Washington Warns of Iranian Piracy Targeting World Sectors

An FBI special agent investigates a scene in Queens, New York March 25, 2010. (Reuters)
An FBI special agent investigates a scene in Queens, New York March 25, 2010. (Reuters)
TT
20

Washington Warns of Iranian Piracy Targeting World Sectors

An FBI special agent investigates a scene in Queens, New York March 25, 2010. (Reuters)
An FBI special agent investigates a scene in Queens, New York March 25, 2010. (Reuters)

In a joint US-UK operation, US security and law enforcement agencies issued a warning of Iranian-affiliated hacking operations targeting a range of government and private organizations in multiple sectors around the world.

The Federal Bureau of Investigation (FBI), the Cybersecurity and Infrastructure Security Agency (CISA), and other British and US agencies were quoted by Reuters as saying that they had observed Iranian entities, known as MuddyWater, carrying out cyber-espionage targeting the defense, local government, oil and natural gas and telecommunications sectors across the globe.

An alert issued by the US Cyber Security Agency stated that it had revealed, in cooperation with the FBI, the US National Cyber Command Force, and the National Cyber Security Center in the United Kingdom, the presence of “a group of Iranian government-sponsored advanced persistent threat (APT) actors, known as MuddyWater, conducting cyber espionage and other malicious cyber operations targeting a range of government and private-sector organizations across sectors…”

The US Cyber Security Agency said that MuddyWater was a “subordinate element within the Iranian Ministry of Intelligence and Security” and had “conducted broad cyber campaigns in support of MOIS objectives since approximately 2018.”

“MuddyWater actors are positioned both to provide stolen data and accesses to the Iranian government and to share these with other malicious cyber actors,” according to the agency.

The alert read: “MuddyWater actors are known to exploit publicly reported vulnerabilities and use open-source tools and strategies to gain access to sensitive data on victims’ systems and deploy ransomware. These actors also maintain persistence on victim networks via tactics such as side-loading dynamic link libraries (DLLs)—to trick legitimate programs into running malware…”

The US warning comes less than two weeks after the Cyber Security Agency had cautioned against a “new storm” of cyber-attacks targeting individuals and facilities.

A report by the FBI and the Cyber Security Agency of the Department of Homeland Security on Feb. 10 disclosed major plans that some hackers might carry out to target civilian facilities and individuals with the aim to cause wider damage.

However, the latest warning pointed specifically to Iran’s MuddyWater which mainly targeted Middle Eastern, European and North American countries. The group’s victims are mainly in the telecommunications and government sectors, as well as oil.

The group was previously associated with the FIN7, but MuddyWater may have been motivated by espionage.

FIN7 has been working on active financially motivated threats since 2013 and primarily targeting the retail, restaurant and hospitality sectors in the United States, often using point-of-sale malware.



Danish General Says He Is Not Losing Sleep over US Plans for Greenland

FILE - A view of a Greenland flag in the village of Igaliku in Greenland, Friday, July 5, 2024. (Ida Marie Odgaard/ Ritzau Scanpix via AP, File)
FILE - A view of a Greenland flag in the village of Igaliku in Greenland, Friday, July 5, 2024. (Ida Marie Odgaard/ Ritzau Scanpix via AP, File)
TT
20

Danish General Says He Is Not Losing Sleep over US Plans for Greenland

FILE - A view of a Greenland flag in the village of Igaliku in Greenland, Friday, July 5, 2024. (Ida Marie Odgaard/ Ritzau Scanpix via AP, File)
FILE - A view of a Greenland flag in the village of Igaliku in Greenland, Friday, July 5, 2024. (Ida Marie Odgaard/ Ritzau Scanpix via AP, File)

The head of Denmark's Arctic command said the prospect of a US takeover of Greenland was not keeping him up at night after talks with a senior US general last week but that more must be done to deter any Russian attack on the Arctic island.

US President Donald Trump has repeatedly suggested the United States might acquire Greenland, a vast semi-autonomous Danish territory on the shortest route between North America and Europe vital for the US ballistic missile warning system.

Trump has not ruled out taking the territory by force and, at a congressional hearing this month, Defense Secretary Pete Hegseth did not deny that such contingency plans exist.

Such a scenario "is absolutely not on my mind," Soren Andersen, head of Denmark's Joint Arctic Command, told Reuters in an interview, days after what he said was his first meeting with the general overseeing US defense of the area.

"I sleep perfectly well at night," Anderson said. "Militarily, we work together, as we always have."

US General Gregory Guillot visited the US Pituffik Space Base in Greenland on June 19-20 for the first time since the US moved Greenland oversight to the Northern command from its European command, the Northern Command said on Tuesday.

Andersen's interview with Reuters on Wednesday were his first detailed comments to media since his talks with Guillot, which coincided with Danish military exercises on Greenland involving one of its largest military presences since the Cold War.

Russian and Chinese state vessels have appeared unexpectedly around Greenland in the past and the Trump administration has accused Denmark of failing to keep it safe from potential incursions. Both countries have denied any such plans.

Andersen said the threat level to Greenland had not increased this year. "We don't see Russian or Chinese state ships up here," he said.

DOG SLED PATROLS

Denmark's permanent presence consists of four ageing inspection vessels, a small surveillance plane, and dog sled patrols tasked with monitoring an area four times the size of France.

Previously focused on demonstrating its presence and civilian tasks like search and rescue, and fishing inspection, the Joint Arctic Command is now shifting more towards territorial defense, Andersen said.

"In reality, Greenland is not that difficult to defend," he said. "Relatively few points need defending, and of course, we have a plan for that. NATO has a plan for that."

As part of the military exercises this month, Denmark has deployed a frigate, F-16s, special forces and extra troops, and increased surveillance around critical infrastructure. They would leave next week when the exercises end, Andersen said, adding that he would like to repeat them in the coming months.

"To keep this area conflict-free, we have to do more, we need to have a credible deterrent," he said. "If Russia starts to change its behavior around Greenland, I have to be able to act on it."

In January, Denmark pledged over $2 billion to strengthen its Arctic defense, including new Arctic navy vessels, long-range drones, and satellite coverage. France offered to deploy troops to Greenland and EU's top military official said it made sense to station troops from EU countries there.

Around 20,000 people live in the capital Nuuk, with the rest of Greenland's 57,000 population spread across 71 towns, mostly on the west coast. The lack of infrastructure elsewhere is a deterrent in itself, Andersen said.

"If, for example, there were to be a Russian naval landing on the east coast, I think it wouldn't be long before such a military operation would turn into a rescue mission," he said.