FBI Warns US Companies about Iranian Hackers

Iranian hackers have searched cybercriminal websites for sensitive data stolen from American and foreign organizations that could be useful in future efforts to hack those organizations, said the FBI. (Getty Images)
Iranian hackers have searched cybercriminal websites for sensitive data stolen from American and foreign organizations that could be useful in future efforts to hack those organizations, said the FBI. (Getty Images)
TT

FBI Warns US Companies about Iranian Hackers

Iranian hackers have searched cybercriminal websites for sensitive data stolen from American and foreign organizations that could be useful in future efforts to hack those organizations, said the FBI. (Getty Images)
Iranian hackers have searched cybercriminal websites for sensitive data stolen from American and foreign organizations that could be useful in future efforts to hack those organizations, said the FBI. (Getty Images)

Iranian hackers have searched cybercriminal websites for sensitive data stolen from American and foreign organizations that could be useful in future efforts to hack those organizations, the FBI said in an advisory sent to US companies obtained by CNN.

The Iranian hackers have taken an interest in dark-web forums, where scammers leak information on their victims such as stolen emails and network configurations, according to the November 8 advisory. The FBI is concerned that the Iranian hacking group could use that information to plot ways into US corporate networks in the future.

Organizations at risk are advised to take mitigation measures to block hacking attempts by securing Remote Desktop Protocol (RDP) servers, Web Application Firewalls, and Kentico CMS installations targeted by this adversary, said Bleeping Computer, a cybersecurity news outlet, which was the first to report on the FBI analysis.

"Among the Tactics, Techniques, and Procedures (TTPs) used in attacks by this threat actor since May 2021, the FBI mentions the use of auto-exploiter tools used to compromise WordPress sites to deploy web shells, breaching RDP servers and using them to maintain access to victims' networks."

It is unclear which Iranian hacking group is behind the activity. The FBI did not identify the hackers by name or say if they are linked to the Iranian government.

Adam Meyers, senior vice president of intelligence at security firm CrowdStrike, told CNN that Iranian government-linked hackers have increasingly dabbled in cybercriminal activity, such as ransomware, as a means of blurring the lines between state and non-state cyber operations.

"It is well within (Iranian groups') modus operandi to purchase access to networks held by a criminal group if it serves their interests," he added.

An unnamed Iranian hacking group used similar tools to steal voter registration data from state election sites between September and October 2020, Bleeping Computer.

"That voter info was later used to impersonate the far-right Proud Boys organization and send threatening emails to Democratic voters warning that they must vote for Trump or face the consequences."

"The FBI's Cyber Division also warned in a private industry notification issued last week that ransomware gangs have compromised the networks of several tribal-owned casinos, taking down their servers and disabling connected systems."

"The same week, the federal agency also alerted the public that criminals are increasingly using cryptocurrency ATMs and QR codes for fraud, making it harder for law enforcement to recover the victims' financial losses."



Mojtaba Khamenei Says Closure of Strait of Hormuz Should be Used as 'Leverage'

(FILES) In this picture obtained from Iran's ISNA news agency, Mojtaba Khamenei (C), son of Iran's supreme leader Ayatollah Ali Khamenei, walks along a street in Tehran on May 31, 2019. (Photo by Hamid FOROUTAN / ISNA / AFP)
(FILES) In this picture obtained from Iran's ISNA news agency, Mojtaba Khamenei (C), son of Iran's supreme leader Ayatollah Ali Khamenei, walks along a street in Tehran on May 31, 2019. (Photo by Hamid FOROUTAN / ISNA / AFP)
TT

Mojtaba Khamenei Says Closure of Strait of Hormuz Should be Used as 'Leverage'

(FILES) In this picture obtained from Iran's ISNA news agency, Mojtaba Khamenei (C), son of Iran's supreme leader Ayatollah Ali Khamenei, walks along a street in Tehran on May 31, 2019. (Photo by Hamid FOROUTAN / ISNA / AFP)
(FILES) In this picture obtained from Iran's ISNA news agency, Mojtaba Khamenei (C), son of Iran's supreme leader Ayatollah Ali Khamenei, walks along a street in Tehran on May 31, 2019. (Photo by Hamid FOROUTAN / ISNA / AFP)

Iran’s Supreme Leader Mojtaba Khamenei issued his first statement on the war on Thursday, saying that the leverage of closing the Strait of Hormuz should be used.

