Iranian Ransomware Programs Take Cybersecurity Experts by Surprise

Ransomware encrypts files on a victim’s computer. The perpetrator then demands ransom payments in exchange for decrypting the files and sometimes also threatens to leak the victim’s data. (Reuters)
Ransomware encrypts files on a victim’s computer. The perpetrator then demands ransom payments in exchange for decrypting the files and sometimes also threatens to leak the victim’s data. (Reuters)
TT

Iranian Ransomware Programs Take Cybersecurity Experts by Surprise

Ransomware encrypts files on a victim’s computer. The perpetrator then demands ransom payments in exchange for decrypting the files and sometimes also threatens to leak the victim’s data. (Reuters)
Ransomware encrypts files on a victim’s computer. The perpetrator then demands ransom payments in exchange for decrypting the files and sometimes also threatens to leak the victim’s data. (Reuters)

Iranian hackers have recently launched cyberattacks against vital institutions and facilities in the United States, raising the concern of law enforcement authorities in the country.

These attacks are added to various others launched by several parties against the US.

With much attention this year on Russian ransomware attacks against the US, the Iranian threat may come as a surprise, said a report by the Foreign Policy magazine, adding that Iranian ransomware groups were quietly emerging as a global force to be reckoned with elsewhere in the world.

On November, the US, Britain and Australia issued a joint warning that Iranian actors have conducted ransomware attacks against US targets and gained access to a wide range of critical infrastructure networks, including the children’s hospital, that would enable more attacks, the report read.

Experts in the Federal Bureau of Investigation (FBI), the Cybersecurity and Infrastructure Security Agency (CISA), the Australian Cyber Security Center (ACSC) and the United Kingdom’s National Cyber Security Center (NCSC) found out that an ongoing malicious cyber activity by an advanced persistent threat (APT) group is associated with the government of Iran.

Ransomware encrypts files on a victim’s computer. The perpetrator then demands ransom payments in exchange for decrypting the files and sometimes also threatens to leak the victim’s data.

“The Iranian government-sponsored APT actors are actively targeting a broad range of victims across multiple US critical infrastructure sectors,” the experts warned.

While Iranian ransomware may be relatively unfamiliar to Americans, it has been a part of everyday life in Israel for more than a year, the US magazine noted.

“Iranian actors have targeted almost every sector of Israel’s economy and society.”

The report pointed out that Iran’s successful use of ransomware against Israel has likely emboldened it to expand its focus to the United States.

In September 2020, an Israeli cybersecurity firm first detected Iranian ransomware activity against unspecified “prominent Israeli organizations.”

Another hacking group, Black Shadow, believed to be linked to Iran, was accused of carrying out a major cyberattack in October targeting an Internet service provider in Israel.

The report warned that Iran’s ransomware campaign appears to be on the brink of global expansion.

In 2019, a report prepared by researchers at the US giant Microsoft Corporation said that Iranian hackers are working to infiltrate systems, companies and governments around the world, causing damages amounting to hundreds of millions of dollars.

Some believe these attacks may be part of Iran’s attempts not only to influence cybersecurity and its open conflict with its “rivals” but also to obtain foreign cash, especially the US dollar, to break the blockade imposed on it.



Iran Says Could Abandon Nuclear Weapons But Has Conditions

A sample of the surveillance cameras that monitor the Iranian nuclear facilities presented at a press conference in Vienna. (Reuters)
A sample of the surveillance cameras that monitor the Iranian nuclear facilities presented at a press conference in Vienna. (Reuters)
TT

Iran Says Could Abandon Nuclear Weapons But Has Conditions

A sample of the surveillance cameras that monitor the Iranian nuclear facilities presented at a press conference in Vienna. (Reuters)
A sample of the surveillance cameras that monitor the Iranian nuclear facilities presented at a press conference in Vienna. (Reuters)

Iran on Saturday hinted it would be willing to negotiate on a nuclear agreement with the upcoming administration of US President-elect Donald Trump, but that it has conditions.
Last Thursday, the UN atomic watchdog's 35-nation Board of Governors passed a resolution ordering Iran to urgently improve cooperation with the agency and requesting a “comprehensive” report aimed at pressuring Iran into fresh nuclear talks.
Ali Larijani, advisor to Supreme Leader Ali Khamenei, said Iran and the US are now in a new position concerning the nuclear file.
In a post on X, he said, “If the current US administration say they are only against Iran’s nuclear weapons, they must accept Iran’s conditions and provide compensation for the damages caused.”

He added, “The US should accept the necessary conditions... so that a new agreement can be reached.”
Larijani stated that Washington withdrew from the JCPOA, thus causing damage to Iran, adding that his country started increasing its production of 60% enriched uranium.
The Iran nuclear accord, formally known as the Joint Comprehensive Plan of Action (JCPOA), was reached to limit the Iranian nuclear program in exchange for sanctions relief.
The deal began unraveling in 2018, when Washington, under Trump’s first administration, unilaterally withdrew from the accord and re-imposed a sanction regime of “maximum pressure” on Tehran.
In retaliation, Iran has rapidly ramped up its nuclear activities, including by increasing its stockpiles of enriched uranium to 60% — close to the 90% threshold required to develop a nuclear bomb.
It also began gradually rolling back some of its commitments by increasing its uranium stockpiles and enriching beyond the 3.67% purity -- enough for nuclear power stations -- permitted under the deal.
Since 2021, Tehran has significantly decreased its cooperation with the IAEA by deactivating surveillance devices to monitor the nuclear program and barring UN inspectors.
Most recently, Iran escalated its confrontations with the Agency by announcing it would launch a series of “new and advanced” centrifuges. Its move came in response to a resolution adopted by the United Nations nuclear watchdog that censures Tehran for what the agency called lack of cooperation.
Centrifuges are the machines that enrich uranium transformed into gas by rotating it at very high speed, increasing the proportion of fissile isotope material (U-235).
Shortly after the IAEA passed its resolution last Thursday, Tehran spoke about the “dual role” of IAEA’s chief, Raphael Grossi.
Chairman of the Iranian Parliamentary National Security and Foreign Policy Committee, Ebrahim Azizi said, “The statements made by Grossi in Tehran do not match his actions in Vienna.”
And contrary to the statements of Azizi, who denied his country’s plans to build nuclear weapons, Tehran did not originally want to freeze its uranium stockpile enriched to 60%
According to the IAEA’s definition, around 42 kg of uranium enriched to 60% is the amount at which creating one atomic weapon is theoretically possible. The 60% purity is just a short, technical step away from weapons-grade levels of 90%.
Spokesperson and deputy head of Iran’s Atomic Energy Organization, Behrouz Kamalvandi, said on Friday that IAEA inspectors were scheduled to come immediately after the meeting of the Board of Governors to evaluate Iran’s capacity, “with those capacities remaining for a month without any interruption in enrichment at 60% purity.”
Iran’s news agency, Tasnim, quoted Kamalvandi as saying that “the pressures resulting from the IAEA resolution are counterproductive, meaning that they increase our ability to enrich.”
He added: “Currently, not only have we not stopped enrichment, but we have orders to increase the speed, and we are gradually working on that."