• العربية
  • فارسی
Brand
  • Iran Insight
  • Politics
  • Economy
  • Analysis
  • Special Report
  • Opinion
  • Podcast
  • Iran Insight
  • Politics
  • Economy
  • Analysis
  • Special Report
  • Opinion
  • Podcast
  • Theme
  • Language
    • العربية
    • فارسی
  • Iran Insight
  • Politics
  • Economy
  • Analysis
  • Special Report
  • Opinion
  • Podcast
All rights reserved for Volant Media UK Limited
volant media logo

Cyber Security Firm Reveals Details About Attacks On Entities In Iran

Iran International Newsroom
Feb 21, 2022, 13:41 GMT+0Updated: 17:29 GMT+1
Video grab of an image that appeared on Iranian TV on February 1, 2022
Video grab of an image that appeared on Iranian TV on February 1, 2022

Cyber security provider Check Point has shed light on the new wave of cyberattacks that have hit Iranian state infrastructure in the past few months.

The American-Israeli software and hardware security company said in a comprehensive technical analysis published on February18 that the recent wave of attacks that caused major disruptions to public services are far from minor website defacements.

The report provided in-depth breakdowns for some of the attacks, including the targeted hack of the state broadcaster (IRIB) in late January, saying the attackers’ aim was also to disrupt the IRIB’s programs, with the damage to the TV and radio networks possibly more serious than officially reported.

Several television and radio channels of the state broadcaster were hacked on January 27 with photos of leaders of an opposition group briefly aired. The image of Massoud and Maryam Rajavi, leaders of the Albania-based opposition Mujahideen-e Khalq (MEK), were broadcast for around 10 seconds with audio footage from one of their speeches in the background.

After the picture of the MEK leaders, the video showed a photo of Iran’s Supreme leader Ali Khamenei with a red cross on it, as an off-camera voice said, “Death to Khamenei.” Khamenei was badly injured in 1981 in one of a series of bombings attributed to the MEK.

Check Point research team probed the cyberattack and was able to retrieve the files and forensic evidence from publicly available resources, finding malicious executables whose purpose was to air the protest message, as well as evidence that a wiper malware was used.

The security firm provided a technical analysis of the tools used in the attack, as well as the attackers’ tactics, identifying malware that takes screenshots of the victims’ screens, several custom-made backdoors, and related batch scripts and configuration files used to install and configure the malicious executables.

Hacking of Iranian institutions timeline by Check point.
100%
Hacking of Iranian institutions timeline by Check point.

Check Point also gave a detailed report about other major cyber-attacks such as an attack that hit the Iranian national railway and cargo services in July 2021. The attack caused “unprecedented disruptions” to the country’s trains, a day before media outlets reported that the website of Iran’s Roads Ministry, in charge of transportation, was taken down in a ‘cyber disruption’, preventing access to their official portal and sub-services.

A message was also displayed on the train schedule boards referred perplexed passengers to the Supreme Leader’s office phone number.

A group called ‘Predatory Sparrow’ claimed responsibility for the attacks, whose tools and tactics were used in similar operations against private companies in Syria by an anti-regime group called Indra.

In August 2021, the hacktivist group Tapandegan (Palpitations), previously known for hacking and displaying protest messages on the electronic flight arrival and departure boards in Mashhad and Tabriz international airports in 2018, released security camera footage from Tehran's Evin Prison, where many political prisoners are held. Tapandegan said the images had been acquired by hackers called Edalat-e Ali (Ali's Justice) and were being circulated to draw attention to human rights violations, particularly against political prisoners.

In October 2021, all gas stations in Iran were paralyzed by an attack that disrupted the electronic payment process, leading to extremely long queues for two days that prevented customers from paying with the government-issued electronic cards used to purchase subsidized fuel. When the card was swiped for payment, the supreme leader’s office phone number appeared on the screen. Iranian officials claimed that foreign actors, such as Israel and the US, were behind the attack. However, Predatory Sparrow claimed responsibility for this attack as well.

On February 1, the web-based streaming platform of IRIB, Telewebion, was hijacked yet again to broadcast protest messages urging citizens to rebel and stating that “the regime’s foundations are rattling” in the middle of a live broadcast of the Iran-UAE soccer match.

Recently, on February 7, 2022, the Edalat-e Ali group released footage from closed-circuit cameras in another Iranian prison, Ghezel Hesar.

Check Point says it is still not clear how the attackers gained initial access to these networks that are “completely isolated, are equipped with acceptable security protocols and are not accessible via the Internet”.

It concluded that “the actor may have many capabilities that have yet to be explored. On the one hand, the attackers managed to pull off a complicated operation to bypass security systems and network segmentation, penetrate the broadcaster’s networks, produce and run the malicious tools that heavily rely on internal knowledge of the broadcasting software used by victims, all while staying under the radar during the reconnaissance and initial intrusion stages”.

