• Tech News
    • Games
    • Pc & Laptop
    • Mobile Tech
    • Ar & Vr
    • Security
  • Startup
    • Fintech
  • Reviews
  • How To
What's Hot

Elementor #32036

January 24, 2025

The Redmi Note 13 is a bigger downgrade compared to the 5G model than you might think

April 18, 2024

Xiaomi Redmi Watch 4 is a budget smartwatch with a premium look and feel

April 16, 2024
Facebook Twitter Instagram
  • Contact
  • Privacy Policy
  • Terms & Conditions
Facebook Twitter Instagram Pinterest VKontakte
Behind The ScreenBehind The Screen
  • Tech News
    1. Games
    2. Pc & Laptop
    3. Mobile Tech
    4. Ar & Vr
    5. Security
    6. View All

    Bring Elden Ring to the table with the upcoming board game adaptation

    September 19, 2022

    ONI: Road to be the Mightiest Oni reveals its opening movie

    September 19, 2022

    GTA 6 images and footage allegedly leak

    September 19, 2022

    Wild west adventure Card Cowboy turns cards into weird and silly stories

    September 18, 2022

    7 Reasons Why You Should Study PHP Programming Language

    October 19, 2022

    Logitech MX Master 3S and MX Keys Combo for Business Gen 2 Review

    October 9, 2022

    Lenovo ThinkPad X1 Carbon Gen10 Review

    September 18, 2022

    Lenovo IdeaPad 5i Chromebook, 16-inch+120Hz

    September 3, 2022

    It’s 2023 and Spotify Still Can’t Say When AirPlay 2 Support Will Arrive

    April 4, 2023

    YouTube adds very convenient iPhone homescreen widgets

    October 15, 2022

    Google finishes iOS 16 Lock Screen widgets rollout w/ Maps

    October 14, 2022

    Is Apple actually turning iMessage into AIM or is this sketchy redesign rumor for laughs?

    October 14, 2022

    MeetKai launches AI-powered metaverse, starting with a billboard in Times Square

    August 10, 2022

    The DeanBeat: RP1 simulates putting 4,000 people together in a single metaverse plaza

    August 10, 2022

    Improving the customer experience with virtual and augmented reality

    August 10, 2022

    Why the metaverse won’t fall to Clubhouse’s fate

    August 10, 2022

    How Apple privacy changes have forced social media marketing to evolve

    October 16, 2022

    Microsoft Patch Tuesday October Fixed 85 Vulnerabilities – Latest Hacking News

    October 16, 2022

    Decentralization and KYC compliance: Critical concepts in sovereign policy

    October 15, 2022

    What Thoma Bravo’s latest acquisition reveals about identity management

    October 14, 2022

    What is a Service Robot? The vision of an intelligent service application is possible.

    November 7, 2022

    Tom Brady just chucked another Microsoft Surface tablet

    September 18, 2022

    The best AIO coolers for your PC in 2022

    September 18, 2022

    YC’s Michael Seibel clarifies some misconceptions about the accelerator • DailyTech

    September 18, 2022
  • Startup
    • Fintech
  • Reviews
  • How To
Behind The ScreenBehind The Screen
Home»Tech News»US charges three Iranians over CNI cyber attacks
Tech News

US charges three Iranians over CNI cyber attacks

September 17, 2022No Comments4 Mins Read
Facebook Twitter Pinterest LinkedIn Tumblr Email
Consumers left out of pocket as security costs soar
Share
Facebook Twitter LinkedIn Pinterest Email

Three Iranian nationals, named as Mansour Ahmadi, Ahmad Khatibi Aghda, and Amir Hossein Nickaein Ravari, have been indicted in the US over their alleged involvement in a campaign of cyber attacks targeting multiple victims in the US, UK, Israel and Iran, including operators of critical national infrastructure (CNI).

The three are accused of exploiting known vulnerabilities in commonly used networking hardware and software to gain access to their targets’ systems, exfiltrate data and other information from them, and conduct a number of ransomware attacks.

Besides organistions in the government, healthcare, transport and utility sectors, the trio also targeted educational institutions, non-profits, religious bodies, and small and medium-sized enterprises (SMEs).

“Ransom-related cyber attacks – like what happened here – are a particularly destructive form of cyber crime,” said US attorney Philip Sellinger.

“No form of cyber attack is acceptable, but ransomware attacks that target critical infrastructure services, such as healthcare facilities and government agencies, are a threat to our national security. Hackers like these defendants go to great lengths to keep their identities secret, but there is always a digital trail. And we will find it.”

