Страницы

Thursday, December 4, 2014

Cybersecurity

 Toplaps
http://www.freeimages.com/photo/537046
Iranian Hackers Targeting Critical Infrastructure Across The Globe
By: Amanda Vicinanzo, Senior Editor
12/04/2014 (11:00am)

Iranian hackers have penetrated the computer networks of government agencies and major critical infrastructure companies in the United States and 15 other countries over the past two years in a campaign that could eventually cause physical damage, according to a report by cybersecurity company Cylance.

California-based Cylance released an 87-page report detailing the actions of the global surveillance and infiltration campaign dubbed “Operation Cleaver” because the attackers used the string “cleaver” in a variety of the custom software used in the campaign.

“We believe our visibility into this campaign represents only a fraction of Operation Cleaver’s full scope,” the report stated. “We believe that if the operation is left to continue unabated, it is only a matter of time before the world’s physical safety is impacted by it.”

Targets have included some of the most sensitive global critical infrastructure companies across the globe, including: military, oil and gas, energy and utilities, transportation, hospitals, telecommunications, technology, education, aerospace, defense contractors, chemical, companies and governments.

The report did not name companies, but identified over 50 victims impacted by the attacks. The hackers have hit firms in the United States, Canada, China, England, France, Germany, India, Israel, Kuwait, Mexico, Pakistan, Qatar, Saudi Arabia, South Korea, Turkey and the United Arab Emirates.

Targeting a broad array of companies in countries across the globe, Cylance believes the scope of Iran has positioned itself to impact critical infrastructure globally.

“With minimal separation between private companies and the Iranian government, their modus operandiseems clear: blur the line between legitimate engineering companies and state-sponsored cyber hacking teams to establish a foothold in the world’s critical infrastructure,” the report stated.

The report noted Iranian hacking campaigns are nothing new. The 2012 Operation Shamoon campaign launched in retaliation to Stuxnet—the computer worm that ravaged Iran’s Natanz nuclear facility—impacted over 30,000 computer endpoints and cost the companies affected by the attacks tens of thousands of dollars in recovery expenses.

The Shamoon malware destroyed three-quarters of the PCs at Saudi Arabian oil company, Saudi Aramco, marking the most destructive attack against a corporate network to date. Stuart McClure, CEO of Cylance, explained in a blog post that, “Such an attack is just the beginning, it serves as a proof of concept to prove that such large scale and devastating attacks are not only possible but impending.”

In September 2013, the Wall Street Journal reported that Iran hacked into unclassified US Navy computers in San Diego’s Navy Marine Corp Intranet. Cylance linked this attack to Operation Cleaver.

“While to date Cylance has yet to see Operation Cleaver result in loss of life or disruption of critical services, with the history of this group I see that as a likely consequence of these attacks,” said McClure.

Although not confirmed, the report speculated the attacks are state-sponsored and are being conducted in retaliation to Stuxnet. Iran’s cyber sophistication has grown rapidly since the dawn of Stuxnet and the report indicates that "they have used hard dollars combined with national pride to help build their cyber army."

Operation Cleaver’s intentions may be to damage industrial control systems (ICS), supervisory control and data acquisition (SCADA) systems, and impact critical infrastructure and key resources (CIKR).

“This campaign could be a way to demonstrate Iran’s cyber capabilities for additional geopolitical leverage, due to the breadth and depth of their global targets,” the report said.

At least 20 hackers and developers are believed to be behind Operation Cleaver and Cylance was able to uncover a considerable amount of information on the members of the campaign. The group's techniques overlap with those used by the Iranian Cyber Army and Syrian Electronic Army. However, Cylance believes Operation Cleaver is the work of a new team.

“Ultimately we believe the Cleaver team is a mix of existing team members and new recruits pulled from the universities in Iran,” Cylance explained. To protect themselves, companies must bolster their current security posture and demand that their security vendors step up to the plate. McClure believes prevention is the key to protecting against Operation Cleaver.

The report urged organizations in the US to contact the FBI if they believe they have become a victim of Operation Cleaver.

“Unfortunately, many critical infrastructure organizations are unable to secure their complex environments against modern attacks. They fall victim to the “glue flu," a malaise of feeling stuck, not wanting to change the status quo for fear they will find problems that they have no idea how to prevent. This “security anaphylaxis” spells real disaster,” the report concluded. “If Operation Cleaver doesn’t get the world to wake up to what is happening in the silent world of cyber, then perhaps nothing will. Prevention is everything and we should never give up until it’s achieved.”



No comments:

Post a Comment