Khamenei called on people in Gulf countries to “shut down” US bases, saying promised US protection is “nothing more than a lie.”

Khamenei did not appear on camera. Israeli intelligence assessed that he was likely wounded in the war’s opening salvo, which he said also killed his wife, one of his sisters, his niece and his father, Supreme Leader Ali Khamenei.

US President Donald Trump has promised to “finish the job,” even as Iran is “virtually destroyed.” The first week of the war cost the United States $11.3 billion, according to the Pentagon.

“One point I must emphasize is that, in any case, we will obtain compensation from the enemy,” Khamenei said.

“If it refuses, we will take from its assets to the extent we deem appropriate, and if that is not possible, we will destroy its assets to the same extent.”

 

 

 

 


Russia Condemns Trump Comments on 'Takeover' of Cuba

US President Donald Trump greets Russian President Vladimir Putin, Aug. 15, 2025, at Joint Base Elmendorf-Richardson, Alaska. (AP Photo/Julia Demaree Nikhinson, File)
US President Donald Trump greets Russian President Vladimir Putin, Aug. 15, 2025, at Joint Base Elmendorf-Richardson, Alaska. (AP Photo/Julia Demaree Nikhinson, File)
TT

Russia Condemns Trump Comments on 'Takeover' of Cuba

US President Donald Trump greets Russian President Vladimir Putin, Aug. 15, 2025, at Joint Base Elmendorf-Richardson, Alaska. (AP Photo/Julia Demaree Nikhinson, File)
US President Donald Trump greets Russian President Vladimir Putin, Aug. 15, 2025, at Joint Base Elmendorf-Richardson, Alaska. (AP Photo/Julia Demaree Nikhinson, File)

Russia condemned on Thursday what it called blackmail and threats by US President Donald Trump to initiate a "takeover" of Cuba, a traditional ally of Moscow.

Russian Foreign Ministry spokeswoman Maria Zakharova said Moscow would provide all possible political and diplomatic support to Cuba and called for a diplomatic solution to the tensions with Washington, Reuters reported.

Trump said on Monday that Cuba was in "deep trouble" and that US Secretary of State Marco Rubio was dealing with the issue, which may or may not be a "friendly takeover."


Trump Says Stopping a Nuclear Iran More Important than Oil Prices

US President Donald Trump talks to the media upon his arrival at Joint Base Andrews, Maryland, US, March 11, 2026.  REUTERS/Kevin Lamarque
US President Donald Trump talks to the media upon his arrival at Joint Base Andrews, Maryland, US, March 11, 2026. REUTERS/Kevin Lamarque
TT

Trump Says Stopping a Nuclear Iran More Important than Oil Prices

US President Donald Trump talks to the media upon his arrival at Joint Base Andrews, Maryland, US, March 11, 2026.  REUTERS/Kevin Lamarque
US President Donald Trump talks to the media upon his arrival at Joint Base Andrews, Maryland, US, March 11, 2026. REUTERS/Kevin Lamarque

US President Donald Trump on Thursday said that stopping Iran from getting nuclear weapons was more important to him than controlling oil prices, Reuters reported.

"The United States is the largest Oil Producer in the World, by far, so when oil prices go up, we make a lot of money. BUT, of far greater interest and importance to me, as President, is stopping an evil Empire, Iran, from having Nuclear Weapons, and destroying the Middle East and, indeed, the World," said Trump in a post on his Truth Social platform.