Russian hackers have taken part in an Iranian cyber espionage operation aimed at attacking government and industrial organizations in dozens of countries while posing as hackers from the Islamic Republic, according to British and American officials. The Russian group, codenamed “Turla,” has been accused by Estonia and the Czech Republic of acting on behalf of Russia’s FSB security service . They are said to have used Iranian tools and IT infrastructure to hack organizations in at least 20 countries in the past 18 months alone.

The hacking attacks were mainly active in the Middle East and targeted organizations in Great Britain. Paul Chichester, a senior official at Britain's intelligence agency GCHQ, said the operation showed that state-backed hackers were developing new attacks and methods to better cover their tracks. GCHQ also said it wanted to raise awareness of the activity and make these attacks more difficult.
For the record, neither Russia nor Iran immediately responded to Sunday's comments. Moscow and Tehran have repeatedly disputed Western hacking allegations.
Westerners argue that Russia and Iran are two of the most dangerous threats on the internet, along with North Korea and China. They are often blamed for hacking attacks around the world.

The actions of the Turla group show the dangers of mistaken cyberattacks, British officials said, adding that they were not aware of any public events that had been wrongly attributed to Iran due to Russian operations.
Similar covert attacks have also been carried out by the West, but GCHQ refused to comment on the matter.
By gaining access to Iranian infrastructure, Turla was able to use systems to develop its own malware, GCHQ and the NSA said. The Russian group was also able to access the networks of APT34’s victims and gain access to the code needed to create its own hacking tools.
