US, Iranian hackers in tit-for-tat cyberattacks amid rising tensions

A US Department of Justice employee puts up a poster of the seven indicted hackers prior to a news conference on March 2 in Washington. (AFP)
Updated 23 June 2019
Follow

US, Iranian hackers in tit-for-tat cyberattacks amid rising tensions

  • Iran has long targeted the US oil and gas sectors and other critical infrastructure
  • Tensions spiked this past week after Iran shot down an unmanned US drone

WASHINGTON: US military cyber forces launched a strike against Iranian military computer systems on Thursday as President Donald Trump backed away from plans for a more conventional military strike in response to Iran’s downing of a US surveillance drone, US officials said Saturday.
Two officials told The Associated Press that the strikes were conducted with approval from Trump. A third official confirmed the broad outlines of the strike. All spoke on condition of anonymity because they were not authorized to speak publicly about the operation.
The cyberattacks — a contingency plan developed over weeks amid escalating tensions — disabled Iranian computer systems that controlled its rocket and missile launchers, the officials said. Two of the officials said the attacks, which specifically targeted Iran’s Islamic Revolutionary Guard Corps computer system, were provided as options after Iranian forces blew up two oil tankers earlier this month.
The IRGC, which was designated a foreign terrorist group by the Trump administration earlier this year, is a branch of the Iranian military.
The action by US Cyber Command was a demonstration of the US’s increasingly mature cyber military capabilities and its more aggressive cyber strategy under the Trump administration. Over the last year US officials have focused on persistently engaging with adversaries in cyberspace and undertaking more offensive operations.
Tensions have escalated between the two countries ever since the US withdrew last year from the 2015 nuclear deal with Iran and began a policy of “maximum pressure.” Iran has since been hit by multiple rounds of sanctions. Tensions spiked this past week after Iran shot down an unmanned US drone — an incident that nearly led to a US military strike against Iran on Thursday evening.
The cyberattacks are the latest chapter in the US and Iran’s ongoing cyber operations targeting the other. Yahoo News first reported the cyber strike.

Iranian attacks
In recent weeks, hackers believed to be working for the Iranian government have targeted US government agencies, as well as sectors of the economy, including finance, oil and gas, sending waves of spear-phishing emails, according to representatives of cybersecurity companies CrowdStrike and FireEye, which regularly track such activity. This new campaign appears to have started shortly after the Trump administration imposed sanctions on the Iranian petrochemical sector this month.
It was not known if any of the hackers managed to gain access to the targeted networks with the emails, which typically mimic legitimate emails but contain malicious software.
Tensions have run high between the two countries since the US withdrew from the 2015 nuclear deal with Iran last year and began a policy of “maximum pressure.” Iran has since been hit by multiple rounds of sanctions. Then Iran shot down an unmanned US drone this week.
“Both sides are desperate to know what the other side is thinking,” said John Hultquist, director of intelligence analysis at FireEye. “You can absolutely expect the regime to be leveraging every tool they have available to reduce the uncertainty about what’s going to happen next, about what the US’s next move will be.”
CrowdStrike shared images of the spear-phishing emails with the AP.
One such email that was confirmed by FireEye appeared to come from the Executive Office of the President and seemed to be trying to recruit people for an economic adviser position. Another email was more generic and appeared to include details on updating Microsoft Outlook’s global address book.
The Iranian actor involved in the cyberattack, dubbed “Refined Kitten” by CrowdStrike, has for years targeted the US energy and defense sectors, as well as allies such as Saudi Arabia and the United Arab Emirates, said Adam Meyers, vice president of intelligence at CrowdStrike.
The Department of Homeland Security said in a statement released Saturday that its agency tasked with infrastructure security has been aware of a recent rise in malicious cyber activities directed at US government agencies by Iranian regime actors and proxies.
Cybersecurity and Infrastructure Security Agency Director Christopher C. Krebs said the agency has been working with the intelligence community and cybersecurity partners to monitor Iranian cyber activity and ensure the US and its allies are safe.
“What might start as an account compromise, where you think you might just lose data, can quickly become a situation where you’ve lost your whole network,” Krebs said.
The National Security Agency would not discuss Iranian cyber actions specifically, but said in a statement to the AP on Friday that “there have been serious issues with malicious Iranian cyber actions in the past.”
“In these times of heightened tensions, it is appropriate for everyone to be alert to signs of Iranian aggression in cyberspace and ensure appropriate defenses are in place,” the NSA said.

