The FBI, the U.S. Department of Homeland Security (DHS), and CISA have issued a new advisory providing more details about how Iranian hackers managed to steal voter registration information from government websites, including election websites. The stolen voter information was then used to intimidate Democratic voters via emailspurporting to come from the Proud Boys, to persuade them to vote for Trump. The efforts to collect voter information from election websites occurred between September 29 and October 17.

According to the FBI, DHS, and CISA, Iranian hackers aimed to interfere in this year's US elections by exploiting known vulnerabilities, web shell uploads, structured query language (SQL) injection, and by exploiting unique website flaws
Specifically, Iranian hackers first used the vulnerability scanner “Acunetix” to detect security flaws affecting target sites, which later allowed them to exploit unsecured servers. With attacks , they were able to successfully download data for at least one U.S., exploiting misconfigurations and vulnerabilities in election sites.
To do this, they used scripts designed to use the “cURL” tool to replicate voter registrations, automatically going to databases and subsequently downloading them.

As the FBI reported in an alert issued a few days ago, many of the IP addresses used by Iranian hackers in the Proud Boys fake email campaign come from the NordVPN, and may also correspond to other VPN providers, including CDN77, HQSERV, and M247.
During the investigation, the FBI also found evidence indicating that Iranian hackers researched the following information during their attempts to scan and exploit election sites:
- Exploiting YOURLS
- Bypassing ModSecurity Web Application Firewall
- Detection of Web Application Firewalls
- Tool “SQLmap”

As noted by BleepingComputer, the FBI and CISA provide the following mitigation measures to prevent future attacks:
- Applying updates and patches to systems and applications
- Scanning web applications for SQL injection and other common web vulnerabilities
- Development of web application firewall
- Development of protection techniques against web shells
- Use of multi-factor authentication (MFA) for administrator accounts
- Remediation of critical web application security risks