Check Point also concluded that “the attackers’ tools are of relatively low quality and sophistication and are launched by clumsy and sometimes buggy 3-line batch scripts”, which supports their “theory that the attackers might have had help from insiders or indicate a yet unknown collaboration between different groups with different skills”.

Most Viewed

State media slam Araghchi's Hormuz tweet, say it let Trump claim victory
1

State media slam Araghchi's Hormuz tweet, say it let Trump claim victory

2

Iran International says it won’t be silenced after London arson attack

3
INSIGHT

How Tehran bends its own red lines to boost state rallies

4
VOICES FROM IRAN

Hope and anger in Iran as fragile ceasefire persists

5

Iran halts petrochemical exports to supply domestic market

Banner
Banner

Spotlight

  • Too early to tell who is winning Iran war, experts say
    PODCAST

    Too early to tell who is winning Iran war, experts say

  • How Tehran bends its own red lines to boost state rallies
    INSIGHT

    How Tehran bends its own red lines to boost state rallies

  • Iran blackout cripples freelancer, small business incomes
    VOICES FROM IRAN

    Iran blackout cripples freelancer, small business incomes

  • Ideology may be fading in Iran, but not in Kashmir's ‘Mini Iran'
    INSIGHT

    Ideology may be fading in Iran, but not in Kashmir's ‘Mini Iran'

  • US blockade enters murky phase as tankers spoof signals and buyers hesitate
    ANALYSIS

    US blockade enters murky phase as tankers spoof signals and buyers hesitate

  • Why the $100 billion Hormuz toll revenue is a myth
    ANALYSIS

    Why the $100 billion Hormuz toll revenue is a myth

•
•
•

More Stories

Fars Says COVID Vaccines Sent Back To Poland Were US-Made

Feb 21, 2022, 13:17 GMT+0

Iran is returning about 820,000 doses of AstraZeneca COVID-19 vaccines donated to the country by Poland presumably because they were made in the United States.

In a letter to the Customs Administration released to media on Monday, the Health Ministry said the vaccines were from "unauthorized sources" without mentioning they were made in the US. But Fars news agency affiliated with the Revolutionary Guard claimed the vaccines were returned because the were US-made.

The Biden Administration last year donated about 60 million doses of AstraZeneca to other countries because they were never used in the US.

According to the document the health ministry ordered the customs administration to return the last consignment back to Poland.

The Polish embassy in Tehran said in October that Poland was donating a million AstraZeneca COVID-19 shots to the Islamic Republic.

AstraZeneca is a British-Swedish multinational pharmaceutical and biotechnology company with its headquarters at the Cambridge Biomedical Campus in Cambridge, England.

Supreme Leader Ali Khamenei had banned the purchase of US and British-made vaccinesin January 2021, saying that "Importing vaccines made in the US or the UK is prohibited. They are completely untrustworthy. It is not unlikely that they would want to contaminate other nations… French vaccines are not trustworthy either”.

Health authorities, who have said the country is in its sixth wave of the pandemic, warn the figures are expected to increase exponentially during the next two months.

President Ebrahim Raisi has rejected proposals for a nationwide shutdown.

Raisi Travels To Qatar To Represent Iran At Gas Exporting Forum

Feb 21, 2022, 11:09 GMT+0

Iranian President Ebrahim Raisi (Raeesi) has traveled to Qatar to attend the sixth summit of the Gas Exporting Countries Forum (GECF).

Raeisi arrived in Doha on Monday to hold high-level talks with Emir Tamim bin Hamad Al Thani and is also scheduled to address the GECF summit on Tuesday.

Several ministers and officials are accompanying Raisi and several agreements and memorandums of understanding (MoUs) are to be signed during his two-day visit. Iran and Qatar share the world’s largest gas-field, with the Iranian part known as South Pars and Qatar’s as North Dome.

Iran’s roads and transport minister, Rostam Ghasemi, told the state broadcaster that four agreements will be signed between the two countries, the most important of which is about a plan to connect Iran and Qatar via an underwater tunnel.

According to Ghasemi, two of the other agreements are about shipping and boosting maritime trade, and the fourth relates to improving air travel.

The trip could also be an opportunity for Qatar to discuss Iran’s nuclear negotiations with world powers and the issue of direct talks with the United States. Iran has rejected any mediation on the issue.

Washington is also liaising with energy-producing states and firms over possible diversion of supplies to Europe should Russia invade Ukraine. Moscow supplies one-third of Europe’s natural gas and might stop winter deliveries if sanctioned by the US or western Europe over any action in Ukraine.

Aging US-Built Fighter Jet Crashes In Iran

Feb 21, 2022, 09:06 GMT+0

An Iranian F-5 fighter jet has crashed into a stadium in the northwest city of Tabriz Monday morning, killing a civilian and its two pilots.

The crash happened in a residential area in the center of Tabriz, a city of 1.6 million residents. The third person killed was a passerby in the area.

