FBI Warns US Companies about Iranian Hackers

Iranian hackers have searched cybercriminal websites for sensitive data stolen from American and foreign organizations that could be useful in future efforts to hack those organizations, said the FBI. (Getty Images)
Iranian hackers have searched cybercriminal websites for sensitive data stolen from American and foreign organizations that could be useful in future efforts to hack those organizations, said the FBI. (Getty Images)
TT

FBI Warns US Companies about Iranian Hackers

Iranian hackers have searched cybercriminal websites for sensitive data stolen from American and foreign organizations that could be useful in future efforts to hack those organizations, said the FBI. (Getty Images)
Iranian hackers have searched cybercriminal websites for sensitive data stolen from American and foreign organizations that could be useful in future efforts to hack those organizations, said the FBI. (Getty Images)

Iranian hackers have searched cybercriminal websites for sensitive data stolen from American and foreign organizations that could be useful in future efforts to hack those organizations, the FBI said in an advisory sent to US companies obtained by CNN.

The Iranian hackers have taken an interest in dark-web forums, where scammers leak information on their victims such as stolen emails and network configurations, according to the November 8 advisory. The FBI is concerned that the Iranian hacking group could use that information to plot ways into US corporate networks in the future.

Organizations at risk are advised to take mitigation measures to block hacking attempts by securing Remote Desktop Protocol (RDP) servers, Web Application Firewalls, and Kentico CMS installations targeted by this adversary, said Bleeping Computer, a cybersecurity news outlet, which was the first to report on the FBI analysis.

"Among the Tactics, Techniques, and Procedures (TTPs) used in attacks by this threat actor since May 2021, the FBI mentions the use of auto-exploiter tools used to compromise WordPress sites to deploy web shells, breaching RDP servers and using them to maintain access to victims' networks."

It is unclear which Iranian hacking group is behind the activity. The FBI did not identify the hackers by name or say if they are linked to the Iranian government.

Adam Meyers, senior vice president of intelligence at security firm CrowdStrike, told CNN that Iranian government-linked hackers have increasingly dabbled in cybercriminal activity, such as ransomware, as a means of blurring the lines between state and non-state cyber operations.

"It is well within (Iranian groups') modus operandi to purchase access to networks held by a criminal group if it serves their interests," he added.

An unnamed Iranian hacking group used similar tools to steal voter registration data from state election sites between September and October 2020, Bleeping Computer.

"That voter info was later used to impersonate the far-right Proud Boys organization and send threatening emails to Democratic voters warning that they must vote for Trump or face the consequences."

"The FBI's Cyber Division also warned in a private industry notification issued last week that ransomware gangs have compromised the networks of several tribal-owned casinos, taking down their servers and disabling connected systems."

"The same week, the federal agency also alerted the public that criminals are increasingly using cryptocurrency ATMs and QR codes for fraud, making it harder for law enforcement to recover the victims' financial losses."



UN: Record 281 Aid Workers Killed in 2024

The UN agency for Palestinian refugees has seen more than 200 staff killed since the Gaza war began. Eyad BABA / AFP/File
The UN agency for Palestinian refugees has seen more than 200 staff killed since the Gaza war began. Eyad BABA / AFP/File
TT

UN: Record 281 Aid Workers Killed in 2024

The UN agency for Palestinian refugees has seen more than 200 staff killed since the Gaza war began. Eyad BABA / AFP/File
The UN agency for Palestinian refugees has seen more than 200 staff killed since the Gaza war began. Eyad BABA / AFP/File

A staggering 281 aid workers have been killed around the world so far this year, making 2024 the deadliest year for humanitarians, the UN aid chief said Friday.
"Humanitarian workers are being killed at an unprecedented rate, their courage and humanity being met with bullets and bombs," said Tom Fletcher, the United Nations' new under-secretary-general for humanitarian affairs and emergency relief coordinator.
With more than a month left to go of 2024, the "grim milestone was reached", he said, after 280 humanitarians were killed across 33 countries during all of 2023.
"This violence is unconscionable and devastating to aid operations," Fletcher said.
Israel's devastating war in Gaza was driving up the numbers, his office said, with 333 aid workers killed there -- most from the UN agency supporting Palestinian refugees, UNRWA -- since Hamas's October 7, 2023 attacks, which sparked the war, AFP reported.
"States and parties to conflict must protect humanitarians, uphold international law, prosecute those responsible, and call time on this era of impunity," Fletcher said.
Aid workers were subject to kidnappings, injuries, harassment and arbitrary detention in a range of countries, his office said, including Afghanistan, the Democratic Republic of the Congo, Sudan, and Ukraine.
The majority of deaths involve local staff working with non-governmental organizations, UN agencies and the Red Cross Red Crescent movement, Fletcher's office said.
"Violence against humanitarian personnel is part of a broader trend of harm to civilians in conflict zones," it warned.
"Last year, more than 33,000 civilian deaths were recorded in 14 armed conflicts -- a staggering 72 per cent increase from 2022."
The UN Security Council adopted a resolution last May in response to the surging violence and threats against aid workers.
The text called for recommendations from the UN chief -- set to be presented at a council meeting next week -- on measures to prevent and respond to such incidents and to increase protection for humanitarian staff and accountability for abuses.