Showing posts with label iran cyber. Show all posts
Showing posts with label iran cyber. Show all posts

Wednesday, January 5, 2022

Iranian hackers Shia Eagle hack Jerusalem Post and Maariv Online on anniversary of Soleimani's death. ⚰️

On Monday it was revealed that the Israeli newspapers Jerusalem Post and Maariv Online had been hacked and hacked exactly two years since Soleimani's death. Both newspaper websites with defaced with a threatening image claiming revenge for Soleimani's death. This image shows the Dimona nuclear base in Israel being destroyed by a rocket fired from a hand very similar to Soleimani's.


        Image that was displayed on hacked websites after attack

No hacker group inside Iran has officially claimed responsibility for the attack, but a Twitter account called @shiaeagle posted several tweets at the time of the attack that strongly claimed responsibility. Twitter has since blocked the account.



                Shia Eagle twitter account which is now banned 

It is clear that in 2022 this cyber war between Israel and Iran has no sign of stopping.😢 This cyber attack could also be a statement by this corrupt Iranian regime that its nuclear program is being implemented at 100 percent and could be used as another negotiating tactic in the JCPOA Vienna talks. very sad!!!! 😭

Wednesday, November 17, 2021

Lyceum is back! Targeting ISPs and other strategic targets 😡

Reports this week indicate that the notorious Iranian hacker group Lyceum has returned to chaos and this time mainly attacking Internet service providers and telecom companies in Morocco, Saudi Arabia, Israel and other companies in the wider Middle East including the African Ministry of foreign Affairs

The Lyceum group which was first discovered in 2017 and also known as Hexene has been identified as responsible for a number of cyberattacks in July and October 2021 according to information from Accenture Cyber ​​Threat (ACTI) and Prevailion's Adversarial counterintelligence groups (PACT). The main focus of the Lyceum Group is the implementation of computer network penetration events on a number of strategic target that are appropriate for the Iranian regime. It also now appears that they are expanding their reach to other targets even including places that are friendly to the Iran such as Tunisia.

                        Lyceum: Puppets of Regime!   

The hacker group appears to have stop used its famous Danbot .NET scripts and Powershell scripts to gain unauthorized access to the systems, and is now using a number of new technical techniques to do its evil work. Like the Base64-encoded Powershell scripts and new backdoors written in C++ which are new types of malware called James and Kevin. The group also relies on DNS tunneling which is an intrusion method for using DNS as a secret communication channel which is allowing the group to execute HTTP (S) commands using malicious C2 functionality. More scrutiny of source code also shows that Lyceum is also upgrading its backdoors to stay ahead of defense systems.

Lyceum is evil and guilty perpetrators of Iranian regime and seems to have continue committing ugly acts against other countries in the region regardless of whether they are friends or not. Please friends protect yourself against these types of attacks 🙏 by monitoring DNS traffic and being aware of suspicious domains and report them to threat information platforms.


Will this regime ever stop committing ugly acts in the region?? 😡😡


#cybercrime #cybersecurity #cybercrime #NET #Powershell #cyber #attack #C++ #HTTP #HTTPS #Morocco #SaudiArabia #Tunisa #Israel #Iran #IranianRegime #corrupt #evil   

Friday, November 27, 2020

Corona Censorship



It is well known that Iran has not been truthful about Corona. The Iranian government has lied to the world about the deaths of Iranian people. The Iranian state say that 40,000 Iranian have perished but other sources say that this is actually 150,000. This is more than Italy! Why does the government try to cover this up?

This is the latest example of the Iranian governments control and censorship over Iranian people. It also shows how far the Iranian state will go to protect itself from scrutiny. What has the government done to stop Corona. Why has it taken so long to begin lockdown. And is it too late?

It is more important than ever that Iranians have access to the Internet. Iranians are the only people who know what is really going on. Corona has come at a time where Iran continues to control internet access and service providers. Ever since the November 2019 protests Iranian government has stepped up its attempts to censor the Iranian people and hide them from the world.

Last year I blogged about how to avoid Iranian censorship by using Tor to overcome government barriers. This is now more relevant and necessary because of Corona. Maybe in ten years we will know the truth about Corona. Until then the people must continue to document the truth.

Thursday, December 5, 2019

The truth always comes out


Censorship comes in many forms and most recently that includes at the barrel of a gun. I speak of course of the murder in Istanbul of Masoud Molavi on 14 November. Molavi was a complicated person and realised the last two years the work he did in the name of Irans national security was not in service of the Iranian people. He fled to Turkey and founded Black Box on Twitter and Telegram to highlight the illegal activity of the Iranian government. He spoke the truth for the Iranian people and paid the highest price for that.



There is little doubt to me that members of the Iranian State were behind this. Molavi's exposure of malicious cyber activity by the Iranian government was too much but what they still do not understand is that every person killed, or tortured, or imprisoned, just inspires other ordinary Iranians to seek the truth.