The accident was followed by a huge fire in central Tabriz, which was put out following the intervention of the firefighters.

An Vietnam war era F5 warplane still flying in the Iranian air force.
100%
A Vietnam war era F5 warplane still flying in the Iranian air force.

According to the commander of the Tabriz air base, General Reza Yousefi, the jet had been used for training while it suffered a technical problem on its final flight. He said that due to the technical problem “pilots could not reach the runway”.

Yousefi claimed that the pilots could have used the ejection system, but they refused to do it and “sacrificed themselves” to guide the jet to the stadium and not crash into a populated area “to keep people safe”.

The jet, however, initially hit the ground of a school according to local reports before crashing into the stadium but the school was closed, and no one was injured or killed there.

Iran’s air force has an assortment of US-made military aircraft purchased before the 1979 Islamic Revolution, which are not considered in optimal condition as decades of Western sanctions have made it hard to maintain the aging fleet.

Iran Hardliners Attack Writer For Love Without Marriage Comment

Feb 21, 2022, 08:05 GMT+0
•
Iran International Newsroom

Hardliner clerics and lawmakers in Iran are up in arms for a comment by a screenwriter perceived as condoning male and female partnership without marriage.

The parliament has summoned Culture Minister Mohammad Mehdi Esmaili to offer his explanation about the comments made by a female screenwriter at the closing ceremony of Fajr Film Festival that was meant to celebrate the victory of Iran's Islamic revolution on its 43rd anniversary in mid-February.

In her controversial comments, Noushin Meraji had shyly defended the relationship between the protagonists in her screenplay who were not married but lived together. Hardliners and fundamentalist clerics were quick to raise the cry of blasphemy.

In a video that was released later, Meraji apologized for her comment. She said only 10 seconds of her remarks turned out to be controversial because it was made under huge media pressure during a news conference after the screening of the movie Namour [Damp]. She said what her comment did not mean that a love affair without a marriage was legitimate.

Meraji said in the video that she is a devoted Muslim and a family woman and stressed that she was deeply sorry if her comment led to a misunderstanding. But the temptation to start an outcry was too great for fundamentalists to miss the opportunity.

The Chairman of the Cultural Committee of the Majles, hardline cleric Morteza Aaq-Tehrani, however, said that he has already told the Culture Minister that "such an insult" cannot be tolerated by the Majles. This comes while Esmaili had explained the matter and apologized in a live interview on the state television Saturday night.

In an interview with Tasnim news agency, the lawmaker accused the screenwriter of undermining divine laws. Acknowledging that she had apologized he still insisted that the Minister should come to the Majles to offer his explanation.

In another development, the right-wing association of seminary teachers in a statement lashed out at the screen writer and criticized the Ministry of Culture and Guidance for the "un-Islamic mood" at the festival which "undermined Islamic values including hijab."

Later, female seminarians and Basij militia issued a separate statement condemning Meraji for her remarks. They said in their statement that "The government should slap shameless actresses in the face for their shameless behavior." It appears that the seminarians did not know that Meraji was not an actress. According to the statement, "As far as God is concerned, there is no difference between those who commit a bad act and those who advocate such an act." The statement added that "It is shameful that the festival has advocated adultery.”

However, former conservative lawmaker Ali Motahari criticized Meraji's critics and condemned the controversy surrounding her remarks. Motahari told Nameh News website: "Nearly all of those who criticized Merajicalled for punishing her by slapping her in the mouth or in the face. This is not how Muslim scholars should behave." He called on clerics at the seminary to follow the teachings of his father Ayatollah Mortaza Motahari and respond to controversial statements in a rational way and offer their own argument rather than attacking someone for controversial remarks.

US Envoy In Kuwait Calls Iran’s Proxies A Real Problem For Region

Feb 20, 2022, 10:49 GMT+0

US Ambassador to Kuwait Alina Romanowski has accused Iran of continuing its “destabilizing activities” across the Middle East.

Romanowski, who will soon head to Baghdad after she was nominated as ambassador to Iraq by President Joe Biden, said on Sunday that the Iran’s proxies are a real problem for the stability of the region.

“Iran in our view is promoting very destabilizing activities in the region, which doesn’t help the security of the region; the support they are giving to non-state actors is a real problem in terms of stability”, she told TimesKuwait.

She said Washington is trying to find a solution for the Islamic Republic’s support for Houthis, noting that “Our efforts are focused on assisting people in Yemen on humanitarian grounds, but at the same time in the UAE we are giving support on the defense side”.

About the Biden administration’s indirect nuclear negotiations with Iran in Vienna, she said, “We are in a very delicate time now in this negotiation… We are consulting our partners and allies in the region, and also with the EU. We see that time is running out in terms of finding a solution and our ways to go back to the JCPOA. We have the Iranians as partners too, but at the end of the day, our objective is for us not to see Iran acquiring the capability to further destabilize the region”.