Showing posts with label regime. Show all posts
Showing posts with label regime. Show all posts

Saturday, March 5, 2022

Iranian hacking group MuddyWater runs new cyber attack campaign in shadows of Russia invasion of Ukraine

 


Khamenei Loves War and Terror! 

Russia Invasion of Ukraine have now entered a full scale cyber war 😢. Hacktivist group Anonymous have retaliated taking out several key communication tools of Russia but it has been reported by Hacker News and Several Other News outlets that Iran has now come to the aid of its ally Russia with State-backed Hacking group MuddyWater now increasing it's activity 😡

In a joint US and UK Release multiple security agencies has put out a warning on MuddyWater saying they are targeting government industries and small private business including those in critical infrastructure and healthcare! 



Manually Generated Telegram Beacon 


The MuddyWater Hacking group steals data like passwords and online accesses which is then passed to disgusting regime controlling Iran and its allies including Russia. They use tools such as manually generated Beacon to harvest data of Telegram like one above. 



 

        MuddyWater runs under Iran's Ministry of Intelligence (MOIS)

The US Cybersecurity and Infrastructure Security Agency (CISA) in there report said MuddyWater is under the control of the Iranian Ministry of Intelligence and Security agency otherwise known as MOIS. Iran is a staunch Russia ally and needs support of Russia  especially now its increasing its nuclear program with JCPOA talks stalling. 

Khamenei has not denounced the Russian military operation in Ukraine and has suggested the root cause of the war was the “mafia regime” of the US and the polices of Western powers.

CISA Report : https://www.cisa.gov/uscert/ncas/alerts/aa22-055a


End these evil dictatorships! We want Peace!#StandWithUkraine 



Thursday, December 30, 2021

JCPOA Negotiations: How Iranian regime delegation in Vienna are leading world partners down a path of deceit and delay 🤬🤬🤬


JCPOA Vienna Talks (Image credit: Foreign Brief) 

Private talks in Vienna between Iran and Western powers aimed at reviving nuclear deal reached in 2015 have been going on for some time but there have been reports of numerous differences between the two sides. E3 diplomats say Iranian regime delegation unwilling to negotiate genuinely and as Iran's deceptive regime continues to stockpile uranium E3 diplomats warn that the nuclear deal will become a hollow shell in the not-too-distant future.

Iran's response to these allegations is as usual a deceptive and deviant response saying that diplomacy is a two-way street that goes so far as to accuse Western powers of playing the blame game. But the reality is very different as usual. Leaked notes from these talks indicate that the Iranian regime wants all sanctions to be lifted by the United States regardless of whether the sanctions were imposed because of  nuclear deal. 🤦‍♂️🤦‍♂️

It is clear that this delegation and by proxy this evil regime of mullahs have no interest in negotiating with the Western powers in this regard. They continue to delay and deceive their partners into thinking that an agreement can be reached while behind scenes they continue to stockpile uranium for nuclear weapons. this is so BAD! Western powers must be ready to withdraw from these negotiations and take further measures to eliminate this regime.

The innocent people of Iran suffer every day because they fail to act 😭😭

Wednesday, December 22, 2021

Charming Kitten AKA APT35 activity up rapidly in 2021: Google Issue public warning

 



It has been reported that the servant group of this corrupt Iranian regime called the Charming Kitten also known as APT35 has steadily increased its cyber attacks this year and increased the complexity of its cyber attacks. Google has now issued a public warning against the group.

Charming Kitten became famous in 2020 for phishing the accounts of US White House staff in the run-up to the 2020 US presidential election and they continued their evil ways in 2021. They Withdraw credentials from a British university called SOAS using a phishing kit and deploying a piece of spyware in mobile app stores that pretend to be VPNs. They also used telegram sendMessage API to find out the IP addresses and whereabouts of victims who clicked on their phishing links, as well as pretending to be staff members at Think20 conventions in Munich and here at home in Italy sending malicious phishing links to innocent victims.

Google have issues public warning of State-Sponsored cyber attacks 

It is worrying trend that Google feels that the threat posed by Charming Kitten is strong enough to issue a public announcement because they feel that the complexity of attacks from this horrific group is increasing. When will this corrupt regime stop trying to turn the lives of others into hell ??? 😡😡



Wednesday, November 24, 2021

Mahan Air Cyberattack - Exposing dirty secrets of IRGC QF and Further Technical Analysis

Hello friends 🙏 As I promised I continued my research on Mahan Air cyber attack and collected technical analysis for all of you.

