Cybersecurity

http://www.freeimages.com/photo/537046
Iranian Hackers
Targeting Critical Infrastructure Across The Globe
By: Amanda Vicinanzo, Senior Editor
12/04/2014 (11:00am)
Iranian hackers have
penetrated the computer networks of government agencies and major critical
infrastructure companies in the United States and 15 other countries over the
past two years in a campaign that could eventually cause physical damage,
according to a report by cybersecurity company Cylance.
California-based Cylance
released an 87-page report detailing the
actions of the global surveillance and infiltration campaign dubbed “Operation
Cleaver” because the attackers used the string “cleaver” in a variety of the
custom software used in the campaign.
“We believe our
visibility into this campaign represents only a fraction of Operation Cleaver’s
full scope,” the report stated. “We believe that if the operation is left to
continue unabated, it is only a matter of time before the world’s physical
safety is impacted by it.”
Targets have included
some of the most sensitive global critical infrastructure companies across the
globe, including: military, oil and gas, energy and utilities, transportation,
hospitals, telecommunications, technology, education, aerospace, defense
contractors, chemical, companies and governments.
The report did not name
companies, but identified over 50 victims impacted by the attacks. The hackers
have hit firms in the United States, Canada, China, England, France, Germany,
India, Israel, Kuwait, Mexico, Pakistan, Qatar, Saudi Arabia, South Korea,
Turkey and the United Arab Emirates.
Targeting a broad array
of companies in countries across the globe, Cylance believes the scope of Iran
has positioned itself to impact critical infrastructure globally.
“With minimal separation
between private companies and the Iranian government, their modus
operandiseems clear: blur the line between legitimate engineering companies
and state-sponsored cyber hacking teams to establish a foothold in the world’s
critical infrastructure,” the report stated.
The report noted Iranian
hacking campaigns are nothing new. The 2012 Operation Shamoon campaign launched
in retaliation to Stuxnet—the computer worm that ravaged Iran’s Natanz nuclear
facility—impacted over 30,000 computer endpoints and cost the companies
affected by the attacks tens of thousands of dollars in recovery expenses.
The Shamoon malware
destroyed three-quarters of the PCs at Saudi Arabian oil company, Saudi
Aramco, marking the most destructive attack against a corporate network to
date. Stuart McClure, CEO of Cylance, explained in a blog post that, “Such an
attack is just the beginning, it serves as a proof of concept to prove that
such large scale and devastating attacks are not only possible but impending.”
In September 2013, the Wall
Street Journal reported that Iran hacked into unclassified US Navy
computers in San Diego’s Navy Marine Corp Intranet. Cylance linked this attack
to Operation Cleaver.
“While to date Cylance
has yet to see Operation Cleaver result in loss of life or disruption of
critical services, with the history of this group I see that as a likely
consequence of these attacks,” said McClure.
Although not confirmed,
the report speculated the attacks are state-sponsored and are being conducted
in retaliation to Stuxnet. Iran’s cyber sophistication has grown rapidly since
the dawn of Stuxnet and the report indicates that "they have used hard
dollars combined with national pride to help build their cyber army."
Operation Cleaver’s
intentions may be to damage industrial control systems (ICS), supervisory
control and data acquisition (SCADA) systems, and impact critical
infrastructure and key resources (CIKR).
“This campaign could be
a way to demonstrate Iran’s cyber capabilities for additional geopolitical
leverage, due to the breadth and depth of their global targets,” the report
said.
At least 20 hackers and
developers are believed to be behind Operation Cleaver and Cylance was able to
uncover a considerable amount of information on the members of the campaign.
The group's techniques overlap with those used by the Iranian Cyber Army and
Syrian Electronic Army. However, Cylance believes Operation Cleaver is the work
of a new team.
“Ultimately we believe
the Cleaver team is a mix of existing team members and new recruits pulled from
the universities in Iran,” Cylance explained. To protect themselves, companies
must bolster their current security posture and demand that their security
vendors step up to the plate. McClure believes prevention is the key to
protecting against Operation Cleaver.
The report urged
organizations in the US to contact the FBI if they believe they have become a
victim of Operation Cleaver.
“Unfortunately, many
critical infrastructure organizations are unable to secure their complex
environments against modern attacks. They fall victim to the “glue flu," a
malaise of feeling stuck, not wanting to change the status quo for fear they
will find problems that they have no idea how to prevent. This “security
anaphylaxis” spells real disaster,” the report concluded. “If Operation Cleaver
doesn’t get the world to wake up to what is happening in the silent world of
cyber, then perhaps nothing will. Prevention is everything and we should never
give up until it’s achieved.”
No comments:
Post a Comment