Iranian hackers might target US energy, defence firms, warns FBI

FBI's confidential 'Flash' report provides technical details about malicious software and techniques used in the attacks, along with advice on thwarting the hackers

Image
Reuters Boston
Last Updated : Dec 15 2014 | 12:53 AM IST
The Federal Bureau of Investigation (FBI) has warned US businesses to be on the alert for a sophisticated Iranian hacking operation whose targets include defence contractors, energy firms and educational institutions, according to a confidential agency document.

The operation is the same as one flagged last week by cyber security firm Cylance Inc as targeting critical infrastructure organisations worldwide, cyber security experts said. Cylance has said it uncovered more than 50 victims from what it dubbed Operation Cleaver, in 16 countries, including the United States.

The FBI's confidential "Flash" report, seen by Reuters on Friday, provides technical details about malicious software and techniques used in the attacks, along with advice on thwarting the hackers. It asked businesses to contact the FBI if they believed they were victims.

Cylance Chief Executive Stuart McClure said the FBI warning suggested that the Iranian hacking campaign may have been larger than its own research revealed. "It underscores Iran's determination and fixation on large-scale compromise of critical infrastructure," he said.

The FBI's technical document said the hackers typically launch their attacks from two IP addresses that are in Iran, but did not attribute the attacks to the Tehran government. Cylance has said it believes Iran's government is behind the campaign, a claim Iran has vehemently denied.

An FBI official did not provide further details, but said the agency routinely provides private industry with advisories to help it fend off cyber threats.

The Pentagon and National Security Agency had no immediate comment.

Tehran has been substantially increasing investment in its cyber capabilities since 2010, when its nuclear program was hit by the Stuxnet computer virus, widely believed to have been launched by the United States and Israel. Cyber security professionals who investigate cyber attacks said that they are seeing evidence that Iran's investment is paying off.

"They are good and have a lot of talent in the country," said Dave Kennedy, CEO of TrustedSEC LLC. "They are definitely a serious threat, no question."

Iranian hackers are increasingly being blamed for sophisticated cyberattacks. Bloomberg Businessweek on Thursday reported that Iranian hacker activists were responsible for a devastating February 2014 attack on casino operator Las Vegas Sands Corp, which crippled thousands of servers by wiping them with destructive malware. It said the hackers sought to punish Sands CEO Sheldon Adelson for comments he made about detonating a nuclear bomb in Iran.
*Subscribe to Business Standard digital and get complimentary access to The New York Times

Smart Quarterly

₹900

3 Months

₹300/Month

SAVE 25%

Smart Essential

₹2,700

1 Year

₹225/Month

SAVE 46%
*Complimentary New York Times access for the 2nd year will be given after 12 months

Super Saver

₹3,900

2 Years

₹162/Month

Subscribe

Renews automatically, cancel anytime

Here’s what’s included in our digital subscription plans

Exclusive premium stories online

  • Over 30 premium stories daily, handpicked by our editors

Complimentary Access to The New York Times

  • News, Games, Cooking, Audio, Wirecutter & The Athletic

Business Standard Epaper

  • Digital replica of our daily newspaper — with options to read, save, and share

Curated Newsletters

  • Insights on markets, finance, politics, tech, and more delivered to your inbox

Market Analysis & Investment Insights

  • In-depth market analysis & insights with access to The Smart Investor

Archives

  • Repository of articles and publications dating back to 1997

Ad-free Reading

  • Uninterrupted reading experience with no advertisements

Seamless Access Across All Devices

  • Access Business Standard across devices — mobile, tablet, or PC, via web or app

More From This Section

First Published: Dec 15 2014 | 12:06 AM IST

Next Story