Showing posts with label russia. Show all posts
Showing posts with label russia. Show all posts

Saturday, March 5, 2022

Iranian hacking group MuddyWater runs new cyber attack campaign in shadows of Russia invasion of Ukraine

 


Khamenei Loves War and Terror! 

Russia Invasion of Ukraine have now entered a full scale cyber war 😢. Hacktivist group Anonymous have retaliated taking out several key communication tools of Russia but it has been reported by Hacker News and Several Other News outlets that Iran has now come to the aid of its ally Russia with State-backed Hacking group MuddyWater now increasing it's activity 😡

In a joint US and UK Release multiple security agencies has put out a warning on MuddyWater saying they are targeting government industries and small private business including those in critical infrastructure and healthcare! 



Manually Generated Telegram Beacon 


The MuddyWater Hacking group steals data like passwords and online accesses which is then passed to disgusting regime controlling Iran and its allies including Russia. They use tools such as manually generated Beacon to harvest data of Telegram like one above. 



 

        MuddyWater runs under Iran's Ministry of Intelligence (MOIS)

The US Cybersecurity and Infrastructure Security Agency (CISA) in there report said MuddyWater is under the control of the Iranian Ministry of Intelligence and Security agency otherwise known as MOIS. Iran is a staunch Russia ally and needs support of Russia  especially now its increasing its nuclear program with JCPOA talks stalling. 

Khamenei has not denounced the Russian military operation in Ukraine and has suggested the root cause of the war was the “mafia regime” of the US and the polices of Western powers.

CISA Report : https://www.cisa.gov/uscert/ncas/alerts/aa22-055a


End these evil dictatorships! We want Peace!#StandWithUkraine 



Sunday, October 15, 2017

UK Parliament Hacked By Iran



The United Kingdom (UK) Parliament appears to have been hacked by Iran. The cyber-attack on 23 June 2017 was a brute-force attack against 9000 email accounts including the UK Prime Minister Theresa May and in total between 30 to 90 members of Parliament.

The UK Times newspaper which broke the story, said that it was Iran’s first significant act of cyber-warfare on the UK and underlines its emergence as one of the world’s biggest cyber powers and that Iran is highly capable of such attacks.

The decision to publish the information now is interesting, coming after the US President Donald Trump's intent to withdraw from the JCPOA (Joint Comprehensive Plan of Action) against Iran, which could threaten to re-instate sanctions against Iran. The UK, France and Germany do not agree with the USA on the matter. Without complete agreement, perhaps Iran will not suffer from any new sanctions against it, as it appears that Iran has not violated any of the sanctions.


Iranian regime attack or amateur hackers?

The attack, which was suspected of being originally from Russia, may have been carried out by amateur hackers. At the time of the attack in June, it was said that the attackers could only break into the email accounts of members of Parliament (MPs) which had simple, easy to hack passwords. As a security response at the time, MPs were unable to access their accounts and had to communicate using SMS texts instead. It now seems, however, that the regime may perhaps have after all been behind the attack?

Reasons for the attack

The reasons for the attack are unknown (or at least the British Intelligence services are not saying), but could be:
  • Exploratory activities: Iran may have been looking for UK data that Iran could then force the UK to make concessions with, or that could compromise the interests of the UK
  • Iran may have been looking for a trade advantage
  • More worryingly is the possibility that the IRGC (Iranian Revolutionary Guards Corps) may be seeking to undermine Iran's anti-nuclear proliferation deal in order to get it scrapped; Iran could then restart its nuclear weapons research.
The IRGC are at odds with President Hassan Rouhani, who they see as being too pro-West and the religious leader of the regime, Ayatollah Khamenei is linked with the IRGC, so there is an ongoing rift between the religious and political leadership of Iran, partly due to Rouhani slashing the IRGC's budget to restrict their economic activities.



An uncertain future

In my previous article, it is possible that Iran may seek to increase cyber-attacks against the USA if the US walked away from the JCPOA. Now that President Trump appears to be doing that, even if Germany, UK and France don't agree, we may see an increase in the cyber war from Iran against the West.

Sunday, March 27, 2016

U.S. Indicts Iranians for Hacking Many Banks & New York Bowman Dam


On Thursday March 24 2016, the US Department of Justice indicted seven hackers associated with the Iranian government, making history for the first time where the USA has charged state-sponsored individuals with hacking to disrupt important US industry networks.
The crimes include attacking U.S. banking websites between 2011 to May 2013 and also breaking into a computer system at Bowman Dam in Rye Brook, Westchester County, NY in a possible attempt to disrupt the operation of the dam.


The attackers have been charged with conspiracy to commit and aid and abet computer hacking for their roles in hacks of the U.S financial sector on more than 176 days.



According to the indictment, all seven men were working for two Iranian computer security companies — ITSecTeam and MERSAD Co. — on behalf of the Iranian Revolutionary Guard Corps (IRGC), a branch of the Iranian military established to defend the country’s Islamic system and promote its ideology.

