Microsoft: Iranian Hackers Scout US Election-Related Websites

Voters wait in line to cast their ballots on the first day of early in-person voting in one of the mountainous counties badly affected by Hurricane Helene, in Marion, North Carolina, US October 17, 2024. REUTERS/Jonathan Drake
Voters wait in line to cast their ballots on the first day of early in-person voting in one of the mountainous counties badly affected by Hurricane Helene, in Marion, North Carolina, US October 17, 2024. REUTERS/Jonathan Drake
TT

Microsoft: Iranian Hackers Scout US Election-Related Websites

Voters wait in line to cast their ballots on the first day of early in-person voting in one of the mountainous counties badly affected by Hurricane Helene, in Marion, North Carolina, US October 17, 2024. REUTERS/Jonathan Drake
Voters wait in line to cast their ballots on the first day of early in-person voting in one of the mountainous counties badly affected by Hurricane Helene, in Marion, North Carolina, US October 17, 2024. REUTERS/Jonathan Drake

An Iranian hacking group is actively scouting US election-related websites and American media outlets as Election Day nears, with activity suggesting preparations for more “direct influence operations,” according to a Microsoft blog published on Wednesday.

The hackers – dubbed Cotton Sandstorm by Microsoft and linked to Iran's Revolutionary Guard Corps – performed reconnaissance and limited probing of multiple “election-related websites” in several unnamed battleground states, the report said, according to Reuters.

In May, they also scanned an unidentified US news outlet to understand its vulnerabilities.

US Vice President Kamala Harris, the Democratic candidate, faces Republican rival Donald Trump in the Nov. 5 presidential elections, which polls suggest is an extremely tight race.

“Cotton Sandstorm will increase its activity as the election nears given the group's operational tempo and history of election interference,” researchers wrote. The development is particularly concerning because of the group's past efforts, they said.

A spokesperson for Iran's mission to the United Nations said that “such allegations are fundamentally unfounded, and wholly inadmissible.”

He added, “Iran neither has any motive nor intent to interfere in the US election.”

In 2020, Cotton Sandstorm launched a different cyber-enabled influence operation shortly before the last presidential election, according to US officials.

The group also released a video on social media, purporting to come from activist hackers, where they showed them probing an election system.

While that operation never affected individual voting systems, the goal was to cause chaos, confusion and doubt, senior US officials said at the time.

Following the 2020 election, Cotton Sandstorm also ran a separate operation that encouraged violence against US election officials who had denied claims of widespread voter fraud, Microsoft said.

The Office of the Director of National Intelligence, which is coordinating the US federal effort to protect the election from foreign influence, referred Reuters to a past statement that said: “Foreign actors — particularly Russia, Iran, and China — remain intent on fanning divisive narratives to divide Americans and undermine Americans’ confidence in the US democratic system.”



Thiel’s Palantir Dumped by Norwegian Investor over Work for Israel

The logo of US software company Palantir Technologies is seen in Davos, Switzerland, May 22, 2022. Picture taken May 22, 2022. (Reuters)
The logo of US software company Palantir Technologies is seen in Davos, Switzerland, May 22, 2022. Picture taken May 22, 2022. (Reuters)
TT

Thiel’s Palantir Dumped by Norwegian Investor over Work for Israel

The logo of US software company Palantir Technologies is seen in Davos, Switzerland, May 22, 2022. Picture taken May 22, 2022. (Reuters)
The logo of US software company Palantir Technologies is seen in Davos, Switzerland, May 22, 2022. Picture taken May 22, 2022. (Reuters)

One of the Nordic region's largest investors has sold its holdings in Palantir Technologies because of concerns that the US data firm's work for Israel might put the asset manager at risk of violating international humanitarian law and human rights.

Storebrand Asset Management disclosed this week that it had "excluded Palantir Technologies Inc. from our investments due (to) its sales of products and services to Israel for use in occupied Palestinian territories."

The investor, which manages about 1 trillion crowns ($91.53 billion) in assets, held around 262 million crowns ($24 million) in Palantir, a spokesperson told Reuters. A representative for Palantir, based in Denver, did not immediately respond to a request for comment.

Storebrand said Palantir had not replied to any of its requests for information, first lodged in April. The data analytics firm, co-founded by billionaire Peter Thiel, provides militaries with artificial-intelligence models. Earlier this year, it agreed to a strategic partnership to supply technology to Israel to assist in the ongoing war in Gaza.

Palantir has previously defended its work for Israel. CEO Alex Karp said he was proud to have worked with the country following the Hamas attacks in October last year and in March told CNBC that Palantir had lost employees and that he expected to lose more over his public support for Israel.

Storebrand's exit follows a recommendation from Norway's government in March warning businesses about engaging in economic or financial activity in the Israeli settlements in the Palestinian territories, the asset manager said in its third-quarter investment review published on Wednesday. The International Court of Justice, the United Nations' highest court, said in July that Israel's occupation of Palestinian territories including the settlements was illegal.

Israel's foreign ministry rejected that opinion as "fundamentally wrong" and one-sided, and repeated its stance that a political settlement in the region can be reached only by negotiations.

Storebrand said its analysis indicated that Palantir provides products and services "including AI-based predictive policing systems" that support Israeli surveillance of Palestinians in the West Bank and Gaza.

Palantir's systems are supposed "to identify individuals who are likely to launch 'lone wolf terrorist' attacks, facilitating their arrests preemptively before the strikes that it is projected they would carry out," Storebrand said.

It added that, according to the United Nations, Israeli authorities have a history of incarcerating Palestinians without charge or trial. A UN Special Rapporteur said in a 2023 report that "the occupied Palestinian territory had been transformed as a whole into a constantly surveilled open-air prison."

Israel rejected the UN's findings. In September Reuters reported that Norway's $1.7 trillion wealth fund may have to divest shares of companies that violate the fund watchdog's tougher interpretation of ethics standards for businesses that aid Israel's operations in the occupied Palestinian territories.