US, Iranian hackers in tit-for-tat cyberattacks amid rising tensions

A US Department of Justice employee puts up a poster of the seven indicted hackers prior to a news conference on March 2 in Washington. (AFP)
Updated 23 June 2019
Follow

US, Iranian hackers in tit-for-tat cyberattacks amid rising tensions

  • Iran has long targeted the US oil and gas sectors and other critical infrastructure
  • Tensions spiked this past week after Iran shot down an unmanned US drone

WASHINGTON: US military cyber forces launched a strike against Iranian military computer systems on Thursday as President Donald Trump backed away from plans for a more conventional military strike in response to Iran’s downing of a US surveillance drone, US officials said Saturday.
Two officials told The Associated Press that the strikes were conducted with approval from Trump. A third official confirmed the broad outlines of the strike. All spoke on condition of anonymity because they were not authorized to speak publicly about the operation.
The cyberattacks — a contingency plan developed over weeks amid escalating tensions — disabled Iranian computer systems that controlled its rocket and missile launchers, the officials said. Two of the officials said the attacks, which specifically targeted Iran’s Islamic Revolutionary Guard Corps computer system, were provided as options after Iranian forces blew up two oil tankers earlier this month.
The IRGC, which was designated a foreign terrorist group by the Trump administration earlier this year, is a branch of the Iranian military.
The action by US Cyber Command was a demonstration of the US’s increasingly mature cyber military capabilities and its more aggressive cyber strategy under the Trump administration. Over the last year US officials have focused on persistently engaging with adversaries in cyberspace and undertaking more offensive operations.
Tensions have escalated between the two countries ever since the US withdrew last year from the 2015 nuclear deal with Iran and began a policy of “maximum pressure.” Iran has since been hit by multiple rounds of sanctions. Tensions spiked this past week after Iran shot down an unmanned US drone — an incident that nearly led to a US military strike against Iran on Thursday evening.
The cyberattacks are the latest chapter in the US and Iran’s ongoing cyber operations targeting the other. Yahoo News first reported the cyber strike.

Iranian attacks
In recent weeks, hackers believed to be working for the Iranian government have targeted US government agencies, as well as sectors of the economy, including finance, oil and gas, sending waves of spear-phishing emails, according to representatives of cybersecurity companies CrowdStrike and FireEye, which regularly track such activity. This new campaign appears to have started shortly after the Trump administration imposed sanctions on the Iranian petrochemical sector this month.
It was not known if any of the hackers managed to gain access to the targeted networks with the emails, which typically mimic legitimate emails but contain malicious software.
Tensions have run high between the two countries since the US withdrew from the 2015 nuclear deal with Iran last year and began a policy of “maximum pressure.” Iran has since been hit by multiple rounds of sanctions. Then Iran shot down an unmanned US drone this week.
“Both sides are desperate to know what the other side is thinking,” said John Hultquist, director of intelligence analysis at FireEye. “You can absolutely expect the regime to be leveraging every tool they have available to reduce the uncertainty about what’s going to happen next, about what the US’s next move will be.”
CrowdStrike shared images of the spear-phishing emails with the AP.
One such email that was confirmed by FireEye appeared to come from the Executive Office of the President and seemed to be trying to recruit people for an economic adviser position. Another email was more generic and appeared to include details on updating Microsoft Outlook’s global address book.
The Iranian actor involved in the cyberattack, dubbed “Refined Kitten” by CrowdStrike, has for years targeted the US energy and defense sectors, as well as allies such as Saudi Arabia and the United Arab Emirates, said Adam Meyers, vice president of intelligence at CrowdStrike.
The Department of Homeland Security said in a statement released Saturday that its agency tasked with infrastructure security has been aware of a recent rise in malicious cyber activities directed at US government agencies by Iranian regime actors and proxies.
Cybersecurity and Infrastructure Security Agency Director Christopher C. Krebs said the agency has been working with the intelligence community and cybersecurity partners to monitor Iranian cyber activity and ensure the US and its allies are safe.
“What might start as an account compromise, where you think you might just lose data, can quickly become a situation where you’ve lost your whole network,” Krebs said.
The National Security Agency would not discuss Iranian cyber actions specifically, but said in a statement to the AP on Friday that “there have been serious issues with malicious Iranian cyber actions in the past.”
“In these times of heightened tensions, it is appropriate for everyone to be alert to signs of Iranian aggression in cyberspace and ensure appropriate defenses are in place,” the NSA said.

