IBM sounds alarm about more data
Full article642 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
The new research is the latest indication of Iran’s disruptive capabilities in cyberspace.
IBM’s security experts said Wednesday they have uncovered previously unknown malware developed by Iranian hackers that was used in a data-wiping attack against unnamed energy and industrial organizations the Middle East.
The newfound malware, dubbed ZeroCleare, “spread to numerous devices on the affected network, sowing the seeds of a destructive attack that could affect thousands of devices and cause disruption that could take months to fully recover from,” Limor Kessem, an Israel-based analyst with IBM’s X-Force incident response team, wrote in a blog post.
The discovery adds to years of evidence that hackers linked to the Iranian government have developed and deployed data-destroying code against multiple targets in the Middle East. Security analysts have warned that Iran could step up its use of cyberattacks amid heightened tensions with Saudi Arabia and the United States.
IBM analysts believe APT34 — a hacking group linked with the Iranian government — and at least one other group based in Iran “collaborated on the destructive portion of the ZeroCleare attack.”
Like Shamoon, the infamous malware also linked to Iran that damaged tens of thousands of computers at oil giant Saudi Aramco in 2012, ZeroCleare is designed to overwrite the master boot record (MBR) on Windows machines. The MBR is a program that executes every time a computer is restarted, making it a vital engine for an operating system.
Both sets of malware abuse EldoS RawDisk, a legitimate program used to handle files and digital partitions, according to Kessem.
“It is possible that it is a recently developed malware and that the campaign we analyzed is one of the first to use this version,” she wrote, noting that ZeroCleare exploits a vulnerable computer driver to get around Windows controls.
The new IBM research is the latest indication of Iran’s disruptive intentions in cyberspace.
Last month, Microsoft security researchers said APT33, an aggressive Iran-linked hacking group, had shifted its targeting to industrial control systems used in the energy sector. “You have an actor that has been linked to deployment of destructive payloads in the past,” said Microsoft security researcher Ned Moran, laying out his concerns.
A decade ago, it was Iran that suffered a cyberattack that actually destroyed physical equipment when Stuxnet, the computer worm reportedly developed by the U.S. and Israel, was used to knock out centrifuges at an Iranian uranium enrichment facility. NSA officials have worried that the Iranians learned from capabilities such as Stuxnet to augment their own hacking abilities, according to a document leaked by former NSA contractor Edward Snowden.
Latest Podcasts
Government
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
Feds accuse China of ‘systematic’ distillation of U.S. AI models
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
Jail time for Maine child in 764 marks turning point in federal law enforcement
Technology
Threats
Chinese espionage groups swarm to exploit triple-link chain of zero-days
Microsoft discloses two actively exploited zero-days among 974 vulnerabilities
Russian national extradited to US for alleged involvement in bank-account takeover scheme
Attackers exploit zero-days in consistently besieged SonicWall product
Policy
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
Election official says Tina Peters would be consultant, won’t have access to election systems
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/iran-destructive-malware-ibm/