The indictment alleges that the suspects caused DDoS attacks to crash the sites of 46 U.S. financial institutions. At one point, the attacks happened almost weekly and affected many major institutions. The indictment alleges such actions left hundreds of thousands of customers unable to access online bank accounts.

The seven identified hackers (see photo above),range in ages from 23 to 37 are:

Ahmad Fathi (37)
Hamid Firoozi (34)
Amin Shokohi (25)
Sadegh Ahmadzadegan (23)
Omid Ghaffarinia (25)
Sina Keissar (25) and
Nader Seidi (26)


Hamid Firoozi is charged alone for hacking the dam. Amin Shokohi allegedly received credit from the Iranian government toward his mandatory military service for his work in the attacks.

The affected institutions and businesses included:

  • Bank of America
  • Nasdaq
  • New York Stock Exchange (NYSE)
  • Capital One
  • AT&T
  • PNC
U.S. Attorney General Loretta E. Lynch said the attacks caused tens of millions of $USD in losses.

Sadegh Ahmadzadegan and Omid Ghaffarinia also claimed responsibility for hacking into NASA servers and defacing NASA websites, and Firoozi obtained access to a computer control system for the Bowman Avenue Dam. That access would have allegedly allowed Hamid Firoozi to operate and manipulate a gate on the dam. The attack by Hamid Firoozi took place between August 28 2013 and Sept 18 2013.
He was able to access information related to the status and operation of the dam and the status of the sluice gate—responsible for controlling water levels and flow rates.
However, at the time of the hacks the Bowman Dam sluice gate had been manually disconnected for maintenance.

Wrong target/dry run?

Mayor Paul Rosenberg in the village of Rye Brook, NY has theories why the sluice-gate small Bowman dam had been targeted by the Iranians.
One theory is that Iranian hackers had confused the dam with another dam named Bowman — the Arthur R. Bowman Dam on the Crooked River in Oregon. That dam is 245 feet tall and 800 feet long and is used to irrigate many local farms.
Mayor Rosenberg also thought the hackers had gone after the Rye Brook dam as a dry run for a more disruptive invasion such as, for example a major hydroelectric generator or some other part of the USA's critical power grid.

Reasons, Iranian & Russian Collaboration

The reasons for the DDoS attacks by Iran are probably in response to strong economic sanctions by the USA and Europe in attempts to make Iran stop its nuclear activities.


The IRGC operates in the cyberspace using front companies, which allows the IRGC to circumvent Western law & give them some anonymity.

The Iranian state may be receiving help from Russian hackers affiliated with the Kremlin, which involves writing code or providing malware tools they can adapt.

Iran has previously been suspected in hacking attempts. A Wall Street Journal report linked the IRGC to similar hacking and phishing attempts targeting the email and social-media accounts of President Obama's administration officials.


Details

The indictment can be read here

Wednesday, November 25, 2015

Iranian Hackers Attack State Dept. via Social Media Accounts


Iran launched sophisticated computer espionages leading to a series of cyberattacks against US State Department officials over the past month.

It is possible that cyberespionage is becoming the tool of seeking the type of influence that Iranian hardliners hoped that that country's nuclear program will eventually provide.

According to diplomatic and law enforcement officials who are familiar with the investigation Iranian hackers over the past month identified individual State Department officials who focus on Iran and the Middle East and broke into their email and social media accounts. The State Department became aware of the compromises when Facebook told the victims that the state-sponsored hackers compromised their accounts.

Iran’s cyberskills are not yet equal to those of Russia or China but the attack against the State Department by using the social media accounts of young government employees to gain access to their friends across the administration is a focus that was not seen before.

Iranians have been less destructive than they could be, but they are getting far more aggressive in cyberespionage, which they know is less likely it will prompt a response from the United States.

Iranian hackers have been responsible for a series of powerful attacks against American banks that took their websites offline as well as a destructive attack on Saudi Aramco, the world’s largest oil producer, that replaced data on employee machines with an image of a burning American flag. American government officials also blame Iran for a similarly destructive attack at RasGas, the Qatari natural gas giant,and for an attack on Sands Casino in Las Vegas, where a large number of computers were destroyed.

Last year Iranians began using cyberattacks for espionage rather than for destruction and disruption. From May 2014 Iranian hackers were targeting Iranian dissidents and later policy makers,senior military personnel and defense contractors in the United States, England and Israel.

The attacks were basic “spear phishing” attempts, in which attackers tried to lure their victims to click on a malicious link, in this case by impersonating members of the news media.
Iranian hackers were successful in more than a quarter of their attempts. The number of such attacks reached its climax in May just ahead of the nuclear talks in Vienna in July and reached more than 1,500 attempts.

In the months before the talks, Iran’s hackers began probing critical infrastructure networks in what appeared reconnaissance for cyberattacks with the objective of causing physical damage but in June and July as American and Iranian negotiators gathered in Vienna to agree a deal on Iran’s nuclear program, attacks against targets in the United States stopped. Instead of this, Iran started targeting victims in Israel as well as members of Daesh in July as the militant group began expanding territory across Iraq.

