Two hackers are accused by the U.S. Department of Justice (DoJ) of orchestrating a mass defacement campaign against U.S. websites. The campaign was launched after the killing of Iranian military commander Qasem Soleimani by U.S. forces in early January. According to the indictment, the two hackers behind the campaign are 19-year-old Iranian Behzad Mohammadzadeh, also known as Mrb3hz4d, and 25-year-old Palestinian Marwan Abusrour, also known as Mrwn007.

Mohammadzadeh had given an exclusive interview to SECNEWS last March, following an ALERT issued by the FBI at the time..
The FBI noted in its related announcement that it had observed a series of breaches of sites by Iranian hackers. It also emphasized that many of these breaches may have been the result of exploiting known vulnerabilities in Content Management Systems (CMSS) to upload defacement files. Thus, the FBI advised users, businesses and organizations at the time to be aware of the techniques, tactics and indicators provided in their ALERT, as they were very likely to be targeted by Iranian hackers.
Mohammadzadeh has hacked, among other things, the website of the National Transparency Authority (aead.gr) which belongs to SYZEFXIS. Thus, the SecNews team got in touch with him to learn more about the hacker, his goals, the attacks on Greek sites, his opinion on the level of online security of Europeans and more.
Now Mohammadzadeh, considered the main perpetrator of the attacks, has been accused of hacking into over 50 US sites and then publishing images of the late Soleimani, as well as messages such as “Down with America.

The breaches mostly affected domains hosted in the US, starting on January 3, a day after US officials announced the killing of Soleimani in a strike on his car near Baghdad International Airport.
According to the indictment, after this announcement, Mohammadzadeh began a widespread hacking campaign. Furthermore, while the DoJ has accused Mohammadzadeh of hacking approximately 51 sites, US officials claim that a profile on Zone-H (a site where hackers post details of their breaches and boast about their exploits) lists over 1,100 sites that have been hacked by the Iranian hacker, with 400 of them showing pro-Soleimani messages.

Abusrour, on the other hand, was charged with a lesser role in the campaign. Prosecutors said the young Palestinian provided Mohammadzadeh with access to seven websites, which his Iranian counterpart later manipulated as part of his campaign.
However, US officials said Abusrour also had a history of defacement against sites, with the hacker monicker being found on more than 337 sites defaced with pro-Palestinian messages dating back to June 2016.

The breaches carried out by the two hackers were widely reported in the media. However, the coverage of the news was slightly exaggerated, with some news agencies presenting these breaches as a response by the Iranian government in the context of an upcoming “nuclear cyberwar”. However, this does not correspond to reality. Among the most popular sites compromised by Mohammadzadeh was the portal of the US Federal Depository Library Program, which was taken down almost immediately and restored after the defacement.
According to the DoJ, if the two hackers are found guilty, they could face up to 10 years in prison and fines of up to $250,000. It is worth noting, however, that the two hackers remain at large.
