kitten, it is still unclear if this group and other Iranian hacking groups are working for the Iranian government.

Tuesday, January 2, 2018

Iranian hackers join Chinese in the use of fake social media profiles:

In December, reports were published that the German intelligence services have uncovered use of fake social media profiles by Chinese intelligence. However, it is not just the Chinese that use this type of deception; Clearsky have reported that Iranian cyber criminals are doing the same

The report provides evidence demonstrating that the Iranian cyber group Charming Kitten have created LinkedIn company pages and profiles for a fake news-agency called 'British News', in an attempt to authenticate their British News website, which has been set up to infect targeted visitors. The hacking group also used false Facebook and Twitter profiles to 'verify' fake personas when emailing targets. These more innovative methods were being used alongside more 'well-known' techniques, such as spear phishing.


The LinkedIn sign-in page is displayed on an Apple iPad Air in an arranged photograph in Hong Kong, China, on Feb. 25, 2014.

Tuesday, December 19, 2017

The web is no safe house when it comes to protesting about violation of human rights in Iran:

Last month the UN General Assembly once again condemned Iran for its continuing and systematic violations of human rights. Sunday 10 December was United Nations Day of Human Rights and was marked by protests such as those involving Iranians who live in Paris, which highlighted the terrible human rights record of the Islamic Regime.




The regime of the clerics is swift to identify and crush any such activities within Iran, but this anti-human rights sentiment appears now to have spread to the web; the Clearsky report indicates human right activities have been specifically isolated and targeted by the Charming Kitten hackers. Are the hackers acting upon direct orders from the regime or are they acting for themselves because they support the regime's views on human rights?

Sunday, October 15, 2017

UK Parliament Hacked By Iran



The United Kingdom (UK) Parliament appears to have been hacked by Iran. The cyber-attack on 23 June 2017 was a brute-force attack against 9000 email accounts including the UK Prime Minister Theresa May and in total between 30 to 90 members of Parliament.

The UK Times newspaper which broke the story, said that it was Iran’s first significant act of cyber-warfare on the UK and underlines its emergence as one of the world’s biggest cyber powers and that Iran is highly capable of such attacks.

The decision to publish the information now is interesting, coming after the US President Donald Trump's intent to withdraw from the JCPOA (Joint Comprehensive Plan of Action) against Iran, which could threaten to re-instate sanctions against Iran. The UK, France and Germany do not agree with the USA on the matter. Without complete agreement, perhaps Iran will not suffer from any new sanctions against it, as it appears that Iran has not violated any of the sanctions.


Iranian regime attack or amateur hackers?

The attack, which was suspected of being originally from Russia, may have been carried out by amateur hackers. At the time of the attack in June, it was said that the attackers could only break into the email accounts of members of Parliament (MPs) which had simple, easy to hack passwords. As a security response at the time, MPs were unable to access their accounts and had to communicate using SMS texts instead. It now seems, however, that the regime may perhaps have after all been behind the attack?

Reasons for the attack

The reasons for the attack are unknown (or at least the British Intelligence services are not saying), but could be:
  • Exploratory activities: Iran may have been looking for UK data that Iran could then force the UK to make concessions with, or that could compromise the interests of the UK
  • Iran may have been looking for a trade advantage
  • More worryingly is the possibility that the IRGC (Iranian Revolutionary Guards Corps) may be seeking to undermine Iran's anti-nuclear proliferation deal in order to get it scrapped; Iran could then restart its nuclear weapons research.
The IRGC are at odds with President Hassan Rouhani, who they see as being too pro-West and the religious leader of the regime, Ayatollah Khamenei is linked with the IRGC, so there is an ongoing rift between the religious and political leadership of Iran, partly due to Rouhani slashing the IRGC's budget to restrict their economic activities.



An uncertain future

In my previous article, it is possible that Iran may seek to increase cyber-attacks against the USA if the US walked away from the JCPOA. Now that President Trump appears to be doing that, even if Germany, UK and France don't agree, we may see an increase in the cyber war from Iran against the West.

Monday, October 2, 2017

Iranian Hacking Threat to USA if Nuclear Deal Collapses



Since the signing of the nuclear deal between the USA and Iran in 2015 (the Joint Comprehensive Plan of Action (JCPOA)), Iranian cyber attacks against the USA have dropped off. 

