Iranian Ransomware Programs Take Cybersecurity Experts by Surprise

Ransomware encrypts files on a victim’s computer. The perpetrator then demands ransom payments in exchange for decrypting the files and sometimes also threatens to leak the victim’s data. (Reuters)
Ransomware encrypts files on a victim’s computer. The perpetrator then demands ransom payments in exchange for decrypting the files and sometimes also threatens to leak the victim’s data. (Reuters)
TT

Iranian Ransomware Programs Take Cybersecurity Experts by Surprise

Ransomware encrypts files on a victim’s computer. The perpetrator then demands ransom payments in exchange for decrypting the files and sometimes also threatens to leak the victim’s data. (Reuters)
Ransomware encrypts files on a victim’s computer. The perpetrator then demands ransom payments in exchange for decrypting the files and sometimes also threatens to leak the victim’s data. (Reuters)

Iranian hackers have recently launched cyberattacks against vital institutions and facilities in the United States, raising the concern of law enforcement authorities in the country.

These attacks are added to various others launched by several parties against the US.

With much attention this year on Russian ransomware attacks against the US, the Iranian threat may come as a surprise, said a report by the Foreign Policy magazine, adding that Iranian ransomware groups were quietly emerging as a global force to be reckoned with elsewhere in the world.

On November, the US, Britain and Australia issued a joint warning that Iranian actors have conducted ransomware attacks against US targets and gained access to a wide range of critical infrastructure networks, including the children’s hospital, that would enable more attacks, the report read.

Experts in the Federal Bureau of Investigation (FBI), the Cybersecurity and Infrastructure Security Agency (CISA), the Australian Cyber Security Center (ACSC) and the United Kingdom’s National Cyber Security Center (NCSC) found out that an ongoing malicious cyber activity by an advanced persistent threat (APT) group is associated with the government of Iran.

Ransomware encrypts files on a victim’s computer. The perpetrator then demands ransom payments in exchange for decrypting the files and sometimes also threatens to leak the victim’s data.

“The Iranian government-sponsored APT actors are actively targeting a broad range of victims across multiple US critical infrastructure sectors,” the experts warned.

While Iranian ransomware may be relatively unfamiliar to Americans, it has been a part of everyday life in Israel for more than a year, the US magazine noted.

“Iranian actors have targeted almost every sector of Israel’s economy and society.”

The report pointed out that Iran’s successful use of ransomware against Israel has likely emboldened it to expand its focus to the United States.

In September 2020, an Israeli cybersecurity firm first detected Iranian ransomware activity against unspecified “prominent Israeli organizations.”

Another hacking group, Black Shadow, believed to be linked to Iran, was accused of carrying out a major cyberattack in October targeting an Internet service provider in Israel.

The report warned that Iran’s ransomware campaign appears to be on the brink of global expansion.

In 2019, a report prepared by researchers at the US giant Microsoft Corporation said that Iranian hackers are working to infiltrate systems, companies and governments around the world, causing damages amounting to hundreds of millions of dollars.

Some believe these attacks may be part of Iran’s attempts not only to influence cybersecurity and its open conflict with its “rivals” but also to obtain foreign cash, especially the US dollar, to break the blockade imposed on it.



ICC Warrants are Binding, EU Cannot Pick and Choose, Borrell Says

23 May 2023, Israel, Jerusalem: Israeli Prime Minister Benjamin Netanyahu gives a statement in the Knesset. (dpa)
23 May 2023, Israel, Jerusalem: Israeli Prime Minister Benjamin Netanyahu gives a statement in the Knesset. (dpa)
TT

ICC Warrants are Binding, EU Cannot Pick and Choose, Borrell Says

23 May 2023, Israel, Jerusalem: Israeli Prime Minister Benjamin Netanyahu gives a statement in the Knesset. (dpa)
23 May 2023, Israel, Jerusalem: Israeli Prime Minister Benjamin Netanyahu gives a statement in the Knesset. (dpa)

European Union governments cannot pick and choose whether to execute arrest warrants issued by the International Criminal Court against two Israeli leaders and a Hamas commander, the EU's foreign policy chief said on Saturday.

The ICC issued the warrants on Thursday against Israeli Prime Minister Benjamin Netanyahu, his former defense minister Yoav Gallant and Hamas leader Ibrahim Al-Masri, for alleged crimes against humanity.

All EU member states are signatories to the ICC's founding treaty, called the Rome Statute.

Several EU states have said they will meet their commitments under the statute if needed, but Hungarian Prime Minister Viktor Orban has invited Netanyahu to visit his country, assuring him he would face no risks if he did so.

"The states that signed the Rome convention are obliged to implement the decision of the court. It's not optional," Josep Borrell, the EU's top diplomat, said during a visit to Cyprus for a workshop of Israeli and Palestinian peace activists.

Those same obligations were also binding on countries aspiring to join the EU, he said.

"It would be very funny that the newcomers have an obligation that current members don't fulfil," he told Reuters.

The United States rejected the ICC's decision and Israel said the ICC move was antisemitic.

"Every time someone disagrees with the policy of one Israeli government - (they are) being accused of antisemitism," said Borrell, whose term as EU foreign policy chief ends this month.

"I have the right to criticize the decisions of the Israeli government, be it Mr Netanyahu or someone else, without being accused of antisemitism. This is not acceptable. That's enough."

Israel's 13-month campaign in Gaza has killed about 44,000 Palestinians and displaced nearly all the enclave's population while creating a humanitarian crisis, Gaza officials say.

In their decision, the ICC judges said there were reasonable grounds to believe Netanyahu and Gallant were criminally responsible for acts including murder, persecution and starvation as a weapon of war as part of a "widespread and systematic attack against the civilian population of Gaza".

The warrant for Masri lists charges of mass killings during the Oct. 7, 2023, attacks. Israel says it has killed Masri.