Showing posts with label Iran. Show all posts
Showing posts with label Iran. Show all posts

Wednesday, January 24, 2018

Iranian Protests: Propaganda War

Wapack Labs is monitoring the developments in the ongoing Iran protests. Wapack analysts continue to observe an increase in Internet restriction and disabling of communication applications; Facebook, Twitter, Telegram, Google, WhatsApp, and Signal. To date, ProtonMail’s free VPN service for Android phones, and Psiphon, an app that circumnavigates network firewalls, are the only means of providing anonymity for Iranian citizens. As information censorship increases, so too does pro-regime propaganda. The current climate in Iran may give way to Iranian-backed threat actors targeting the anti-regime demonstrators. Wapack Labs assesses, with moderate confidence, that the cyber activity will remain confined to Iran, but continues to monitor the situation for movement affecting our customer base...READ MORE

Wapack Labs has cataloged and reported on protests and cyber activity in Iran in the past. An archive of related reporting can be found in the Red Sky Alliance portal.

WWW.WAPACKLABS.COM

Wednesday, January 17, 2018

Iranian Protests: Communication Bans & Targeting of Protestors

Wapack Labs has been monitoring the developing Iran protests. By Day 9, Wapack analysts observed an uptick in Internet and communication restrictions, including social media platforms, phone applications, encrypted/secure messaging, and Virtual Private Network (VPN) services, and other platforms. Formerly accepted by the Iranian government, the Instant Messaging Service ‘Telegram’, which had tremendous activity on Day 2 of the protests, is now disabled. At the moment, Google is preventing Iranians from using the Google Search Engine and from using ‘Signal’, an end-to-end encryption messenger that circumnavigates government filtering. To date, ProtonMail’s free VPN service for Android phones, is the only means of providing anonymity for Iranian citizens. As the Iranian government continues to disrupt communications, they are implementing scare tactics to persuade protestors to stop the movement. Irancell, a mobile network service provider, is tracking down its users - who have posted videos and pictures online - and sending them text notifications, warning them that they have been participating in illegal protests. Additionally, the Twitter account of the Tasnim News Agency (@Tasnimnews_Fa) is posting pictures of protestors, asking followers to identify protestors and report them to Iranian security forces. The current climate in Iran may give way to another wave of Iranian cyber hacktivists targeting the anti-regime demonstrators...READ MORE

Wapack Labs has cataloged and reported on Iranian protests and communications in the past. An archive of related reporting can be found in the Red Sky Alliance portal.

WWW.WAPACKLABS.COM

Friday, January 5, 2018

Iranian Protests and Cyber Hacktivism

Wapack Labs analysts have been monitoring the recent demonstrations in Iran involving discontent toward the Islamic Republic seated in the aftermath of the 1979 Revolution. Iranian dissidents and activists took to the streets by the thousands, chanting slogans like “We don’t want an Islamic Republic” and “Death to the dictator”, as they tore down pictures of Supreme Leader Khamenei and set fire to the Governor’s office. Protests began in the second most populous city in Iran, Mashhad, built centered on the Holy Shrine of Imam Reza, which remains a place for religious pilgrimage. By day two, the protests, with the help of the instant messaging service ‘Telegram’, gained momentum reaching the very western city of Kermanshah. As the Iranian government took steps to block media platforms like Instagram, Twitter, and Telegram, the third day of protests had already spread from the northern city of Tabriz to the southern port city of Bandar Abbas...READ MORE
 
Wapack Labs has cataloged and reported on cyber hacktivism in the past. An archive of related reporting can be found in the Red Sky Alliance portal.

Thursday, January 4, 2018

The Iranian Cyber Evolution: RATs, Backdoors, and Droppers

Wapack Labs has been monitoring Iranian cyber activity for several years, specifically the evolving OilRig and Greenbug campaigns. Their adoption of a cyber operational paradigm involving both cyber hacktivism and cyber espionage tactics resembles cyber activity patterns employed by Chinese APT groups, whereby different groups perform different campaigns, with multiple teams conducting separate phases of a cyber campaign. With President Trump’s refusal to re-certify Iran’s compliance with the 2015 Iran nuclear agreement, Wapack analysts are researching the continued efforts of Iranian-backed cyber threats in order to detect and defend against next moves. 

