http://www.hstoday.us/single-article/iranian-hackers-targeting-critical-infrastructure-across-the-globe/f296951da4ef8b7e70135456a92a59af.html



Iranian Hackers Targeting Critical Infrastructure Across the Globe

By: Amanda Vicinanzo, Senior Editor

12/04/2014 (11:00am)

[image: Bookmark and Share]
<http://www.addthis.com/bookmark.php?v=250&pub=xa-4a8ac57416db70f7>



Iranian hackers have penetrated the computer networks of government
agencies and major critical infrastructure companies in the United States
and 15 other countries over the past two years in a campaign that could
eventually cause physical damage, according to a report by cybersecurity
company Cylance.



California-based Cylance released an 87-page report
<http://www.cylance.com/assets/Cleaver/Cylance_Operation_Cleaver_Report.pdf>
detailing the actions of the global surveillance and infiltration campaign
dubbed “Operation Cleaver” because the attackers used the string “cleaver”
in a variety of the custom software used in the campaign.



“We believe our visibility into this campaign represents only a fraction of
Operation Cleaver’s full scope,” the report stated. “We believe that if the
operation is left to continue unabated, it is only a matter of time before
the world’s physical safety is impacted by it.”



Targets have included some of the most sensitive global critical
infrastructure companies across the globe, including: military, oil and
gas, energy and utilities, transportation, hospitals, telecommunications,
technology, education, aerospace, defense contractors, chemical, companies
and governments.



The report did not name companies, but identified over 50 victims impacted
by the attacks. The hackers have hit firms in the United States, Canada,
China, England, France, Germany, India, Israel, Kuwait, Mexico, Pakistan,
Qatar, Saudi Arabia, South Korea, Turkey and the United Arab Emirates.



Targeting a broad array of companies in countries across the globe, Cylance
believes the scope of Iran has positioned itself to impact critical
infrastructure globally.



“With minimal separation between private companies and the Iranian
government, their *modus operandi* seems clear: blur the line between
legitimate engineering companies and state-sponsored cyber hacking teams to
establish a foothold in the world’s critical infrastructure,” the report
stated.



The report noted Iranian hacking campaigns are nothing new. The 2012
Operation Shamoon campaign launched in retaliation to Stuxnet—the computer
worm that ravaged Iran’s Natanz nuclear facility—impacted over 30,000
computer endpoints and cost the companies affected by the attacks tens of
thousands of dollars in recovery expenses.



The Shamoon malware destroyed three-quarters of the PCs at Saudi Arabian
oil company, Saudi Aramco, marking the most destructive attack against a
corporate network to date. Stuart McClure, CEO of Cylance, explained in a
blog post
<http://blog.cylance.com/operation-cleaver-prevention-is-everything> that,
“Such an attack is just the beginning, it serves as a proof of concept to
prove that such large scale and devastating attacks are not only possible
but impending.”



In September 2013, the *Wall Street Journal* reported that Iran hacked into
unclassified US Navy computers in San Diego’s Navy Marine Corp Intranet.
Cylance linked this attack to Operation Cleaver.



“While to date Cylance has yet to see Operation Cleaver result in loss of
life or disruption of critical services, with the history of this group I
see that as a likely consequence of these attacks,” said McClure.



Although not confirmed, the report speculated the attacks are
state-sponsored and are being conducted in retaliation to Stuxnet. Iran’s
cyber sophistication has grown rapidly since the dawn of Stuxnet and the
report indicates that "they have used hard dollars combined with national
pride to help build their cyber army."



Operation Cleaver’s intentions may be to damage industrial control systems
(ICS), supervisory control and data acquisition (SCADA) systems, and impact
critical infrastructure and key resources (CIKR).



“This campaign could be a way to demonstrate Iran’s cyber capabilities for
additional geopolitical leverage, due to the breadth and depth of their
global targets,” the report said.



At least 20 hackers and developers are believed to be behind Operation
Cleaver and Cylance was able to uncover a considerable amount of
information on the members of the campaign. The group's techniques overlap
with those used by the Iranian Cyber Army and Syrian Electronic Army.
However, Cylance believes Operation Cleaver is the work of a new team.



“Ultimately we believe the Cleaver team is a mix of existing team members
and new recruits pulled from the universities in Iran,” Cylance explained.
To protect themselves, companies must bolster their current security
posture and demand that their security vendors step up to the plate.
McClure believes prevention is the key to protecting against Operation
Cleaver.



The report urged organizations in the US to contact the FBI if they believe
they have become a victim of Operation Cleaver.



“Unfortunately, many critical infrastructure organizations are unable to
secure their complex environments against modern attacks. They fall victim
to the “glue flu," a malaise of feeling stuck, not wanting to change the
status quo for fear they will find problems that they have no idea how to
prevent. This “security anaphylaxis” spells real disaster,” the report
concluded. “If Operation Cleaver doesn’t get the world to wake up to what
is happening in the silent world of cyber, then perhaps nothing will.
Prevention is everything and we should never give up until it’s achieved.”




__._,_.___
 ------------------------------
Posted by: "beowulf" <[email protected]>
------------------------------


 Visit Your Group
<https://groups.yahoo.com/neo/groups/grendelreport/info;_ylc=X3oDMTJmaWg4anBjBF9TAzk3MzU5NzE0BGdycElkAzIwMTk0ODA2BGdycHNwSWQDMTcwNTMyMzY2NwRzZWMDdnRsBHNsawN2Z2hwBHN0aW1lAzE0MTc3MTI2ODU->


 [image: Yahoo! Groups]
<https://groups.yahoo.com/neo;_ylc=X3oDMTJlbDVlOWx2BF9TAzk3NDc2NTkwBGdycElkAzIwMTk0ODA2BGdycHNwSWQDMTcwNTMyMzY2NwRzZWMDZnRyBHNsawNnZnAEc3RpbWUDMTQxNzcxMjY4NQ-->
• Privacy <https://info.yahoo.com/privacy/us/yahoo/groups/details.html> •
Unsubscribe <[email protected]?subject=Unsubscribe>
• Terms of Use <https://info.yahoo.com/legal/us/yahoo/utos/terms/>

__,_._,___

-- 
-- 
Thanks for being part of "PoliticalForum" at Google Groups.
For options & help see http://groups.google.com/group/PoliticalForum

* Visit our other community at http://www.PoliticalForum.com/  
* It's active and moderated. Register and vote in our polls. 
* Read the latest breaking news, and more.

--- 
You received this message because you are subscribed to the Google Groups 
"PoliticalForum" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to [email protected].
For more options, visit https://groups.google.com/d/optout.

Reply via email to