Cyberwarfare by Iran explained

Cyberwarfare is a part of Iran's "soft war" military strategy. Being both a victim and wager of cyberwarfare,[1] Iran is considered an emerging military power in the field.[2] Since November 2010, an organization called "The Cyber Defense Command" (Persian: قرارگاه دفاع سایبری; Gharargah-e Defa-e Saiberi) has been operating in Iran under the supervision of the country's "Passive Civil Defense Organization" (Persian: سازمان پدافند غیرعامل; Sazeman-e Padafand-e Gheyr-e Amel) which is itself a subdivision of the Joint Staff of Iranian Armed Forces.[3]

According to a 2014 report by Institute for National Security Studies, Iran is "one of the most active players in the international cyber arena".[4] In 2013, a Revolutionary Guards general stated that Iran has "the 4th biggest cyber power among the world's cyber armies."[5] [6] According to a 2021 report by a cyber-security company, "Iran is running two surveillance operations in cyber-space, targeting more than 1,000 dissidents".[7]

As of 2024, Iran's cyber activities have advanced, particularly in their precision and intelligence-gathering capabilities, allowing for more accurate and targeted attacks against Israel. Following directives from Iran's supreme leader Ali Khamenei after the October 7 attacks, cyber operations expanded, including joint efforts with Hezbollah. Despite these advances, Iran's cyber capabilities still fall short of Israel's, with Iranian hackers' skills being likened to those of mid-level organized crime gangs. However, Israeli officials remain concerned that Iran could rapidly enhance its capabilities, particularly through potential cooperation with Russia.[8]

NIN

Iranian cyber defense system - digital fortress part of national information network (national internet) - is developed for thwarting attacks and engaging attackers.[9] In November 2022, the Iranian Majlis Islamic Consultative Assembly recommended a Passive Defence Incorporation.[10]

Attacks against Iran

In June 2010, Iran was the victim of a cyber-attack when its nuclear facility in Natanz was infiltrated by the cyber-worm 'Stuxnet'.[11] Reportedly a combined effort by the United States and Israel,[12] Stuxnet destroyed perhaps over 1,000 nuclear centrifuges and, according to a Business Insider article, "[set] Tehran's atomic programme back by at least two years."[13] The worm spread beyond the plant to allegedly infect over 60,000 computers, but the government of Iran indicates it caused no significant damage. Iran crowdsourced solutions to the worm and is purportedly now better positioned in terms of cyber warfare technology. No government has claimed responsibility for the worm. The cyber-worm was also used against North Korea.

Events

Attacks by Iran

The Iranian government has been accused by Western analysts of its own cyber-attacks against the United States, Israel and Persian Gulf Arab countries, but denied this, including specific allegations of 2012 involvement in hacking into American banks. The conflict between Iran and the United States has been called "history's first known cyber-war" by Michael Joseph Gross in mid-2013.[41]

2010-2020

2022

2023

2024

Command and control

Iranian armed forces install malware apps for espionage on Android phones.[67] They could steal victims identity according to Microsoft.[68]

Suspended Iranian accounts

On May 5, 2020, Reuters reported, quoting a monthly Facebook report, that Iranian state-run media had targeted hundreds of fake social media accounts to covertly spread pro-Iranian messaging, online since at least 2011, for secretly broadcasting online promotional messages in favor of Iran in order targeting voters in countries including Britain and the United States.[69] Accounts were suspended for coordinated inauthentic behavior, which removed eight networks in recent weeks, including one with links to the Islamic Republic of Iran Broadcasting.

See also

Alleged operations and malware against Iran
Alleged operations and malware by Iran

