Suspected Iranian hackers exploit VPN, Telegram to monitor dissidents
Full article761 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
The research shows the limits of the cyber industry’s knowledge of Tehran-linked hacking against those who often bear the brunt of it.
For the last six years, hackers have stalked Iranian dissidents with spying tools that mimic the software those dissidents use to protect their communications, security firm Kaspersky said Wednesday.
Researchers from Kaspersky and other firms only recently pieced together the activity, showing the limits of the cyber industry’s knowledge of Tehran-linked hacking against those who often bear the brunt of it: Iranian citizens.
While Kaspersky researchers did not attribute the hacking to the Iranian government, FireEye, another security firm, said it suspected the hackers were affiliated with Tehran. The findings are consistent with a surveillance dragnet that Iranian authorities have used to jail and beat protesters who challenge the regime. Iranian security services killed 304 people in a 2019 crackdown, according to Amnesty International.
The hackers, Kaspersky said, have sent their targets malware-laced images and videos claiming to be from prisoners in Iran. When opened, the malicious documents hijack users’ Google Chrome browsers and Telegram, an encrypted app popular among Iranian activists, to try to steal data. The attackers’ also planted malicious code in Psiphon, a virtual private networking software that Iranians use to evade censorship, according to the research.
The researchers said they didn’t know how many people had been breached in the hacking campaign.
The malicious code analyzed by Kaspersky “can take screenshots and has a keylogging capability,” Kaspersky researchers Aseel Kayal, Mark Lechtik and Paul Rascagneres said in an email. “With these two features, it can monitor the victim’s correspondences and conversations such as instant messaging or emails.”
Tehran has a long history of allegedly using its cyber capabilities on its own citizens.
“In addition to the activity documented in this blog, Mandiant has seen Iran-nexus groups deploy mobile malware and spear phish dissidents to try to gain access to email and social media accounts,” said Ben Read, an analyst at FireEye, when questioned on the latest findings.
The U.S. Treasury Department in September announced sanctions against dozens of Iranians, including alleged members of a hacking group known as APT39, for allegedly targeting Iranian dissidents and journalists. Those hackers are accused of operating on behalf of Iran’s Ministry of Intelligence. Then, in February, security researchers from Check Point exposed more Iranian government-linked attempts to break into the devices of dissidents abroad.
“Regime preservation is the primary concern for many of the Iranian security services that sponsor cyber espionage,” said Read, director of analysis at Mandiant Threat Intelligence. “Iran has always used their cyber capabilities to gather information on individuals, inside and outside Iran, that they view as threats to regime stability.”
Iran regularly denies conducting cyberattacks. A spokesperson for the Iranian Mission to the United Nations did not immediately respond to a request for comment on the research.
The Biden administration has pledged to put human rights at the center of its cybersecurity agenda, but it’s unclear how that will manifest in relations with Iran.
“Far too often cybersecurity is used as a pretext to infringe on civil liberties and human rights,” Homeland Security Secretary Alejandro Mayorkas said in March. “At the end of the day, cybersecurity is about people. It is about protecting our way of life and protecting what we hold dear.”
Latest Podcasts
Government
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
Feds accuse China of ‘systematic’ distillation of U.S. AI models
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
The G7 tells industry to hurry up and prep for post-quantum encryption
Technology
Threats
Chinese espionage groups swarm to exploit triple-link chain of zero-days
Microsoft discloses two actively exploited zero-days among 974 vulnerabilities
Russian national extradited to US for alleged involvement in bank-account takeover scheme
Attackers exploit zero-days in consistently besieged SonicWall product
Policy
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/iran-hackers-protests-kaspersky/