Researchers uncover ‘ambitious’ Iranian hacker group that targets the Middle East
July 26, 2018 1 Comment
An American cyber security firm has reported the discovery of a previously undetected, “highly active” Iranian cyber espionage group, whose extensive target list consists mainly of large organizations and companies in the Middle East. The cyber security firm Symantec, makers of Norton antivirus software, which uncovered the cyber espionage group’s existence, has dubbed it “Leafminer”. It said the group has been active since the beginning of 2017, but has “significantly ramped up its activities” in 2018 and is currently involved in dozens of ongoing attacks.
In a report published on Wednesday, Symantec said that its security experts managed to obtain what appears to be Leafminer’s master list of targets. The list is written in the Farsi language and contains just over 800 organizations, which according to Symantec researchers is “an ambitious goal” for any cyber espionage group. The organizations listed on the target sheet come from a variety of sectors, including government, transportation, the financial sector, energy and telecommunications. But the majority of the group’s targets appear to be in the petrochemical and government sectors. Additionally, virtually all of Leafminer’s targets are located in the Middle East and North Africa, in countries such as Israel, Egypt, Bahrain, Qatar, Kuwait and the United Arab Emirates. Some of the group’s targets are located in Afghanistan and Azerbaijan.
Symantec said its researchers observed the Leafminer hackers execute attacks in real time on at least 40 targets in the Middle East, including on the website of an intelligence agency in Lebanon. According to the cyber security company, Leafminer uses a variety of hacking tools, including custom-designed malware and some publicly available software. The group’s operational sophistication is also varied, and ranges from complex, multilayered attacks to brute-force login attempts. Symantec said it concluded that the cyber espionage group originates from Iran because its master target list is written in Farsi and because Iran is virtually the only country in the Middle East that is missing from the target list. However, it said that it did not have sufficient evidence to link Leafminer to the Iranian government. In a separate development, Germany’s domestic intelligence agency, the Federal Office for the Protection of the Constitution (BfV), said this week in its annual report that the government of Iran has significantly expanded its cyber warfare capabilities and “poses a danger to German companies and research institutions”.
► Author: Joseph Fitsanakis | Date: 26 July 2018 | Permalink
Iranian military officials have warned of extracting “revenge from foreign intelligence services”, as Reuters reported that an aggressive campaign against Tehran has been launched by Washington. On Sunday, the Reuters news agency said that senior officials in the administration of US President Donald Trump had launched a concerted offensive “meant to foment unrest” in the Islamic Republic.
Israel helped foil an alleged Iranian-sponsored bomb attack in Paris, which involved arrests of several Iranian agents and at least one diplomat in France, Belgium and Germany, according to media reports. As intelNews
Intelligence directors from Russia, China, Iran and Pakistan met on Tuesday to discuss regional cooperation with particular reference to combating the Islamic State in Afghanistan. Information about the high-level meeting was
Holland has expelled two Iranian diplomats without saying why, leading to speculation that the expulsions may be related to the arrests of members of an alleged Iranian sleeper cell in Belgium, Germany and France last week. On Friday, a spokesperson from Holland’s General Intelligence and Security Service (AIVD)
An Iranian diplomat and members of what authorities described as an “Iranian sleeper cell” were arrested this week in Belgium, Germany and France, as they were allegedly planning to a bomb a high-level meeting in Paris. The arrests came after a complex investigation by several European intelligence agencies and were announced by Belgium’s Minister of the Interior, Jan Jambon.
Israel has charged Gonen Segev, who served as the Jewish state’s Minister of Energy and Infrastructure, with spying for its archenemy, Iran. Segev, 62, was reportedly detained last month during a trip to Equatorial Guinea following a request by Israeli officials. He was then extradited to Israel and arrested as soon as he arrived in Tel Aviv last month, according to a statement by the Shin Bet, Israel’s domestic security service. On Monday it emerged that Israeli authorities had imposed a gag order on the case, forbidding Israeli media from reporting any information about it. The order appears to have now been lifted.
