Join +750K new investors every month who copy stock picks from billionaire's portfoliosSign Up Free

Iran-linked cyber spies use simple yet effective hacks: report

Published 07/25/2017, 10:45 AM
Updated 07/25/2017, 10:50 AM
© Reuters. FILE PHOTO: Man types on a computer keyboard in front of the displayed cyber code in this illustration picture
INTC
-
MSFT
-
META
-
4704
-

TEL AVIV (Reuters) - A cyber spying group with links to Iran and active for the past four years is targeting countries including Israel, Saudi Arabia, Germany and the United States, security researchers said on Tuesday.

A new report by Tokyo-based Trend Micro (T:4704) and ClearSky of Israel detailed incidents as recently as April of this year involving a group known as "CopyKittens".

The group targets its victims using relatively simple techniques like creating fake Facebook (NASDAQ:FB) pages, corrupting websites or Microsoft (NASDAQ:MSFT) Word attachments with a malicious code, according to the report.

It was seen impersonating popular media brands like Twitter, Youtube, the BBC and security firms such as Microsoft, Intel (NASDAQ:INTC) and even Trend Micro.

"CopyKittens is very persistent, despite lacking technological sophistication and operational discipline," the researchers said in a statement.

"These characteristics, however, cause it to be relatively noisy, making it easy to find, monitor and apply counter measures relatively quickly," they said.

Iranian officials were not available for comment.

The report itself does not link the group to Iran. As a matter of company policy, Trend Micro research into state-backed attacks focuses on technical evidence and forgoes political analysis.

However Clearsky researchers told Reuters that CopyKittens was "Iranian government infrastructure," adding that the use of "kitten" in the industry indicates Iranian hackers, just as "panda" or "bear" refer to Chinese and Russians, respectively.

CopyKittens is distinct from another Iran-based cyber spy group dubbed Rocket Kitten, which since 2014 has mounted cyberattacks on high-profile political and military figures in countries near Iran as well as the United States and Venezuela. (http://reut.rs/2tGfOzK)

CopyKittens has been operating since at least 2013, according to the report, though its activities were first exposed publicly in November 2015 by ClearSky and Minerva Labs. Earlier this year, ClearSky wrote another paper detailing more hacking incidents that affected some members of Germany's parliament.

Eyal Sela, head of threat intelligence at ClearSky, said that once an initial hack against a government or commercial target is successful, CopyKittens uses that access to then attack other groups, though it tries to remain very focused.

As recently as late April, the group breached the email account of an employee in the Ministry of Foreign Affairs in Turkish Cypriot-controlled northern Cyprus and then tried to infect multiple targets in other governments, the report said.

© Reuters. FILE PHOTO: Man types on a computer keyboard in front of the displayed cyber code in this illustration picture

Another time it used a document, likely stolen from Turkey's Foreign Ministry, as a decoy.

Latest comments

Risk Disclosure: Trading in financial instruments and/or cryptocurrencies involves high risks including the risk of losing some, or all, of your investment amount, and may not be suitable for all investors. Prices of cryptocurrencies are extremely volatile and may be affected by external factors such as financial, regulatory or political events. Trading on margin increases the financial risks.
Before deciding to trade in financial instrument or cryptocurrencies you should be fully informed of the risks and costs associated with trading the financial markets, carefully consider your investment objectives, level of experience, and risk appetite, and seek professional advice where needed.
Fusion Media would like to remind you that the data contained in this website is not necessarily real-time nor accurate. The data and prices on the website are not necessarily provided by any market or exchange, but may be provided by market makers, and so prices may not be accurate and may differ from the actual price at any given market, meaning prices are indicative and not appropriate for trading purposes. Fusion Media and any provider of the data contained in this website will not accept liability for any loss or damage as a result of your trading, or your reliance on the information contained within this website.
It is prohibited to use, store, reproduce, display, modify, transmit or distribute the data contained in this website without the explicit prior written permission of Fusion Media and/or the data provider. All intellectual property rights are reserved by the providers and/or the exchange providing the data contained in this website.
Fusion Media may be compensated by the advertisers that appear on the website, based on your interaction with the advertisements or advertisers.
© 2007-2024 - Fusion Media Limited. All Rights Reserved.