External links

Notes and References

  1. Web site: Shashank . Joshi . Iran, the Mossad and the power of cyber-warfare . https://web.archive.org/web/20131003104343/http://blogs.telegraph.co.uk/news/shashankjoshi/100239562/iran-the-mossad-and-the-power-of-cyber-warfare/. dead. October 3, 2013. March 18, 2015.
  2. Web site: Iran's military is preparing for cyber warfare. The Telegraph. March 18, 2015. October 3, 2013. August 10, 2018. https://web.archive.org/web/20180810114757/http://flashcritic.com/irans-military-preparing-for-cyber-warfare/. live.
  3. Web site: Hossein. Bastani. Structure of Iran's Cyber Warfare. Institut Français d’Analyse Stratégique. March 18, 2015. December 13, 2012. May 23, 2019. https://web.archive.org/web/20190523162859/http://www.strato-analyse.org/fr/spip.php?article223#outil_sommaire_3. live.
  4. Web site: Gabi. Siboni. Sami. Kronenfeld. Developments in Iranian Cyber Warfare, 2013–2014. INSS Insight. 536. Institute for National Security Studies. March 18, 2015. April 3, 2014. January 5, 2020. https://web.archive.org/web/20200105223245/http://www.inss.org.il/index.aspx?id=4538&articleid=6809. live.
  5. Web site: Israeli Think Tank Acknowledges Iran as Major Cyber Power, Iran Claims its 4th Biggest Cyber Army in World. Hack Read. March 18, 2015. October 18, 2013. May 30, 2019. https://web.archive.org/web/20190530073522/https://www.hackread.com/iran-biggest-cyber-army-israel/. live.
  6. Web site: - IRANIAN CYBER THREAT TO THE U.S. HOMELAND. 2021-10-28. www.govinfo.gov. 2021-10-28. https://web.archive.org/web/20211028120955/https://www.govinfo.gov/content/pkg/CHRG-112hhrg77381/html/CHRG-112hhrg77381.htm. live.
  7. News: Iran 'hides spyware in wallpaper, restaurant and games apps'. BBC News. 8 February 2021. 2021-10-28. 2021-08-07. https://web.archive.org/web/20210807140602/https://www.bbc.com/news/technology-55977537. live.
  8. News: Iran’s electronic confrontation with Israel . 2024-08-18 . The Economist . 0013-0613.
  9. Web site: 2020-02-09. شکست حملات سایبری در مقابل"دژفا". 2021-10-28. https://web.archive.org/web/20200209201319/http://newspaper.hamshahrionline.ir/id/62005/%D8%B4%DA%A9%D8%B3%D8%AA-%D8%AD%D9%85%D9%84%D8%A7%D8%AA-%D8%B3%D8%A7%DB%8C%D8%A8%D8%B1%DB%8C-%D9%85%D9%82%D8%A7%D8%A8%D9%84%C2%AB%D8%AF%DA%98%D9%81%D8%A7%C2%BB.html. 2020-02-09.
  10. Web site: آغاز جلسه علنی مجلس/ طرح تشکیل سازمان پدافند غیرعامل در دستور . 6 November 2022 . 13 November 2022 . 13 November 2022 . https://web.archive.org/web/20221113173140/https://www.imna.ir/news/617254/%D8%A2%D8%BA%D8%A7%D8%B2-%D8%AC%D9%84%D8%B3%D9%87-%D8%B9%D9%84%D9%86%DB%8C-%D9%85%D8%AC%D9%84%D8%B3-%D8%B7%D8%B1%D8%AD-%D8%AA%D8%B4%DA%A9%DB%8C%D9%84-%D8%B3%D8%A7%D8%B2%D9%85%D8%A7%D9%86-%D9%BE%D8%AF%D8%A7%D9%81%D9%86%D8%AF-%D8%BA%DB%8C%D8%B1%D8%B9%D8%A7%D9%85%D9%84-%D8%AF%D8%B1-%D8%AF%D8%B3%D8%AA%D9%88%D8%B1 . live .
  11. News: Stuxnet and the Future of Cyber War . James P. Farwell and Rafal Rohozinski .
  12. News: Obama Order Sped Up Wave of Cyberattacks Against Iran . The New York Times . 1 June 2012 . 1 June 2012 . David E. . Sanger . David E. Sanger . 1 June 2012 . https://web.archive.org/web/20120601112345/http://www.nytimes.com/2012/06/01/world/middleeast/obama-ordered-wave-of-cyberattacks-against-iran.html . live .
