{"id":2224,"date":"2022-03-01T17:51:37","date_gmt":"2022-03-02T00:51:37","guid":{"rendered":"https:\/\/wpsites.ucalgary.ca\/isec-601-f21\/?p=2224"},"modified":"2022-03-01T17:55:08","modified_gmt":"2022-03-02T00:55:08","slug":"in-the-wake-of-ukraine-russia-cyberwar-muddywater-an-iran-backed-hacking-group-has-been-waging-global-cyber-attacks","status":"publish","type":"post","link":"https:\/\/wpsites.ucalgary.ca\/isec-601-f21\/2022\/03\/01\/in-the-wake-of-ukraine-russia-cyberwar-muddywater-an-iran-backed-hacking-group-has-been-waging-global-cyber-attacks\/","title":{"rendered":"In the wake of Ukraine-Russia Cyberwar, &#8216;MuddyWater,&#8217; an Iran-backed hacking group,\u00a0has been waging global cyber-attacks"},"content":{"rendered":"\n<p>With the world&#8217;s attention focused on Russia&#8217;s multifaceted onslaught on Ukraine, Iranian hackers associated with the country&#8217;s military intelligence initiated a worldwide cyber espionage operation, the United States and the United Kingdom said in an unprecedented alert delivered over the weekend.<\/p>\n\n\n\n<p>With the&nbsp;Russian invasion under way, digital intrusions and denial-of-service (DDoS) assaults caused havoc on Ukraine. DDoS attacks occur when a hostile cyber threat actor stops authorised users from accessing computer networks, devices, or other data centers.<\/p>\n\n\n\n<p>Russian military-linked hackers were responsible for a series of DDoS attacks last week that momentarily brought down Ukrainian banking and government websites prior to the Russian invasion. Later, in retaliation to the cyber threats, Ukraine has been looking for volunteer hackers to create an &#8216;IT army&#8217; to&nbsp;execute cyber&nbsp;operations against Russian entities such as corporations, banks, and government agencies.<\/p>\n\n\n\n<p>However, in the midst of their continuous electronic cyber-war, warnings have been sent out\u00a0against the Iran-linked hacker organisation, <strong>MuddyWater<\/strong>.<\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-large\"><img decoding=\"async\" data-src=\"https:\/\/www.thenationalnews.com\/resizer\/KVCwVWqy4H7UUwbkRDIPmWbc0ug=\/arc-photo-thenational\/eu-central-1-prod\/public\/PLQPHMLSKBGLXOW73VF75UFAY4.jpg\" alt=\"\" src=\"data:image\/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==\" class=\"lazyload\" \/><figcaption><a href=\"https:\/\/www.thenationalnews.com\/mena\/iran\/2022\/02\/25\/iran-linked-muddywater-group-carrying-out-cyber-attacks-worldwide-says-us\/\">The Iran-linked cyber operations group, dubbed MuddyWater, is targeting government and private-sector organisations across sectors in Asia, Africa, Europe and North America.<\/a><\/figcaption><\/figure><\/div>\n\n\n\n<h4 class=\"wp-block-heading\" style=\"font-style:normal;font-weight:500\"><strong>Who are they?<\/strong><\/h4>\n\n\n\n<p>According to US Cyber Command, this hacking group has been acting in the interests of Iran&#8217;s Intelligence and Security Ministry and the Iranian Revolutionary Guard Corps. &#8216;MuddyWater&#8217;, sometimes referred to as SeedWorm, has been functioning under several aliases since at least 2015, targeting victims from Israel, Saudi Arabia, Jordan, the United Arab Emirates, and other Asian nations.<\/p>\n\n\n\n<p>An analytical study reported that the hacker gang undertakes cyber espionage and other hostile cyber activities against a variety of state and corporate entities in areas such as communications, defence, local governments, and oil and gas.<\/p>\n\n\n\n<p><\/p>\n\n\n\n<h4 class=\"wp-block-heading\">What they can do.