"Contentious cyber history"

Iran has long targeted the US oil and gas sectors and other critical infrastructure, but those efforts dropped significantly after the nuclear agreement was signed. After Trump withdrew the US from the deal in May 2018, cyber experts said they have seen an increase in Iranian hacking efforts.

“This is not a remote war (anymore),” said Sergio Caltagirone, vice president of threat intelligence at Dragos Inc. “This is one where Iranians could quote unquote bring the war home to the United States.”
Caltagirone said as nations increase their abilities to engage offensively in cyberspace, the ability of the United States to pick a fight internationally and have that fight stay out of the United States physically is increasingly reduced.
The US has had a contentious cyber history with Iran.
In 2010, the so-called Stuxnet virus disrupted the operation of thousands of centrifuges at a uranium enrichment facility in Iran. Iran accused the US and Israel of trying to undermine its nuclear program through covert operations.
Iran has also shown a willingness to conduct destructive campaigns. Iranian hackers in 2012 launched an attack against state-owned oil company Saudi Aramco, releasing a virus that erased data on 30,000 computers and left an image of a burning American flag on screens.
In 2016, the US indicted Iranian hackers for a series of punishing cyberattacks on US banks and a small dam outside of New York City.
The Defense Department refused to comment on the latest Iranian activity. “As a matter of policy and for operational security, we do not discuss cyberspace operations, intelligence or planning,” Pentagon spokeswoman Heather Babb said in a statement. The White House did not respond to a request for comment.
Despite the apparent cyber campaign, experts say the Iranians would not necessarily immediately exploit any access they gain into computer systems and may seek to maintain future capabilities should their relationship with the US further deteriorate.
“It’s important to remember that cyber is not some magic offensive nuke you can fly over and drop one day,” said Oren Falkowitz, a former National Security Agency analyst. It takes years of planning, he said, but as tensions increase, “cyber impact is going to be one of the tools they use and one of the hardest things to defend against.”


UN worker seriously hurt in Israeli Yemen strike moved to Jordan, WHO says

Updated 7 sec ago
Follow

UN worker seriously hurt in Israeli Yemen strike moved to Jordan, WHO says

ZURICH: The UN worker hurt in an Israeli air strike on Yemen’s main international airport on Thursday suffered serious injuries and has been evacuated to Jordan for further treatment, the World Health Organization said on Friday.
Israel said it had struck multiple targets linked to the Iran-aligned Houthi movement in Yemen, including Sanaa International Airport, and Houthi media said at least six people had been killed.
“Attacks on civilians and humanitarians must stop, everywhere. #NotATarget,” WHO Director-General Tedros Adhanom Ghebreyesus said in a post on X that showed him sitting in a plane looking across at what appeared to be the injured man.
Tedros was at the airport waiting to depart when the aerial bombardment took place that injured the man, who worked for the UN Humanitarian Air Service. A spokesperson for the WHO said the man had been seriously injured.
Tedros said he and the UN worker were now in Jordan.
The man underwent a successful surgical procedure prior to his evacuation for further treatment, Tedros said.
He had been in Yemen to negotiate the release of detained UN staff and to assess the humanitarian situation.

Jordan’s King Abdullah reaffirms support for Syria’s sovereignty, calls for Gaza ceasefire

Updated 12 min 17 sec ago
Follow

Jordan’s King Abdullah reaffirms support for Syria’s sovereignty, calls for Gaza ceasefire

  • King in phone conversation with French president

AMMAN: King Abdullah II reaffirmed on Friday Jordan’s commitment to supporting Syria in building a free, independent, and fully sovereign state that reflected the aspirations of all its people.

