Washington Warns of Iranian Piracy Targeting World Sectors

An FBI special agent investigates a scene in Queens, New York March 25, 2010. (Reuters)
An FBI special agent investigates a scene in Queens, New York March 25, 2010. (Reuters)
TT

Washington Warns of Iranian Piracy Targeting World Sectors

An FBI special agent investigates a scene in Queens, New York March 25, 2010. (Reuters)
An FBI special agent investigates a scene in Queens, New York March 25, 2010. (Reuters)

In a joint US-UK operation, US security and law enforcement agencies issued a warning of Iranian-affiliated hacking operations targeting a range of government and private organizations in multiple sectors around the world.

The Federal Bureau of Investigation (FBI), the Cybersecurity and Infrastructure Security Agency (CISA), and other British and US agencies were quoted by Reuters as saying that they had observed Iranian entities, known as MuddyWater, carrying out cyber-espionage targeting the defense, local government, oil and natural gas and telecommunications sectors across the globe.

An alert issued by the US Cyber Security Agency stated that it had revealed, in cooperation with the FBI, the US National Cyber Command Force, and the National Cyber Security Center in the United Kingdom, the presence of “a group of Iranian government-sponsored advanced persistent threat (APT) actors, known as MuddyWater, conducting cyber espionage and other malicious cyber operations targeting a range of government and private-sector organizations across sectors…”

The US Cyber Security Agency said that MuddyWater was a “subordinate element within the Iranian Ministry of Intelligence and Security” and had “conducted broad cyber campaigns in support of MOIS objectives since approximately 2018.”

“MuddyWater actors are positioned both to provide stolen data and accesses to the Iranian government and to share these with other malicious cyber actors,” according to the agency.

The alert read: “MuddyWater actors are known to exploit publicly reported vulnerabilities and use open-source tools and strategies to gain access to sensitive data on victims’ systems and deploy ransomware. These actors also maintain persistence on victim networks via tactics such as side-loading dynamic link libraries (DLLs)—to trick legitimate programs into running malware…”

The US warning comes less than two weeks after the Cyber Security Agency had cautioned against a “new storm” of cyber-attacks targeting individuals and facilities.

A report by the FBI and the Cyber Security Agency of the Department of Homeland Security on Feb. 10 disclosed major plans that some hackers might carry out to target civilian facilities and individuals with the aim to cause wider damage.

However, the latest warning pointed specifically to Iran’s MuddyWater which mainly targeted Middle Eastern, European and North American countries. The group’s victims are mainly in the telecommunications and government sectors, as well as oil.

The group was previously associated with the FIN7, but MuddyWater may have been motivated by espionage.

FIN7 has been working on active financially motivated threats since 2013 and primarily targeting the retail, restaurant and hospitality sectors in the United States, often using point-of-sale malware.



Russia Advances in Ukraine at Fastest Monthly Pace Since Start of War, Analysts Say

A police officer drives a vehicle past burning trees during an evacuation of civilians from the outskirts of the Kurakhove town, amid Russia's attack on Ukraine, in Donetsk region, Ukraine September 16, 2024. (Reuters)
A police officer drives a vehicle past burning trees during an evacuation of civilians from the outskirts of the Kurakhove town, amid Russia's attack on Ukraine, in Donetsk region, Ukraine September 16, 2024. (Reuters)
TT

Russia Advances in Ukraine at Fastest Monthly Pace Since Start of War, Analysts Say

A police officer drives a vehicle past burning trees during an evacuation of civilians from the outskirts of the Kurakhove town, amid Russia's attack on Ukraine, in Donetsk region, Ukraine September 16, 2024. (Reuters)
A police officer drives a vehicle past burning trees during an evacuation of civilians from the outskirts of the Kurakhove town, amid Russia's attack on Ukraine, in Donetsk region, Ukraine September 16, 2024. (Reuters)

Russian forces are advancing in Ukraine at the fastest rate since the early days of the 2022 invasion, taking an area half the size of Greater London over the past month, analysts and war bloggers say.

The war is entering what some Russian and Western officials say could be its most dangerous phase after Moscow's forces made some of their biggest territorial gains and the United States allowed Kyiv to strike back with US missiles.

"Russia has set new weekly and monthly records for the size of the occupied territory in Ukraine," independent Russian news group Agentstvo said in a report.

The Russian army captured almost 235 sq km (91 sq miles) in Ukraine over the past week, a weekly record for 2024, it said.

Russian forces had taken 600 sq km (232 sq miles) in November, it added, citing data from DeepState, a group with close links to the Ukrainian army that studies combat footage and provides frontline maps.

Russia began advancing faster in eastern Ukraine in July just as Ukrainian forces carved out a sliver of its western region of Kursk. Since then, the Russian advance has accelerated, according to open source maps.

Russia's forces are moving into the town of Kurakhove, a stepping stone towards the logistical hub of Pokrovsk in Donetsk, and have been exploiting the vulnerabilities of Kyiv troops along the frontline, analysts said.

"Russian forces recently have been advancing at a significantly quicker rate than they did in the entirety of 2023," analysts at the Washington-based Institute for the Study of War said in a report.

The General Staff of Ukraine's armed forces said in its Monday update that 45 battles of varying intensity were raging along the Kurakhove part of the frontline that evening.

The Institute for the Study of War report and pro-Russian military bloggers say Russian troops are in Kurakhove. Deep State said on its Telegram messaging app on Monday that Russian forces are near Kurakhove.

"Russian forces' advances in southeastern Ukraine are largely the result of the discovery and tactical exploitation of vulnerabilities in Ukraine's lines," Institute analysts said in their report.

Russia says it will achieve all of its aims in Ukraine no matter what the West says or does.

Ukrainian President Volodymyr Zelenskiy has repeatedly said peace cannot be established until all Russian forces are expelled and all territory captured by Moscow, including Crimea, is returned.

But outnumbered by Russian troops, the Ukrainian military is struggling to recruit soldiers and provide equipment to new units.

Zelenskiy has said he believed Russian President Vladimir Putin's main objectives were to occupy the entire Donbas, spanning the regions of Donetsk and Luhansk, and oust Ukrainian troops from the Kursk region, parts of which they have controlled since August.