Then in August just two weeks after the nuclear accord was reached, the trickle of cyberattacks against the group’s usual targets resumed against included 1600 individuals from scholars, scientists, chief executives and ministry officials to education institutes, journalists and human rights activists. If facebook last month had not decided to use a new alert system to notify users when facebook's security team believed state-sponsored hackers had hijacked their accounts, and US State Department officials began to see a troubling new message pop up on their facebook accounts, it is possible that the victims didn't learn of the compromises.

Wednesday, June 10, 2015

Duqu 2.0: ‘Almost Invisible’ Cyber Espionage Tool Targeted Russian Co., Linked to Iran Nuclear Talks

 

A Russian cyber security company says that it has discovered a highly-technical, “almost invisible” cyber espionage tool that targeted the company’s own servers and other systems around the world, including some linked to the controversial Iranian nuclear negotiations.
Kaspersky Labs which is based in Moscow announced that the discovery of the worm, called Duqu 2.0, which the company said it found this spring after the worm had penetrated through its system for “months.”



Kaspersky claims that after discovering the worm, started its investigation to find out other victims of the attack and found that some of the “infections are linked to the P5+1 events and venues related to negotiations with Iran about a nuclear deal.”
The Wall Street Journal was the first news agency to publish the news about Duqu 2.0. According to the Wall Street, computers at three luxury European hotels where negotiations had been held were among the worm’s victims.

Eugene Kaspersky said that the company cannot say definitely who is behind the attack, but he believes that due to its sophistication and technical links to previous next-generation computer worms, the attack is most possibly been carried out by a government.

Kaspersky said that the name of the Duqu 2.0 was chosen for this worm because it appeared to be an upgraded version of the Duqu worm which was another highly-sophisticated espionage tool discovered in 2011.
Kaspersky said, We can’t prove attribution because they’re going through proxy servers. “There are technical attributions we can read from the code. This attack is a relative, it’s a new generation of the Duqu attack, most probably made by the same people, or they shared the source code with others.”
Symantec which is a large cyber security company in America agreed that Duqu 2.0 is a evolution of the original threat that was created by the same group of attackers.



Symantec also reported Duqu 2.0 appears to have targeted European and North African telecom operators and a South East Asian electronic equipment manufacturer. Symantec had reported in 2012 that the Duqu threat had not been eliminated and that a new version of the worm had been discovered then.

Duqu and Duqu 2.0 is closely linked to Stuxnet, which is a revolutionary cyber-weapon that was believed to have physically damaged an Iranian nuclear facility and that was suspected to be a result of the joint US-Israeli top secret operation’s. 

 

When the original Duqu was discovered in 2011, Symantec reported that it “shares large number of codes with Stuxnet” and the same suspicions were raise about whether the attackers were the same or if source code had been shared.

Wall Street Journal in its report today said that Duqu 2.0 was “commonly believed to be used by Israeli spies.”
But according to Kaspersky Labs, Duqu 2.0 code also included a number of “false flag” clues to hide/mislead who was behind it. One was a mention in the code of a nickname for a Chinese military officer who was one of five indicted by the U.S. in an extraordinary move by the Department of Justice against Chinese cyber espionage. Another report mentioned a prolific Romanian hacker.

Kaspersky claims that such false flags are relatively easy to spot, especially when the attacker is very careful not to make any other mistakes,”

Saturday, April 12, 2014

Iran: The World's Worst Cyber-Terrorists – For Now



Iran became a major cyber terror threat to the US in the last 12 months and targeted several US government agencies but with regard to the Iranian lack of skills in this area it means that for now it has not been possible that Iran causes significant damage. Iran is more than five years behind countries like China, the US and Russia in terms of cyber capabilities but with the right resources that gap could be removed quickly especially considering Iran is the historical enemy of the US.

Security company Mandiant in its latest report describes Iran's development from cyber-obscurity to becoming a credible but unsophisticated threat. Mandiant is the same company which last year revealed the extent that Chinese government funded cyber espionage was carried out. In the company's report M Trends 2014 it is written that “threat actors” based in Iran "pose an ever-increasing threat due to Iran's historical hostility towards US business and government interests."

The report reveals that it observed "threat actors" based in Iran who target the networks of several US government agencies. In the report it is written that "Employees at a US state government office discovered evidence that someone had accessed multiple systems within their network without authorization. An internal IT department investigation found indications of data theft and unauthorized use of privileged credentials."
The security company said that the data that these actors steal "lacked a discernible focus or demonstrated intent". This suggests that the purpose of the attack is more likely "reconnaissance of the potential target's networks." Attacks that originate in Iran, are on a very low level of technical skill and those carrying out the attacking use off-the-shelf tools which are relatively easy to defend. Mandiant says that the victim detects 75% of all attacks from Iran.