Tracking Iran’s cyberterrorism

Updated 01 March 2019
Follow

Tracking Iran’s cyberterrorism

  • Tehran is stepping up its malicious online attacks, experts say — and Saudi Arabia is one of its main targets
  • In 2012, some 35,000 computers were affected by a major cyberattack against Saudi Arabia

DUBAI: Iran is one of the biggest threats in cyberspace, according to experts who warn that a global response is needed to repel its rising wave of cyberattacks on government and communications infrastructure worldwide.

The leading state sponsor of terror is extending its malign presence online, with Saudi Arabia among its main targets. Iran’s growing digital prowess is part of its “soft war” strategy to spy on adversaries and spread its rhetoric. 

“Iran is increasingly active and a growing cyber threat, though it isn’t the most sophisticated actor,” Michael Eisenstadt, Kahn fellow and director of the military and security studies program at the Washington Institute for Near East Policy, told Arab News. “But as past Russian hacking efforts in the US have shown, you don’t need to be technologically sophisticated to hack and then leak emails, causing embarrassment to adversaries.”

In recent months, cybersecurity firms and tech companies have exposed attacks linked to faceless enemies in Iran. 

“Cyber holds a certain appeal” for the country, Eisenstadt said. “Because of the difficulty attributing responsibility for cyber-attacks, it provides Tehran with a degree of deniability,” he said. “Perhaps most importantly, it allows Iran to strike its adversaries globally, instantaneously and on a sustained basis, and to achieve strategic effects in ways it can’t in the physical domain.”

Iran’s greatest adversaries are the US, Israel and Saudi Arabia “in that order,” Eisenstadt said. “In March 2018, the US government designated an Iranian entity, the Mabna Institute, and nine individuals associated with the institute, for operating a massive hacking and cyberspying operation that targeted hundreds of universities and companies in dozens of countries to steal proprietary data and academic research, presumably to help Iran’s own research and development efforts, to circumvent sanctions, and to compensate for its economic isolation. These activities had been going on for years.”

Joyce Hakmeh, a research fellow of cyber policy and co-editor at the Journal of Cyber Policy at the International Security Department at Chatham House, said Iran has been linked to several attacks in the Middle East, including in Saudi Arabia. One of the biggest attacks was identified in 2012, when an Iranian hacker group deployed the Shamoon computer virus to cripple thousands of hard drives at Saudi Aramco. “Everyone remembers the big attack against Saudi Arabia in 2012, which affected 35,000 computers. It was called the biggest hack in history at the time,” she said.

Eisenstadt said there were several attempted strikes on Saudi government and private sector entities using the Shamoon 2.0 malware in 2016 and 2017, and on Italy’s Saipem oil services firm (whose biggest customer is Saudi Aramco) in December 2018.

Hakmeh said while “attribution is a challenge” when it comes to cyber activity, a host of groups have been linked to Tehran’s terror online, including Magic Hound, MuddyWater, APT33, APT34, APT39, Cobalt Gypsy, Rocket Kitten and NewsBeef.

Collectively, these have targeted organizations across the Middle East in industries including finance, government, energy, chemicals and telecommunications.

A 2018 report by the Carnegie Endowment for International Peace noted: “While Iran’s offensive cyber operations have required modest resources to develop, they have allowed Tehran to project itself as an emerging cyber power able to cause significant harm to its adversaries.”

The report said: “As judged from the evidence of coordination between security agency actions and observed cyber operations, the campaigns of Iranian threat actors almost certainly have a direct relationship with government entities, specifically the Islamic Revolutionary Guard Corps and the Ministry of Intelligence. Attempts to forecast the future of Iranian cyber operations are constrained by the secrecy on the part of the Iranian state about its activities and an uncertain geopolitical climate.”

Eisenstadt said when it comes to the biggest threats in cyberspace, the most formidable actors are Russia followed by China, North Korea and Iran. “Iran’s activities in the cyber domain generally serve its broader foreign policy objectives. In some cases, the goal might be to advance Iran’s propaganda line. In others, it might be to steal intellectual property and propriety information, in order to circumvent sanctions and benefit its own research and development efforts,” he said.

Hakmeh said countries, especially in the Middle East, need to build resilience against cyberattacks by sharing information, preparing strategies and educating people about good “cyber hygiene,” such as changing passwords. “While Iran for some years has been considered a third-tier threat, the threat is considerable. It’s a country to monitor, to keep on the map,” she added. “It doesn’t have the same capabilities as China, Russia or the US, but it has been able to be very destructive.” 

While Iran spreads fake news to support its rhetoric against Israel, Saudi Arabia and the US, its more serious attacks are geopolitically motivated, said Hakmeh. “Most of the attacks that Iran has been linked to are for espionage reasons to get a competitive advantage — Saudi Arabia’s petrochemical industry, for example, to see what technology it’s using — or to gain insight into Saudi Arabia’s military capacities so Iran can enhance its own,” she said.

Dr. Johannes Ullrich, dean of research at the SANS Institute, a US company that specializes in information security and cybersecurity training, said as Iran’s conflict with its neighbors grows, so has its presence on the dark web.

“Iran is believed to maintain a significant effort to conduct offensive cyber operations against its adversaries,” he added. “It may not be among the most sophisticated, but it’s very aggressive in applying the skills it has.

“One technique that has been employed in the attacks is domain hijacking. For this attack, an administrator’s password is used to alter settings for an organization’s domain. The attack itself is pretty simple, and the hard part is to get the administrator’s password. It isn’t clear how the administrator password was obtained in these cases, but typically phishing attacks are used. Overall these attacks aren’t terribly sophisticated, but the impact can be huge.”

Aside from hacks on government and company infrastructure, Iran has been linked to a global network of fake news websites. ClearSky, a Tel Aviv-based cyber tech security firm, recently issued a report linking Iranian propagandists to fake news sites in 28 countries that spread misinformation about their targets — chiefly in the Middle East and Asia — and advance Tehran’s ideological and geopolitical interests.

In recent months, FireEye, a US  cybersecurity firm, issued a warning about fake news sites and profiles on Facebook and Twitter that it believed were operated
by Tehran as part of its cyber-
influence campaign.  Such campaigns were also exposed by Twitter, which posted 1 million tweets generated by fake accounts. 

Facebook said it had deleted dozens of fake profiles. Just this month, the platform said it removed 783 accounts tied to Iran that appeared to be engaging in a manipulation campaign against people in almost 30 countries.

Still, experts at the Institute for National Security Studies in the US have said Tehran’s efforts have not been foolproof, with a report noting: “Use of Iranian contact data (such as phone numbers and email addresses), copied content and poor writing has led to their public exposure. Until then, however, Iran managed to reach many people … some contents were viewed by millions of views, and some earned responses by hundreds of thousands of surfers.”

Simone Vernacchia, cybersecurity and digital infrastructure advisory lead at PwC Middle East, said that while it is against his company’s policy to attribute cyberattacks to a specific “nation-state actor,” the firm had noted an “increase in disruptive attacks, which may be sponsored by a nation-state.”

Although there has been a big increase in investment in cybersecurity in past months, many Middle Eastern countries’ defense systems remain less advanced than those in the West, he said.

“A stronger collaboration among privately owned critical infrastructure and government defense systems, as well as a strong and periodically tested set of organizational and technical interfaces, would strengthen the ability to respond to crises,” he said.


UN chief condemns ‘escalation’ between Yemen’s Houthis and Israel

Updated 27 December 2024
Follow

UN chief condemns ‘escalation’ between Yemen’s Houthis and Israel

NEW YORK: The UN chief on Thursday denounced the “escalation” in hostilities between Yemen’s Houthi rebels and Israel, terming strikes on the Sanaa airport “especially alarming.”
“The Secretary-General condemns the escalation between Yemen and Israel. Israeli airstrikes today on Sana’a International Airport, the Red Sea ports and power stations in Yemen are especially alarming,” said a spokesperson for UN Secretary-General Antonio Guterres in a statement.
Israeli air strikes pummelled Sanaa’s international airport and other targets in Yemen on Thursday, with Houthi rebel media reporting six deaths.
The attack came a day after the Houthis fired a missile and two drones at Israel.
World Health Organization chief Tedros Adhanom Ghebreyesus said on social media he was at the airport during the strike, with the UN saying that a member of its air crew was injured.
The United Nations put the death toll from the airport strikes at three, with “dozens more injured.”
UN chief Guterres expressed particular alarm at the threat that bombing transportation infrastructure posed to humanitarian aid operations in Yemen, where 80 percent of the population is dependent on aid.
“The Secretary-General remains deeply concerned about the risk of further escalation in the region and reiterates his call for all parties concerned to cease all military actions and exercise utmost restraint,” he said.
“He also warns that airstrikes on Red Sea ports and Sana’a airport pose grave risks to humanitarian operations at a time when millions of people are in need of life-saving assistance.”
The UN chief condemned the Houthi rebels for “a year of escalatory actions... in the Red Sea and the region that threaten civilians, regional stability and freedom of maritime navigation.”
The Houthis are part of Iran’s “axis of resistance” alliance against Israel.


Bodies of about 100 Kurdish women, children found in Iraq mass grave

Updated 27 December 2024
Follow

Bodies of about 100 Kurdish women, children found in Iraq mass grave

TAL AL-SHAIKHIA, Iraq: Iraqi authorities are working to exhume the remains of around 100 Kurdish women and children thought to have been killed in the 1980s under former Iraqi ruler Saddam Hussein, three officials said.
The grave was discovered in Tal Al-Shaikhia in the Muthanna province in southern Iraq, about 15-20 kilometers (10-12 miles) from the main road there, an AFP journalist said.
Specialized teams began exhuming the grave earlier this month after it was initially discovered in 2019, said Diaa Karim, the head of the Iraqi authority for mass graves, adding that it is the second such grave to be uncovered at the site.
“After removing the first layer of soil and the remains appearing clearly, it was discovered that they all belonged to women and children dressed in Kurdish springtime clothes,” Karim told AFP on Wednesday.
He added that they likely came from Kalar in the northern Sulaimaniyah province, part of what is now Iraq’s autonomous Kurdistan region, estimating that there were “no less than 100” people buried in the grave.
Efforts to exhume all the bodies are ongoing, he said, adding that the numbers could change.
Following Iraq’s deadly war with Iran in the 1980s, Saddam’s government carried out the ruthless “Anfal Operation” between 1987 and 1988 in which it is thought to have killed around 180,000 Kurds.
Saddam was toppled in 2003 following a US-led invasion of Iraq and was hanged three years later, putting an end to Iraqi proceedings against him on charges of genocide over the Anfal campaign.
Karim said a large number of the victims found in the grave “were executed here with live shots to the head fired at short range.”
He suggested some of them may have been “buried alive” as there was no evidence of bullets in their remains.
Ahmed Qusai, the head of the excavation team for mass graves in Iraq, meanwhile pointed to “difficulties we are facing at this grave because the remains have become entangled as some of the mothers were holding their infants” when they were killed.
Durgham Kamel, part of the authority for exhuming mass graves, said another mass grave was found at the same time that they began exhuming the one at Tal Al-Shaikhia.
He said the burial site was located near the notorious Nugrat Al-Salman prison where Saddam’s authorities held dissidents.
The Iraqi government estimates that about 1.3 million people disappeared between 1980 and 1990 as a result of atrocities and other rights violations committed under Saddam.


Brother of suspected ‘terrorist’ stabs Tunisia National Guard officer

Updated 27 December 2024
Follow

Brother of suspected ‘terrorist’ stabs Tunisia National Guard officer

TUNIS: The brother of a suspected “terrorist” on Thursday stabbed a Tunisian National Guard officer in the eastern Monastir governorate, a judicial source told AFP.
Earlier in the day, a National Guard unit attempted to arrest the suspect — accused by authorities of being a member of a “terrorist group” — at his home, said the source, speaking on condition of anonymity.
During the arrest operation, his brother attacked the officer, the source added.
The source said the officer was hospitalized following the stabbing in his abdomen and was recovering after undergoing surgery.
An investigation was opened by the judicial division combatting terrorism, the source added.
Neither of the brothers, both of whom were taken into police custody, have been named, and the Tunisian interior ministry did not respond to AFP’s request for comment.
Tunisia saw a surge in jihadist groups after the 2011 revolution that overthrew the dictatorship of Zine El Abidine Ben Ali.
Attacks claimed by jihadists in recent years have killed dozens of soldiers and police officers, as well as some civilians and foreign tourists.
Jihadist attacks in Sousse and the capital Tunis in 2015 killed dozens of tourists and police, but authorities say they have since made significant progress against extremism.


Palestinian hospital director says Israeli strike kills 5 staff in Gaza

A woman and children react at the site of an Israeli strike in a residential area in the Tuffah neighbourhood, east of Gaza City
Updated 26 December 2024
Follow

Palestinian hospital director says Israeli strike kills 5 staff in Gaza

  • WHO has described conditions at Kamal Adwan hospital as “appalling” and said it was operating at a “minimum” level

