Search This Blog

Popular Posts

Powered by Blogger.

Blog Archive

Labels

Footer About

Footer About

Labels

Showing posts with label Iranian cyber group. Show all posts

Iran-Linked Hackers Suspected in Cyberattacks Targeting Minnesota Water Systems

 

Several water systems in Minnesota were under attack from cyber intruders over the weekend. Investigators believe the attacks were launched from an Iranian hacking group called CyberAv3ngers. The attacks targeted approximately 30 water systems in Minnesota on Sunday and Monday and caused a brief interruption in the water supply for one community. 

The most significant attack was in the small town of Braham, located in the Minneapolis area, which was without water for two hours due to a cyberattack. The water supply was cut off, but it was quickly restored. Cybersecurity firm Tenable indicated that the attack methods used were similar to those previously used by the Iranian hacking group. US authorities are investigating whether Iran was behind the cyberattack on the water systems in Minnesota. 

However, officials do not believe that the attacks in Minnesota were carried out by Iran or that the attacks were orchestrated by the group CyberAv3ngers. The attacks in Minnesota occurred shortly after the US Cybersecurity and Infrastructure Security Agency issued an alert about attacks launched by Iran’s proxies on internet-connected systems controlled by infrastructure operators. This warning highlighted the potential for such groups to target critical infrastructure. Water utilities may be particularly vulnerable to such attacks since they use internet-connected machines to control and monitor operations. 

A relatively small amount of protection of these machines can allow hackers to intervene in the functioning of critical infrastructure, even if they cannot access the main corporate IT system. CyberAv3ngers has been accused of targeting industrial control systems by various companies, including water utilities, in the past. This hacking group has attracted increased attention from US authorities due to its suspected Iranian origin and potential access to critical infrastructure. The attack on Minnesota water utilities is part of a wave of cyberattacks launched against the US and its allies. 

Another hacking group, Handala, claimed to have attacked the medical equipment company Stryker and the payment processing company Verifone. Stryker confirmed that it was a victim of a cyberattack, while Verifone rejected the accusations. The group Handala claimed that it carried out these attacks in retaliation for the US-Israeli military operation against Iran. The attack by Handala was reportedly in response to the assassination of an Iranian military commander and the bombing of a school in Iran, which resulted in the death of more than 150 people. 

The US military investigation concluded that the attack on the school in Minab was due to the “inadvertent engagement” of the school by US aircraft, which was targeting a military installation. The attacks on the water utilities in Minnesota illustrate the potential for geopolitical tensions to spill over into attacks on critical infrastructure. Even though it is unclear whether the attacks in Minnesota were launched by Iran, the fact that they were able to occur highlights the need for increased protection of internet-connected infrastructure equipment, as well as monitoring and rapid response systems.

Iranian APT Group Charming Kitten Updates Powerstar Backdoor

According to researchers from cybersecurity firm Volexity, the most recent variant of malware is probably backed by a custom server-side component. This component assists the Powerstar backdoor operator by automating basic tasks. The latest version of the malware utilizes a distributed file protocol to disseminate personalized phishing links. 

Researchers have discovered that the malware incorporates various functionalities, such as leveraging the InterPlanetary File System (IPFS) and employing publicly accessible cloud hosts to remotely host its decryption function and configuration details. 

In April, Microsoft identified a group named Mint Sandstorm. This group utilized an implant called CharmPower, which was distributed through targeted spear-phishing campaigns. The campaigns specifically targeted individuals associated with the security community, as well as those affiliated with think tanks or universities in Israel, North America, and Europe. 

The threat actor known as Charming Kitten also referred to as Phosphorus, TA453, APT35, Cobalt Illusion, ITG18, and Yellow Garuda, has been involved in surveillance activities targeting journalists and activists since at least 2013. Recently, researchers have discovered that the attackers are adopting the guise of a reporter from an Israeli media organization. 

Their strategy involves sending targeted individuals an email containing a malicious attachment. The phishing email urges the recipient to review a document pertaining to U.S. foreign policy. To mitigate the chances of detection and analysis, the malware employs a tactic that separates the decryption method from the initial code and ensures it is never written to the disk. This approach minimizes the risk of exposure during analysis and detection processes. 

Volexity researchers found that the malware captures and uploads screenshots to the attacker's server, detects antivirus software, establishes persistence using a Registry Run key for the IPFS variant of Powerstar, collects system information, and employs a clean-up module to erase traces. 

The InterPlanetary File System (IPFS) is a decentralized network where files are stored and accessed through unique content identifiers. It functions similarly to a BitTorrent swarm and Git repository, facilitating decentralized file storage and retrieval.