• العربية
  • فارسی
Brand
  • Iran Insight
  • Politics
  • Economy
  • Analysis
  • Special Report
  • Opinion
  • Podcast
  • Live TV
  • Iran Insight
  • Politics
  • Economy
  • Analysis
  • Special Report
  • Opinion
  • Podcast
  • Live TV
  • Theme
  • Language
    • العربية
    • فارسی
  • Iran Insight
  • Politics
  • Economy
  • Analysis
  • Special Report
  • Opinion
  • Podcast
  • Live TV
All rights reserved for Volant Media UK Limited
volant media logo

Iranian hacking group steps up global cyber war

Jul 17, 2024, 13:06 GMT+1Updated: 21:34 GMT+1

Iranian hacker group MuddyWater has expanded its operations to countries such as Azerbaijan, Portugal, Turkey, Saudi Arabia, and India, using newly developed malware.

According to a detailed report by cybersecurity firm Check Point, MuddyWater has employed BugSleep malware to allow hackers to execute remote commands and transfer files between infected systems and their servers with targets including government organizations, media outlets, and travel agencies.

International organizations, including the US Cybersecurity and Infrastructure Security Agency, have attributed MuddyWater to Iran's ministry of intelligence. MuddyWater, also known as APT34 and OilRig, has been active for several years, focusing on cyber-espionage against private and governmental organizations in the Middle East and Western countries.

Their activities are characterized by a mix of strategic intelligence gathering and disruptive cyberattacks, aiming to further Iran's geopolitical interests.

The primary and most successful method of the new malware so far, also targeting countries such as Israel and Saudi Arabia, has been through phishing emails.

Since February 2024, over 50 such emails have been distributed to hundreds of recipients, crafted to deceive recipients into clicking malicious links or downloading infected attachments.

Cybersecurity company Sekoia has also highlighted a surge in MuddyWater's activities. One of the significant findings from Sequoia's investigation is a shift in the hackers' tactics.

Instead of embedding infected links directly in the text of phishing emails, MuddyWater now places these malicious links in PDF files attached to the emails, an attempt to bypass security filters that scrutinize email contents for suspicious links.

Iran has a long history of using cyberattacks, not least on its archenemy, Israel, targeting entities like the Israel Electric Corporation.

These attacks have stepped up since the outbreak of the Gaza war. In November, just weeks after the war began, a group going by the name of “Cyber Toufan” targeted Israeli companies and organizations and dumped huge troves of data online that it claims to have stolen.

Israel's National Institute for Security Studies says Iran was one of the first countries to develop a national cyber strategy. It has developed the institutions and infrastructure to ensure its proxy war could disrupt, sabotage and even destroy civil and commercial targets, critical national infrastructure and military capabilities.

Most Viewed

Alamolhoda seeking presidency of Iran’s Assembly of Experts - report
1

Alamolhoda seeking presidency of Iran’s Assembly of Experts - report

2
EXCLUSIVE

Satellite images show Iran’s key ports falling quiet under US blockade

3
INSIGHT

What is Pickaxe Mountain, and why does Trump keep saying he will bomb it?

4

London penthouses linked to Iran’s Supreme Leader put up for sale – Sunday Times

5

Iran has only 30 million barrels of oil left for China, Bessent says

Banner
Banner
Banner

Spotlight

  • The gamble behind US attacks on Iran’s oil tankers
    ANALYSIS

    The gamble behind US attacks on Iran’s oil tankers

  • Iran, where eggs are a better bet than cash
    PODCAST

    Iran, where eggs are a better bet than cash

  • Satellite images show Iran’s key ports falling quiet under US blockade
    EXCLUSIVE

    Satellite images show Iran’s key ports falling quiet under US blockade

  • Iran's appliance industry is collapsing, and so is the market it was built for
    INSIGHT

    Iran's appliance industry is collapsing, and so is the market it was built for

  • In Hormuz, Iran only needs to keep ships guessing
    PODCAST

    In Hormuz, Iran only needs to keep ships guessing

  • If Britain backs US plan, Iran's London bank shuts down on October 22
    ANALYSIS

    If Britain backs US plan, Iran's London bank shuts down on October 22

  • 'If I'm not happy, they'll execute me': Iran's new grammar of dissent
    ANALYSIS

    'If I'm not happy, they'll execute me': Iran's new grammar of dissent