http://www.nytimes.com/2015/11/25/world/middleeast/iran-hackers-cyberespionage-state-department-social-media.html?ref=world
Iranian Hackers Attack State Dept. via Social Media Accounts

Secretary of State John Kerry, second from left, with members of the
American delegation in Vienna during nuclear talks with Iran in July. Over
the past month, Iranian hackers identified individual State Department
officials who focus on Iran and the Middle East and broke into their email
and social media accounts. Pool photo by Carlos Barria

WASHINGTON — Four months after a historic accord with Tehran
<http://www.nytimes.com/2015/07/15/world/middleeast/iran-nuclear-deal-is-reached-after-long-negotiations.html>
to limit its atomic ambitions, American officials and private security
groups say they see a surge in sophisticated computer espionage by Iran
<http://topics.nytimes.com/top/news/international/countriesandterritories/iran/index.html?inline=nyt-geo>,
culminating in a series of cyberattacks against State Department officials
over the past month.

The surge has led American officials to a stark conclusion: For Iran
<http://topics.nytimes.com/top/news/international/countriesandterritories/iran/index.html?inline=nyt-geo>,
cyberespionage — with the power it gives the Iranians to jab at the
United States and its neighbors without provoking a military response —
is becoming a tool to seek the kind of influence that some hard-liners in
Iran may have hoped its nuclear program
<http://topics.nytimes.com/top/news/international/countriesandterritories/iran/nuclear_program/index.html?inline=nyt-classifier>
would eventually provide.

While American officials doubt cyber skills, or even the most advanced
cyber weapons, will ever have that kind of power, Iran’s cyber focus
these days is notable.

Over the past month, Iranian hackers identified individual State Department
officials who focus on Iran and the Middle East, and broke into their email
and social media accounts, according to diplomatic and law enforcement
officials familiar with the investigation. The State Department became
aware of the compromises only after Facebook told the victims that
state-sponsored hackers had compromised their accounts.

“It was very carefully designed and showed the degree to which they
understood which of our staff was working on Iran issues now that the
nuclear deal is done,†said one senior American official who oversees much
of that operation and who requested anonymity to discuss a continuing
investigation. “It was subtle.â€

Iran’s cyberskills are not yet equal to those of Russia or China. But the
attack against the State Department by using the social media accounts of
young government employees to gain access to their friends across the
administration — a focus that had not been seen before — showed an
ingenuity beyond the Russian brute-force attack that infiltrated the State
Department’s unclassified email system a year ago.

In the aftermath of the nuclear accord, American intelligence officials
have warned senior officials that they expect Iran to ramp up its use of
cyberespionage.

The director of national intelligence, James R. Clapper Jr., has told
Congress in closed sessions that he believes state-sponsored Iranian
hackers are not attempting big attacks that could threaten their ability to
reap the financial rewards of complying with the nuclear accord, according
to two officials familiar with those briefings. But he said they were
stepping up traditional cyberespionage, and getting better at it.

“The Iranians have not been as destructive as they could be, but they are
getting far more aggressive in cyberespionage, which they know is less
likely to prompt a response from the United States,†said James Lewis, who
runs the cyberprogram at the Center for Strategic and International Studies
in Washington. “They seem very attuned to every stage of implementing the
nuclear agreement.â€

Congress is responding. In the defense bill
<http://www.nytimes.com/2015/11/11/us/politics/senate-passes-military-bill-that-bars-transfers-of-guantanamo-detainees.html>
lawmakers passed this month, United States Cyber Command, which runs the
military’s offensive and defensive Internet activities, is instructed to
conduct computer war games
<http://www.defenseone.com/threats/2015/11/lawmakers-demand-us-military-carry-out-pretend-cyber-war-against-china-russia/123684/>
next year. The games are intended to replicate the threats from China,
Iran, North Korea and Russia.

Iranian cyberattacks are hardly new. They arose after the American cyberattacks
on Iran’s nuclear facility
<http://www.nytimes.com/2012/06/01/world/middleeast/obama-ordered-wave-of-cyberattacks-against-iran.html>
at Natanz, an operation
<http://www.nytimes.com/interactive/2012/06/01/world/middleeast/how-a-secret-cyberwar-program-worked.html>
that destroyed upward of a thousand Iranian centrifuges and drove home to
the Iranian leadership the destructive power of computer weapons. The
American attacks began toward the end of the George W. Bush administration.

Since then, American government officials and private security researchers
say Iranian hackers have been behind a series of powerful attacks against
American banks that took their websites offline, as well as a destructive
attack at Saudi Aramco
<http://www.nytimes.com/2012/10/24/business/global/cyberattack-on-saudi-oil-firm-disquiets-us.html>,
the world’s largest oil
<http://topics.nytimes.com/top/news/business/energy-environment/oil-petroleum-and-gasoline/index.html?inline=nyt-classifier>
producer, that replaced data on employee machines with an image of a
burning American flag.

American government officials also blame Iran for a similarly destructive
attack at RasGas, the Qatari natural gas giant, and for an attack at the
Sands Casino
<http://www.nytimes.com/2015/04/16/world/middleeast/iran-is-raising-sophistication-and-frequency-of-cyberattacks-study-says.html>
in Las Vegas, where a large number of computers were destroyed.