In a phone conversation with French President Emmanuel Macron, the king emphasized the importance of Syria’s security, and stability for the Middle East region as a whole. He also reiterated Jordan’s firm stance against any violations of Syria’s territorial integrity and sovereignty, Jordan News Agency reported.

Syria faced nearly 14 years of devastating civil war before the fall of President Bashar Assad’s regime earlier this month following a swift takeover by militants led by Hayat Tahrir Al-Sham.

The country remains fragmented, grappling with the challenges of rebuilding amid competing political and military influences.

The discussion between King Abdullah and Macron also addressed the ongoing Israeli war on Gaza.

The conflict, which erupted in the aftermath of a Hamas attack on Israeli territory on Oct. 7 last year, has led to a humanitarian crisis in the Palestinian enclave, with tens of thousands of lives lost and infrastructure heavily damaged.

King Abdullah called for an immediate cessation of hostilities and a strengthened humanitarian response to alleviate the suffering of Palestinians trapped there.

He also stressed the urgent need for progress toward a just and comprehensive peace in the region, underscoring the two-state solution as the basis for resolving the Israeli-Palestinian conflict.

King Abdullah highlighted the importance of sustained efforts to ensure the success of the ceasefire in Lebanon.


Syrian equestrian champ reveals 21 years of torture at hands of Assad regime

Updated 18 min 20 sec ago
Follow

Syrian equestrian champ reveals 21 years of torture at hands of Assad regime

  • Adnan Kassar was friends with Bassel Assad until overshadowing him at a championship event in 1993
  • Kassar was detained, and his treatment worsened after Bassel’s death a year later

LONDON: A former champion equestrian has revealed the torture he suffered when he was detained by the Syrian regime after besting the older brother of former ruler Bashar Assad.

Adnan Kassar told Sky News he endured 21 years of imprisonment, during which he was physically and mentally abused, after Bassel Assad, his teammate at the 1993 International Equestrian Championship, became irritated at his performances.

The two had been good friends, but Kassar’s showing won his team the gold medal at the event on home soil in the port city of Latakia, after Bassel had produced a poor display.

“The crowd lifted me on their shoulders. It was a moment of pure joy, but for Bassel, it wasn’t the same. That day marked the beginning of my nightmare,” Kassar told Sky.

He was later arrested over what he called “fabricated” accusations and subjected to severe physical and psychological abuse.

“I was kept underground for six months, beaten constantly, and interrogated without end,” he said.

Bassel had originally been tipped to succeed his father, Hafez Assad, as Syria’s ruler. However, Bassel died in a car crash in 1994, propelling the younger Bashar to power.

For Kassar, though, Bassel’s death only made his situation more dire, as he was transferred to Sednaya Prison, where “the torture only got worse.”

Kassar said: “They blamed me for his death. Every year on the anniversary of his passing, the torture intensified.”

He was later sent to Tadmur Prison for seven-and-a-half years.

“They pierced my ear one morning and broke my jaw in the evening,” Kassar said. “For praying, they lashed me 1,000 times. My feet were torn apart, my bones exposed.”

Kassar was released in 2014 after a campaign of appeals by international human rights groups. For years, he resisted discussing his time in captivity for fear of reprisals but felt ready to speak after the fall of the Assad family.

“After years of imprisonment, torture, and injustice, the revolution finally toppled the dictatorial regime,” he said.


Iran FM warns against ‘destructive interference’ in Syria’s future

Updated 27 December 2024
Follow

Iran FM warns against ‘destructive interference’ in Syria’s future

  • Abbas Araghchi: Iran ‘considers the decision-making about the future of Syria to be the sole responsibility of the people... without destructive interference or foreign imposition’

BEIJING: Iran’s top diplomat warned Friday against “destructive interference” in Syria’s future and said decisions should lie solely with the country’s people, writing in Chinese state media as he visited Beijing.
Abbas Araghchi touched down in the Chinese capital on Friday afternoon, Iranian state media reported, to begin his first official visit to the country since being appointed foreign minister.
China and Iran were both supporters of ousted Syrian president Bashar Assad.
Assad fled Syria this month after an Islamist-led offensive wrested city after city from his control, with the capital Damascus falling on December 8.
Iran “considers the decision-making about the future of Syria to be the sole responsibility of the people... without destructive interference or foreign imposition,” Araghchi wrote in a Chinese-language article in People’s Daily published on Friday.
He also emphasized Iran’s respect for Syria’s “unity, national sovereignty and territorial integrity.”
Iran’s supreme leader – a key backer of Assad’s administration – predicted on Sunday “the emergence of a strong, honorable group” that would stand against “insecurity” in Syria.
Ayatollah Ali Khamenei said Syria’s young men would “stand with strength and determination against those who have designed this insecurity and those who have implemented it, and God willing, he will overcome them.”
In People’s Daily, Araghchi said supporting the Syrian people was a “definite principle (that) should be taken into consideration by all the actors.”
Beijing had also built strong ties with Assad – he met President Xi Jinping in China last year, where the two leaders announced a “strategic partnership.”
China has affirmed its support for the Syrian people and has said it opposes terrorist forces taking advantage of the situation to create chaos.
Araghchi’s two-day visit will include talks with his Chinese counterpart Wang Yi, according to Iran’s foreign ministry.
China is Iran’s largest trade partner, and a top buyer of its sanctioned oil.
Xi pledged in October to increase ties with Iran during talks with his counterpart Masoud Pezeshkian in Russia on the sidelines of a BRICS summit.
Araghchi told reporters in a video published by Iranian state media as he arrived in Beijing that the visit was taking place “at a very suitable time.”
“Now it is natural that there are sensitive situations, both the region has various tensions, and there are various issues at the international level, also our nuclear issue in the new year will face a situation that needs more consultations,” he said.
“The invitation of our Chinese friends was for this reason, that at the beginning of the new year... we should think together, consult and be ready for the challenges that will come.”
He wrote in his editorial that Iran and China shared the “common view” that calling for an immediate ceasefire in Gaza was the biggest priority in the Middle East.


Lebanese university students launch donation campaign to aid war-displaced families

Updated 27 December 2024
Follow

Lebanese university students launch donation campaign to aid war-displaced families

  • ‘Hardship of war should never be faced alone,’ says student Nour Farchoukh
  • More than 1,000 families benefit from food and clothing donations

DUBAI: Three American University of Beirut students have launched a donation campaign to support families across Lebanon displaced by the 13-month war with Israel.

Titled “Hope for our Lebanon,” the campaign distributes food supplies, sanitary boxes, and clothes through a collaboration with ‘Wahad Activism’ charity organization.  

Nour Farchoukh, Celine Ghandour, and Kian Azad told Arab News that they provide the aid based on the needs of each family.

“We put snacks or diapers if there are children. We also ask if they need clothes,” said Ghandour, adding that the group depends on people’s in-kind donations.

So far, the donation campaign has reached more than 1,000 families in Baabda, Beirut, Chouf, Batroun, Barouk, and Hazmieh among other areas.

Israel stepped up its military campaign in south Lebanon in late September after nearly a year of cross-border exchanges launched by Hezbollah in retaliation for the war on Gaza.

Over 13 months, the war killed more than 4,000 people across Lebanon, injured over 16,600 people, and displaced 1 million people, according to the latest figures of the Lebanese health ministry.

On Nov. 27, a 60-day ceasefire agreement, brokered by US and France, was signed between Hezbollah and Israel.

Azad said the campaign was still running after the ceasefire, with clothes donations being distributed to orphanages.

“We know that no matter how small the number of families we help, it will still make a difference,” he added.

“Every volunteer and every donation help rebuild Lebanon bit by bit. The hardship of war should never be faced alone,” Farchoukh said.

The three students have invited the community to take part in the initiative through donations or volunteering.