News: 1699579636

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Microsoft: Iran's cybercrews got stuck into Israel days after Hamas attacked – not in tandem

(2023/11/10)


Iran's role in the Israel-Hamas war has been largely "reactive and opportunistic," says Microsoft, in contrast to reports that Tehran's spies plotted cyberattacks against Israel to coincide with the October 7 Hamas terrorist atrocity.

Iran's claims about the impact of subsequent computer network breaches were widely inflated, the Windows giant explained in a presentation at the CyberWarCon defense conference in Washington DC. Redmond has been monitoring cybercrews affiliated with Iran's Ministry of Intelligence and Security (MOIS) and Islamic Revolutionary Guard Corps (IRGC) for years now, but noted they didn't appear to be acting with prior knowledge of Hamas's actions.

There's significant overlap between the Iranian cybergangs, but in general security researchers track the MOIS-linked teams as [1]MuddyWater and APT35 (Mandiant), and [2]Rocket Kitten , while [3]APT42 (Mandiant) , [4]Charming Kitten , Imperial Kitten, and [5]Mint Sandstrom (Microsoft) are usually associated with the IRGC.

[6]

"It took 11 days from the start of the ground conflict before Microsoft saw Iran enter the war in the cyber domain," according to Microsoft Threat Intelligence, which posted [7]detailed research presented at the conference on Thursday.

[8]

[9]

The first of two observed destructive cyberattacks targeting Israel's infrastructure occurred on October 18, the threat hunters added, but did not provide details about what infrastructure Iranian cybercrews targeted nor the damage they caused.

It is worth noting that, in separate research published today, CrowdStrike [10]attributed a "series" of cyberattacks in October targeting Israeli transportation, logistics, and technology firms to the IRGC's Imperial Kitten group.

[11]

CrowdStrike also doesn't provide details about the October attacks or their impact, if any, but says the operations and malware used indicate similar tactics and techniques that Imperial Kitten has employed for the last year or so.

[12]Hacktivist attacks erupt in Middle East following Hamas assault on Israel

[13]Adobe sells fake AI-generated Israel-Hamas war images – then the news ran them as real

[14]Iran-linked Charming Kitten espionage gang bares claws to pollies, power orgs

[15]Iran steps up its cybercrime game and Uncle Sam punches back

The Microsoft research indicates that Iranian crews have deployed ransomware at least once since the Israel conflict began.

"Operators leveraged existing access or acquired access to the first available target. Further, the data shows that, in the case of a ransomware attack, Iranian actors' claims of impact and precision targeting were almost certainly fabricated."

This is true to form for Iran-backed miscreants, Microsoft explained, and part of their "tried-and-true" method of "exaggerating the success of their computer network attacks and amplifying those claims and activities via a well-integrated deployment of information operations."

In other words propaganda, amplified by social media, which has become increasingly popular in cyberwar — as we've seen in the ongoing illegal [16]Russian invasion of Ukraine.

[17]

As an example of this in Israel, Redmond's team spotted Iranian crews compromising webcams and then framing this as a strategic operation against a specific military installation.

"In reality, the compromised cameras were located at scattered sites outside any one defined region," Microsoft wrote.

"This suggests that despite Iran actors' strategic claims, this camera example was ultimately a case of adversaries continuing to opportunistically discover and compromise vulnerable connected devices and try to reframe this routine work as more impactful in the context of the current conflict." ®

Get our [18]Tech Resources



[1] https://www.theregister.com/2022/02/24/cyberwarfare_russia_ukraine/

[2] https://www.theregister.com/2022/04/26/iran_rocket_kitten_vmware_exploit/

[3] https://www.theregister.com/2022/09/07/mandiant_apt42_irgc/

[4] https://www.theregister.com/2022/12/15/charming_kitten_ta453_expands_targets//

[5] https://www.microsoft.com/en-us/security/blog/2023/04/18/nation-state-threat-actor-mint-sandstorm-refines-tradecraft-to-attack-high-value-targets/

[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/publicsector&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZU249wFh00uT8YLD7QBJagAAAAc&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[7] https://www.microsoft.com/en-us/security/blog/2023/11/09/microsoft-shares-threat-intelligence-at-cyberwarcon-2023/

[8] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/publicsector&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZU249wFh00uT8YLD7QBJagAAAAc&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[9] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/publicsector&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZU249wFh00uT8YLD7QBJagAAAAc&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[10] https://www.crowdstrike.com/blog/imperial-kitten-deploys-novel-malware-families/

[11] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/publicsector&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZU249wFh00uT8YLD7QBJagAAAAc&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[12] https://www.theregister.com/2023/10/09/hacktivism_middle_east/

[13] https://www.theregister.com/2023/11/08/adobe_ai_israel_hamas_war_pics/

[14] https://www.theregister.com/2022/12/15/charming_kitten_ta453_expands_targets/

[15] https://www.theregister.com/2022/09/15/iran_cybercrime_indictments_sanctions/

[16] https://www.theregister.com/2023/07/20/ukraine_busts_russian_bot_farm/

[17] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/publicsector&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZU249wFh00uT8YLD7QBJagAAAAc&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[18] https://whitepapers.theregister.com/



Under heaven all can see beauty as beauty only because there is ugliness.
All can know good as good only because there is evil.
Therefore having and not having arise together.
Difficult and easy complement each other.
Long and short contrast each other:
High and low rest upon each other;
Voice and sound harmonize each other;
Front and back follow one another.
Therefore the sage goes about doing nothing, teaching no-talking.
The ten thousand things rise and fall without cease,
Creating, yet not.
Working, yet not taking credit.
Work is done, then forgotten.
Therefore it lasts forever.