#hacking | Iranian hackers breach US government website in retaliation for airstrike 

Source: National Cyber Security – Produced By Gregory Evans

A website operated by the U.S. government has been hacked by a group claiming to represent the government of Iran.

The website operated by the little-known Federal Depository Library Program, fdlp.gov, was hacked and defaced on Saturday, and has been taken offline.

A message from the hackers left on the website read: ‘in the name of god. >>>>> Hacked By Iran Cyber Security Group HackerS … ;)<<<<<. This is only small part of Iran’s cyber ability ! We’re always ready.’

The FDLP is a program created to make federal government publications available to the public at no cost. 

The image above appeared on fdlp.gov on Saturday before the website was taken offline

The hackers in their message made reference to the death of Qassem Soleimani, and depicted President Donald Trump being beaten by a fist with the Revolutionary Guard insignia

The hackers in their message made reference to the death of Qassem Soleimani, and depicted President Donald Trump being beaten by a fist with the Revolutionary Guard insignia

Current Google results show the defaced page title text of the fdlp.gov website

Current Google results show the defaced page title text of the fdlp.gov website

It followed the similar hacking of websites for a number of obscure, non-governmental entities, including the Sierra Leone Commercial Bank, the Taiwan Lung Meng Technology Company, and the Human Rights Protection Association of India.

The website for a British company called Bigways was also struck in the cyber attacks.

Security experts have already warned that cyber attacks could be part of Iran’s retaliation for the U.S. airstrike on Friday that killed Revolutionary Guard General Qassem Soleimani, a top official in Iran and beloved there. 

Iran’s state-backed hackers are already among the world’s most aggressive and could inject malware that triggers major disruptions to the U.S. public and private sector.

Potential targets include manufacturing facilities, oil and gas plants and transit systems. A top U.S. cybersecurity official is warning businesses and government agencies to be extra vigilant.

The websites of several obscure, non-government entities were also defaced on Saturday

The websites of several obscure, non-government entities were also defaced on Saturday

In 2012 and 2013, in response to U.S. sanctions, Iranian state-backed hackers carried out a series of disruptive denial-of-service attacks that knocked offline the websites of major U.S. banks including Bank of America as well as the New York Stock Exchange and NASDAQ. 

Two years later, they wiped servers at the Sands Casino in Las Vegas, crippling hotel and gambling operations.

The destructive attacks on U.S. targets ebbed when Tehran reached a nuclear deal with the Obama administration in 2015. 

The killing early Friday in Iraq of Quds Force commander Soleimani – long after Trump scrapped the nuclear deal – completely alters the equation.

‘Our concern is essentially that things are going to go back to the way they were before the agreement,’ said John Hultquist, director of intelligence analysis at the cybersecurity firm FireEye. ‘There are opportunities for them to cause real disruption and destruction.’

Iran has been doing a lot of probing of critical U.S. industrial systems in recent years – trying to gain access – but has limited its destructive attacks to targets in the Middle East, experts say.

It’s not known whether Iranian cyberagents have planted destructive payloads in U.S. infrastructure that could now be triggered.

‘It’s certainly possible,’ Hultquist said. ‘But we haven´t actually seen it.’

Member of the Iranian Basij paramilitary militia, affiliated to the Revolutionary Guard, mourn Gen. Qassem Soleimani, in Tehran, Iran on Saturday

Member of the Iranian Basij paramilitary militia, affiliated to the Revolutionary Guard, mourn Gen. Qassem Soleimani, in Tehran, Iran on Saturday

Iranians take part in an anti-US rally in Tehran, Iran on Saturday

Iranians take part in an anti-US rally in Tehran, Iran on Saturday

Robert M. Lee, chief executive of Dragos Inc., which specializes in industrial control system security, said Iranian hackers have been very aggressive in trying to gain access to utilities, factories, and oil and gas facilities. 