"Contentious cyber history"

Iran has long targeted the US oil and gas sectors and other critical infrastructure, but those efforts dropped significantly after the nuclear agreement was signed. After Trump withdrew the US from the deal in May 2018, cyber experts said they have seen an increase in Iranian hacking efforts.

“This is not a remote war (anymore),” said Sergio Caltagirone, vice president of threat intelligence at Dragos Inc. “This is one where Iranians could quote unquote bring the war home to the United States.”
Caltagirone said as nations increase their abilities to engage offensively in cyberspace, the ability of the United States to pick a fight internationally and have that fight stay out of the United States physically is increasingly reduced.
The US has had a contentious cyber history with Iran.
In 2010, the so-called Stuxnet virus disrupted the operation of thousands of centrifuges at a uranium enrichment facility in Iran. Iran accused the US and Israel of trying to undermine its nuclear program through covert operations.
Iran has also shown a willingness to conduct destructive campaigns. Iranian hackers in 2012 launched an attack against state-owned oil company Saudi Aramco, releasing a virus that erased data on 30,000 computers and left an image of a burning American flag on screens.
In 2016, the US indicted Iranian hackers for a series of punishing cyberattacks on US banks and a small dam outside of New York City.
The Defense Department refused to comment on the latest Iranian activity. “As a matter of policy and for operational security, we do not discuss cyberspace operations, intelligence or planning,” Pentagon spokeswoman Heather Babb said in a statement. The White House did not respond to a request for comment.
Despite the apparent cyber campaign, experts say the Iranians would not necessarily immediately exploit any access they gain into computer systems and may seek to maintain future capabilities should their relationship with the US further deteriorate.
“It’s important to remember that cyber is not some magic offensive nuke you can fly over and drop one day,” said Oren Falkowitz, a former National Security Agency analyst. It takes years of planning, he said, but as tensions increase, “cyber impact is going to be one of the tools they use and one of the hardest things to defend against.”


Israel says 8 hostages due for release in first phase of truce are dead

Updated 18 sec ago
Follow

Israel says 8 hostages due for release in first phase of truce are dead

JERUSALEM: Eight of the hostages due for release in the first phase of a truce deal between Israel and Hamas are dead, Israeli government spokesman David Mencer said Monday.
“The families have been informed of the situation of their relatives,” Mencer told reporters, without providing the names of the deceased.
That means that of the 26 hostages yet to be freed under the first phase of the agreement, only 18 are still alive.
The truce deal, announced earlier in January after months of fruitless negotiations, took effect on January 19, bringing to a halt more than 15 months of war sparked by Hamas’s October 7, 2023 attack.
Under the first phase of the agreement, 33 hostages held by militants in Gaza are to be released in exchange for more than 1,900 Palestinians held by Israel.
Seven Israeli women have been released since the start of the truce, as have 290 Palestinian prisoners.

Bahraini king, crown prince meet Italian PM in Manama

Updated 27 January 2025
Follow

Bahraini king, crown prince meet Italian PM in Manama

  • King Hamad welcomed Giorgia Meloni at Al-Gudaibiya Palace
  • They discussed bilateral relations, ways to boost cooperation

LONDON: Bahraini King Hamad bin Isa Al-Khalifa received Italian Prime Minister Giorgia Meloni in Manama on Monday.

The Italian premier embarked on an official visit to the Middle East this week, meeting the Saudi leadership in AlUla on Sunday before heading to the Bahraini capital.

