Showing posts with label iranian state. Show all posts
Showing posts with label iranian state. Show all posts

Friday, November 27, 2020

Corona Censorship



It is well known that Iran has not been truthful about Corona. The Iranian government has lied to the world about the deaths of Iranian people. The Iranian state say that 40,000 Iranian have perished but other sources say that this is actually 150,000. This is more than Italy! Why does the government try to cover this up?

This is the latest example of the Iranian governments control and censorship over Iranian people. It also shows how far the Iranian state will go to protect itself from scrutiny. What has the government done to stop Corona. Why has it taken so long to begin lockdown. And is it too late?

It is more important than ever that Iranians have access to the Internet. Iranians are the only people who know what is really going on. Corona has come at a time where Iran continues to control internet access and service providers. Ever since the November 2019 protests Iranian government has stepped up its attempts to censor the Iranian people and hide them from the world.

Last year I blogged about how to avoid Iranian censorship by using Tor to overcome government barriers. This is now more relevant and necessary because of Corona. Maybe in ten years we will know the truth about Corona. Until then the people must continue to document the truth.

Thursday, December 5, 2019

The truth always comes out


Censorship comes in many forms and most recently that includes at the barrel of a gun. I speak of course of the murder in Istanbul of Masoud Molavi on 14 November. Molavi was a complicated person and realised the last two years the work he did in the name of Irans national security was not in service of the Iranian people. He fled to Turkey and founded Black Box on Twitter and Telegram to highlight the illegal activity of the Iranian government. He spoke the truth for the Iranian people and paid the highest price for that.



There is little doubt to me that members of the Iranian State were behind this. Molavi's exposure of malicious cyber activity by the Iranian government was too much but what they still do not understand is that every person killed, or tortured, or imprisoned, just inspires other ordinary Iranians to seek the truth.

Black Box was a brave piece of work, and those who were a part of it will find new places to share truth and knowledge of Iran's oppressive cyber activities.

Friday, March 16, 2018

Are large scale human casualties inevitable in state sponsored cyber war?



The attack on the Saudi Petrochemical Company in August represents a terrifying escalation in cyber wars. The machinery was the primary target, but human casualties would have been almost certain. Whether human death was the intention or just an accepted consequence is not known, but doesn't really matter - the attackers would have been aware that large scale casualties were likely and still went ahead with the attack.

Worryingly, the complexity of the malware indicates a level of resourcing that suggests the attacks were state sponsored. Although the culprit has not yet been confirmed by investigators, the open hostility between Iran and Saudi Arabia and the step change in the intensity of hostile cyber activity, make the Iranians an obvious candidate.

The malware (which has been named Trisis) compromised machinery that is common in other nuclear and oil companies throughout the world - this demonstrates the potentially global destruction that can be rapidly released by a single well planned cyber attack.

Where do we go from here? For now we can be thankful that the attacked failed and was detected. But if the bug that caused the malware to fail has been fixed, are all industrial systems sitting on a ticking time bomb with human casualties inevitable collateral damage? Attribution will be difficult, but if a government such as Iran are behind these attacks, then their consideration towards human life is very worrying. These are scary times.






Tuesday, January 9, 2018

Mesri remains silent; where next for exposed Iranian hackers?

Just over a month ago, the US announced the indictment of Behzad Mesri (Skote Vahshat) who has been indicted by the FBI for computer fraud, extortion, and identity theft. 


Image result for mesri iran hbo

It seems that Mesri is a member of Turk Black Hat Iranian hacking group, which is responsible for defacing hundreds of websites, and most famously, the hacking of HBO's computer servers. As expected, we have heard nothing from Mesri himself.

Silence, in such cases, means that the accused is unable to justify their actions; was he doing it for someone else? Was it for money or ideology? The fate of exposed hackers in Iran is unlikely to be good. 

As noted in the US indictment, Mesri will be unable to travel abroad and presumably for this reason, there will not be so many opportunities for employment in the future. Whether staying silent is Meri's own decision, or whether he was obeying orders form higher up the command chain, is not known. Although the cybersecurity consulting and intelligence company Clearsky have recently reported evidence linking Mesri to the Iranian hacking group Charming Kitten, it is still unclear if this group and other Iranian hacking groups are working for the Iranian government.

Friday, May 30, 2014

NEWSCASTER: Iran Attacks Social Media


Iranian state targeted the public and private sector in the US, Israel, UK and beyond using social media.

Iranian hackers use more than ten fake identities on social networking sites (Facebook, Twitter, LinkedIn, Google+, YouTube, Blogger) in a coordinated long-term cyber espionage campaign.  At least 2,000 people are caught in the snare and are connected to the false identities.

This campaign is working undetected since 2011 and targets senior American military and diplomatic personnel, congressional personnel, Washington DC journalists, US think tanks, defense contractors in the US and Israel, and others who are loud supporters of Israel to covertly obtain log-in credentials to the email systems of these victims. They targeted also additional victims in the UK as well as Saudi Arabia and Iraq.

The targeting, operational schedule and infrastructure used in this campaign is consistent with Iranian origins.
The fake identities claim they work in journalism, government and defense contracting. These accounts are elaborate and create credibility using among other tactics a fictitious journalism website newsonair.org that copies news content from other media outlets.

These credible identities then connected, linked, followed and friended target victims to get access to information on location, activities and relationships from updates and other common content.

These identities then targeted accounts with spear-phishing messages. Links which appeared to be legitimate asked recipients to log in to false pages to capture credential information. It is not clear at this time how many credentials the attack captured so far.

Additionally this campaign is linked to malware. While the malware is not very sophisticated, but it includes capability that can be used for data exfiltration.
The discovery and investigation of the attack reveals three critical insights:
  1. Social media offers a powerful and hidden route to target key government and industry leadership through an external base possibly outside of existing security measures.
  2. With reference to targeting associated with this campaign it is possible that Iranian hackers used accesses gained through these activities to support the development of weapon systems, reveal the disposition of the US military or the US alliance with Israel or give an advantage in negotiations between Iran and the US. Furthermore it is possible that any access or knowledge could be used as reconnaissance-for-attack before disruptive or destructive activities
  3. These adversaries are improving in finding and exploiting opportunities to carry out cyber espionage, even if they lacked sophisticated capability.  NEWSCASTER’s success is largely due to patience, brazen nature and innovative use of multiple social media platforms.

    It seems that the NEWSCASTER network targets mainly senior military and policymakers, companies associated with defense technology and the US-Israel lobby, however there are also victims in the financial and energy sectors as well as elsewhere and only a part of the accounts connected to this network were seen. Organizations involved in critical infrastructure or have information that may be of strategic or tactical interest to a nation-state adversary should be concerned about a threat such as this.