HomeSecurityUS: Sanctions on company linked to the Iranian regime for hacking...

US: Sanctions on company linked to Iranian regime for hacking businesses

The U.S. government today imposed sanctions on a company that covered up a massive hacking operation organized and executed by the Iranian regime against its own citizens as well as companies and governments of other countries. The sanctions were imposed on “Rana Intelligence Computing Company,” also known as the Rana Institute or Rana. However, the sanctions were imposed not only on the company itself but also on 45 current and former employees, including directors, programmers and hacking specialists. U.S. officials said that Rana operated as a “front” for Iran’s Ministry of Intelligence and Security (MOIS). Its primary tasks were to conduct hacking campaigns both domestically and internationally.

US sanctions Iranian company for hacking businesses

Through her local activities, Rana helped the Iranian regime monitor Iranian citizens, dissidents, journalists, former government officials, environmentalists, refugees, students, professors, and anyone else she deemed a threat to the regime.

In addition, Rana hacked government networks in Iran's neighboring countries, as well as foreign companies operating in various sectors such as telecommunications, travel and education. According to officials, by hacking companies in other countries, Rana was able to identify individuals that MOIS considered a threat.

At times, Rana's hacking operations left traces, through which cybersecurity were able to connect them to the Iranian regime.

Rana company linked to Iranian regime

Investigations into these hacking operations, which Rana is behind, can be found in cybersecurity reports concerning the activities of a hacking group known as APT39, Chafer, Cadelspy, Remexi or ITG07. Each of these names was assigned by different cybersecurity companies, but they all refer to the same threat, which in this case is Rana.

However, for a long time, no one knew about Rana’s existence, let alone that it was a company that was working with APT39 and the Iranian regime. The first time people heard about it was in a ZDNet article published in May 2019 that reported on the leak of information linked to Iranian hacking groups. At that time, unknown individuals leaked the source code of malware , data about the MuddyWater server backends, and excerpts from internal Rana documents marked “secret.”

US sanctions VS Iranian regime

Israeli cybersecurity firm ClearSky said in a report published in May 2019 that these Rana documents included lists of victims, cyberattackareas access, a list of employees, and screenshots of sites related to spyware. Additionally, at the time, cybersecurity firms suspected Rana was an Iranian APT, but no one could link her to any known hacking group.

That mystery has now been solved, however. In press releases from the US Treasury Department and the Federal Bureau of Investigation, the US government officially linked Rana to APT39 and MOIS. According to US officials, some of Rana’s hacking operations may not have been limited to intelligence gathering, but also involved abuses , with arbitrary arrests followed by physical and psychological intimidation by MOIS agents.

The sanctions now imposed prohibit US companies from doing business with Rana and her 45 current or former employees. Concurrent with today's sanctions, the FBI issued an alertthat lists eight separate malware suites that Rana (MOIS) used to infiltrate computers.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS