viralamo

Menu
  • Technology
  • Science
  • Money
  • Culturs
  • Trending
  • Video

Subscribe To Our Website To Receive The Last Stories

Join Us Now For Free
Home
Technology
Cyberattack on Albanian government suggests new Iranian aggression
Technology

Cyberattack on Albanian government suggests new Iranian aggression

06/08/2022

Tirane, Albania.
Enlarge / Tirane, Albania.

Pawel Toczynski | Getty Images

In mid-July, a cyberattack on the Albanian government knocked out state websites and public services for hours. With Russia’s war raging in Ukraine, the Kremlin might seem like the likeliest suspect. But research published on Thursday by the threat intelligence firm Mandiant attributes the attack to Iran. And while Tehran’s espionage operations and digital meddling have shown up all over the world, Mandiant researchers say that a disruptive attack from Iran on a NATO member is a noteworthy escalation.

The digital attacks targeting Albania on July 17 came ahead of the “World Summit of Free Iran,” a conference scheduled to convene in the town of Manëz in western Albania on July 23 and 24. The summit was affiliated with the Iranian opposition group Mujahadeen-e-Khalq, or the People’s Mojahedin Organization of Iran (often abbreviated MEK, PMOI, or MKO). The conference was postponed the day before it was set to begin because of reported, unspecified “terrorist” threats.

Mandiant researchers say that attackers deployed ransomware from the Roadsweep family and may have also utilized a previously unknown backdoor, dubbed Chimneysweep, as well as a new strain of the Zeroclear wiper. Past use of similar malware, the timing of the attacks, other clues from the Roadsweep ransomware note, and activity from actors claiming responsibility for the attacks on Telegram all point to Iran, Mandiant says.

Advertisement

“This is an aggressive escalatory step that we have to recognize,” says John Hultquist, Mandiant’s vice president of intelligence. “Iranian espionage happens all the time all over the world. The difference here is this isn’t espionage. These are disruptive attacks, which affect the lives of everyday Albanians who live within the NATO alliance. And it was essentially a coercive attack to force the hand of the government.”

Iran has conducted aggressive hacking campaigns in the Middle East and particularly in Israel, and its state-backed hackers have penetrated and probed manufacturing, supply, and critical infrastructure organizations. In November 2021, the US and Australian governments warned that Iranian hackers were actively working to gain access to an array of networks related to transportation, health care, and public health entities, among others. “These Iranian government-sponsored APT actors can leverage this access for follow-on operations, such as data exfiltration or encryption, ransomware, and extortion,” the Department of Homeland Security’s Cybersecurity and Infrastructure Security Agency wrote at the time.

Tehran has limited how far its attacks have gone, though, largely keeping to data exfiltration and reconnaissance on the global stage. The country has, however, participated in influence operations, disinformation campaigns, and efforts to meddle in foreign elections, including targeting the US.

“We’ve become used to seeing Iran being aggressive in the Middle East where that activity just has never stopped, but outside of the Middle East they’ve been far more restrained,” Hultquist says. “I’m concerned that they may be more willing to leverage their capability outside of the region. And they clearly have no qualms about targeting NATO states, which suggests to me that whatever deterrents we believe exist between us and them may not exist at all.”

With Iran claiming that it now has the ability to produce nuclear warheads, and representatives from the country meeting with US officials in Vienna about a possible revival of the 2015 nuclear deal between the countries, any signal about Iran’s possible intentions and risk tolerance when it comes to dealing with NATO are significant.

This story originally appeared on wired.com.

Source link

Share
Tweet
Pinterest
Linkedin
Stumble
Google+
Email
Prev Article
Next Article

Related Articles

Tech companies adapt as cities linger in lockdown
With billions of people around the world forced into lockdown …

Tech companies adapt as cities linger in lockdown

Fast & Furious: Crossroads lives video games a quarter-mile at a time
TechCrunch ist Teil von Verizon Media. Klicken Sie auf ‘Ich …

CRV’s Saar Gur wants to invest in a new wave of games built for VR, Twitch and Zoom

Leave a Reply Cancel reply

Find us on Facebook

Related Posts

  • Samsung Galaxy S20 begins shipping March 6
    Samsung Galaxy S20 begins shipping March 6
    11/02/2020
  • We can reduce gender bias in natural-language AI, but it will take a lot more work
    We can reduce gender bias in natural-language …
    07/12/2020
  • Never-before-seen attackers are targeting Mideast industrial organizations
    Never-before-seen attackers are targeting Mideast industrial organizations
    25/03/2020
  • Amazon says CEO Jeff Bezos willing to testify before U.S. Congress
    Amazon says CEO Jeff Bezos willing to …
    16/06/2020
  • 2020 will be a big year for online childcare — here are 7 startups to watch
    Apple and Google are launching a joint …
    10/04/2020

Popular Posts

  • Ring patched an Android bug that could have exposed video footage
    Ring patched an Android bug that could …
    18/08/2022 0
  • 10 Best Everyday Items for Survival Situations …
    21/07/2022 0
  • 10 Popular TV Characters That Weren’t Part …
    21/07/2022 0
  • 4 vulnerabilities under attack give hackers full control of Android devices
    Zero-day used to infect Chrome users could …
    21/07/2022 0
  • Ten Gender-Swapped Cover Songs That Altered the …
    22/07/2022 0

viralamo

Pages

  • Contact Us
  • Privacy Policy
Copyright © 2022 viralamo
Theme by MyThemeShop.com

Ad Blocker Detected

Our website is made possible by displaying online advertisements to our visitors. Please consider supporting us by disabling your ad blocker.

Refresh