A lengthy exposé by a leading American newsmagazine has claimed that Israel and the United Arab Emirates, two countries that officially have no relations, have been secretly collaborating for more than two decades. Their secret cooperation has been extremely tight and has included clandestine weapons sales and intelligence-sharing, according to the exposé, which was published on the website of The New Yorker on Monday and will feature in the magazine’s print edition on June 18. The lengthy piece, which deals with the changing geopolitics of the Middle East, is written by Adam Entous, national security correspondent for The Washington Post, who has previously reported for more than two decades for Reuters and The Wall Street Journal.
The government of Sweden has granted citizenship to an academic who is on death row in Iran for allegedly helping Israel kill Iranian nuclear scientists. Sweden’s Foreign Affairs Ministry confirmed on Saturday that Ahmadreza Djalali, who lives in Sweden and has lectured at Stockholm’s renowned Karolinska Institute, is now a Swedish citizen. IntelNews has
The former chief of staff of Iran’s Armed Forces has said that foreign governments used different species of lizards, including chameleons, to spy on the Iranian nuclear program. The claim was made by Hassan Firuzabadi, a veteran Iranian military official, who from 1989 to 2016 served as the chief of staff of the Iranian Armed Forces —the most senior military post in the Islamic Republic. Since his retirement in 2016, Firuzabadi has served in a number of key consultancy roles and is currently a senior military advisor to Ayatollah Ali Khamenei, Iran’s reform-minded supreme leader.
A cyber espionage group that has alarmed security researchers by its careful targeting of government agencies has links to the Iranian state, according to a new report. The existence of the group calling itself CopyKittens was first confirmed publicly in November of 2015. Since that time, forensic analyses of cyber attacks against various targets have indicated that the group has been active since at least early 2013. During that time, CopyKittens has carefully targeted agencies or officials working for Jordan, Saudi Arabia, Turkey, Israel, the United States, and Germany, among other countries. It has also targeted specific offices and officials working for the United Nations.
A contractor for the United States Central Intelligence Agency has complained in an interview that no action has been taken in the seven years since he revealed a “billion-dollar fraud” and “catastrophic intelligence failure” within the Agency’s ranks. John Reidy argues that his case illustrates the unreasonable delay that impedes investigations by whistleblowers like him inside the CIA. Individuals like him, he argues, are forced to seek justice through leaks to the media, something which could be avoided if the CIA’s Office of the Inspector General addressed concerns more promptly.






US announces arrest of two men charged with spying for Iran
August 21, 2018 by Joseph Fitsanakis 2 Comments
According to the US government, the men were observed “conducting surveillance of political opponents and engaging in other activities that could put Americans at risk”. The press statement alleges that Doostdar carried out surveillance of a Jewish center in Chicago, while Ghorbani attended meetings and rallies organized by Iranian opposition groups operating in the US. The press release identifies one such group as the Mujahideen-e Khalq (MEK), a militant faction that has roots in radical Islam and Marxism. Between 1970 and 1976, the group assassinated six American officials in Iran and in 1970 tried to kill the United States ambassador to the country. It initially supported the Islamic Revolution of 1979, but later withdrew its support, accusing the government of Ayatollah Khomeini of “fascism”. It continued its operations in exile, mainly from Iraq, where its armed members were trained by the Palestine Liberation Organization and other Arab leftist groups. Until 2009, the European Union and the US officially considered the MEK a terrorist organization. But the group’s sworn hatred against the government in Iran brought it close to Washington after the 2003 US invasion of Iraq. By 2006, the US military was openly collaborating with MEK forces in Iraq, and in 2012 the group was dropped from the US Department of State’s list of foreign terrorist organizations. Today the group enjoys open protection from the EU and the US.
On June 30 of this year, authorities in Belgium arrested a married Belgian couple of Iranian descent, who were found to be carrying explosives and a detonator. On the following day, July 1, German police arrested an Iranian diplomat stationed in Iran’s embassy in Vienna, Austria, while a fourth person was arrested by authorities in France, reportedly in connection with the three other arrests. All four individuals were charged with having planned a foiled plot to bomb the annual conference of the MEK-affiliated National Council of Resistance of Iran (NCRI) that took place on June 30 in Paris, France. It is not known whether the arrests in Europe are in any way connected with the cases of the two men held in the US.
Filed under Expert news and commentary on intelligence, espionage, spies and spying Tagged with Ahmadreza Mohammadi Doostdar, espionage, Iran, Majid Ghorbani, Mujahedeen-e Khalq, News, United States