Linchakin

Microsoft Warns of Iranian Hacker Group That Rapidly Adapts New Tools & Techniques

 November 19, 2021     No comments   

Microsoft Warns of Iranian Hacker Group That Rapidly Adapts New Tools & Techniques

At the CyberWarCon 2021 conference, the cybersecurity experts of Microsoft Threat Intelligence Center (MSTIC) has presented an analysis of the activities and evolution of several Iranian cybercriminal groups.

In this analysis, the Microsoft Threat Intelligence Center (MSTIC) has claimed that the attacks by the Iranian hackers are becoming more sophisticated and evolving rapidly with new tools and techniques.

Notable Trends

The Microsoft Threat Intelligence Center (MSTIC) has noted three key trends, and here they are mentioned below:-

To collect funds or disrupt their targets they are increasingly utilizing ransomware.

While engaging with their targets they are more patient and persistent.

They employ aggressive brute force attacks on their targets since they are more patient and persistent with their social engineering campaigns.

Ransomware

While apart from this, Microsoft has traced six Iranian hacker groups since September 2020, and here they are mentioned below:-

  • Thanos (DEV-0146)
  • Moses Staff (DEV-0500)
  • Phosphorus
  • Rubidium (pay2key)
  • Vice Leaker (DEV-0198)
  • Agrius (DEV-0227)

In waves every six to eight weeks on average all these ransomware deployments were launched by these Iranian hacker groups to accomplish their targets and goals.

In their campaigns, the Iranian hackers primarily install ransomware and steal data in order to cause malfunctioning of targets’ systems. However, over time, these Iranian hacker groups have evolved into deploying and performing:- 

  • Cyber-espionage
  • Multi-platform malware
  • Ransomware
  • Viper operations
  • Phishing attacks
  • Supply chain attacks
  • Disk wipers
  • Password spray attacks
  • Mass exploitation attacks
  • Cloak C2 communications behind legitimate cloud services

Not only that even the hackers have also scanned the Network for Fortinet FortiOS SSL VPN devices and Microsoft Exchange servers containing ProxyShell vulnerabilities, etc.

So far this year the hackers have already managed to gain more than 900 valid credentials in plain text by scanning for unpatched Fortinet VPN systems only.

Patient Credential Harvesting

The increased levels of patience and perseverance in social engineering campaigns is another trend that has surfaced in the past year.

Here it has been noted that the previous actors like Phosphorus (also known as Charming Kitten) sent out emails with malicious links and attachments, but rarely managed to accomplish their goals.

As for now, Phosphorus follows the cumbersome route of “interview invitation” to instruct their victims in attacks to click on credential collection pages as part of a fake interview process.

Using an extensive network of fake social media accounts, usually disguised as attractive women, the new Curium group also pursue a similar strategy. Like this, on a daily basis, they connect with potential victims and try to win their trust for long-run operations.

After a while, the threat actors send a malicious document to their lured target one day which leads the target to the hidden installation of malware on their system.

Apart from this, to trick Israeli soldiers into installing malware on their phones, a hacker group affiliated with the Islamist movement known as Hamas also uses a similar tactic.

While others on the list to aggressively gain access to Microsoft Office 365 user accounts prefer to use brute force attacks, and this shows that they are sophisticated and well organized.

And here in this segment, there is one group that attacked US defense technology companies and ran massive password spraying attacks last month; this group is tracked as DEV-0343.

You can follow us on Linkedin, Twitter, Facebook for daily Cybersecurity, and hacking news updates.

Adblock test (Why?)


You may be interested in:
>> Is a Chromebook worth replacing a Windows laptop?
>> Find out in detail the outstanding features of Google Pixel 4a
>> Top 7 best earbuds you should not miss

Related Posts:
>> Recognizing 12 Basic Body Shapes To Choose Better Clothes
>>Ranking the 10 most used smart technology devices
>> Top 5+ Best E-readers: Compact & Convenient Pen
  • Share This:  
  •  Facebook
  •  Twitter
  •  Google+
  •  Stumble
  •  Digg
Email ThisBlogThis!Share to XShare to Facebook

Related Posts:

  • A Safe and Secure Way to DecommissionWhen it comes time to decommission data storage systems, there is much that must be planned and thoroughly carried out. It’s not just about the activi… Read More
  • Mobile Phishing Attacks Surge 161% in the Energy IndustryThe need for increased mobile security in the Energy sector has become evident with new data highlighting why these phishing attacks are occurring and… Read More
  • Big Cyber Monday AirPods Pro deals are still liveByJoseph Foley 30 November 2021dealsYou're not too late to grab a $70 discount. Cyber Monday has been and gone, but some retailers are letting their sales run, which is fantastic news for anyone who wasn't quick enough to grab on… Read More
  • Fantastic Surface Pro 7+ Cyber Monday deals continueByJoseph Foley 30 November 2021dealsGet this fantastic hybrid tablet for under $700. Cyber Monday is over and with it all of the deals that we'd spotted on the brand new Surface Pro 8, but that doesn't mean that you can't still save b… Read More
  • Samsung Galaxy S22 and S22 Plus leak reveals all about the camerasNew main and telephoto sensors for the two smaller models We're expecting the Samsung Galaxy S22 to be the first big flagship phone of 2022, so all eyes are on its rumored specs. The most recent alleged leak… Read More
Newer Post Older Post Home

0 Comments:

Post a Comment


Copyright © 2025 Linchakin | Powered by Blogger
Design by Hardeep Asrani | Blogger Theme by NewBloggerThemes.com | Distributed By Gooyaabi Templates