Black Box was a brave piece of work, and those who were a part of it will find new places to share truth and knowledge of Iran's oppressive cyber activities.

Wednesday, September 5, 2018

Can you spot fake accounts? Iran continues to spread disinformation through fake news agencies and social media


Back in January I blogged about how Iran had followed the Chinese in the creation and use of fake social media accounts to further their political agenda. A report by FireEye shows that Iran continues to exploit social medial to promote its political interests and influence other unsuspecting users - fake news appears to be back on the agenda!

The report identifies 'Liberty Front Press' as a fake news agency created by the Iranians to further their political interests, along with a number of associated counterfeit social media accounts. The site promotes Senator Bernie Sanders whilst making anti-trump sentiments. Clearly the Iranians and Russians were not collaborating on this at least! It seems likely the Iranians were worried about Trump's negativity towards the JCPOA and thought Mr Sanders would be the safer option. That has not worked out so well for them.



Other fake news agencies and websites with an Iranian footprint include the 'Real Progressive Front', 'The British Left' and 'Instituto Manquehue'. All these sites go out of their way to state that they are 'completely' or 'genuinely independent', in an attempt to deceive the reader. All have similar political narratives; anti-Saudi, anti-Israeli, pro-Palestinian and pro-Iranian.

It appears the Social Media giants, like Facebook and Twitter, are finally trying to crack down on fake accounts. In the last week, it has emerged that YouTube has blocked 39 channels linked to the Iranian-state-run IRIB network and Facebook has announced the closing of 562 pages all linked to the Iranian regime.The regime, of course, denies all connection to the government.

Social media platforms have the difficult task of distinguishing fake from real accounts - but what identifies an account as suspicious? Whilst the algorithms used by the platforms are unknown, there are probably a number of contributing factors like low levels of original content (copying material from elsewhere), absence of personal photographs in profile pictures, accessing sites through a proxy, inflated number of followers or friends, and promotion of suspect websites. However, this is not easy and there will inevitably be collateral damage; I know a number of people who have had their real accounts shut down for unspecified 'suspicious' behavior. I am worried that banning customers that access platforms through a VPN will have a big impact on Iranian citizens trying to overcome the regime's access restrictions. I hope that in the future they can accurately separate real users who are drawing attention to important human rights issues, from the Iranian, Chinese or Russian (and probably a lot of other countries) actors who are abusing the right of free speech and circulating disinformation.


Wednesday, April 4, 2018

A cyber-attack on ideas: Mabna behind latest frightening global phising campaign that targets intellectual property, with allegations of state-sponsorship.

An indictment for nine Iranians was unsealed on March 23 2018. They each stand accused of a variety of crimes relating to cyber-attacks conducted on universities, government agencies, and private organisations around the globe. 31 terabytes of data was stolen - that is a lot of data! The nine suspects are all affiliated with Mabna, the group responsible for the HBO hacking (in which Game of Thrones episodes were leaked), which led to the indictment of Mesri for his involvement in the hacking and attempts to extort US$6 million. It has been revealed that the cyber-assault used customized phishing emails that were sent under the disguise of academics at other institutions. The emails contained links to academic papers that directed the victim to a malicious domain masquerading as a university web page, prompting the victim to give away his log-in details.

Among the victims were government agencies and private companies, but the primary target was universities, with around 8000 professors falling victims. So, unlike the targets identified in previous indictments, we now appear to be seeing a diversification of the type and location of the target. Furthermore, the attack was indiscriminate with regards to academic discipline. Whilst the economic value of the data should not be given disregarded (the indictment makes the cost of the stolen research to USE institutions as US$3.4 billion), the financial loss is only one implication. The concept of targeting innovation, ideas and information, acquired through years of research effort, is new and frightening. The attacks demonstrate the need for academic institutions, to improve their cyber-security, both in terms of the awareness and implementation. It is worrying that the attacks reached beyond the usual suspects of the US and Israel; universities in 22 different counties, including many in Europe, and also China, were victims. Among the non-academic targets was the Unite Nations Children's Fund, demonstrating the callous and indiscriminate way in which the Iranian cyber machine selects victims.

Whilst considered innocent until proven guilty in a court of law, presumably investigators must be pretty convinced of guilt to name these individuals in the indictment. These men will join those previously indicted by the FBI for cyber-criminals, in not being able to leave Iran without fear of arrest. This limitation of freedom will surely deter some of those considering a 'career' in hacking, and slow recruitment to the Iranian cyber-army.

Who is backing Mabna? The indictment reveals that spear-phising email attacks were then conducted on behalf of the Islamic Revolutionary Guard Corps (IRGC) of Iran. But were there other governmental bodies involved? This is a persistent question which resurfaces with each attack. Given their close association, it seems likely that there is some level of co-ordination between the IRGC and other government offices, like those within the Iranian Ministry of Foreign Affairs, when planning the cyber-attacks. Will this public condemnation deter Iran form undertaking further attacks on university, or will the stat simply distance themselves form cyber criminals?