HomeSecurityHomeland Security USA: Warns of attacks by Iranian hackers

US Homeland Security: Warns of attacks by Iranian hackers

The US Department of Homeland Security (DHS) has issued a warning about the increased threat of cyberattacks from pro-Iranian groups and state-backed Iranian hackers, amid tension in the Middle East and recent military attacks on Iranian nuclear facilities.

Iranian hackers Department of Homeland Security

The warning was incorporated into Sunday's National Terrorism Advisory System bulletin and describes an "elevated risk environment" for US infrastructure, with an increased likelihood of attacks low-intensity, primarily in cyberspace.

According to DHS, the possibility of isolated acts by violent extremists within the United States may be further heightened if there is a call for retaliation from Iranian religious or political leadership.

See also: Bloomberg: Iran hacks cameras to monitor Israelis

The ministry notes that several recent terrorist acts in the United States have been motivated by anti-Semitic and anti-Israel sentiment, an element that may fuel further violent acts, combined with the ongoing Israel-Iran crisis.

Previous incidents and known threat groups

DHS notes that the United States has already been targeted by Iranian state-controlled groups, as well as digital activists who attack infrastructure with inadequate cybersecurity. The attacks include techniques such as password spraying, brute-forcing , and MFA fatigue (also known as push bombing).

In a separate bulletin in October, the US, Canada and Australia had also warned that Iranian hackers were acting as initial access brokers, targeting sectors such as health, public services, energy and IT.

See also: Predatory Sparrow “hit” Iranian Nobitex – Crypto theft

Particular emphasis was placed on the well-known threat Br0k3r (also known as Pioneer Kitten, Fox Kitten, UNC757, Parisite, RUBIDIUM, Lemon Sandstorm), a state-backed group that sells access to compromised networks to ransomware groups (in exchange for a percentage of the ransom).

Homeland Security
US Homeland Security: Warns of attacks by Iranian hackers

Geopolitical background of cyber threats

Although not officially named in the NTAS bulletin, the escalation of the cyber threat appears to be linked to the US attacks on Iranian nuclear facilities (Fordow, Natanz, Isfahan) that occurred on Saturday, a few days after similar strikes by Israel.

Iranian Foreign Minister Abbas Araghchi responded by stating that Tehran retains “all options” to defend its national sovereignty and warned of “lasting consequences.”.

The situation with Iranian cyberattacks is worrying but expected, given the tension in the Middle East and the continued involvement of cyberspace in geopolitical conflicts. It is a hybrid battlefield, where physical attacks are almost always accompanied by digital operations, and pro-government APT groups have proven their competence in this context.

See also: Iranian man confesses to involvement in Robbinhood ransomware

What should organizations do to protect themselves:

  1. Active defense strategy –not just firewall and antivirus.
  2. MFA that doesn't tire users – use FIDO2 or biometrics where possible.
  3. Regular penetration tests – Iranian groups are doing reconnaissance, we should do the same for our own systems.
  4. Scenarios and exercises (tabletop exercises) focusing on cyberattacks and business continuity (BCP/DR).

Source: www.bleepingcomputer.com

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS