FBI Warns US Companies about Iranian Hackers

Iranian hackers have searched cybercriminal websites for sensitive data stolen from American and foreign organizations that could be useful in future efforts to hack those organizations, said the FBI. (Getty Images)
Iranian hackers have searched cybercriminal websites for sensitive data stolen from American and foreign organizations that could be useful in future efforts to hack those organizations, said the FBI. (Getty Images)
TT

FBI Warns US Companies about Iranian Hackers

Iranian hackers have searched cybercriminal websites for sensitive data stolen from American and foreign organizations that could be useful in future efforts to hack those organizations, said the FBI. (Getty Images)
Iranian hackers have searched cybercriminal websites for sensitive data stolen from American and foreign organizations that could be useful in future efforts to hack those organizations, said the FBI. (Getty Images)

Iranian hackers have searched cybercriminal websites for sensitive data stolen from American and foreign organizations that could be useful in future efforts to hack those organizations, the FBI said in an advisory sent to US companies obtained by CNN.

The Iranian hackers have taken an interest in dark-web forums, where scammers leak information on their victims such as stolen emails and network configurations, according to the November 8 advisory. The FBI is concerned that the Iranian hacking group could use that information to plot ways into US corporate networks in the future.

Organizations at risk are advised to take mitigation measures to block hacking attempts by securing Remote Desktop Protocol (RDP) servers, Web Application Firewalls, and Kentico CMS installations targeted by this adversary, said Bleeping Computer, a cybersecurity news outlet, which was the first to report on the FBI analysis.

"Among the Tactics, Techniques, and Procedures (TTPs) used in attacks by this threat actor since May 2021, the FBI mentions the use of auto-exploiter tools used to compromise WordPress sites to deploy web shells, breaching RDP servers and using them to maintain access to victims' networks."

It is unclear which Iranian hacking group is behind the activity. The FBI did not identify the hackers by name or say if they are linked to the Iranian government.

Adam Meyers, senior vice president of intelligence at security firm CrowdStrike, told CNN that Iranian government-linked hackers have increasingly dabbled in cybercriminal activity, such as ransomware, as a means of blurring the lines between state and non-state cyber operations.

"It is well within (Iranian groups') modus operandi to purchase access to networks held by a criminal group if it serves their interests," he added.

An unnamed Iranian hacking group used similar tools to steal voter registration data from state election sites between September and October 2020, Bleeping Computer.

"That voter info was later used to impersonate the far-right Proud Boys organization and send threatening emails to Democratic voters warning that they must vote for Trump or face the consequences."

"The FBI's Cyber Division also warned in a private industry notification issued last week that ransomware gangs have compromised the networks of several tribal-owned casinos, taking down their servers and disabling connected systems."

"The same week, the federal agency also alerted the public that criminals are increasingly using cryptocurrency ATMs and QR codes for fraud, making it harder for law enforcement to recover the victims' financial losses."



Russia: Hypersonic Missile Strike on Ukraine Was a Warning to 'Reckless' West

Russian President Vladimir Putin makes a televised address, dedicated to a military conflict in Ukraine and in particular to Russia's launch of a hypersonic intermediate-range ballistic missile attack on a military facility in response to recent Ukrainian long-range strikes with Western weapons, in Moscow, Russia November 21, 2024. Sputnik/Vyacheslav Prokofyev/Pool via REUTERS
Russian President Vladimir Putin makes a televised address, dedicated to a military conflict in Ukraine and in particular to Russia's launch of a hypersonic intermediate-range ballistic missile attack on a military facility in response to recent Ukrainian long-range strikes with Western weapons, in Moscow, Russia November 21, 2024. Sputnik/Vyacheslav Prokofyev/Pool via REUTERS
TT

Russia: Hypersonic Missile Strike on Ukraine Was a Warning to 'Reckless' West

Russian President Vladimir Putin makes a televised address, dedicated to a military conflict in Ukraine and in particular to Russia's launch of a hypersonic intermediate-range ballistic missile attack on a military facility in response to recent Ukrainian long-range strikes with Western weapons, in Moscow, Russia November 21, 2024. Sputnik/Vyacheslav Prokofyev/Pool via REUTERS
Russian President Vladimir Putin makes a televised address, dedicated to a military conflict in Ukraine and in particular to Russia's launch of a hypersonic intermediate-range ballistic missile attack on a military facility in response to recent Ukrainian long-range strikes with Western weapons, in Moscow, Russia November 21, 2024. Sputnik/Vyacheslav Prokofyev/Pool via REUTERS

The Kremlin said on Friday that a strike on Ukraine using a newly developed hypersonic ballistic missile was designed as a message to the West that Moscow will respond to their "reckless" decisions and actions in support of Ukraine.
Kremlin spokesman Dmitry Peskov was speaking a day after President Vladimir Putin said Moscow had fired the new missile - the Oreshnik or Hazel Tree - at a Ukrainian military facility.
"The main message is that the reckless decisions and actions of Western countries that produce missiles, supply them to Ukraine and subsequently participate in strikes on Russian territory cannot remain without a reaction from the Russian side," Peskov told reporters.
"The Russian side has clearly demonstrated its capabilities, and the contours of further retaliatory actions in the event that our concerns are not taken into account have been quite clearly outlined,” Reuters quoted him as saying.
Peskov said Russia had not been obliged to warn the United States about the strike, but had informed the US 30 minutes before the launch anyway.
President Vladimir Putin remained open to dialogue, Peskov said, but he said the outgoing administration of US President Joe Biden "prefers to continue down the path of escalation".
Putin said on Thursday that Russia had fired the new missile after Ukraine, with approval from the Biden administration, struck Russia with six US-made ATACMS missiles on Tuesday and with British Storm Shadow cruise missiles and US-made HIMARS on Thursday.
He said this meant that the Ukraine war had now "acquired elements of a global character".
Ukrainian President Volodymyr Zelenskiy has said Russia's use of the new missile amounted to "a clear and severe escalation" in the war and called for strong worldwide condemnation.