(The casino, while a seemingly odd target, is controlled by Sheldon
Adelson, a major funder of Republican candidates, and the attack followed
his suggestion that the United States detonate a nuclear weapon in the
Iranian desert to force the country to give up its nuclear technology.)

But last year, private security researchers say, Iranians began using
cyberattacks for espionage, rather than for destruction and disruption.

Beginning in May 2014, researchers found evidence that Iranian hackers were
targeting Iranian dissidents, and later policy makers, senior military
personnel and defense contractors in the United States, England and Israel,
according to a report by iSight Partners, a computer intelligence firm in
Dallas.

For the most part, researchers said, the attacks were basic “spear
phishing†attempts, in which attackers tried to lure their victims into
clicking on a malicious link, in this case by impersonating members of the
news media. Iranian hackers were successful in more than a quarter of their
attempts.

The number of such attacks reached a climax in May — just ahead of the
nuclear talks in Vienna in July — reaching more than 1,500 attempts,
according to researchers at Check Point, the Israeli cybersecurity company.

Some researchers witnessed an even more troubling trend: In the months
leading up to the talks, Iran’s hackers began probing critical
infrastructure networks in what appeared to be reconnaissance for
cyberattacks meant to cause physical damage, said John Hultquist, the
director of cyberespionage analysis at iSight Partners.

And then something curious happened: In June and July, as American and
Iranian negotiators gathered in Vienna to cut a deal on Iran’s nuclear
program, attacks against targets in the United States stopped. Not a single
phishing attempt was logged by Check Point. And the critical infrastructure
probes went silent as well, according to iSight Partners, and have not
resumed.

Instead, iSight’s researchers saw Iran’s hackers switch focus. They
began targeting victims in Israel as well as members of the Islamic State
in July as the militant group began expanding its territory across Iraq.

And then, in August, just two weeks after the nuclear accord was reached,
the trickle of cyberattacks against the group’s usual targets resumed.
Check Point’s researchers were able to hack the attackers’ target list,
which included 1,600 individuals, from scholars, scientists, chief
executives and ministry officials to education institutes, journalists and
human rights activists across the globe.

The victims may have never learned of the compromises were it not for a
decision by Facebook last month to use a new alert system to notify users
when Facebook’s security team believed state-sponsored hackers had
hijacked their accounts. Just weeks into the new alert system, State
Department officials began to see a troubling new message pop up on their
Facebook accounts:

“We believe your Facebook account and your other online accounts may be
the target of attacks by state-sponsored actors,†the message read.

Some details of the espionage on State Department employees were first
<http://www.wsj.com/articles/u-s-detects-flurry-of-iranian-hacking-1446684754>
reported
<http://www.wsj.com/articles/u-s-detects-flurry-of-iranian-hacking-1446684754>
by The Wall Street Journal.

State Department officials say none of this will affect the coming turning
points
<http://www.nytimes.com/interactive/2015/03/31/world/middleeast/simple-guide-nuclear-talks-iran-us.html>
in the nuclear deal. The International Atomic Energy Agency reported last
week that Iran is already beginning to dismantle some of its centrifuges
— at the same site the United States and Israel attacked with
cyberweapons.






__._,_.___
------------------------------
Posted by: "Beowulf" <[email protected]>
------------------------------


Visit Your Group
<https://groups.yahoo.com/neo/groups/grendelreport/info;_ylc=X3oDMTJmYmloYTcxBF9TAzk3MzU5NzE0BGdycElkAzIwMTk0ODA2BGdycHNwSWQDMTcwNTMyMzY2NwRzZWMDdnRsBHNsawN2Z2hwBHN0aW1lAzE0NDg0ODQ2MDg->

   - New Members
   
<https://groups.yahoo.com/neo/groups/grendelreport/members/all;_ylc=X3oDMTJncTNrZjYyBF9TAzk3MzU5NzE0BGdycElkAzIwMTk0ODA2BGdycHNwSWQDMTcwNTMyMzY2NwRzZWMDdnRsBHNsawN2bWJycwRzdGltZQMxNDQ4NDg0NjA4>
   1

[image: Yahoo! Groups]
<https://groups.yahoo.com/neo;_ylc=X3oDMTJlbTN1c3NuBF9TAzk3NDc2NTkwBGdycElkAzIwMTk0ODA2BGdycHNwSWQDMTcwNTMyMzY2NwRzZWMDZnRyBHNsawNnZnAEc3RpbWUDMTQ0ODQ4NDYwOA-->
• Privacy <https://info.yahoo.com/privacy/us/yahoo/groups/details.html> •
Unsubscribe <[email protected]?subject=Unsubscribe>
• Terms of Use <https://info.yahoo.com/legal/us/yahoo/utos/terms/>

__,_._,___

-- 
-- 
Thanks for being part of "PoliticalForum" at Google Groups.
For options & help see http://groups.google.com/group/PoliticalForum

* Visit our other community at http://www.PoliticalForum.com/  
* It's active and moderated. Register and vote in our polls. 
* Read the latest breaking news, and more.

--- 
You received this message because you are subscribed to the Google Groups 
"PoliticalForum" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to [email protected].
For more options, visit https://groups.google.com/d/optout.

Reply via email to