

Microsoft disrupts Iranian-linked hackers targeting organizations in Israel
source link: https://finance.yahoo.com/news/microsoft-disrupts-iran-linked-hackers-161158362.html
Go to the source link to view the article. You can view the picture content, updated content and better typesetting reading experience. If the link is broken, please click the button below to view the snapshot at that time.

Microsoft disrupts Iranian-linked hackers targeting organizations in Israel
Microsoft said on Thursday that it has successfully "identified and disabled" a previously unreported Lebanon-based hacking group that it believes is working with Iranian intelligence.
The hacking group, tracked by the Microsoft Threat Intelligence Center (MSTIC) as “Polonium,” targeted or compromised more than 20 organizations based in Israel and one intergovernmental organization with operations in Lebanon over the past three months, with a focus on critical manufacturing, IT and Israel’s defense industry. In one case a cloud services provider “was used to target a downstream aviation company and law firm in a supply chain attack," Microsoft said in a blog post.
It added that Polonium operators have also targeted multiple victims compromised by the MuddyWater APT group, tracked by Microsoft as Mercury, which U.S. Cyber Command earlier this year linked to Iranian intelligence.
The previously unknown hacking group created legitimate Microsoft OneDrive accounts and then utilized those accounts as command and control (C2) to execute part of their attack operation. The observed activity was not related to any security issues or vulnerabilities within OneDrive, the Microsoft researchers wrote.
MSTIC said it determined with high confidence the group behind the attacks is based in Lebanon, adding that they were "moderately" confident that Polonium was collaborating with Iran’s Ministry of Intelligence and Security (MOIS).
“The uniqueness of the victim organizations suggests a convergence of mission requirements with MOIS,” Microsoft said. “It may also be evidence of a ‘hand-off’ operational model where MOIS provides Polonium with access to previously compromised victim environments to execute new activity.”
Microsoft says it successfully suspended more than 20 malicious OneDrive applications created by the Polonium threat actors. The company added that it has also notified affected organizations and deployed a series of security intelligence updates that will quarantine tools developed by the Iranian-linked hackers.
It’s still unclear how the attackers gained initial access to their victims’ networks, but Microsoft notes roughly 80% of compromised organizations were running Fortinet appliances, which “suggests, but does not definitively prove” that the Polonium compromised the Fortinet using a three-year-old vulnerability identified as CVE-2018-13379.
Microsoft’s action comes just months after the U.S. government, along with counterparts in Australia and the U.K., warned that Iranian state-backed hackers are targeting U.S. organizations in critical infrastructure sectors — in some cases with ransomware. The advisory said that Iranian-backed hackers accessed a web server hosting the domain for a U.S. municipal government in May last year, before accessing the networks of a U.S.-based hospital specializing in healthcare for children the following month.
Recommend
-
9
Possible breach of sovereignty following websites seizure The Justice Department announced Tuesday the seizure of several Iran's state-linked news website domains accusing them of propagating disinf...
-
1
The 14-Year-Old Who Founded Girls Who Hack Is Inspiring the Next Generation of Hackers“Women aren't really taken as seriously in the cybersecurity field, and I've noticed that with most of my girlfriends, they...
-
8
National SecurityU.S. indicts two Iranian hackers over 2020 election disinformation campaignVoters participate in early vot...
-
8
FBI warns that North Korean hackers are targeting US healthcare organizations with ransomware attacks It's been happening for over a year now By
-
3
Get WIRED for just $29.99 $10. Subscribe Now...
-
9
State-backed Iranian hackers spread malware through links to fake VPN apps By Chiara Castro
-
9
Iranian Hackers Used Victims’ Printers to Issue Ransom Demands, DOJ SaysProsecutors have identified three Iranian nationals and accused them of being behind a series of ransomware attacks in the U.S., and around the...
-
7
Iranian hackers breach Federal Civilian Executive Branch using Log4Shell vulnerability
-
5
News Chinese hackers targeted Iranian government entities for months: Report The...
-
5
TechMeta says it has disrupted a massive disinformation campaign linked to Chinese l...
About Joyk
Aggregate valuable and interesting links.
Joyk means Joy of geeK