Iranian Ransomware Programs Take Cybersecurity Experts by Surprise

Ransomware encrypts files on a victim’s computer. The perpetrator then demands ransom payments in exchange for decrypting the files and sometimes also threatens to leak the victim’s data. (Reuters)
Ransomware encrypts files on a victim’s computer. The perpetrator then demands ransom payments in exchange for decrypting the files and sometimes also threatens to leak the victim’s data. (Reuters)
TT

Iranian Ransomware Programs Take Cybersecurity Experts by Surprise

Ransomware encrypts files on a victim’s computer. The perpetrator then demands ransom payments in exchange for decrypting the files and sometimes also threatens to leak the victim’s data. (Reuters)
Ransomware encrypts files on a victim’s computer. The perpetrator then demands ransom payments in exchange for decrypting the files and sometimes also threatens to leak the victim’s data. (Reuters)

Iranian hackers have recently launched cyberattacks against vital institutions and facilities in the United States, raising the concern of law enforcement authorities in the country.

These attacks are added to various others launched by several parties against the US.

With much attention this year on Russian ransomware attacks against the US, the Iranian threat may come as a surprise, said a report by the Foreign Policy magazine, adding that Iranian ransomware groups were quietly emerging as a global force to be reckoned with elsewhere in the world.

On November, the US, Britain and Australia issued a joint warning that Iranian actors have conducted ransomware attacks against US targets and gained access to a wide range of critical infrastructure networks, including the children’s hospital, that would enable more attacks, the report read.

Experts in the Federal Bureau of Investigation (FBI), the Cybersecurity and Infrastructure Security Agency (CISA), the Australian Cyber Security Center (ACSC) and the United Kingdom’s National Cyber Security Center (NCSC) found out that an ongoing malicious cyber activity by an advanced persistent threat (APT) group is associated with the government of Iran.

Ransomware encrypts files on a victim’s computer. The perpetrator then demands ransom payments in exchange for decrypting the files and sometimes also threatens to leak the victim’s data.

“The Iranian government-sponsored APT actors are actively targeting a broad range of victims across multiple US critical infrastructure sectors,” the experts warned.

While Iranian ransomware may be relatively unfamiliar to Americans, it has been a part of everyday life in Israel for more than a year, the US magazine noted.

“Iranian actors have targeted almost every sector of Israel’s economy and society.”

The report pointed out that Iran’s successful use of ransomware against Israel has likely emboldened it to expand its focus to the United States.

In September 2020, an Israeli cybersecurity firm first detected Iranian ransomware activity against unspecified “prominent Israeli organizations.”

Another hacking group, Black Shadow, believed to be linked to Iran, was accused of carrying out a major cyberattack in October targeting an Internet service provider in Israel.

The report warned that Iran’s ransomware campaign appears to be on the brink of global expansion.

In 2019, a report prepared by researchers at the US giant Microsoft Corporation said that Iranian hackers are working to infiltrate systems, companies and governments around the world, causing damages amounting to hundreds of millions of dollars.

Some believe these attacks may be part of Iran’s attempts not only to influence cybersecurity and its open conflict with its “rivals” but also to obtain foreign cash, especially the US dollar, to break the blockade imposed on it.



Israel Says No Foreign Courts Have Warrants Issued against Reservists

 Israeli military vehicles operate on a base near the border to Gaza, amid the ongoing conflict between Israel and Hamas, as seen from southern Israel, January 7, 2025. (Reuters)
Israeli military vehicles operate on a base near the border to Gaza, amid the ongoing conflict between Israel and Hamas, as seen from southern Israel, January 7, 2025. (Reuters)
TT

Israel Says No Foreign Courts Have Warrants Issued against Reservists

 Israeli military vehicles operate on a base near the border to Gaza, amid the ongoing conflict between Israel and Hamas, as seen from southern Israel, January 7, 2025. (Reuters)
Israeli military vehicles operate on a base near the border to Gaza, amid the ongoing conflict between Israel and Hamas, as seen from southern Israel, January 7, 2025. (Reuters)

Israel said on Tuesday pressure groups were pushing foreign courts to take action against Israelis over alleged war crimes in Gaza but described the actions as "propaganda activity" and said no warrants had been issued.

The International Criminal Court has issued arrest warrants against Israeli Prime Minister Benjamin Netanyahu and former Defense Minister Yoav Gallant, as well as a Hamas leader, Ibrahim Al-Masri, over alleged war crimes in Gaza.

The warrants sparked outrage in Israel but also drew fears that similar warrants could be issued against Israelis who served in the military in Gaza.

On Sunday, an Israeli reservist on holiday in Brazil left the country after a Brazilian federal judge in Salvador ordered police to open an investigation into allegations that he had committed war crimes while serving with the military in Gaza.

The Hind Rajab Foundation, the pro-Palestinian group which brought the action, says on its website it "focuses on offensive legal action against perpetrators, accomplices and inciters of war crimes and crimes against humanity in Palestine."

The Belgium-based group, named after a Palestinian girl killed in Gaza last year, also said it had filed evidence of alleged war crimes with the ICC against 1,000 Israelis, including video and audio reports, forensic reports and other documentation. The ICC confirmed it had received a filing and said it would "analyze the materials submitted, as appropriate".

Israel's foreign ministry offered assistance to the reservist singled out by the action but officials said the issue was not widespread.

"This is a phenomenon of very limited scope in numbers," foreign ministry director general Eden Bar Tal told reporters in Jerusalem, saying there had been no more than 10-12 cases since the beginning of Israel's campaign in Gaza 15 months ago.

"There was no warrant issued in any of these cases. So it was, I would say, a relatively strong PR activity but with very low, very, very low - zero - in judicial results," he said.

"We believe it's a lot of propaganda activity in general and it's sponsored by entities, a very low number of entities, that have direct connections to terrorist organizations," he said.

Hind Rajab Foundation founder, Dyab Abou Jahjah, posts messages on the social media platform X promising to file legal action against Israeli soldiers and asking for help identifying them. He has also posted messages in support of the Iranian-backed Hezbollah movement, designated as a terrorist organization by many Western countries.

The group did not immediately respond to a request for comment.

The case in Brazil attracted wide attention in Israel, underscoring fears that individuals beyond the government and military leadership could be drawn into the war crimes issue, particularly through social media posts.

The Israeli military has warned reservists that they could face arrest abroad over alleged war crimes in Gaza, according to documents published by Israeli media. The left-wing Haaretz newspaper said complaints against IDF soldiers have been filed in South Africa, Belgium and France as well as Brazil.

However, Rubens Becak, a law professor at the University of Sao Paulo in Brazil, said it was not always straightforward for third countries to respond to suits of this kind.

"Without specific legislation, it becomes very difficult for institutions such as the Federal Police to act in cases like this," he said.