The U.S. and six partners began discussions with Iran in 2013 to lift some economic sanctions to limit Iranian nuclear developments, and since then Iranian hackers have largely reduced attacks against the U.S., focusing instead on industrial espionage and hitting rival Middle Eastern countries. However, with the threat by the U.S. President Donald Trump to walk away from the deal, there are fears that Iran will re-start cyber-attacks against the USA.

The cyber-security research company FireEye have produced a report which has identified an Iranian-government group that FireEye have called APT33 (APT means Advanced Persistent Threat, indicating state-involvement). APT33 has previously attacked using spear-phishing techniques to target companies involved in the petrochemical industry and in military and commercial aviation. Could APT33 or similar be ready to attack the U.S. if Trump quits the JCPOA?

A Short History of Iranian Cyber-attacks

  • 2010: It was suspected that the U.S. and Israel attacked Iran with the Stuxnet malware, damaging Iranian nuclear control equipment at the Natanz uranium enrichment plant.
  • 2011/2013: In possible response to Stuxnet, Iran used DDoS (Distributed Denial of Service) Operation Ababil attacks against over 45 major financial institutions. Seven members of the Iranian ITSec Team were subsequently indicted by the FBI for over 176 days of DDoS attacks against the U.S. and also the attack against the Bowman Dam.
  • 2012: APT33 attack the Saudi Aramco oil company using the Shamoon malware, destroying thousands of computers in that company.
  • 2015: After JCPOA, large-scale Iranian attacks against the U.S. dropped off, although this may also have been due to Iran's concerns with Syria and Yemen. Also, APT33 continued espionage attacks against the U.S., South Korea and Saudi. In 2015, many Iranian hacking forums and use of hacker handles disappeared, probably because Iran realized that they were under greater scrutiny. 
  • 2016/2017: APT33 attacked Saudi and U.S. aerospace companies, along with attacks against a South Korean petrochemical company. In May 2017, APT33 attacked a Saudi organization and a South Korean company using malicious spear-phishing emails attempting to target victims with job vacancies for a Saudi petrochemical company.

The FireEye APT33 Report

FireEye state that APT33 used an Iranian developed web-shell developed by the hacker Solevisibile to craft the spear-phishing emails to targets. The webshell (called ALFASHELL, ALFA TEaM Shell v2-Fake Mail), has the default sender email address of solevisible@gmail.com. It is not known if Solevisible is linked with APT33 or not.

APT33 used domain masquerading as the following companies: Boeing, Alsalam Aircraft Company, Northrop Grumman Aviation Arabia, and Vinnell Arabia. APT33 used the domains to target victims with spear-phishing emails.

FireEye identified the hacker xman_1365_x as being the developer of a backdoor used in APT33 malware. It appears that xman_1365_x was also a manager in the Barnamenevis Iranian programming & software engineering forum, and registered accounts in the Iranian Shabgard and Ashiyane forums. The hacker xman_1365_x is also linked with the Nasr Institute, which is similar to Iran’s cyber army and controlled by the Iranian government. The Nasr Institute appears to be linked to the 2011-2013 DDoS attacks on the financial industry (Operation Ababil).

Further indications that Iran is behind APT33

  • A malware dropper (known as StoneDrill) used by APT33 has Farsi language artifacts in it.
  • APT33’s targeting of organizations involved in aerospace and energy is aligned with with nation-state interests (not those of cyber-criminal groups), implying that APT33 is probably government sponsored.
  • Iranian working hours; APT33 worked at the time zone close to 04:30 hours ahead of UTC, which heavily indicates Iran. APT33 largely operated on days that correspond to the Iranian working week (Saturday to Wednesday). Iran is one of few countries that subscribes to a Saturday to Wednesday working week.
  • APT33 used popular Iranian hacker tools and DNS servers used by other suspected Iranian hackers. The publicly available backdoors & tools utilized by APT33 (including NANOCORE, NETWIRE, and ALFA Shell) are available on Iranian hacking websites, associated with Iranian hackers, and used by other suspected Iranian threat groups.

Tuesday, August 15, 2017

IRGC and the Risks of Iranian Malware Development

IRGC

Recent articles have shown that the Iranian State has used computer malware Shamoon and linked malware StoneDrill and NewsBeef to damage others. Instead of glorifying Iran, the exposing of such activity by well-known companies like Kaspersky Lab, discussion on the Iranian Exploit Database (IEDB) forum and articles on the Iran Cyber News Agency (ICNA) site has damaged its reputation.