<\/h4>\n\n\n\n<p>The warning indicates that&nbsp;the organisation specialises in gaining unauthorised access to IT systems and deploying malware by exploiting publicly publicised flaws and open-source technologies. MuddyWater actors are well-positioned to both,&nbsp;give intercepted data and access to the Iranian government and to share this information with other hostile cyber actors.<\/p>\n\n\n\n<p>According to the advisory, MuddyWater has implemented a new Python back channel termed Small Sieve that focuses on providing its users with &#8220;basic functionality required to maintain and expand a foothold in victim infrastructure and avoid detection by using custom string and traffic obfuscation schemes in conjunction with the Telegram Bot application programming interface (API).&#8221;<\/p>\n\n\n\n<p>The authorities also stated that the group used a variety of viruses, like PowGoop, to execute second-stage invasions on previously compromised networks and systems, allowing it to extract information and get remote access.<\/p>\n\n\n\n<p><\/p>\n\n\n\n<h4 class=\"wp-block-heading\">Why is the advisory crucial?<\/h4>\n\n\n\n<p>The MuddyWater threat comes&nbsp;particularly at a time when Iran has expressed opposition to the conflict in Ukraine but has also stated that it will not openly denounce Russia&#8217;s military action, rather condemned&nbsp;NATO&#8217;s influence in the region on the West.<\/p>\n\n\n\n<p>Iran&#8217;s Foreign Minister Hossein Amirabdollahian stated in a tweet that Iran does not view violence as a means and has urged for an immediate cease-fire as well as a &#8220;political and democratic settlement,&#8221; without using terminology like &#8220;invasion.&#8221;<\/p>\n\n\n\n<p>Iran&#8217;s relations with Russia have gotten stronger in past few years, owing mostly to disagreements with the West on matters such as the nuclear program. Furthermore, the Iranian president paid a two-day visit to Moscow in January, throughout which both he and Putin pledged admiration for deeper relations.<\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-large is-resized\"><img decoding=\"async\" data-src=\"https:\/\/static01.nyt.com\/images\/2022\/01\/19\/world\/19iran-russia\/19iran-russia-superJumbo.jpg?quality=75&amp;auto=webp\" alt=\"\" width=\"810\" height=\"539\" src=\"data:image\/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==\" class=\"lazyload\" style=\"--smush-placeholder-width: 810px; --smush-placeholder-aspect-ratio: 810\/539;\" \/><figcaption><a href=\"https:\/\/www.nytimes.com\/2022\/01\/19\/world\/europe\/russia-iran-unity-us.html\">A photograph released by Russian state media shows Vladimir V. Putin, left, and President Ebrahim Raisi of Iran at a meeting, when the Iranian President visited Moscow in January 2022.<\/a><\/figcaption><\/figure><\/div>\n\n\n\n<h4 class=\"wp-block-heading\">References<\/h4>\n\n\n\n<ul class=\"wp-block-list\"><li><a href=\"https:\/\/therecord.media\/iran-linked-muddywater-carrying-out-digital-attacks-worldwide-u-s-warns\/\">https:\/\/therecord.media\/iran-linked-muddywater-carrying-out-digital-attacks-worldwide-u-s-warns\/<\/a><\/li><li><a href=\"https:\/\/www.nextgov.com\/cybersecurity\/2022\/02\/iran-linked-hackers-conducting-operations-against-government-networks-intel-agencies-warn\/362391\/\">https:\/\/www.nextgov.com\/cybersecurity\/2022\/02\/iran-linked-hackers-conducting-operations-against-government-networks-intel-agencies-warn\/362391\/<\/a><\/li><li><a href=\"https:\/\/thehackernews.com\/2022\/02\/iranian-hackers-using-new-spying.html\">https:\/\/thehackernews.com\/2022\/02\/iranian-hackers-using-new-spying.html<\/a><\/li><li><a