Assistant attorney general Matthew Olsen added: “These defendants may have been hacking and extorting victims – including critical infrastructure providers – for their personal gain, but the charges reflect how criminals can flourish in the safe haven that the government of Iran has created and is responsible for.

“According to the indictment, even other Iranians are less safe because their own government fails to follow international norms and stop Iranian cyber criminals.”

See also  Austrian knowledge agency accused of promoting malware, conducting cyber assaults

The specific charges in the indicments, which were unsealed on 14 September in the state of New Jersey (NJ), relate to two incidents in the state over the course of a year.

In the first incident, the defendants and their co-conspirators are accused of targeting a township in Union County, New Jersey, in February 2021, exploiting known vulnerabilities to gain access to and control of local government networks, and establish remote access to a domain registered to Ahmadi.

A year later, in February 2022, they are accused of targeting an accounting firm in nearby Morris County, again gaining access and establishing a connection to a server controlled by Nickaein, which was used to exfiltrate data and subsequently, to launch a double extortion ransomware attack, in which they demanded the sum of $50,000 in cryptocurrency.

The group’s other victims are believed to number in the hundreds, and are known to have included another accountancy firm in Illinois, a county government in Wyoming, a construction company in Washington, a domestic violence shelter in Pennsylvania, electrical utilities in Indiana and Mississippi, a public housing corporation in Washington, and an undisclosed state bar association.

The indictment charges all three with one count of conspiracy to commit computer fraud and related activity, one count of intentionally damaging a protected computer, and one count of transmitting a demand in relation to damaging a protected computer. Ahmadi is additionally charged with an extra count of intentionally damaging a protected computer.

Cumulatively, the charges carry a maximum sentence of 20 years in prison, and fines of up to $250,000, but as all three men are resident in Iran, barring significant geopolitical changes in the region, it is unlikely that they will ever be extradited to stand trial.

See also  Norway has NOK200m plan to bolster cyber defences

Mandiant vice-president John Hultquist said that he had been tracking the group, which Mandiant links to a cluster of threat activity known as UNC2448, which is also tracked by others as DEV-0270 and Cobalt Mirage, for some time. The group is known for its widespread scanning of various vulnerabilities, the use of the Fast Reverse Proxy tool, and ransomware activity using BitLocker.

It is linked with some degree of confidence to the Iranian Revolutionary Guards Corps. However, said Hultquist, the activities with which the men are charged may not have been ordered by Tehran.

“We believe these organisations may have been moonlighting as criminals in addition to their status as contractors in the service of the IRGC. The IRGC leans heavily on contractors to carry out their cyber operations,” he said.

“This group has been carrying out a brazen, widespread vulnerability scanning operation against targets in the US, Canada, Israel, UAE, and Saudi Arabia, seeking vulnerabilities in VPNs and MS Exchange among others.

“More often than not, they are monetising their access, but their relationship to the IRGC makes them especially dangerous. Any access they gain could be served up for espionage or disruptive purposes,” said Hultquist.

“For most people, this actor will probably be a criminal problem, but if you’re the right target, they will turn you over for espionage or disruption,” he warned.

Source link

attacks charges CNI Cyber Iranians
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related Posts

How AI Protects (and Attacks) Your Inbox

June 3, 2023

What is a Service Robot? The vision of an intelligent service application is possible.

November 7, 2022

SecondSight enters cyber insurance market with AI-driven platform for ‘inside-out’ underwriting

October 13, 2022

Immersive Labs uses cyber resilience to solve human security risk, raises $66M

October 13, 2022
Add A Comment

Comments are closed.

Editors Picks

How Elon Musk, SpaceX, and T-Mobile are helping the satellite-to-cellular business

August 28, 2022

Researcher Hacked Space-X Starlink Via A $25 Tool

August 16, 2022

A look at progress toward venture equity this Women’s Equality Day – DailyTech

August 27, 2022

Oral-B iO3 electric toothbrush review

August 9, 2023

Subscribe to Updates

Get the latest news and Updates from Behind The Scene about Tech, Startup and more.

Top Post

Elementor #32036

The Redmi Note 13 is a bigger downgrade compared to the 5G model than you might think

Xiaomi Redmi Watch 4 is a budget smartwatch with a premium look and feel

Behind The Screen
Facebook Twitter Instagram Pinterest Vimeo YouTube
  • Contact
  • Privacy Policy
  • Terms & Conditions
© 2025 behindthescreen.uk - All rights reserved.

Type above and press Enter to search. Press Esc to cancel.