IEDB

Iranian Cyber News Agency (ICNA)

Despite trying to hide their identities, simple investigations have revelaed the identities of those who are involved within the IRGC at the Imam Hossein University (IHU).


Imam Hossein University (IHU)


This is supposed to be a seat of learning, but it seems that the education of students is for purposes other than knowledge. The IRGC officers who pose as professors and academics, have put their hands in the hand of their masters. We have seen the State has turned against its own with controls on the Internet. Are students there helping to suffocate the true Iranian voice?

Instead of serving the people of Iran, students can apply to trade-off their military service, by doing 'project' work. The IRGC claim to offer a trade-off to students to exchange time spent on projects for a reduction of their military commitment. The IHU offered sites for students to do this. What sort of exchange do students actually receive? Months of hard work for a few days respite? Military service should be exactly this: to protect the people of Iran, not hiding away working on developing malware that has only served to show us in a bad light internationally, and does not benefit the State.

It is far from unknown for the IRGC to make money from their work, and some of this malware development may be to extort money from victims to gain finances for their own personal 'projects'. The ill-gotten gains will not be shared with the authors.

There are other Universities - University of Tehran, Iran University of Science and Technology, and Sharif University of Technology, that are not so closely linked to the State, where studies can be conducted without the shadow that hangs over the Imam Hossein University.

Already, there are people being sought by foreign nations for arrest because of their work for the State against others. Last year with the ITSec Team and again this year, with other actors Ajily and Rezakhah that the Americans have indicted those involved in malware attacks. With the publication of the recent articles we are sure that the concentration of the West will be even more closely focused on Iran. This work is linked back to the IHU, so how long will it be before others are exposed?

The risks of working for the Iranian State

It may be in the future that Iranians will be freer to travel and work overseas; already we see that Russia is keen to allow visa-free travel to Iranians. If those involved with this malware work are identified, they will be denied the opportunities this would bring them and their families. Travelling overseas, individuals would be at risk of being diverted to an airport in a country with an extradition agreement with the U.S. Students could then be arrested and then sent to face the justice of the U.S. courts. They must realize that they are jeopardizing their futures...

Not only is it their futures at stake; President Rouhani has worked hard to lift sanctions on Iran. Can it be that the IRGC will use students to bring down a new round of punishment for all citizens?

CNN has recently suggested that Iranian cyber actors are using LinkedIn to target U.S. nationals. The U.S. will not stand idly by as we know from the past. Only last month, new sanctions were put in place by the U.S. congress.

The selfish actions of a few will affect the many. If blame is sought from within, will the IRGC shoulder the responsibility, or will they suggest that students had acted on their own and leave them to face the resulting severe penalties and national shame?




Tuesday, July 18, 2017

FBI Indicts Iranian Hackers



The U.S. FBI -Federal Bureau of Investigation- has announced the indictments of two Iranian hackers.

The hackers are Mohammed Reza Rezakhah -aged 39- and Mohammed Saeed Ajily -aged 35-. They have both been charged with the following:

  • Criminal conspiracy relating to computer fraud and abuse
  • Unauthorized access to and theft of information from computers
  • Wire fraud
  • Exporting a defense article without a license, and
  • Violating sanctions against Iran 
Arrow Tech: Vermont Software Company

Rezakhah and Ajily have been charged for activity starting in around 2007, where they and a third hacker, Nima Golestaneh -who has already pleaded guilty-, hacked into computers in order to obtain software which they would then sell and redistribute in Iran and elsewhere outside the U.S. It appears that Golestaneh worked with Rezakhah, in supplying servers for Rezakhah to conduct illegal activities.

Ajily tasked Rezakhah and other hackers with stealing or unlawfully cracking particular pieces of software. Rezakhah then hacked into victim networks to steal the software they wanted & once they got the software, Ajily marketed and sold the software through various companies and associates to Iranian entities, including universities, military and government entities, specifically noting that such sales were in contravention of U.S. export controls and sanctions. The Universities and company included: Malek Ashtar Defense University, Tehran University, Sharif Technical University, Khvajeh Nasir University, and Shiraz Electro Optic Industry. Rezakhah worked with Golestaneh, selling their "cracked" solution to the Arrow Tech software -they formed a company called "Dongle Labs", which sold a crack to the software that normally requires a hardware "dongle" for the software to work-.