href=\"https:\/\/www.haaretz.com\/israel-news\/tech-news\/.premium-in-shadow-of-ukraine-russia-cyberwar-iranian-hackers-go-on-the-offensive-1.10638690\">https:\/\/www.haaretz.com\/israel-news\/tech-news\/.premium-in-shadow-of-ukraine-russia-cyberwar-iranian-hackers-go-on-the-offensive-1.10638690<\/a><\/li><li><a href=\"https:\/\/www.thenationalnews.com\/mena\/iran\/2022\/02\/25\/iran-linked-muddywater-group-carrying-out-cyber-attacks-worldwide-says-us\/\">https:\/\/www.thenationalnews.com\/mena\/iran\/2022\/02\/25\/iran-linked-muddywater-group-carrying-out-cyber-attacks-worldwide-says-us\/<\/a><\/li><li><a href=\"https:\/\/www.nytimes.com\/2022\/01\/19\/world\/europe\/russia-iran-unity-us.html\">https:\/\/www.nytimes.com\/2022\/01\/19\/world\/europe\/russia-iran-unity-us.html<\/a><\/li><\/ul>\n\n\n\n<p><\/p>\n","protected":false},"excerpt":{"rendered":"<p>With the world&#8217;s attention focused on Russia&#8217;s multifaceted onslaught on Ukraine, Iranian hackers associated with the country&#8217;s military intelligence initiated a worldwide cyber espionage operation, the United States and the United Kingdom said in an unprecedented alert delivered over the weekend. With the&nbsp;Russian invasion under way, digital intrusions and denial-of-service (DDoS) assaults caused havoc on &hellip; <\/p>\n<p class=\"link-more\"><a href=\"https:\/\/wpsites.ucalgary.ca\/isec-601-f21\/2022\/03\/01\/in-the-wake-of-ukraine-russia-cyberwar-muddywater-an-iran-backed-hacking-group-has-been-waging-global-cyber-attacks\/\" class=\"more-link\">Continue reading<span class=\"screen-reader-text\"> &#8220;In the wake of Ukraine-Russia Cyberwar, &#8216;MuddyWater,&#8217; an Iran-backed hacking group,\u00a0has been waging global cyber-attacks&#8221;<\/span><\/a><\/p>\n","protected":false},"author":416,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"ngg_post_thumbnail":0,"footnotes":""},"categories":[15],"tags":[16,41,39,40],"class_list":["post-2224","post","type-post","status-publish","format-standard","hentry","category-cpsc-329-602-w22","tag-cpsc329","tag-ddos","tag-russia","tag-ukraine","entry"],"featured_image_src":null,"featured_image_src_square":null,"author_info":{"display_name":"Chirag Asrani","author_link":"https:\/\/wpsites.ucalgary.ca\/isec-601-f21\/author\/chirag-asrani\/"},"_links":{"self":[{"href":"https:\/\/wpsites.ucalgary.ca\/isec-601-f21\/wp-json\/wp\/v2\/posts\/2224","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/wpsites.ucalgary.ca\/isec-601-f21\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/wpsites.ucalgary.ca\/isec-601-f21\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/wpsites.ucalgary.ca\/isec-601-f21\/wp-json\/wp\/v2\/users\/416"}],"replies":[{"embeddable":true,"href":"https:\/\/wpsites.ucalgary.ca\/isec-601-f21\/wp-json\/wp\/v2\/comments?post=2224"}],"version-history":[{"count":6,"href":"https:\/\/wpsites.ucalgary.ca\/isec-601-f21\/wp-json\/wp\/v2\/posts\/2224\/revisions"}],"predecessor-version":[{"id":2231,"href":"https:\/\/wpsites.ucalgary.ca\/isec-601-f21\/wp-json\/wp\/v2\/posts\/2224\/revisions\/2231"}],"wp:attachment":[{"href":"https:\/\/wpsites.ucalgary.ca\/isec-601-f21\/wp-json\/wp\/v2\/media?parent=2224"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/wpsites.ucalgary.ca\/isec-601-f21\/wp-json\/wp\/v2\/categories?post=2224"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/wpsites.ucalgary.ca\/isec-601-f21\/wp-json\/wp\/v2\/tags?post=2224"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}