King Hamad welcomed Meloni at Al-Gudaibiya Palace in the presence of Prince Salman bin Hamad Al-Khalifa, the crown prince and prime minister.

They discussed bilateral relations and ways to boost cooperation in economics, trade and investment, according to the official Bahrain News Agency.

The king commended Italy’s efforts to promote peace and highlighted the importance of dialogue and diplomatic solutions to address regional as well as global issues, the BNA added.

Meloni expressed her gratitude for King Hamad’s warm hospitality and his efforts to strengthen historical relations between Rome and Manama.

King Hamad hosted a luncheon in honor of the Italian prime minister and her delegation.


Palestinians say two killed in Israeli West Bank strike

Palestinians drive their vehicles past the carcass of a car that was destroyed in an Israeli airstrike in Nur Shams refugee camp
Updated 27 January 2025
Follow

Palestinians say two killed in Israeli West Bank strike

  • Official Palestinian news agency Wafa identified the two killed as Ramez Damiri and Ihab Abu Atwi, both residents of the Nur Shams refugee camp

TULKAREM: The Palestinian health ministry said Monday two Palestinians were killed in an Israeli air strike in the occupied West Bank city of Tulkarem, an attack confirmed by the Israeli military.
The Ramallah-based ministry said in a statement that two dead and three injured arrived at Tulkarem’s Governmental Hospital “following the occupation’s targeting of a vehicle in Nur Shams refugee camp,” adjacent to the city of Tulkarem.
The Israeli army confirmed the strike, and said in a statement that “in a joint operation by the Israeli army and the Shin Bet (internal security agency), an air force aircraft launched an attack shortly ago in the Tulkarem area.”
Official Palestinian news agency Wafa identified the two killed as Ramez Damiri and Ihab Abu Atwi, both residents of the Nur Shams refugee camp.
The health ministry also announced the death of a young man killed Sunday night by Israeli forces in Qalandiya refugee camp, north of Jerusalem.
The ministry reported one dead and two injured “by (Israeli) bullets near Qalandiya camp.”
Wafa news agency identified the man killed as Adam Sab Laban, shot by Israeli forces who were stationed at a military tower by the Qalandiya checkpoint into Jerusalem, and who “opened fire at a group of citizens.”
Violence has soared throughout the West Bank since the war in Gaza broke out on October 7, 2023.
Israeli troops or settlers have killed at least 861 Palestinians in the West Bank since the start of the Gaza war, according to the health ministry.
At least 29 Israelis have been killed in Palestinian attacks or during Israeli military raids in the territory over the same period, according to Israeli official figures.


Lebanon says Israeli fire kills one as residents try to go home

A wounded man who was reportedly shot by Israeli soldiers while attempting to reach southern Lebanon.
Updated 27 January 2025
Follow

Lebanon says Israeli fire kills one as residents try to go home

  • The bloodshed came hours after the extension of a deadline for Israeli forces to withdraw from south Lebanon under a November ceasefire deal

