Wednesday, October 14, 2015

Iranian Hackers and Romanian Hackers Work Together




Norse Intelligence Analysis Team identified several indicators that reveal a trend of hacking groups in Middle East working closely with European hackers to share tactics and techniques for conducting attacks.

According to Norse reports this trend shows a pattern of direct and continuous contact between Middle Eastern hackers traveling to Europe to obtain training and experience then staying or returning home to begin political attacks on global targets.



Norse offers three cases to support this theory, including one case of Iranian hacking group Ashiyane Digital Security Team -ADST-.




According to Norse reports Ashiyane Digital Security Team and Romanian Security Team -RST-, which is the largest online hacker community based in Romania, have been exchanging exploit and target data.

A series of posts on the RST forum announced a list of compromised Simple Message Text Protocol -SMTP- systems. A large number of the same compromised systems appeared six months later in a post on the Ashiyane forum from a hacker, who it is known he operates in France. Some of the compromised SMTP systems were identified by Norse that they are used in phishing campaigns as well as other malicious activity.

Reference:

The Ottoman Hackers? Middle Eastern and Eastern European Exploit Exchange Program


Links:

Ashiyane Digital Security Team
Romanian Security Team

Monday, August 10, 2015

Iranian Dark Coders Hacking Team: Everywhere and Anywhere but not Harmless



A presentation at American security conference BlackHat USA in Las Vegas, has said that Iran appears to be actively seeking for critical national infrastructure systems connected to the Internet to exploit them.

At BlackHat USA Trend Micro researchers Kyle Wilhoit and Stephen Hilt revealed how their honeypot version of a Vedeer-Root Guardian AST gas gauge monitoring system (nickname «Gaspot») apparently fooled some Iranian hackers.




The Iranian hacking group Iranian Dark Coders, so called IDC-Team, modified the names of two pumps situated in Jordan. The IDC-Team which is best known for defacements and malware distribution, renamed two different tank names in the systems, one as «H4CK3D by IDC-TEAM» and other as «AHAAD Was Here»




IDC-Team

This is not a new thing. As a Google search will show IDC-Team has been hacking websites for a long time. According to their Facebook page the team started in 2012 and have grown since then in to a team with many members on its forum talking about hacks and bugs and computer security.

Over the last year IDC-Team have submitted more than 950 website defacements of targets all over the world. Many of these defacements are government sites (gov.pl, gov.co, gov.in) or companies with famous products (Jeep). This shows that the team have hacking skills that are enough advanced to damage to secure websites.

Why do they hack?

Despite the amount of hacks by IDC-Team and who they hack it is clear their agenda is little more than publicity. Their defacements are advertisements for their community and the individuals involved and they are not messages of hate and violence.

IDC-Team is everywhere and goes anywhere as Trend Micro revealed. However they appear to be looking for recognition as computer security experts and not hacktivists.