That doesn’t mean they’ve succeeded, however. In one case in 2013 where they did break into the control system of a U.S. dam – garnering significant media attention – Lee said they probably didn’t know the compromised target was a small flood control structure 20 miles north of New York City.

Iran has been increasing its cyber capabilities but is not in the same league as China or Russia – which have proved most adept at sabotaging critical infrastructure, witnessed in attacks on Ukraine´s power grid and elections, experts agree.

And while the U.S. power grid is among the most secure and resilient in the world, plenty of private companies and local governments haven’t made adequate investments in cybersecurity and are highly vulnerable, experts say.

‘My worst-case scenario is a municipality or a cooperative-type attack where power is lost to a city or a couple of neighborhoods,’ Lee said.

Consider the havoc an epidemic of ransomware attacks has caused U.S. local governments, crippling services as vital as tax collection. While there´s no evidence of coordinated Iranian involvement, imagine if the aggressor – instead of scrambling data and demanding ransoms – simply wiped hard drives clean, said Hultquist.

‘You could see many cities and hospitals targeted at once with ransomware that encrypts data to make it unusable, but there is no way to decrypt it by paying a ransom,’ said cybersecurity veteran Chris Wysopal, the chief technical officer of Veracode.

Members of Iran-backed Iraqi Shiite armed groups popular mobilization forces carry the coffin of slain Abu Mahdi al-Muhandis during a funeral procession in Karbala city, southern Baghdad

Members of Iran-backed Iraqi Shiite armed groups popular mobilization forces carry the coffin of slain Abu Mahdi al-Muhandis during a funeral procession in Karbala city, southern Baghdad

The only known cybersecurity survey of U.S. local governments, county and municipal, found that the networks of 28% were being attacked at least hourly – and that nearly the same percentage said they didn´t even know how frequently they were being attacked. Although the study was done in 2016, the authors at the University of Maryland-Baltimore County don´t believe the situation has improved since.

The top cybersecurity official at the Department of Homeland Security, Christopher Krebs, urged companies and government agencies to refresh their knowledge of Iranian state-backed hackers’ past exploits and methods after Soleimani’s death was announced. ‘Pay close attention to your critical systems,’ he tweeted.

In June, Krebs warned of a rise in malicious Iranian cyberactivity, particularly attacks using common methods like spear-phishing that could erase entire networks: ‘What might start as an account compromise, where you think you might just lose data, can quickly become a situation where you´ve lost your whole network.’

Wysopal said the Iranians are apt to have learned a lot from the 2017 NotPetya attack, which the U.S. and Britain have attributed to state-backed Russian hackers and which caused at least $10 billion in damage globally. The worst cyberattack to date, it exploited unpatched software after being delivered through an unwitting Ukrainian tax software provider and spread on networks without human intervention.

When then-Director of National Intelligence James Clapper blamed Iran for the Sands Casino attack, it was one of the first cases of American intelligence agencies identifying a specific country as hacking for political reasons: The casino´s owner, Sheldon Adelson, is a big Israel backer. Clapper also noted the value of hacking for collecting intelligence. North Korea´s hack of Sony Pictures in retaliation for a movie that mocked its leader followed.

The vast majority of the nearly 100 Iranian targets leaked online last year by a person or group known as Lab Dookhtegan – a defector, perhaps – were in the Middle East, said Charity Wright, a former National Security Agency analyst at the threat intelligence firm InSights. She said it´s highly likely Iran will focus its retaliation on U.S. targets in the region as well as in Israel and the U.S.

Iran is widely believed to have been behind a devastating 2012 attack on Aramco, the Saudi oil company, that wiped the data from more than 30,000 computers. It was also a victim of the Stuxnet computer virus. First uncovered in 2010, it destroyed thousands of centrifuges involved in Iran’s contested nuclear program and is widely reported to have been a U.S.-Israeli invention. 

Source link

The post #hacking | Iranian hackers breach US government website in retaliation for airstrike  appeared first on National Cyber Security.

View full post on National Cyber Security

Print Friendly, PDF & Email

Comments are Closed