Posts

Showing posts with the label Iran

Iran-Linked MuddyWater Deploys Atera for Surveillance in Phishing Attacks

Image
By  The Hacker News Key Points MuddyWater Phishing : MuddyWater used seemingly harmless PDF attachments containing malicious links. Clicking these links downloaded an installer for the real Atera Agent (RMM software), granting them unauthorized access to compromised systems. Shift in Tactics : This campaign represents a shift for MuddyWater, who previously relied on directly embedded malicious links. This new tactic increases deception and potentially widens their attack reach. MuddyWater Targets : This is not the first time MuddyWater has targeted organizations. Since October 2023, they’ve used other legitimate remote access tools for infiltration attempts. Supply Chain Attack : Another Iranian group, Lord Nemesis, compromised a software provider in a supply chain attack, potentially impacting their clients. Dangers of Supply Chain Attacks : This attack highlights the growing risk of supply chain attacks, where compromising a trusted vendor grants access to a wider network of targ...

Iranian hack likely set off sirens in Jerusalem, Eilat, say cyber-security experts

Report: The attack targeted municipal alert systems but did not breach essential IDF infrastructure. By  JNS A suspected Iranian cyber attack likely set off rocket-warning sirens in the cities of Jerusalem and Eilat on Sunday, Israeli media reported. Israeli cyber-security authorities said the attack targeted municipal alert systems but did not breach essential IDF infrastructure, according to Ynet. Authorities “instructed local councils to take precautionary steps to secure their alert systems, since they were activated by municipal alert systems and not by the IDF’s Home Front Command,” the report issued on Monday said. The report cited Yoram Cohen, head of the Israel Internet Association, as saying that the hack “did not appear to harm any vital infrastructure,” but that it had once again exposed vulnerabilities in civilian systems. “There is a gap between Israel’s excellent cyber defenses on critical infrastructure compared to non-critical civilian systems,” said Cohen. “This w...

WATCH: Israeli Cyber Pros Expose Iranians Hacking Top Officials

Image
Israeli cybersecurity company CheckPoint revealed that Iranian hackers broke into email accounts of senior Israeli officials to gather critical intel. By  United With Israel As tensions mount between Iran and Israel, Israeli cyber security company CheckPoint revealed that Iranian hackers broke into the email accounts of senior Israeli officials to gather critical intel. Some of the high-profile targets included former Foreign Minister Tzipi Livni, a reserve general who dealt with sensitive and complex matters, the former US ambassador to Israel, and the head of a large security research institute in Israel. Gil Messing, CEO of CheckPoint, discusses what the hackers managed to achieve and what all Israelis should do to protect themselves.

Wray: FBI blocked planned cyberattack on children’s hospital

By Eric Tucker & Alan Suderman, NBC The FBI thwarted a planned cyberattack on a children’s hospital in Boston that was to have been carried out by hackers sponsored by the Iranian government, FBI Director Christopher Wray said Wednesday. Wray told a Boston College cybersecurity conference that his agents learned of the planned digital attack from an unspecified intelligence partner and got Boston Children’s Hospital the information it needed last summer to block what would have been “one of the most despicable cyberattacks I’ve seen.” “And quick actions by everyone involved, especially at the hospital, protected both the network and the sick kids who depended on it,” Wray said. The FBI chief recounted that anecdote in a broader speech about cyber threats from Russia, China and Iran, and the need for partnerships between the U.S. government and the private sector. He said the bureau and Boston Children’s Hospital had worked closely after a hacktivist attacked the hospital’s computer...

Iranian hackers exposed in a highly targeted espionage campaign

By Bill Toulas, Bleeping Computer Threat analysts have spotted a novel attack attributed to the Iranian hacking group known as APT34 group or Oilrig, who targeted a Jordanian diplomat with custom-crafted tools. The attack involved advanced anti-detection and anti-analysis techniques and had some characteristics that indicate lengthy and careful preparation. Security researchers at Fortinet have gathered evidence and artifacts from the attack in May 2022 and compiled a technical report to highlight APT34’s latest techniques and methods. Targeting diplomats The spear-phishing email seen by Fortinet targeted a Jordanian diplomat, pretending to be from a colleague in the government, with the email address spoofed accordingly. The email carried a malicious Excel attachment that contained VBA macro code that executes to create three files, a malicious executable, a configuration file, and a signed and clean DLL. The macro also creates persistence for the malicious executable (update.exe) by ...

Cybersecurity Stocks Increase—Bad News for US Businesses and Agencies?

Image
By Griffin Davis, Tech Times Cybersecurity stocks are now increasing as more people invest in security firms. This may sound like a good thing since the industry that focuses on preventing hackers, and other online attackers is further growing.   A participant looks at lines of code on a laptop on the first day of the 28th Chaos Communication Congress (28C3) - Behind Enemy Lines computer hacker conference on December 27, 2011 in Berlin, Germany. The Chaos Computer Club is Europe's biggest network of computer hackers and its annual congress draws up to 3,000 participants. However, this is bad news for some U.S. companies and government agencies. Among the cybersecurity firms that experience share increases are FireEye Inc. and Crowdstrike Holdingfs Inc.  "It's really the pure-play security companies that do threat detection that are the ones that can be the direct beneficiary of something like this," said Mandeep Singh, an intelligence analyst working for Bloomberg.  ...