• العربية
  • فارسی
BrandBrand
  • Iran Insight
  • Politics
  • Economy
  • Analysis
  • Special Report
  • Opinion
  • Podcast
  • Live TV
  • Iran Insight
  • Politics
  • Economy
  • Analysis
  • Special Report
  • Opinion
  • Podcast
  • Live TV
  • Theme
  • Language
    • العربية
    • فارسی
  • Iran Insight
  • Politics
  • Economy
  • Analysis
  • Special Report
  • Opinion
  • Podcast
  • Live TV
All rights reserved for Volant Media UK Limited
volant media logo

Iranian hacking group steps up global cyber war

Jul 17, 2024, 13:06 GMT+1Updated: 21:34 GMT+1

Iranian hacker group MuddyWater has expanded its operations to countries such as Azerbaijan, Portugal, Turkey, Saudi Arabia, and India, using newly developed malware.

According to a detailed report by cybersecurity firm Check Point, MuddyWater has employed BugSleep malware to allow hackers to execute remote commands and transfer files between infected systems and their servers with targets including government organizations, media outlets, and travel agencies.

International organizations, including the US Cybersecurity and Infrastructure Security Agency, have attributed MuddyWater to Iran's ministry of intelligence. MuddyWater, also known as APT34 and OilRig, has been active for several years, focusing on cyber-espionage against private and governmental organizations in the Middle East and Western countries.

Their activities are characterized by a mix of strategic intelligence gathering and disruptive cyberattacks, aiming to further Iran's geopolitical interests.

The primary and most successful method of the new malware so far, also targeting countries such as Israel and Saudi Arabia, has been through phishing emails.

Since February 2024, over 50 such emails have been distributed to hundreds of recipients, crafted to deceive recipients into clicking malicious links or downloading infected attachments.

Cybersecurity company Sekoia has also highlighted a surge in MuddyWater's activities. One of the significant findings from Sequoia's investigation is a shift in the hackers' tactics.

Instead of embedding infected links directly in the text of phishing emails, MuddyWater now places these malicious links in PDF files attached to the emails, an attempt to bypass security filters that scrutinize email contents for suspicious links.

Iran has a long history of using cyberattacks, not least on its archenemy, Israel, targeting entities like the Israel Electric Corporation.

These attacks have stepped up since the outbreak of the Gaza war. In November, just weeks after the war began, a group going by the name of “Cyber Toufan” targeted Israeli companies and organizations and dumped huge troves of data online that it claims to have stolen.

Israel's National Institute for Security Studies says Iran was one of the first countries to develop a national cyber strategy. It has developed the institutions and infrastructure to ensure its proxy war could disrupt, sabotage and even destroy civil and commercial targets, critical national infrastructure and military capabilities.

Most Viewed

Iran’s own surveys reveal demand for 'fundamental change'
1

Iran’s own surveys reveal demand for 'fundamental change'

2
ANALYSIS

Houthi gains reversed at Bab al-Mandab, but Iran’s leverage runs deeper

3
INSIGHT

Iran, US back to ‘square one’ as diplomacy stalls

4

Tehran divided over $2 billion plan to prop up rial

5

Iran says economy holding up as pressure mounts on oil, rial

Banner
Banner

Spotlight

  • Hezbollah recruitment network in Iran exposed, four safe houses identified
    EXCLUSIVE

    Hezbollah recruitment network in Iran exposed, four safe houses identified

  • From talks to war: Tehran sees the gap narrowing
    ANALYSIS

    From talks to war: Tehran sees the gap narrowing

  • Iran looks for escape routes as US sanctions close in
    INSIGHT

    Iran looks for escape routes as US sanctions close in

  • China's turn to Iraqi crude shows growing impact of Iran oil blockade
    ANALYSIS

    China's turn to Iraqi crude shows growing impact of Iran oil blockade

  • Tehran divided over $2 billion plan to prop up rial

    Tehran divided over $2 billion plan to prop up rial

  • Parsian Exchange transferred millions of dollars for Iran despite sanctions
    EXCLUSIVE

    Parsian Exchange transferred millions of dollars for Iran despite sanctions

  • Iran protester recounts torture, mock execution after January arrest

    Iran protester recounts torture, mock execution after January arrest

  • Iran’s own surveys reveal demand for 'fundamental change'

    Iran’s own surveys reveal demand for 'fundamental change'

  • Iran executes nearly two people a week since January protests

    Iran executes nearly two people a week since January protests

  • Iran, US back to ‘square one’ as diplomacy stalls
    INSIGHT

    Iran, US back to ‘square one’ as diplomacy stalls

Banner
Banner