Washington Warns of Iranian Piracy Targeting World Sectors

An FBI special agent investigates a scene in Queens, New York March 25, 2010. (Reuters)
An FBI special agent investigates a scene in Queens, New York March 25, 2010. (Reuters)
TT
20

Washington Warns of Iranian Piracy Targeting World Sectors

An FBI special agent investigates a scene in Queens, New York March 25, 2010. (Reuters)
An FBI special agent investigates a scene in Queens, New York March 25, 2010. (Reuters)

In a joint US-UK operation, US security and law enforcement agencies issued a warning of Iranian-affiliated hacking operations targeting a range of government and private organizations in multiple sectors around the world.

The Federal Bureau of Investigation (FBI), the Cybersecurity and Infrastructure Security Agency (CISA), and other British and US agencies were quoted by Reuters as saying that they had observed Iranian entities, known as MuddyWater, carrying out cyber-espionage targeting the defense, local government, oil and natural gas and telecommunications sectors across the globe.

An alert issued by the US Cyber Security Agency stated that it had revealed, in cooperation with the FBI, the US National Cyber Command Force, and the National Cyber Security Center in the United Kingdom, the presence of “a group of Iranian government-sponsored advanced persistent threat (APT) actors, known as MuddyWater, conducting cyber espionage and other malicious cyber operations targeting a range of government and private-sector organizations across sectors…”

The US Cyber Security Agency said that MuddyWater was a “subordinate element within the Iranian Ministry of Intelligence and Security” and had “conducted broad cyber campaigns in support of MOIS objectives since approximately 2018.”

“MuddyWater actors are positioned both to provide stolen data and accesses to the Iranian government and to share these with other malicious cyber actors,” according to the agency.

The alert read: “MuddyWater actors are known to exploit publicly reported vulnerabilities and use open-source tools and strategies to gain access to sensitive data on victims’ systems and deploy ransomware. These actors also maintain persistence on victim networks via tactics such as side-loading dynamic link libraries (DLLs)—to trick legitimate programs into running malware…”

The US warning comes less than two weeks after the Cyber Security Agency had cautioned against a “new storm” of cyber-attacks targeting individuals and facilities.

A report by the FBI and the Cyber Security Agency of the Department of Homeland Security on Feb. 10 disclosed major plans that some hackers might carry out to target civilian facilities and individuals with the aim to cause wider damage.

However, the latest warning pointed specifically to Iran’s MuddyWater which mainly targeted Middle Eastern, European and North American countries. The group’s victims are mainly in the telecommunications and government sectors, as well as oil.

The group was previously associated with the FIN7, but MuddyWater may have been motivated by espionage.

FIN7 has been working on active financially motivated threats since 2013 and primarily targeting the retail, restaurant and hospitality sectors in the United States, often using point-of-sale malware.



Iran Turns to Moscow and Beijing to Thwart ‘Snapback’ Sanctions Threat

Sergei Lavrov and Wang Yi met in Beijing on July 13 (Reuters)
Sergei Lavrov and Wang Yi met in Beijing on July 13 (Reuters)
TT
20

Iran Turns to Moscow and Beijing to Thwart ‘Snapback’ Sanctions Threat

Sergei Lavrov and Wang Yi met in Beijing on July 13 (Reuters)
Sergei Lavrov and Wang Yi met in Beijing on July 13 (Reuters)

Iran is turning to Russia and China in a bid to head off the potential reimposition of international sanctions, amid escalating tensions over its nuclear program.

Iranian Foreign Minister Abbas Araghchi has held talks with his Chinese and Russian counterparts to discuss the future of the nuclear accord and the possibility that the European troika could trigger the “snapback” mechanism.

Iranian state media reported on Monday that Araghchi arrived in Beijing at the head of an official delegation to attend a meeting of the Shanghai Cooperation Organization’s foreign ministers. The trip comes as debate intensifies within Iran over the stances of Moscow and Beijing, particularly in the aftermath of the recent conflict between Iran and Israel.

Speaking at a press conference, Foreign Ministry spokesman Ismail Baghaei stressed that Gulf security remains a priority for China.

“Araghchi’s visit follows an official invitation from the Chinese Foreign Minister,” he said, adding that the Iranian diplomat will hold bilateral meetings Tuesday on the sidelines of the gathering.

Baghaei emphasized Tehran’s ongoing coordination with both Russia and China, who are parties to the nuclear deal.

“Russia and China have consistently expressed their readiness to play a constructive role in the process related to Iran’s nuclear file, and this continues,” he noted. “We have longstanding, friendly relations with both countries and a strategic partnership.”

Addressing reports that Moscow has privately urged Tehran to halt uranium enrichment, Baghaei said: “We have not received any specific proposal from Russia on this matter.”

In Beijing, China’s Foreign Ministry confirmed that Foreign Minister Wang Yi discussed Iran’s nuclear issue with his Russian counterpart, Sergei Lavrov, alongside other bilateral and international topics.

Meanwhile, Moscow on Sunday denounced a report claiming President Vladimir Putin had urged Iran to accept a deal with the United States that would bar it from enriching uranium. Russia’s Foreign Ministry dismissed the claim as “defamation” aimed at inflaming tensions over the Iranian nuclear program.

According to the American outlet Axios, sources familiar with the issue said Putin recently pressed Iran to agree to “zero enrichment.”

But Russia rebuffed the report as baseless, insisting its position is well known: "Invariably and repeatedly, we have emphasized the necessity of resolving the crisis concerning Iran's nuclear program exclusively through political and diplomatic means, and expressed our willingness to help find mutually acceptable solutions," the ministry statement read.

It added that Moscow stands ready to help broker mutually acceptable solutions.

Since the start of Russia’s invasion of Ukraine in 2022, Moscow has strengthened its ties with Tehran. While publicly backing Iran’s right to enrich uranium, Putin has reportedly adopted a tougher line behind closed doors following the 12-day conflict between Israel and Iran.

According to European and Israeli officials, Moscow has encouraged Tehran to accept a “zero enrichment” compromise and shared this position with Israeli authorities. “We know this is what Putin told the Iranians,” a senior Israeli official confirmed.

Last week, Putin is said to have relayed his stance in calls with US President Donald Trump and French President Emmanuel Macron.