It turned out that the hacker group responsible for this cyberattack Hooshyarane Vatan had succeeded in accessing Mahan air systems due to the fact that all sensitive information was not encrypted. It was also revealed that Mahan Airs IT department had actually identified the hackers on the network and had not yet been able to remove them. How bad are the security measures in Mahan Air ???? 😳😳


Hacktivist group responsible for Mahan Air Hack - Hooshyarane Vatan

The first revelation that came out of this cyber attack was evidence that multiple passengers called MR Hamrah Hamrah had boarded flights more than 70000 times on Iranian flights to Syria !! All are booked using the same travel agency called Utab Gasht. Utab Gasht seems to be a legitimate company but it turned out that they regularly transfer funds to a company called Hamrah or Hamrah SYR. Hamrah Company was rarely mentioned by Mahan Air employees, but a number of employees accidently leaked this information and wrote letters to the esteemed CEO of the company Mr. Golparast. Mr. Golparast is an exposed officer of the IRGC and the owner of Qeshm Fars Company which is a front for IRGC!! Mahan air is making dirty deals with IRGC officers !! Incredible! 🤯🤯



Leaked Letter 

Further analysis of this cyber attack also reveals numerous receipts for charter flights fully booked by the Hamrah company along with hundreds of illegal passengers traveling between Tehran, Damascus and Beruit. This evidence as well as further evidence indicating that passenger load exceeds limits over hundreds of kilograms shows that Mahan Air is actively facilitating the IRGCs QF activities and arms deals in Syria and Hezbollah in Lebanon. There is also a big difference with passengers who board flights and who are registered in the flight system. More than 400 passengers are lost every month under this name. Who knows what other dangerous personnel and cargo the Islamic Revolutionary Guard Corps carries on these flights alongside innocent civilians on flights? Absolutely embarrassing!! 😡



Leaked Invoice for hidden chartered flights 

It was also revealed that all these flights are booked with only 15 phone numbers and also certain people with special privilege are mentioned to board Mahan Air flights. Most likely these are QF IRGC officials. These are listed below:



Phone Numbers and Names used for IRGC QF flight bookings at Mahan Air 


After the technical analysis of this cyber attack it is revealed that Mahan Air has sold its soul to the IRGC and QF. How can Mahan Air do this to the Iranian people? A catastrophe could easily have happened when all these covert and evil deals and trips were completed. The Hamrah company are accompanying Utab Gasht and Qeshm Fars as front companies of the IRGC and its sinister motives and Mahan Air is in bed with them. disgusting! Friends, please do not travel with this airline anymore 🙏🙏

Wednesday, November 17, 2021

Lyceum is back! Targeting ISPs and other strategic targets 😡

Reports this week indicate that the notorious Iranian hacker group Lyceum has returned to chaos and this time mainly attacking Internet service providers and telecom companies in Morocco, Saudi Arabia, Israel and other companies in the wider Middle East including the African Ministry of foreign Affairs

The Lyceum group which was first discovered in 2017 and also known as Hexene has been identified as responsible for a number of cyberattacks in July and October 2021 according to information from Accenture Cyber ​​Threat (ACTI) and Prevailion's Adversarial counterintelligence groups (PACT). The main focus of the Lyceum Group is the implementation of computer network penetration events on a number of strategic target that are appropriate for the Iranian regime. It also now appears that they are expanding their reach to other targets even including places that are friendly to the Iran such as Tunisia.

                        Lyceum: Puppets of Regime!   

The hacker group appears to have stop used its famous Danbot .NET scripts and Powershell scripts to gain unauthorized access to the systems, and is now using a number of new technical techniques to do its evil work. Like the Base64-encoded Powershell scripts and new backdoors written in C++ which are new types of malware called James and Kevin. The group also relies on DNS tunneling which is an intrusion method for using DNS as a secret communication channel which is allowing the group to execute HTTP (S) commands using malicious C2 functionality. More scrutiny of source code also shows that Lyceum is also upgrading its backdoors to stay ahead of defense systems.

Lyceum is evil and guilty perpetrators of Iranian regime and seems to have continue committing ugly acts against other countries in the region regardless of whether they are friends or not. Please friends protect yourself against these types of attacks 🙏 by monitoring DNS traffic and being aware of suspicious domains and report them to threat information platforms.


Will this regime ever stop committing ugly acts in the region?? 😡😡


#cybercrime #cybersecurity #cybercrime #NET #Powershell #cyber #attack #C++ #HTTP #HTTPS #Morocco #SaudiArabia #Tunisa #Israel #Iran #IranianRegime #corrupt #evil   

Wednesday, September 5, 2018

Can you spot fake accounts? Iran continues to spread disinformation through fake news agencies and social media


Back in January I blogged about how Iran had followed the Chinese in the creation and use of fake social media accounts to further their political agenda. A report by FireEye shows that Iran continues to exploit social medial to promote its political interests and influence other unsuspecting users - fake news appears to be back on the agenda!

