Iranian Ransomware Programs Take Cybersecurity Experts by Surprise

Ransomware encrypts files on a victim’s computer. The perpetrator then demands ransom payments in exchange for decrypting the files and sometimes also threatens to leak the victim’s data. (Reuters)
Ransomware encrypts files on a victim’s computer. The perpetrator then demands ransom payments in exchange for decrypting the files and sometimes also threatens to leak the victim’s data. (Reuters)
TT

Iranian Ransomware Programs Take Cybersecurity Experts by Surprise

Ransomware encrypts files on a victim’s computer. The perpetrator then demands ransom payments in exchange for decrypting the files and sometimes also threatens to leak the victim’s data. (Reuters)
Ransomware encrypts files on a victim’s computer. The perpetrator then demands ransom payments in exchange for decrypting the files and sometimes also threatens to leak the victim’s data. (Reuters)

Iranian hackers have recently launched cyberattacks against vital institutions and facilities in the United States, raising the concern of law enforcement authorities in the country.

These attacks are added to various others launched by several parties against the US.

With much attention this year on Russian ransomware attacks against the US, the Iranian threat may come as a surprise, said a report by the Foreign Policy magazine, adding that Iranian ransomware groups were quietly emerging as a global force to be reckoned with elsewhere in the world.

On November, the US, Britain and Australia issued a joint warning that Iranian actors have conducted ransomware attacks against US targets and gained access to a wide range of critical infrastructure networks, including the children’s hospital, that would enable more attacks, the report read.

Experts in the Federal Bureau of Investigation (FBI), the Cybersecurity and Infrastructure Security Agency (CISA), the Australian Cyber Security Center (ACSC) and the United Kingdom’s National Cyber Security Center (NCSC) found out that an ongoing malicious cyber activity by an advanced persistent threat (APT) group is associated with the government of Iran.

Ransomware encrypts files on a victim’s computer. The perpetrator then demands ransom payments in exchange for decrypting the files and sometimes also threatens to leak the victim’s data.

“The Iranian government-sponsored APT actors are actively targeting a broad range of victims across multiple US critical infrastructure sectors,” the experts warned.

While Iranian ransomware may be relatively unfamiliar to Americans, it has been a part of everyday life in Israel for more than a year, the US magazine noted.

“Iranian actors have targeted almost every sector of Israel’s economy and society.”

The report pointed out that Iran’s successful use of ransomware against Israel has likely emboldened it to expand its focus to the United States.

In September 2020, an Israeli cybersecurity firm first detected Iranian ransomware activity against unspecified “prominent Israeli organizations.”

Another hacking group, Black Shadow, believed to be linked to Iran, was accused of carrying out a major cyberattack in October targeting an Internet service provider in Israel.

The report warned that Iran’s ransomware campaign appears to be on the brink of global expansion.

In 2019, a report prepared by researchers at the US giant Microsoft Corporation said that Iranian hackers are working to infiltrate systems, companies and governments around the world, causing damages amounting to hundreds of millions of dollars.

Some believe these attacks may be part of Iran’s attempts not only to influence cybersecurity and its open conflict with its “rivals” but also to obtain foreign cash, especially the US dollar, to break the blockade imposed on it.



NKorean Leader Accuses Seoul of Smear Campaign Over Floods

In this photo provided by the North Korean government, North Korean leader Kim Jong Un speaks as he visits an air force helicopter unit to praise the troops for helping rescue people from recent floods, at an undisclosed location in North Korea, Friday, Aug. 2, 2024. (Korean Central News Agency/Korea News Service via AP)
In this photo provided by the North Korean government, North Korean leader Kim Jong Un speaks as he visits an air force helicopter unit to praise the troops for helping rescue people from recent floods, at an undisclosed location in North Korea, Friday, Aug. 2, 2024. (Korean Central News Agency/Korea News Service via AP)
TT

NKorean Leader Accuses Seoul of Smear Campaign Over Floods

In this photo provided by the North Korean government, North Korean leader Kim Jong Un speaks as he visits an air force helicopter unit to praise the troops for helping rescue people from recent floods, at an undisclosed location in North Korea, Friday, Aug. 2, 2024. (Korean Central News Agency/Korea News Service via AP)
In this photo provided by the North Korean government, North Korean leader Kim Jong Un speaks as he visits an air force helicopter unit to praise the troops for helping rescue people from recent floods, at an undisclosed location in North Korea, Friday, Aug. 2, 2024. (Korean Central News Agency/Korea News Service via AP)

North Korean leader Kim Jong Un accused South Korea’s “rubbish” media of tarnishing the North’s image by allegedly exaggerating the death tolls from recent floods that hit the country’s northwest region, and hinted that he would refuse Seoul’s offer for aid.

Kim made the comments Friday during a visit to an air force helicopter unit, where he praised the troops for helping rescue people from the floods, North Korea’s official Korean Central News Agency said Saturday.

During the visit, Kim denied claims by South Korean media that 1,000 to 1,500 North Koreans would have died from the floods and that multiple helicopters might have crashed during the emergency response. According to The Associated Press, he described the reports as a “vicious smear campaign” by the South.
Kim labeled South Korea as an unchangeable enemy and stressed that the North will never sacrifice its national defense to improve disaster recovery or people’s standards of living — hinting that Pyongyang would reject Seoul's aid offer.
South Korea’s government offered Thursday to send aid supplies to address the “humanitarian challenges” facing North Korean residents in flood-affected areas near the country’s border with China.
It was widely expected that North Korea would reject the offer. Animosity between the war-divided rivals is at its highest in years over the North’s growing nuclear ambitions and the South’s expansion of combined military exercises with the United States and Japan to counter the North’s threats.
The North had also rejected South Korea’s offers for help while battling a COVID-19 outbreak in 2022.
North Korean state media reports said recent heavy rains left 4,100 houses, 7,410 acres of agricultural fields and numerous other public buildings, structures, roads and railways flooded in the northwestern city of Sinuiju and the neighboring town of Uiju.
State media has not provided information on deaths, but Kim was quoted blaming public officials who had neglected disaster prevention, causing “the casualty that cannot be allowed.”
During his visit to the helicopter unit, Kim said it was a miracle that no casualties were reported in the Sinuiju area and credited the air force personnel for pulling off successful rescue missions.
Kim also said that one helicopter made an emergency landing during a rescue mission but that all pilots were safe, in what appeared to be a denial of South Korean media claims about multiple helicopter crashes.