Iran Ups its Traditional Cyber Espionage Tradecraft
Iran‘s nation-state hacking machine mostly is known for its destructive cyberattacks: first with Web defacements, then crippling distributed-denial-of-service (DDoS) attacks, and most recently, data-wiping. But Iran increasingly is increasingly honing its operations in pure intelligence-gathering cyber espionage.
Cyber spying is nothing new, but over the past few years it has evolved into more of a step one for sophisticated nation-state hackers to know their targets, burrow in them, and ultimately wage more damaging attacks, such as ransomware, financial crime, data leaks/doxing, intellectual property theft – and in the case of some Iranian hacking teams such as the one behind Shamoon, data-wiping.
FireEye’s research group this week officially christened one Iranian hacking team it has been tracking for more than four years, as APT39 – the same group of hackers that Symantec already calls Chafer and CrowdStrike calls Helix Kitten. The hacking group operates as an old-fashioned cyber espionage operation, but with advanced stealthy tactics and tools to meet its intel-gathering objectives.
Benjamin Read, senior manager of cyber espionage analysis at FireEye, says his team spotted APT39 in December of last year waging attacks against the telecommunications, travel, and technology services sectors, in campaigns aimed at gathering information and records on individuals. The attackers likely were rooting around for details on phone calls of specific individuals, as well as their travel plans and patterns in support of a broad Iranian government espionage operation, he says.
APT39, unlike its counterparts in Iran that wage influence-peddling, disruption, or destructive cyberattacks, focuses specifically on the theft of personal information for use in monitoring, tracking, and surveillance operations by the nation. “They’re generally stealing data … in bulk and then processing it” for usefulness and use, he says, adding that FireEye does not have insight into the types of individuals APT39 is after.
“They’re gaining information on the very target itself,” Jon DiMaggio, senior threat intelligence analyst at Symantec, says of APT39/Chafer. “It appears they do have some cooperation with other groups” in the Middle East region, he says. “That region’s groups really play together often, which is one of the big differences in attacks” there, he notes.
Symantec by policy doesn’t identify nation-state hacking teams by country, but rather, by general region.
Read More: Dark Reading
Iran Briefing | News Press Focus on Human Rights Violation by IRGC, Iran Human Rights
Apr 24, 2019 Comments Off on Trump Administration Sends Warning To Countries That Continue To Import Oil From Iran
Apr 21, 2019 Comments Off on Iran’s Ministry Of Intelligence Arrests Dozens Of Volunteer Relief Workers
Apr 16, 2019 Comments Off on Iraq struggles to distance itself from US-Iran tensions
Apr 16, 2019 Comments Off on Why Trump and Netanyahu are right on Iran
Apr 24, 2019 Comments Off on Workers’ Rights Activists Arrested for Revealing Torture by Intelligence Ministry Held Unlawfully
Apr 22, 2019 Comments Off on Rights Group Calls On Iran To Release Women’s Rights Activists
Apr 22, 2019 Comments Off on Ex-general Says IRGC Was in Bosnia Disguised as Aid Workers
Apr 22, 2019 Comments Off on IRAN’S VIPS JUST GOT A NEW IRGC COMMANDER
Apr 24, 2019 Comments Off on Trump Administration Sends Warning To Countries That Continue To Import Oil From IranTrump Administration Sends Warning To Countries That Continue To Import Oil From Iran Trump Administration Sends Warning To Countries That Continue To Import Oil From Iran The Trump administration is sending a warning...
Apr 17, 2019 Comments Off on Iran Guard’s Former General Says They Were In Bosnia Disguised As Aid WorkersIran Guard’s Former General Says They Were In Bosnia Disguised As Aid Workers Iran Guard’s Former General Says They Were In Bosnia Disguised As Aid Workers Iran’s Islamic Revolution Guards Corps (IRGC)...
Mar 27, 2019 Comments Off on U.S. sanctions firms accused of helping fund Iran’s Revolutionary GuardsU.S. sanctions firms accused of helping fund Iran’s Revolutionary Guards U.S. sanctions firms accused of helping fund Iran’s Revolutionary Guards The United States on Tuesday imposed fresh sanctions on a network of companies and people in Iran, Turkey and the United Arab Emirates it...