Joint UK and US probe finds that a Russian cyber espionage unit hacked the tools of a hacker group linked to Iran's government to lead attacks in 35+ countries
A Russian cyber espionage unit has hacked Iranian hackers to lead attacks in more than 35 countries, a joint UK and US investigation has revealed.
Related Coverage
- Advisory: Turla group exploits Iranian APT to expand coverage of victims National Cyber Security Centre
- Russian hackers disguised cyber attacks using Iranian spying gang Telegraph · James Cook
- NSA And NCSC Warning: Russian Hackers Disguised As Iranian Spies Attacked 35 Countries Forbes · Kate O'Flaherty
- Russian hacking group masquerades as Iranian spy network IT PRO · Keumars Afifi-Sabet
- The Cybersecurity 202: Russia's false flags in Winter Olympics cyberattack herald a more complicated future Reuters · Joseph Marks
- Russian hackers cloak attacks using Iranian group BBC · Gordon Corera
- Russian APT Turla targets 35 countries on the back of Iranian infrastructure ZDNet · Charlie Osborne
- Iran? More like Ivan: Brit and US spies say they can see through Turla hacking group's facade The Register · John Oates
- US: Russian hackers use Iranians to mask their identities Associated Press
- Russia used Iranian hacker infrastructure and tools for espionage Axios · Joe Uchill
- US, UK: Russian Hackers Hijacked Iranian Malware, Infrastructure SecurityWeek · Eduard Kovacs
Discussion
-
@ericgeller
Eric Geller
on x
NSA and GCHQ publish report on Russian hackers' use of Iranian tools: https://www.ncsc.gov.uk/... https://twitter.com/...
-
@thecybersecexp
Robert Pritchard
on x
This is interesting for a number of reasons but if you're unfamiliar with terminology it's a bit hard to read. In short, it details how Russian state hackers piggy backed on Iranian state hacking group successes, and stole and reused their hacking tools. https://twitter.com/...
-
@marietjeschaake
Marietje Schaake
on x
Hackers hacked, and Russians pretending to be Iranians, presumably to avoid accountability. That is what deserves more attention, how to make sure attacks in cyberspace have consequences ↘️ https://www.ft.com/...
-
@zachsdorfman
Zach Dorfman
on x
“Mr Chichester described how Turla began ‘piggybacking’ on Oilrig's attacks by monitoring an Iranian hack closely enough to use the same backdoor route into an organisation or to gain access to the resulting intelligence. Turla is also known as Waterbug or Venomous Bear.”
-
@zachsdorfman
Zach Dorfman
on x
“But the Russian group then progressed to initiating their own attacks using Oilrig's command-and-control infrastructure and software. Organisations in approximately 20 countries were successfully hacked in this way.”
-
@zachsdorfman
Zach Dorfman
on x
Also! bonus points for GCHQ and NSA on this disclosure: create discord between two of your primary adversaries and also perhaps send Iran into a destructive, paranoid counterintelligence spiral
-
@financialtimes
@financialtimes
on x
A Russian cyber espionage unit has hijacked Iranian hackers to lead attacks in more than 35 countries, according to a two-year probe by the UK's National Cyber Security Centre and US National Security Agency https://www.ft.com/...
-
@zachsdorfman
Zach Dorfman
on x
This is a pretty incredible disclosure from GCHQ—and a window into both Russian prowess and a future where assigning attribution is going to become more fraught. https://www.ft.com/...
-
@zachsdorfman
Zach Dorfman
on x
Russian state hackers utterly owned Oilrig. Honestly, if it's true the Iranians didn't know, it's brilliant work on the Russians' part. Formidable.
-
@ncsc
Ncsc Uk
on x
A joint report from the NCSC and @NSAGov exposing Turla group activity https://www.ncsc.gov.uk/... https://twitter.com/...
-
@elliegeranmayeh
Ellie Geranmayeh
on x
UK claims “Russian hacking group dubbed “Turla”, which has been linked to Russia's FSB agency, hacked into Iranian servers to mask attacks against more than 35 different countries [mostly in the Middle East] over the last 18 months”. https://www.telegraph.co.uk/ ...