  13. News: US General: Iran's Cyber War Machine 'A Force To Be Reckoned With' . Business Insider . 2017-11-14 . 2019-04-02 . https://web.archive.org/web/20190402222626/https://www.businessinsider.com/us-general-irans-cyber-war-machine-a-force-to-be-reckoned-with-2013-1 . live .
  14. Web site: Damien. McElroy. Iranian cyber warfare commander shot dead in suspected assassination. The Telegraph. March 18, 2015. October 2, 2013. October 7, 2019. https://web.archive.org/web/20191007044226/https://www.telegraph.co.uk/news/worldnews/middleeast/iran/10350285/Iranian-cyber-warfare-commander-shot-dead-in-suspected-assassination.html. live.
  15. News: Iran accuses Israel of failed cyber attack . Reuters . 5 November 2018 . 2018-11-06 . 2020-05-28 . https://web.archive.org/web/20200528133349/https://www.reuters.com/article/us-iran-israel-cyber/iran-accuses-israel-of-failed-cyber-attack-idUSKCN1NA1LJ . live .
  16. Web site: Iran accuses Israel of failed cyber attack - CNA . 2018-11-06 . 2019-09-10 . https://web.archive.org/web/20190910160854/https://www.channelnewsasia.com/news/world/iran-accuses-israel-of-failed-cyber-attack-10900158 . live .
  17. Web site: Turak . Ryan Browne,Natasha . Hacktivists seek to aid Iran protests with cyberattacks and tips on how to bypass internet censorship . 2023-03-09 . CNBC . 5 October 2022 . en . 2023-01-13 . https://web.archive.org/web/20230113042118/https://www.cnbc.com/2022/10/05/how-anonymous-and-other-hacking-groups-are-aiding-protests-in-iran.html . live .
  18. Web site: 2023-09-24 . ماجرای حمله سایبری به سایت وزارت علوم چه بود؟ . 2023-09-24 . اعتمادآنلاین . fa.
  19. News: فردا . رادیو . 2023-09-24 . سایت وزارت علوم ایران "هک شد"؛ هکرها می‌گویند به "بیش از ۲۰ هزار سند" دست یافته‌اند . fa . رادیو فردا . 2023-09-24.
  20. Web site: قربانی . زهرا . 2023-09-23 . ماجرای هک سایت وزارت علوم چیست؟ / سامانه‌های دولتی زیر ذره‌بین هکر‌ها . 2023-09-24 . راه پرداخت . fa-IR.
  21. Web site: 2023-09-24 . واکنش عجیب رییس بنیاد شهید به هک شدن سرورهای این سازمان؛ اطلاعاتی حساسی نداشتیم! . 2023-09-24 . اعتمادآنلاین . fa.
  22. Web site: 2023-09-24 . ماجرای هک سایت وزارت امور خارجه چه بود؟ . 2023-09-24 . اعتمادآنلاین . fa.
  23. Web site: 2023-09-04 . هک شرکت‌های بیمه در ایران و نگرانی از ضعف امنیت سایبری . 2023-09-24 . BBC News فارسی . fa.
  24. News: فردا . رادیو . 2023-09-04 . برکناری رئیس کل بیمه مرکزی ایران در پی اخبار "هک اطلاعات ۱۸ شرکت بیمه" . fa . رادیو فردا . 2023-09-24.
  25. Web site: 2023-09-04 . پس‌لرزه‌های هک اطلاعات ۱۸ شرکت بیمه؛ رئیس کل بیمه مرکزی ایران برکنار شد . 2023-09-24 . صدای آمریکا . fa.
  26. Web site: 2023-09-24 . ابعاد هک و انتشار اطلاعات شخصی خبرنگاران و کارکنان خبرگزاری فارس بررسی شود . 2023-09-24 . اعتمادآنلاین . fa.
  27. Web site: قربانی . زهرا . 2023-09-20 . ماجرای هک سازمان ثبت‌احوال چه بود؟ . 2023-09-24 . راه پرداخت . fa-IR.
  28. Web site: 2023-09-22 . هشدار هکرهای بلک رویوارد: اگر رژیم به خواست مردم تن ندهد، اسناد هسته‌ای را رو می کنیم . 2023-09-24 . ایران اینترنشنال . fa.
  29. Web site: 2024-01-25 . سند هک شده: وزارت خارجه جمهوری اسلامی نشستی برای مدیریت بحران پهپادی در اوکراین برگزار کرد . 2024-01-25 . ایران اینترنشنال . fa.
  30. Web site: 2023-12-18 . اختلال سراسری در پمپ بنزین‌های ایران؛ "گنجشک درنده": حمله سایبری کار ما بود . 2024-01-25 . BBC News فارسی . fa.
  31. Web site: 2024-01-01 . هکرهای شرکت «اسنپ فود» نهایی شدن دریافت باج را تائید کردند . 2024-03-01 . BBC News فارسی . fa.