BURJ AL-MULUK: Lebanon’s heath ministry said Israeli fire killed one person Monday and wounded seven others in the south, in a second day of violence as residents tried again to return to border villages.
The bloodshed, which one analyst said was unlikely to re-spark war, came hours after the extension of a deadline for Israeli forces to withdraw from south Lebanon under a November ceasefire deal.
The ministry said Israeli fire killed 24 returnees on Sunday.
“Israeli enemy attacks as citizens attempt to return to their towns that are still occupied have led... to one dead and seven wounded,” the health ministry said Monday in a statement.
It reported one dead and two wounded in the border town of Adaysseh, with others wounded in Bani Hayyan, including a child, as well as in Yarun and Hula.
Caretaker Prime Minister Najib Mikati said earlier Monday that Lebanon had agreed to an extension of the ceasefire deal between Hezbollah and Israel until February 18, after the Israeli military missed Sunday’s deadline to withdraw.
In south Lebanon, residents accompanied by the army were again trying to return to their villages, official media and AFP correspondents reported.
Hezbollah chief Naim Qassem is scheduled to deliver a televised address at 6:30 p.m. (1630 GMT).
In the village of Burj Al-Muluk, an AFP photographer saw dozens of men, women and children gathering in the morning behind a dirt barrier, some holding yellow Hezbollah flags, hoping to reach the border town of Kfar Kila, where the Israeli military is still deployed.
In the city of Bint Jbeil, an access point for many border villages, Hezbollah supporters were distributing sweets, water and images of former chief Hassan Nasrallah, who was killed in an Israeli strike in September.
Others handed out stickers celebrating the “victory from God” as women held pictures of slain Hezbollah fighters.
“They think they are scaring us with their bullets, but we lived under the bombing and bullets don’t scare us,” said Mona Bazzi in Bint Jbeil.
The official National News Agency (NNA) said that Lebanese “army reinforcements” had arrived near the border town of Mais Al-Jabal, where people had started to gather at “the entrance of the town” in preparation for entering alongside the military.
It said the Israeli army had “opened fire in the direction of the Lebanese army” near the town, without reporting casualties there.
“We waited in a long line for hours, but couldn’t enter,” said Mohammed Choukeir, 33, from Mais Al-Jabal, adding that Israeli troops “were opening fire from time to time on civilians gathered at the entrance of the town.”
In nearby Hula, where the health ministry reported two wounded, the NNA said residents entered “after the deployment of the army in several neighborhoods.”
Under the ceasefire deal that took effect on November 27, the Lebanese military was to deploy in the south alongside United Nations peacekeepers as the Israeli army withdrew over a 60-day period, which ended on Sunday.
Hezbollah was also to pull back its forces north of the Litani River — about 30 kilometers (20 miles) from the border.
Both sides have traded blame for delays in implementing the deal, which came after more than a year of hostilities between Israel and Hezbollah, including two months of all-out war.
Lebanon’s army said Sunday that it had entered several border areas including Dhayra, Maroun Al-Ras and Aita Al-Shaab.
An AFP photographer in Aita Al-Shaab on Monday saw widespread destruction, with newly returned families among the ruins of their homes, as bulldozers worked to open roads and rescue teams searched for any bodies leftover from the conflict.
Israeli military spokesman Avichay Adraee on Monday called again for south Lebanon residents to “wait” before returning.
Hilal Khashan, professor of political science at the American University of Beirut, said he did not expect a return to major violence.
“Hezbollah no longer wants any further confrontation with Israel, its goal is to protect its achievements in Lebanon,” he told AFP.
The health ministry said Monday that Israeli fire killed 24 people who were trying to return to their villages the previous day, updating an earlier toll of 22 dead.
The Israeli military had said soldiers “fired warning shots to remove threats” where “suspects were identified approaching the troops.”
The Lebanese army said Sunday it would “continue to accompany residents” returning to the south and “protect them from Israeli attacks.”


19 arrested after Turkiye hotel inferno disaster

Updated 27 January 2025
Follow

19 arrested after Turkiye hotel inferno disaster

ANKARA: Turkish authorities have arrested 19 people as part of an investigation into a fire at a ski resort hotel that killed 78 people, Anadolu state news agency reported Monday.
Those detained include a deputy mayor for the town responsible for the Kartalkaya resort, a deputy fire chief and the head of another establishment belonging to the hotel owner, the agency said.
The investigation into the January 21 disaster has focused on the hotel management and the actions of the emergency services and authorities in the town of Bolu.
On Friday, the owner of the Grand Karta hotel, his son-in-law, the hotel’s chief electrician and its head chef were arrested.
Survivors and experts have highlighted the absence of fire alarms and sprinklers, working smoke detectors and proper fire escape routes at the 12-story building that overlooked the ski slopes.
Interior Minister Ali Yerlikaya has said 238 people were staying in the Grand Karta hotel when the inferno tore through the building in the middle of the night.