The report identifies 'Liberty Front Press' as a fake news agency created by the Iranians to further their political interests, along with a number of associated counterfeit social media accounts. The site promotes Senator Bernie Sanders whilst making anti-trump sentiments. Clearly the Iranians and Russians were not collaborating on this at least! It seems likely the Iranians were worried about Trump's negativity towards the JCPOA and thought Mr Sanders would be the safer option. That has not worked out so well for them.



Other fake news agencies and websites with an Iranian footprint include the 'Real Progressive Front', 'The British Left' and 'Instituto Manquehue'. All these sites go out of their way to state that they are 'completely' or 'genuinely independent', in an attempt to deceive the reader. All have similar political narratives; anti-Saudi, anti-Israeli, pro-Palestinian and pro-Iranian.

It appears the Social Media giants, like Facebook and Twitter, are finally trying to crack down on fake accounts. In the last week, it has emerged that YouTube has blocked 39 channels linked to the Iranian-state-run IRIB network and Facebook has announced the closing of 562 pages all linked to the Iranian regime.The regime, of course, denies all connection to the government.

Social media platforms have the difficult task of distinguishing fake from real accounts - but what identifies an account as suspicious? Whilst the algorithms used by the platforms are unknown, there are probably a number of contributing factors like low levels of original content (copying material from elsewhere), absence of personal photographs in profile pictures, accessing sites through a proxy, inflated number of followers or friends, and promotion of suspect websites. However, this is not easy and there will inevitably be collateral damage; I know a number of people who have had their real accounts shut down for unspecified 'suspicious' behavior. I am worried that banning customers that access platforms through a VPN will have a big impact on Iranian citizens trying to overcome the regime's access restrictions. I hope that in the future they can accurately separate real users who are drawing attention to important human rights issues, from the Iranian, Chinese or Russian (and probably a lot of other countries) actors who are abusing the right of free speech and circulating disinformation.


Tuesday, December 2, 2014

North Korea Prime Suspect in Hacking Attack Against Sony Pictures


According to the Wall Street Journal, hackers who took Sony Pictures Entertainment’s computer systems offline used tools which were very similar to those used last year in an attack on South Korean television stations and ATMs. The similarity reinforces a suspicion among some investigators, which include Sony, the FBI and a team from the security company FireEye Inc., that North Korea played a role in the breach. 
 
Sony Pictures is investigating if the North Korean regime was behind a massive hack attack on the studio computer network. Email was damaged and four movies were leaked.

The website Re/code reported that Sony and its security consultants are exploring the possibility that hackers based in China targeted studio computers in retaliation for the upcoming release of the film  The Interview.  In this film, Seth Rogen and James Franco play journalists who arrange an interview with North Korean leader Kim Jong-Un, and the CIA then ask them to assassinate him.

On Friday a North Korean government website called "The Interview" an "evil act of provocation" that deserved "stern punishment." Reportedly North Korea has organized a team of approximately 3,000 hackers to promote the Kim regime.

Saturday, June 14, 2014

Iranian Regime Cracks Down On "Selfie" Culture



Self photography is becoming more popular in Iran and whilst some relish the opportunity of being seen on the Internet, others worry this contributes to the culture of narcissism.

Since the average Iranian must pay at least two monthly wages to acquire a smart phone, the phenomenon is limited mostly to middle and upper-class youths, who have taken to the fashion.

Edit software like Photoshop is cheap and popular in Iran due to an absence of copyright laws and many Iranians alter their selfies before they post them online. While it is difficult to count the exact number of selfies on Iranian social networks, but users say they make the majority of postings on Instagram. According to cafebazaar, an alternative platform that 85% Iranians use to download apps, the social app has over one million users in Iran, while an estimated 82% of these Instagram users are men, the users in this article said women post more selfies than men. 
 
My Stealthy Freedom Facebook page invites Iranian women to share their views on hijab and this controversy illustrates the attitudes of these women as well as the inflexibility of the Islamic regime. 
 
When the page attracted nearly half a million likes and hundreds of hijab-free selfies, Iran's government media started a campaign against the page's founder Masih Alinejad in London and called her a whore and claimed that she was drugged and gang-raped in front of her son. The fear of losing cultural control over Iran's population especially women and youth, is also behind an effort by the country's hardline political spheres to block Instagram, which a 27 May court order added to the government list of banned web sites.