GAZA STRIP: Five staff at one of northern Gaza’s last functioning hospitals were killed by an Israeli strike on Thursday, the facility’s director said, more than two months into an Israeli operation in the area.
Hossam Abu Safiya, head of the Kamal Adwan hospital in Beit Lahia, said “an Israeli strike resulted in five martyrs among the hospital staff.” The Israeli military did not immediately respond to a request for comment.
Israel has been pressing a major offensive in northern Gaza since October 6, saying it aims to prevent Hamas militants from regrouping.
At the other end of the Palestinian territory, the chief paediatric doctor at the Nasser Hospital in Khan Yunis said three babies had died from a “severe temperature drop” this week as winter cold sets in.
Doctor Ahmed Al-Farra said the most recent case was a three-week-old girl who was “brought to the emergency room with a severe temperature drop, which led to her death.”
A three-day-old baby and another “less than a month old” died on Tuesday, he said.
Meanwhile, in central Gaza, a Palestinian TV channel affiliated with a militant group said five of its journalists were killed on Thursday in an Israeli strike on their vehicle in Gaza, with Israel’s military saying it had targeted a “terrorist cell.”
Witnesses said a missile struck the van while it was parked outside Al-Awda Hospital in Nuseirat.
The three-week-old girl, Sila Al-Faseeh, was living in a tent in Al-Mawasi, an area designated a humanitarian safe zone by the Israeli military that is home to huge numbers of displaced Palestinians.
“The tents do not protect from the cold, and it gets very cold at night, with no way to keep warm,” said Farra.
He said many mothers were suffering from malnutrition which affected the quality of their breast milk and compounded the risks to newborns.
Sila’s father Mahmoud Al-Faseeh said it was “extremely cold, and the tent is not suitable for living. The children are always sick.”
The United Nations and other organizations have repeatedly decried the worsening humanitarian conditions in Gaza, particularly in the north, since Israel began its latest military offensive in early October.
The World Health Organization has described conditions at Kamal Adwan hospital as “appalling” and said it was operating at a “minimum” level.
Earlier on Thursday, Gaza’s civil defense agency said that five other people had been killed by Israeli strikes during the day in the north of Gaza.
Meanwhile, the Israeli military said a 35-year-old soldier was killed in the central Gaza Strip. It brings to 390 the number of Israeli soldiers killed since the start of ground operations in the Palestinian territory.


The journalists’ employer Al-Quds Today said in a statement that a missile hit their broadcast van while it was parked in the Nuseirat refugee camp in central Gaza.
The channel is affiliated with Islamic Jihad, whose militants have fought alongside Hamas in the Gaza Strip and took part in the October 7, 2023 attack on Israel that sparked the war.
The station identified the five staffers as Faisal Abu Al-Qumsan, Ayman Al-Jadi, Ibrahim Al-Sheikh Khalil, Fadi Hassouna and Mohammed Al-Ladaa.
They were killed “while performing their journalistic and humanitarian duty,” the statement said.
The Israeli military said it had conducted a “precise strike” and that those killed “were Islamic Jihad operatives posing as journalists.”
The Committee to Protect Journalists’ Middle East arm said in a statement it was “devastated by the reports.”
“Journalists are civilians and must always be protected,” it added.
The Palestinian Journalists Syndicate said last week that more than 190 journalists had been killed and at least 400 injured since the start of the war in Gaza.
The war was triggered by the Hamas-led October 7 attack last year, which resulted in 1,208 deaths, mostly civilians, according to an AFP tally of Israeli official figures.
Israel’s retaliatory military campaign has killed at least 45,399 people in Gaza, a majority of them civilians, according to figures from the Hamas-run territory’s health ministry that the UN considers reliable.


Israeli attorney general orders probe into report that alleged Netanyahu’s wife harassed opponents

Israel's PM Benjamin Netanyahu, from left, his wife Sara Netanyahu, President Isaac Herzog and First Lady Michal Herzog.
Updated 26 December 2024
Follow

Israeli attorney general orders probe into report that alleged Netanyahu’s wife harassed opponents

  • Program uncovered a trove of WhatsApp messages in which Mrs. Netanyahu appears to instruct a former aide to organize protests against political opponents

JERUSALEM: Israel’s attorney general has ordered police to open an investigation into Prime Minister Benjamin Netanyahu’s wife on suspicion of harassing political opponents and witnesses in the Israeli leader’s corruption trial.
The Israeli Justice Ministry made the announcement in a terse message late Thursday, saying the investigation would focus on the findings of a recent report by the “Uvda” investigative program into Sara Netanyahu.
The program uncovered a trove of WhatsApp messages in which Mrs. Netanyahu appears to instruct a former aide to organize protests against political opponents and to intimidate Hadas Klein, a key witness in the trial.
The announcement did not mention Mrs. Netanyahu by name, and the Justice Ministry declined further comment.
But in a video released earlier Thursday, Netanyahu listed what he said were the many kind and charitable acts by his wife and blasted the Uvda report as “lies.”
It was the latest in a long line of legal troubles for the Netanyahus — highlighted by the prime minister's ongoing corruption trial.
Netanyahu is charged with fraud, breach of trust and accepting bribes in a series of cases alleging he exchanged favors with powerful media moguls and wealthy associates. Netanyahu denies the charges and says he is the victim of a “witch hunt” by overzealous prosecutors, police and the media.