Iranian Ransomware Programs Take Cybersecurity Experts by Surprise

Ransomware encrypts files on a victim’s computer. The perpetrator then demands ransom payments in exchange for decrypting the files and sometimes also threatens to leak the victim’s data. (Reuters)
Ransomware encrypts files on a victim’s computer. The perpetrator then demands ransom payments in exchange for decrypting the files and sometimes also threatens to leak the victim’s data. (Reuters)
TT

Iranian Ransomware Programs Take Cybersecurity Experts by Surprise

Ransomware encrypts files on a victim’s computer. The perpetrator then demands ransom payments in exchange for decrypting the files and sometimes also threatens to leak the victim’s data. (Reuters)
Ransomware encrypts files on a victim’s computer. The perpetrator then demands ransom payments in exchange for decrypting the files and sometimes also threatens to leak the victim’s data. (Reuters)

Iranian hackers have recently launched cyberattacks against vital institutions and facilities in the United States, raising the concern of law enforcement authorities in the country.

These attacks are added to various others launched by several parties against the US.

With much attention this year on Russian ransomware attacks against the US, the Iranian threat may come as a surprise, said a report by the Foreign Policy magazine, adding that Iranian ransomware groups were quietly emerging as a global force to be reckoned with elsewhere in the world.

On November, the US, Britain and Australia issued a joint warning that Iranian actors have conducted ransomware attacks against US targets and gained access to a wide range of critical infrastructure networks, including the children’s hospital, that would enable more attacks, the report read.

Experts in the Federal Bureau of Investigation (FBI), the Cybersecurity and Infrastructure Security Agency (CISA), the Australian Cyber Security Center (ACSC) and the United Kingdom’s National Cyber Security Center (NCSC) found out that an ongoing malicious cyber activity by an advanced persistent threat (APT) group is associated with the government of Iran.

Ransomware encrypts files on a victim’s computer. The perpetrator then demands ransom payments in exchange for decrypting the files and sometimes also threatens to leak the victim’s data.

“The Iranian government-sponsored APT actors are actively targeting a broad range of victims across multiple US critical infrastructure sectors,” the experts warned.

While Iranian ransomware may be relatively unfamiliar to Americans, it has been a part of everyday life in Israel for more than a year, the US magazine noted.

“Iranian actors have targeted almost every sector of Israel’s economy and society.”

The report pointed out that Iran’s successful use of ransomware against Israel has likely emboldened it to expand its focus to the United States.

In September 2020, an Israeli cybersecurity firm first detected Iranian ransomware activity against unspecified “prominent Israeli organizations.”

Another hacking group, Black Shadow, believed to be linked to Iran, was accused of carrying out a major cyberattack in October targeting an Internet service provider in Israel.

The report warned that Iran’s ransomware campaign appears to be on the brink of global expansion.

In 2019, a report prepared by researchers at the US giant Microsoft Corporation said that Iranian hackers are working to infiltrate systems, companies and governments around the world, causing damages amounting to hundreds of millions of dollars.

Some believe these attacks may be part of Iran’s attempts not only to influence cybersecurity and its open conflict with its “rivals” but also to obtain foreign cash, especially the US dollar, to break the blockade imposed on it.



Man Killed in Rocket Attack on Israel’s Nahariya

People stand near a hole at the impact site, after Israel's medical services said a man was killed, when shrapnel from a rocket struck a playground in Nahariya, Israel, November 21, 2024. REUTERS/Thomas Peter
People stand near a hole at the impact site, after Israel's medical services said a man was killed, when shrapnel from a rocket struck a playground in Nahariya, Israel, November 21, 2024. REUTERS/Thomas Peter
TT

Man Killed in Rocket Attack on Israel’s Nahariya

People stand near a hole at the impact site, after Israel's medical services said a man was killed, when shrapnel from a rocket struck a playground in Nahariya, Israel, November 21, 2024. REUTERS/Thomas Peter
People stand near a hole at the impact site, after Israel's medical services said a man was killed, when shrapnel from a rocket struck a playground in Nahariya, Israel, November 21, 2024. REUTERS/Thomas Peter

A 30-year-old man was killed by rocket shrapnel next to a playground in the northern Israeli town of Nahariya on Thursday, Israel's MDA medical service said.
The Israeli military said about 10 rockets had been launched from Lebanon towards Nahariya. "Most of the projectiles were intercepted and fallen projectiles were identified," the army said in a statement.
Channel 12 said three rockets hit the coastal town.
Air sirens went off in a number of locations across northern Israel during the morning, but it was not immediately clear how many missiles had been launched from Lebanon.
"The Israeli government is not safeguarding my security, my residents or the residents of the north (of Israel). It is not possible to live in such a situation like this," Nahariya Mayor Ronen Marelly told public broadcaster Kan.
"We are being attacked (by Hezbollah) in a massive way with great force," he said.
The Israeli military has inflicted huge devastation in Lebanon since it went on the offensive against Hezbollah in September, mounting airstrikes across wide parts of the country and sending in troops.

The Israeli military said Wednesday three soldiers, including a 70-year-old, were killed in south Lebanon.

The army announced two soldiers were killed in the same incident including 70-year-old reservist Ze'ev 'Jabo' Hanoch Erlich, after it had said earlier Wednesday that a 22-year-old soldier from Jerusalem "fell during combat in southern Lebanon”

The deaths bring to 52 the army's losses in Lebanon since the start of ground operations.

Another soldier was heavily injured during the same incident that killed the two soldiers including Erlich, the military said, adding he had been taken to hospital.