CISA warns of increased cyber activity by Iranian hackers and urges US companies to take protective measures against the most common practices of these hacker groups – the use of data-wiping malware, password spraying and spear-phishing.
The warning was posted in a tweet by the Director of the Cybersecurity and Infrastructure Security Agency (CISA) Christopher Krebs.

The CISA warning was issued as Iranian hackers launched new waves of cyberattacks against American targets following escalating tensions between the U.S. and Iran, according to a CBS News.
The US responded to these Iranian cyberattacks, according to a report by Yahoo News.
The silent cyberwar between the two countries is expected to continue, and now CISA leadership is warning US businesses to take protective measures against the most common hacking techniques used by known Iranian attackers, including:
- Spear-phishing – A technique used by Iranian hackers, for which many have been indicted in the past by the US Department of Justice.
- Credential stuffing – the use of username and password combinations that have been leaked online and had been used to access other accounts on another service.
- Password spraying – a method that uses a large number of usernames and loops them with a single password (such as 123456), allowing hackers to compromise accounts with “easy” passwords.
- Data wipers – malware that deletes data on already compromised systems to prevent FDA (Forensic Data Analysis).
Iranian hackers have used data-wiping malware in the past. In 2012, they used the Shamoon (DisTrack) malware against Saudi Arabia, Saudi Aramco, and Qatar's RasGas.
The malware wiped hard drives and temporarily shut down the two companies, resulting in huge financial losses. Shamoon was reported to have wiped hard drives on over 35,000 Saudi Aramco computers.

The malware was used again in 2016 and 2018, with the latest incident targeting the network of an Italian oil and gas company operating in the Middle East.
With the US coming into direct conflict with Iran, American authorities fear that such destructive attacks may soon target American companies.