In addition to payment, Ajily received certificates of appreciation for his work from several of the Iranian government and military entities. This implies that Ajily and Rezakhah could be working for the Iranian state?

In October 2012, Rezakhah hacked a Vermont-based engineering consulting and software design company -Arrow Tech-. Arrow Tech's primary product was PRODAS -Projectile Rocket Ordnance Design and Analysis System-; software that provides aerodynamics analysis and design for projectiles -from bullets to GPS guided artillery shells-. This software is designated as a “defense article” on the U.S. Munitions List of the International Traffic in Arms Regulations -ITAR-, meaning it cannot be exported from the U.S. without a license from the U.S. Department of State. Ajily marketed the same software as one of the products he could offer to his Iranian clients.

What does this mean for the hackers?

The court issued arrest warrants for both defendants, which means that if either Rezakhah or Ajily wanted to travel outside of Iran, they would be arrested. This means they are now effectively prisoners inside Iran. No doubt, their activities have brought great shame upon Iran, themselves and their families. Such illegal activities may not help their career chances inside Iran either...

It would appear that the FBI is getting tough on Iranian hackers who may work for or have links to supporting the Iranian state in such illegal activities. The indictment can be read in full here.


Sunday, December 11, 2016

Desperate Iranian Ideas For Social Media Control

Mohammad-Ali Movahedi Kermani: not liking the Internet
In the latest desperate attempt to subvert the freedom of Iranian expression, the regime wants to enforce permits for foreign social network applications, such as Telegram and Instagram, with membership of 5000 or more users. The desire for such control also extends to other domestic platforms including Salam Up, Soroush, BisPhone, Cloob and Syna, along with advertising, news and entertainment channels on social media networks.

The cleric Mohammad-Ali Movahedi Kermani thinks that the Internet is a threat to Islam, because the Internet is full of rampant "tele-sex" and in his eyes is ultimately "immoral". So concerned is Movahedi Kermani, that he puts the importance of subverting such "evil" as being above electoral issues or other pressing concerns, such as use of the Hijab.

Mahmoud Vaezi: deluded
Telecommunications Minister Mahmoud Vaezi thinks that channels with 5000 or more members should require permits so that the poor naive Iranian population can be assured such channels will not be fooling them with false information. Vaezi has been involved in Iran's "filternet", after Ahmadinejad's attempts in 2007 to "control" the Internet, and now the replacement "national-Internet" or Shoma, is vainly trying to do the same thing. Badly.


The Deputy Culture Minister for Communications Technology and Digital Media, Ali-Akbar Shirkavand, also wants a website that will soon be launched for administrators of such “channels” to register and continue their activities after authentication. The fear is, such controls by the regime could affect the opinions of journalists, artists and celebrities.

Cyber Police (FATA): Losing the plot

FATA chief, Brigadier General Kamal Hadianfar said that Telegram is the main platform for cybercrimes among mobile social networks. “The platform for 66% of the crimes is Telegram, while Instagram accounts for 20% and less than 2% is observed on WhatsApp,”  he said, without clarifying what "cybercrimes" were being committed via such applications... perhaps they include (according to Shirkavand anyway) copyright infringement and the sale of "immoral" goods on such channels. 

Kamal Hadianfar: battling the "evils" of social networks
A reality check: discord and feasibility

The regime's desire to crack-down on Internet freedoms is at odds with an overtly more liberal stance on such technology by Hassan Rouhani; Rouhani calls for more freedom of expression, but everyone else wants to suppress it #awkward. For example, Attorney General Hojjatoleslam Mohammad-Jafar Montazeri wants to shut down what he calls "anti-religion" networks and said of them: “Down with the freedom that is destroying everything...this is absolute enslavement”.

There is also the minor issue (conveniently overlooked by the regime) of Iran's inability to see the encrypted communications of platforms such as Telegram, and vain requests to get access to servers that must be placed in Iran are naive, at best. Also, what are the sentences to be expected by such "cybercriminals" who would dare to use such platforms? The whole thing is a joke and everyone knows it (even the regime).