Tag Archive for: Hezbollah

Israel Saw 43% Surge In Cyber Attacks From Iran, Hezbollah In 2023


Israel saw a 43% surge in cyber assaults originating from Iran and Hezbollah in the last year, a recent report from Israel’s National Cyber Directorate has revealed.

The annual publication highlights a significant escalation in cyber warfare tactics during the period from the October 7 invasion from Iran-backed Hamas, to the end of 2023.

According to the report, Israel encountered a 2.5-fold increase in cyber intrusions compared to previous years, with a total of 3,380 attacks documented during the specified timeframe. Notably, 800 of the attacks were deemed to possess “significant potential for damage” by the National Cyber Directorate.

“The war brought with it an increase in cyber attacks that intensified gradually, shifting from a focus on information theft to disruptive and damaging attacks,” the report stated. It said the attacks had aims from simply spreading public discord to more sophisticated endeavors designed to disrupt essential organizations and influential companies within supply chains.

The Directorate underscored the targeting of hospitals as central objectives, attacks aimed at undermining the war effort and intelligence gathering, and a burgeoning collaboration between Iran and Hezbollah in executing cyber operations.

Throughout 2023, the Directorate registered a total of 13,040 verified cyber attack reports, representing a 43% surge compared to the preceding year. Notably, 68% of these reports coincided with the Gaza conflict.

Of the reported attacks, 41% targeted social networks, 25% were phishing attempts, and 13% exploited vulnerabilities in computer systems. The remaining assaults comprised malware attacks, disruptions to operational continuity, and communication disruptions.

The report also emphasized the prevalent use of compromised login data and phishing techniques by attackers, underscoring the need for heightened vigilance and enhanced cybersecurity measures across critical sectors.

Source…

Most Dangerous State-Sponsored Hackers In the World



Hacking Group Linked To Hezbollah Reportedly Hacked Into Telecoms and ISPs Around The World


News Highlights: Hacking Group Linked To Hezbollah Reportedly Hacked Into Telecoms and ISPs Around The World.

Lebanese Cedar, a Hezbollah-affiliated group, is accused of hacking atlas 250 telecom operators and internet providers in several countries, notably the US, Lebanon, UK, Saudi Arabia, Israel, Egypt, Jordan, UAE and Palestinian Authority,.

According to ClearSky Security, shady network activities and hacking tools were found across a spectrum of businesses in early 2020.

“Extensive forensics of the infected systems revealed a strong connection to a threat actor we call ‘Lebanese cedar’ who has been active since 2012,” the cybersecurity agency said in their report. report published on Thursday.

According to the report, the goal of the Hezbollah-affiliated group is to gather intelligence and steal databases.

“The attacks followed a simple pattern. Lebanese Cedar operators used open-source hacking tools to scan the Internet for unparalleled Atlassian and Oracle servers, then use exploits to access the server and install a web shell for future access, ”explains ClearSky.

Adding that “the Hezbollah-linked group then used these web shells to attack a company’s internal network, from which they exfiltrated private documents.”

Credits: Clearsky

ClearSky revealed that once the group gained access, they installed web shells (ASPXSpy, Caterpillar 2, Mamad Warning) as well as an open-source tool called JSP File Browser.

On internal networks, the attackers deployed a tool called the Explosive remote access trojan (RAT), which specializes in data interception, ClearSky said.

ClearSky noted that they were able to link the hacks of the Hezbollah cyber unit because the Explosive RAT’s tool was used exclusively by the Lebanese Cedar group until now.

Mistakes made by the Hezbollah-affiliated group, such as reusing files during break-ins, also made it easier for ClearSky researchers to track the attacks around the world and link them to the group.

Credits: Clearsky

ClearSky has published a list of some of the victims of the hack, including SaudiNet in Saudi Arabia, Vodafone Egypt, Frontier Communications in the US and Etisalat UAE.

Extensive details can be read in it cyber security…

Source…