7 Dec 2014

Iranian Operation Cleaver hackers hit 50 organisations in 16 countries


Iranian hackers have broken into the networks of 50 governments and critical infrastructure firms in 16 nations in the latest major threat to come to light.
A report from security company Cylance details evidence that hackers from Iran have been hitting targets in countries including the UK, the US, Canada, Germany and South Korea from as far back as 2010.
Cylance said that it tracked the source of the attacks to a hacker team named Tarh Andishan in Tehran.
The firm has labelled the campaign Operation Cleaver, warning that those behind the hacks have avoided detection for several years by using advanced evasion techniques.
Cylance said that the group used publicly available and customised tools to attack and compromise targets around the globe.
The targets included military, oil and gas, energy and utilities, transport, telecoms, technology, aerospace, defence contractors, chemical, companies and governments.
Cylance gave some more details on those affected, such as San Diego’s Navy Marine Corp Intranet and a company "specialising in natural gas production", along with "electric utilities organisations" and a number of oil and gas providers.
The fact that the attackers hit such high-profile targets without being uncovered forced Cylance to reveal that it was tracking their work in order to raise awareness of the threat.
"Due to the choice of critical infrastructure victims and the Iranian team’s quickly improving skillset, we are compelled to publish this report," said Stuart McClure, CEO of Cylance.
"By exposing our intelligence on Cleaver, we hope the information we share can reveal the techniques and tools of this group, drawing global attention to attacks on critical infrastructure and preventing attacks which could endanger human lives."
Iran's development of such sophisticated cyber attack tools is significant, according to Cylance, given that only a few years only the country was limited to basic techniques such as website defacement and distributed denial of service attacks.
Souces:
http://www.v3.co.uk/v3-uk/news/2384729/iranian-operation-cleaver-hackers-hit-50-organisations-in-16-countries
http://www.cylance.com/operation-cleaver/


Report:http://www.cylance.com/assets/Cleaver/Cylance_Operation_Cleaver_Report.pdf