Wiper Malware Used in Attack Against Iran’s Train System


Critical Infrastructure Security
,
Cybercrime
,
Endpoint Security

Operational Security Mistakes Left Clues About Developer’s Skills, But Not Identity

Wiper Malware Used in Attack Against Iran's Train System
Tehran’s rail station. (Photo: Mostafa Asgari via Wikimedia Commons/CC)

Nearly three weeks ago, Iran’s state railway operator was hit with a cyberattack that was disruptive and – somewhat unusually – also playful.

See Also: Live Webinar | Improve Cloud Threat Detection and Response using the MITRE ATT&CK Framework


The attack caused train services to be disrupted as well as the transport ministry’s website to go down, Reuters reported.


But the attack wasn’t just designed for disruption. Attackers also programmed screens at train stations to show a number for travelers to call for more information about the problems.



The phone number, 64411, is for the office of Iran’s supreme leader, Ali Khamenei. In other words, as noted by Juan Andres Guerrero-Saade, a threat researcher at security firm…

Source…