One of Iran’s top hacking groups has left a server exposed online, where IBM security researchers have found videos showing hackers “in action.” The researchers believe the videos are tutorials showing hacking techniques that Iranian hackers use to train “new” hackers. The videos were recorded with a screen recording application called “BandiCam ,” which suggests they were taken intentionally and not accidentally by operators infected with their malware . The videos show Iranian hackers performing various tasks, demonstrating the techniques that novice hackers must follow to compromise a victim’s account, using a list of compromised credentials . Email accounts were the primary targets of the hackers, with social media accounts also accessible, in cases where the credentials of the target’s compromised account were available.

Researchers say it was a meticulous and well-planned process, with operators gaining access to every account of a targeted victim, regardless of how important or insignificant their online profile was. The accounts accessed included, among others, accounts the potential victim had for music and video streaming, delivery, credit reporting, banks, video-games and mobile phone companies.
The Iranian hackers accessed the settings of each account and searched for personal information that may not be included in other online accounts, in an attempt to create as comprehensive a profile as possible for each target. IBM does not detail how the hackers obtained the credentials for each victim. Therefore, it is not clear whether the hackers had infected the targets with malware or had purchased the credentials from some “underground” market.
In some of the videos, Iranian hackers demonstrate techniques for stealing data from each account. This includes extracting all of the targeted account’s contacts, photos, and documents from cloud storage services like Google Drive. IBM researchers note that in some cases, the operators also accessed Google Takeout to extract information, such as the full contents of Google Account, including location history, information from Chrome , and connected Android devices.

The operators then added the victim's email credentials to a Zimbra instance operated by the Iranian group, which would allow the hackers to remotely monitor multiple accounts from a backend panel. Other videos also show the operators working on creating puppet email accounts, which IBM researchers believe the hackers will use for future attacks.
Additionally, researchers note that they have identified some of the accounts of the victims depicted in the videos leaked by the Iranian hackers. These include a member of the US and a Greek Navy officer.
The videos also show failed attempts to access target accounts, such as the accounts of officials of the U.S. Department of State. The videos in which the account breach attacks failed mainly involve accounts that use two-factor authentication (2FA).

Researchers say the server on which they found all these videos was part of the attack infrastructure of an Iranian group called “ITG18,” but is better known by the names Charming Kitten, Phosphorous, and APT35. It is one of the most active hacking groups funded by Iran. Some of the group’s most recent campaigns include attacks against a US presidential campaign in 2020, as well as against US pharmaceutical companies during the COVID-19.
Previous campaigns have also targeted the US military, US financial regulators, and US nuclear scientists, as these are industries that have attracted Iranian interest due to rising military tensions between the two countries, economic sanctions imposed on Iran, and Iran's nuclear program.