  32. News: فردا . رادیو . 2024-02-13 . روابط عمومی مجلس هک وب‌سایت‌ها و «دسترسی» هکرها به اسناد مجلس را تأیید کرد . 2024-03-01 . رادیو فردا . fa.
  33. Web site: 2024-02-13 . هک وب‌سایت‌های مجلس؛ هکرها «حقوق ۲۰۰ میلیونی» نمایندگان و مزایایی مانند «آجیل شب یلدا» را فاش کردند . 2024-03-01 . صدای آمریکا . fa.
  34. Web site: 2024-03-01 . حمله سایبری هکرهای روسی به سفارت‌خانه‌های جمهوری اسلامی . 2024-03-01 . ایران اینترنشنال . fa.
  35. Web site: 2024-02-21 . Justice Of Iran . 2024-03-01 . https://web.archive.org/web/20240221081514/https://edaalat.org/home . 2024-02-21 .
  36. Web site: 2024-02-22 . هکرهای گمنام چهارده گیگابایت اطلاعات از سرورهای دانشگاه صنعتی مالک اشتر استخراج کردند . 2024-03-01 . صدای آمریکا . fa.
  37. Web site: 2024-02-16 . US Cyberattack Hit 2 Iranian Military Ships in Red Sea . 2024-03-01 . Voice of America . en.
  38. Web site: زارع‌پور، وزیر ارتباطات: نمی‌خواهیم مردم از حملات سایبری مطلع شوند .
  39. Web site: سایت سازمان حج و زیارت هک شد؟ . June 2024 .
  40. Web site: سایت وزارت علوم پس از حمله هکری به طور موقت از دسترس خارج شد .
  41. http://www.vanityfair.com/culture/2013/07/new-cyberwar-victims-american-business "Silent War"
  42. News: Iran launched major cyberattacks on the Israeli Internet. Politico. 27 April 2015. 22 April 2015. Joseph Marks. 10 November 2014. https://web.archive.org/web/20141110054322/http://www.politico.com/morningcybersecurity/0814/morningcybersecurity15035.html. live.
  43. News: Iran Flexes Its Power by Transporting Turkey to the Stone Age. Observer. 27 April 2015. 22 April 2015. Micah Halpern. 14 December 2019. https://web.archive.org/web/20191214152903/https://observer.com/2015/04/iran-flexes-its-power-by-transporting-turkey-to-the-stone-ages/. live.
  44. Web site: Iran blamed for cyberattack on Parliament that hit dozens of MPs, including Theresa May. The Telegraph. 14 October 2017. 6 December 2017. 6 December 2017. https://web.archive.org/web/20171206135812/https://www.msn.com/en-gb/news/uknews/iran-blamed-for-cyberattack-on-parliament-that-hit-dozens-of-mps-including-theresa-may/ar-AAtpPag?li=AAmiR2Z&ocid=spartanntp. live.
  45. Web site: Israel's Jerusalem Post Website Hacked. Reuters. 3 January 2022. 2022-01-03. 2022-01-03. https://web.archive.org/web/20220103103757/https://www.reuters.com/world/middle-east/israels-jerusalem-post-website-hacked-soleimani-assassination-anniversary-2022-01-03/. live.
  46. Web site: Jerusalem Post website hacked with Iran warning on anniversary of Soleimani killing. The Times of Israel. 2022-01-03. 2022-01-03. https://web.archive.org/web/20220103121617/https://www.timesofisrael.com/israeli-news-sites-hacked-with-iran-warning-on-anniversary-of-soleimani-killing/. live.
  47. Web site: Cyberattack against Israeli sites follows reports of failed Mossad op against Iran . https://web.archive.org/web/20220314214405/https://www.jpost.com/breaking-news/article-701269 . 2022-03-14 . 2022-03-14 . live . Yonah Jeremy Bob . 2022-03-14. The Jerusalem Post.
  48. News: Israeli Government Sites Crash in Cyberattack . https://web.archive.org/web/20220314184356/https://www.haaretz.com/israel-news/.premium-israeli-government-sites-crash-in-cyberattack-1.10674433 . live . 2022-03-14 . 2022-03-14 . Haaretz . Yaniv Kubovich.
