Showing posts with label spyware. Show all posts
Showing posts with label spyware. Show all posts
Tuesday, February 9, 2016
Yaser Balaghi Leaves Calling Card After Hacking the IDF
Iranian hacker made grave error in hacking a former chief of staff of the Israeli Defense Force (IDF).
The hacker Tehran-based Yaser Balaghi (see photo above), later boasted of the hack, but he also accidentally left behind a digital calling card which let his identity be exposed.
His grave error caused Iran to stop the hacking operation which targeted 1800 people globally, including Israeli army generals, human rights activists in the Persian Gulf and scientists.
The cyber operation hacking group known as "Rocket Kitten" (linked with the Iranian Revolutionary Guards and identified in 2014), started the attack in November 2015, and targets received email messages aimed at sending spyware into their computers.
More than 25% of people targeted had opened the emails and without knowing downloaded spyware and allowed hackers to steal information from computers.
The cyber attacks originated from Iran against targets in Israel and the Middle East with Israeli generals among the targets.
The hackers used techniques including "targeted phishing" (where hackers use false web pages that look like real ones to get user identification data) and then hacked 40 targets in Israel and 500 across the world.
The Israeli targets included generals, employees of security consulting firms and academic researchers.
CheckPoint Software researchers revealed the identity of Balaghi when they found that Balaghi goes by the handle of "Wool3n.H4T".
Not only did Rocket Kitten hackers leave default passwords in place and allow password-less root access to their server management software but they infected their own C&C (Command & Control) server with their keylogger malware...but then left it in place #fail.
The CheckPoint researchers were then able to harvest the usernames and passwords of any accounts which the hackers had logged on to from their server.Oh dear...
In addition to allow password-less root access to any browsing visitor the hackers made many other basic mistakes including failing to hide a path to the server from where the attacks originated.
That provided clear evidence that the attacks originated in Iran #timeforanewjob
CheckPoint discovered Balaghi's (Wool3n.H4T) AOL account (AOL, really?!), YaserBalaghi@aol.com with his uber 7337 password of: 123456789 (double #fail). This took them to a Farsi resume which he had posted online to boast of hacking work which he had done for "a cyber-organization" presumably an Iranian security agency :)
The researchers found a database which lists the names of the members of the hacking crew (apparently real ones as they were typical Iranian first and family names #lol),
as well as links to web pages infected with their malware (which was also found on the server).
Additionally the database includes a list of nearly 2000 targets with their names, email addresses and other information, targeted since August 2014 when it appears that the currently used server was activated.
The investigators discovered in one of the false web pages that look like real ones the name of Yaser Balaghi who appears to be "Rocket Kitten" team leader, based on internal messages and emails. From there he is found easily with a quick Internet search (see below).
This is shameful example of bad Iranian OPSEC and completely undermines their otherwise arguable technical skills #awkward
Where's Yaser? Here!:
http://yaserbalaghi.com (His main site)
http://stackoverflow.com/users/5617165/yaser-balaghi
https://evilzone.org/profile/?u=15677
https://www.google.com/imgres?imgurl=http://cdn.timesofisrael.com/uploads/2015/11/Balaghi.jpg
http://www.bridgesforpeace.com/images/content/news/News_10Nov15_3_screenshot_Brians_article.jpg
Labels:
aol,
checkpoint,
IDF,
iran,
israeli defense force,
malware,
opsec,
persian gulf,
phishing,
rocket kitten,
spyware,
yaser balaghi
Sunday, July 5, 2015
Iran claims to stop Dino Malware attack
Iran confirms that spy malware
called Dino is targeting sensitive centers inside the country
since one and half years ago.
Masoud Biglarian, head of the
Computer Emergency Response Team Coordination Center (CERTCC), said
that after malware was discovered the CERTCC which is subset of the
Information and Communication Technology (ICT) sent a secret report
to the countrys officials about the issue.
According to Irans Mehr news agency Biglarian said: «We took appropriate measures to prevent
damage to the strategic centers of the country by Dino».
He also said that Dino is a type of
Spyware such as Stuxnet that is designed for specific
purposes and launches targeted attacks.
He rejected claims that the malware
infected some sensitive centers inside the country.
Last week some western media outlets
reported that Dino malware which searches for specific data and
steals it has infected some organizations inside Iran.