One common attribute is that they all engage in prolonged reconnaissance campaigns of their targets; at times lasting over a year. Greenbug, a cyber-espionage group with suspected Iranian ties, has been dynamically progressing in such campaigns. In August 2017, a Greenbug tool, dubbed ISMAgent (an ISMDoor variant), resurfaced in the wild to harvest account credentials. Wapack Labs discovered evidence of ISMDoor variants relying on the VB:Trojan.Valyria (possibly Clayside) for delivery, linking Greenbug to another group of Iranian actors known as OilRig. Wapack Labs assesses with moderate confidence that recent activity involving ISMDoor is an indicator of the ramping up of another cyber campaign cycle...READ MORE

Wapack Labs has cataloged and reported on Iranian cyber activity in the past. An archive of related reporting can be found in the Red Sky Alliance portal.

Tuesday, April 18, 2017

Shamoon2 Overwrites and Attacks Saudi Targets


Wapack Labs's research has uncovered Iranian actors using Shamoon2 against Saudi infrastructure and industry targets. Shamoon2 renders infected systems inoperable by overwriting the Master Boot Records (MBR). The actors responsible are using commercially available kernel drivers, which may indicate a lack of experience with Windows kernel development. Though, there is evidence indicating the malware was designed by reverse engineering malware attributed to a nation-state, suggesting that their skills are improving. Further attacks against Saudi-related targets using the Shamoon-family of malware are highly likely...READ MORE

Wapack Labs has cataloged and reported extensively on malware in the past. An archive of related reporting can be found in the Red Sky Alliance portal.

Thursday, September 1, 2016

Malware discovered in Iranian Oil Refineries

www.presstv.ir
On 31 August 2016, Wapack Labs identified open source reporting from Iran that two of their oil refinery operations were recently infected with malicious software.  Iranian officials, who claim, fixed the software problem, deny that the malware was responsible for a series of fires at several petrochemical plants in Iran.  With political instability prevalent in Iran and other Middle East countries, the detection of cyber-attacks and numerous fires could indicate further destabilization.  We are providing this information for your situational awareness.

Publication date:                            31 August 2016

Handling requirements:                  Traffic light protocol (TLP) GREEN

Attribution/Threat Actors:              Malware attack to Iranian oil industry  

Actor Type:                                     Tier III   

Potential Targets:                           Iran

Past Reporting:                               DOC-2816, DOC-2713

The full attribution report has been published in its entirety in the Red Sky Alliance portal.  For more information please contact the lab directly at 844-4-WAPACK, 603-606-1246, or feedback@wapacklabs.com.

About Wapack Labs


Wapack Labs, located in New Boston, NH is a Cyber Threat Analysis and Intelligence organization supporting the Red Sky Alliance, the FS-ISAC and individual organizations by offering expert level targeted intelligence analysis answering some of the hardest questions in Cyber.  Wapack Labs’ engineers, researchers and analysts use deep analysis techniques and visualization to design and deliver transformational cyber-security analysis tools that fuse open source and proprietary information.  The intelligence derived from these tools and techniques serve as the foundation of Wapack Labs’ information reporting to the cyber-security teams of its customers and industry partners located around the world.

Thursday, August 25, 2016

Iran & North Korea Expand Cyber Capabilities


www.defenseone.com

On 22 August 2016, Wapack Labs identified potential cyber threats and vulnerabilities to Western interests; threats which span numerous critical infrastructure sectors.  Iran and ally North Korea, continue to grow and expand their cyber capabilities.  We are providing this information for your situational awareness.



Publication date:                         24 August 2016

Handling requirements:               Traffic light protocol (TLP) GREEN

Attribution/Threat Actors:           Iranian and NK Threat Actors

Actor Type:                                  Tier II & III            

Potential Targets:                        USA / International

Past Reporting:                            Red Sky Alliance: DOC 2326, DOC 2741, DOC 4166

The full attribution report has been published in its entirety in the Red Sky Alliance portal.  For more information please contact the lab directly at 844-4-WAPACK, 603-606-1246, or feedback@wapacklabs.com.

About Wapack Labs

Wapack Labs, located in New Boston, NH is a Cyber Threat Analysis and Intelligence organization supporting the Red Sky Alliance, the FS-ISAC and individual organizations by offering expert level targeted intelligence analysis answering some of the hardest questions in Cyber.  Wapack Labs’ engineers, researchers and analysts use deep analysis techniques and visualization to design and deliver transformational cyber-security analysis tools that fuse open source and proprietary information.  The intelligence derived from these tools and techniques serve as the foundation of Wapack Labs’ information reporting to the cyber-security teams of its customers and industry partners located around the world.