  49. Web site: New Entries in the CFR Cyber Operations Tracker: Q3 2022 . 2023-03-09 . Council on Foreign Relations . en . 2023-04-26 . https://web.archive.org/web/20230426120359/https://www.cfr.org/blog/new-entries-cfr-cyber-operations-tracker-q3-2022 . live .
  50. Web site: Agencies . Albania cuts diplomatic ties with Iran, boots out diplomats over July cyberattack . 2023-03-09 . www.timesofisrael.com . en-US . 2022-11-17 . https://web.archive.org/web/20221117041837/https://www.timesofisrael.com/albania-cuts-diplomatic-ties-with-iran-boots-out-diplomats-over-july-cyberattack/ . live .
  51. Web site: Iranian hackers compromise US government network in cryptocurrency generating scheme, officials say . 2022-11-17 . 2022-11-17 . https://web.archive.org/web/20221117112724/https://amp.cnn.com/cnn/2022/11/16/politics/iran-hackers-us-government-network/index.html . live .
  52. Web site: 2023-05-25 . Iranian hacker group Agrius launches Moneybird ransomware attacks on Israeli entities . 2023-05-25 . www.2-spyware.com . en.
  53. Web site: Kleinman . Danielle . 2023-03-07 . Iran Launches Cyberattack on Israeli University . 2023-05-25 . FDD . en.
  54. Web site: 2023-05-24 . Iran suspect in cyberattack targeting Israeli shipping, financial firms - Al-Monitor: Independent, trusted coverage of the Middle East . 2023-05-25 . www.al-monitor.com . en.
  55. Web site: Iran state-backed hackers are shifting to disinformation, Microsoft says.
  56. Web site: 2024-01-25 . هکرهای سپاه پاسداران مخالفان رژیم جمهوری اسلامی را در آلمان هدف قرار می‌دهند . 2024-01-25 . ایران اینترنشنال . fa.
  57. Web site: Kohli . Pankaj . 2023-07-27 . Uncovering an Iranian mobile malware campaign . 2023-12-02 . Sophos News . en-US.
  58. Web site: Sgueglia . Sean Lyngaas, By Kristina . 2023-11-28 . Federal officials investigating after pro-Iran group allegedly hacked water authority in Pennsylvania . 2023-11-29 . CNN . en.
  59. Web site: 2024-03-01 . حمله سایبری هکرهای جمهوری اسلامی موجب قطع آب منطقه‌ای در ایرلند شد . 2024-03-01 . ایران اینترنشنال . fa.
  60. Web site: OilRig's persistent attacks using cloud service-powered downloaders . 2024-01-25 . www.welivesecurity.com . en.
  61. Web site: Disrupting malicious uses of AI by state-affiliated threat actors. February 14, 2024.
  62. Web site: Staying ahead of threat actors in the age of AI. . February 14, 2024.
  63. Web site: Iran-linked Website Leaks Secret Israeli Data - National Security & Cyber - Haaretz.com.
  64. Web site: Iran attempted to hack a high-ranking presidential campaign official: Microsoft .
  65. Web site: MuddyWater Threat Group Deploys New BugSleep Backdoor. July 15, 2024. Check Point Blog.
  66. https://www.washingtonpost.com/technology/2024/08/09/iran-fake-news-microsoft-report/
  67. Web site: Lookout Discovers Android Spyware Tied to Iranian Police Targeting Minorities: BouldSpy . 2023-04-30 . 2023-05-01 . https://web.archive.org/web/20230501045855/https://www.lookout.com/blog/iranian-spyware-bouldspy . live .
  68. Web site: Rinse and repeat: Iran accelerates its cyber influence operations worldwide . 2 May 2023 .
  69. News: Facebook says it dismantles disinformation network tied to Iran's state media . REUTERS . 5 May 2020 . 28 October 2021 . 21 August 2021 . https://web.archive.org/web/20210821180131/https://www.reuters.com/article/us-iran-facebook/facebook-says-it-dismantles-disinformation-network-tied-to-irans-state-media-idUSKBN22H2DK . live .