Google researchers expose Iranian hackers' tool to steal emails from Gmail, Yahoo and Outlook
Full article710 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
Security researchers linked the program to the so-called Charming Kitty Iranian hacker group known to carry out intelligence operations.
Hackers linked to the Iranian government’s cyber espionage unit developed a software tool to retrieve downloaded emails and other data from Gmail, Yahoo and Microsoft Outlook accounts, Google researchers said Tuesday.
The researchers at Google’s Threat Analysis Group, who dubbed the tool “HYPERSCRAPE,” detected the malicious program in December 2021. The Iranian hackers appear to have deployed it against fewer than two dozen accounts located in Iran, according to Ajax Bash, a Google security engineer.
While the oldest known sample dates to 2020, the tool remains under active development, Bash said.
Google took action to secure the affected accounts and notify the victims, Bash said. It’s not clear whether the Iranian hackers actually deployed the code against Yahoo or Outlook email accounts.
The program is likely associated with Charming Kitten, a prolific cyber espionage operation believed to operate under the Iranian Revolutionary Guard Corps, with aspects of its activity tracked variously as APT35, TA453, Phosphorus, ITG18 and Cobalt Illusion. Researchers with cybersecurity firm Secureworks said in May that elements of the group also carry out ransomware attacks, revealing financial motives alongside its traditional espionage role.
Previous research into the group’s tools points to ongoing operational security errors and relatively basic development that aid in attribution yet still work, as was the case with Hyperscrape, Bash said.
“Like much of their tooling, Hyperscrape is not notable for its technical sophistication,” Bash wrote, “but rather its effectiveness in accomplishing Charming Kitten’s objectives.”
For the tool to work, victims either need to be logged into their account or the attackers need their credentials, Bash wrote. Once inside, the tool changes the account’s language settings to English, downloads individual emails and then marks them as unread. The program also deleted any security emails from Google triggered by the activity, Bash wrote.
Older versions of the tool allowed the attacker to request data from Google Takeout, a Google service that enables the bulk downloading of Google account data across a variety of the company’s platforms via downloadable archive file. Subsequent versions did not include the option for unknown reasons.
More Scoops
Iranian hackers ‘tickle’ targets in US, UAE with custom tool, Microsoft says
Peach Sandstorm is said to have focused on the oil and gas, satellite, government and communications sectors.
Iranian hackers impersonate journalists in social engineering campaign
Google: Iranian, regional hacking operations that target Israel remain opportunistic but focused
Latest Podcasts
Government
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
Feds accuse China of ‘systematic’ distillation of U.S. AI models
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
The G7 tells industry to hurry up and prep for post-quantum encryption
Technology
Threats
Microsoft discloses two actively exploited zero-days among 974 vulnerabilities
Russian national extradited to US for alleged involvement in bank-account takeover scheme
Attackers exploit zero-days in consistently besieged SonicWall product
Jail time for Maine child in 764 marks turning point in federal law enforcement
Policy
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
Election official says Tina Peters would be consultant, won’t have access to election systems
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/google-iran-hackers-gmail-irgc-charming-kitten/