Security firm ESET researchers
in Bratislava, Slovakia identified the sophisticated Dino Trojan that
attacked Iranian and Syrian targets in 2013 and it is rumor that the
group is a secret part of the French Intelligence service.
Dino was supposedly created by the
so-called Animal Farm Group which also created other Trojans
like Bunny, Casper and Babar. Casper malwares
claim to fame is that it was involved in a large scale attack on
computer systems in Syria last autumn.
ESET claims that Dinos main goal
seems to be the exfiltration of files from its targets.
Large scale cyber attacks on Iranian
facilities started in 2010 after the US and Israel reportedly tried
to disrupt the operation of Irans nuclear facilities through a worm
that later became known as Stuxnet.
US intelligence officials revealed in
June 2013 that the Stuxnet malware was not only designed to disrupt
the Irans nuclear program but also was part of a wider
campaign directed from Israel that included assassination of
the countrys nuclear scientists.
Stuxnet is the first discovered worm
that spies on industrial systems and reprograms them. It is written
specifically to attack SCADA systems that are used to control
and monitor industrial processes.
In September 2013 the Islamic
Republic of Iran said that the computer worm Stuxnet infected 30
000 IP addresses in Iran but it denied reports that the cyber worm
had damaged computer systems at the countrys nuclear power plants.
Labels:
Animal Farm Group,
Babar,
Bunny,
Casper,
CERTCC,
Dino,
ESET,
iran,
Islamic Republic,
Israel,
malware,
Mehr News,
SCADA,
spyware,
Stuxnet,
worm
Thursday, October 9, 2014
Iranian cyber criminals target PayPal users with phishing attack
PayPal users were targets of a phishing attack in late 2014.This attack involved the perpetrators sending out spam emails that directed unsuspecting members of the public to follow a link that would take them through to web pages that looked similar to PayPal pages and when they were there customers personal details were collected.
A known Iranian cyber criminal who was involved in setting up the attack, first registered a number of web domains, one of which is http://com-paypal-verification.com:2222/ that they used to host phishing sites. The false domains are designed to look like official PayPal money services sites and login screens that will then collect login details, passwords and credit card numbers.
This is a type of credential harvesting attack which is an example of serious cyber crime.
This attack captures account usernames and passwords and then gives them access to the PayPal account. It is best, to hover your mouse over a link or tap and hold it on a mobile device to see its destination. If you do click on such a link then one or more of the following points could happen:
- You will be directed to a spoof website that collects your personal data (as in the Iranian credential-harvesting attack above)
- Install spyware on your system (it can monitor your actions using a keylogger to steal passwords and or credit card numbers you type online)
- Malware could be installed on your computer that could disable it
How to tell a fake PayPal site:
- If it does not include the paypal.com domain then it is not legitimate
- Only enter password on paypal.com site which starts with https
- URLs:
- If the alleged PayPal domain contains @ sign then it is fake
- Only paypal.com domain is legitimate (it could redirect to your country); examples of fake URLs are www.paypalsecure.com; www.secure-paypal.com; or in the case of Iranian attack http://com-paypal-verification.com
Labels:
credential harvesting,
cyber crime,
cyber criminal,
fake website,
iran,
Iranian,
keylogger,
malware,
PayPal,
phishing,
spam,
spoof website,
spyware
Subscribe to:
Posts (Atom)
-
Since my last post in October, there has been no confirmation of which group was behind the cyber-attack on Westminster, or the role of the ...
-
It's back! It appears that the Shamoon malware aka "Shamoon 2" is targeting Saudi computers. Back in 2012, malware known a...
-
Are Iranian hackers involved in using the " Mamba " ransomware (or possibly be behind the ransomware)? It seems unclear but an...
-
Reuters has reported that Binance the worlds largest cryptocurrency market is helping Iran avoid US sanctions because of very weak identity ...
-
Mohammad-Ali Movahedi Kermani: not liking the Internet In the latest desperate attempt to subvert the freedom of Iranian expression, the...
-
Emen Net Pasargad Iranian Hacker Group The FBI recently announced that Emen net Pasargad an Iranian hacker group that successfully posed as...
-
Censorship comes in many forms and most recently that includes at the barrel of a gun. I speak of course of the murder in Istanbul of Mas...
-
Cisco Talos reports that the Iranian-backed hacking group MuddyWater AKA MERCURY AKA Static Kitten has been caught on another hacking campai...





