{"id":2334,"date":"2024-01-10T15:00:00","date_gmt":"2024-01-10T15:00:00","guid":{"rendered":"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/who-is-behind-pro-ukrainian-cyberattacks-iran"},"modified":"2024-01-10T15:00:00","modified_gmt":"2024-01-10T15:00:00","slug":"who-is-behind-pro-ukrainian-cyberattacks-on-iran","status":"publish","type":"post","link":"https:\/\/ddi.mohflo.net\/index.php\/2024\/01\/10\/who-is-behind-pro-ukrainian-cyberattacks-on-iran\/","title":{"rendered":"Who Is Behind Pro-Ukrainian Cyberattacks on Iran?"},"content":{"rendered":"<div class=\"media_block\"><a href=\"https:\/\/i0.wp.com\/eu-images.contentstack.com\/v3\/assets\/blt6d90778a997de1cd\/blteb35faa257ac5836\/659dc6489de123040ae835ac\/Ukraine_Iran_Daniren_Alamy.jpg?ssl=1\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/01\/who-is-behind-pro-ukrainian-cyberattacks-on-iran.jpg?w=640&#038;ssl=1\" class=\"media_thumbnail\"><\/a><\/div>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><span class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_bold\">COMMENTARY<\/span><\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Ukrainian cyber forces have attacked Russian infrastructure and assets almost since the first day of the Russian invasion of Ukraine on Feb. 24, 2022. A now well-oiled machine, the &#8220;IT Army of Ukraine&#8221; (as it is known) works alongside the main cyber directorate of Ukraine, SSSCIP, on the offensive aspects of the cyber conflict. While its mainstay is denial-of-service (DoS) attacks that have knocked out the <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a href=\"https:\/\/twitter.com\/ITArmyUKR\/status\/1630996840316379136\" target=\"_blank\" class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" rel=\"noopener\">Russian customs system<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> and <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a href=\"https:\/\/techmonitor.ai\/technology\/cybersecurity\/russia-cyberattack-flights-grounded-airlines-ddos-ukraine\" target=\"_blank\" class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" rel=\"noopener\">grounded flights at Russian airports<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, among other things, it doesn&#8217;t shy away from breaching Russian assets and making off with huge amounts of data.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Other hacktivist groups have also planted their flag firmly on the Ukrainian side. These include Anonymous, whose main anti-Russian activities fall under the operation #OpRussia. Smaller groups have also supported Ukraine, such as <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a href=\"https:\/\/twitter.com\/xxNB65\" target=\"_blank\" class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" rel=\"noopener\">Network Battalion 65<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> (which ceased operating in August 2022) and <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a href=\"https:\/\/twitter.com\/Nebula00x\" target=\"_blank\" class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" rel=\"noopener\">Nebula<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, a newer player on the scene that became active in May 2023. Regardless of their origin, they share one thing in common: attacking only Russian or Belarusian assets. Well, at least until recently.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\">Nebula Hits an Unexpected Target<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">On Oct. 28, Nebula posted screenshots of its breach of Raykasoft, an Iranian company specializing in medical software. While the breach isn&#8217;t sophisticated \u2014 the group somehow obtained root and is deleting backups and file systems with &#8220;rm -rf &#8211;no-preserve-root&#8221; \u2014 the message they left, which directly references Iran, is unusual. The message begins:<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;<\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><span class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_italic\">Iran, you&#8217;ve overstepped your bounds and you&#8217;re getting involved in conflicts that do not concern you. As a result, we&#8217;ve dropped medical databases containing over 10TB worth of data between several critical servers. We&#8217;ve also destroyed these servers as well. Raykasoft has proved they can&#8217;t secure medical data.&#8221;<\/span><\/span><\/p>\n<div readability=\"7\"><img data-recalc-dims=\"1\" decoding=\"async\" data-testid=\"content-image\" data-component=\"image\" class=\"ContentImage-Image ContentImage-Image_align_left\" data-src=\"https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2024\/01\/who-is-behind-pro-ukrainian-cyberattacks-on-iran.png\" src=\"https:\/\/i0.wp.com\/eu-images.contentstack.com\/v3\/assets\/blt6d90778a997de1cd\/blt01079d5ea73e975a\/659d8adf984e23040a4188b0\/Nebula-statement.PNG?w=640&#038;ssl=1\" loading=\"lazy\" alt=\"Nebula statement on Raykasoft hack\" title=\"Nebula statement on Raykasoft hack\"><\/p>\n<p class=\"ContentImage-Link\">Full statement on the Raykasoft hack by Nebula.<\/p>\n<\/div>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Attacks against non-Russian owned assets by Ukrainian hackers have happened during the conflict, but they are rare. The IT Army of Ukraine has made it a point to target only Russian and Belarusian assets, no doubt to avoid upsetting Western backers that are providing significant military aid. Some Western companies still doing business in Russia are anecdotally targeted, but this has been attributed more often to Anonymous rather than official Ukrainian cyber forces, whose official stance is to focus on Russia.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The &#8220;conflicts that doesn&#8217;t concern you&#8221; in Nebula&#8217;s message refers to the military support Iran has been providing Russia, mainly <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a href=\"https:\/\/en.wikipedia.org\/wiki\/HESA_Shahed_136\" target=\"_blank\" class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" rel=\"noopener\">Shahed drones<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> that have been raining down on Ukrainian cities for over a year and caused untold suffering for the civilian population.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\">Who Is Nebula?<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">So, who is this group exactly? On Nov. 17, Nebula accidentally leaked one of its operational IP addresses in screenshots of its recent breach of Russian software company Insoft.ru.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">In an almost nightmarish scenario for any infosec professional, the screenshots show a half-dozen <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a href=\"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/new-tool-exposes-stealthy-metasploit-hack\" target=\"_blank\" class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" rel=\"noopener\">Meterpreter shells<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> Nebula has open in Insoft&#8217;s infrastructure. (Meterpreter is a Metasploit payload that can be used to download and upload files, run code, and open a command shell.) The source IP is blocked out \u2026 but not very well.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Looking carefully, it appears the source IP looks like 91.92.246.69 or 91.92.246.89. Scanning both with nmap shows 91.92.246.69 with an open <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a href=\"https:\/\/www.darkreading.com\/threat-intelligence\/how-to-identify-cobalt-strike-on-your-network\" target=\"_blank\" class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" rel=\"noopener\">Cobalt Strike<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> beacon on port 4445 running, so that&#8217;s the likely one. These IPs are owned by LimeNet out of the Netherlands \u2014 but in cyberspace, attribution is a difficult thing, so that means little.<\/span><\/p>\n<div readability=\"7\"><img data-recalc-dims=\"1\" decoding=\"async\" data-testid=\"content-image\" data-component=\"image\" class=\"ContentImage-Image ContentImage-Image_align_left\" data-src=\"https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2024\/01\/who-is-behind-pro-ukrainian-cyberattacks-on-iran-1.png\" src=\"https:\/\/i0.wp.com\/eu-images.contentstack.com\/v3\/assets\/blt6d90778a997de1cd\/blte54aabf41ba703ef\/659d8b43ff2676040adc3617\/Meterpreter-sessions.PNG?w=640&#038;ssl=1\" loading=\"lazy\" alt=\"Meterpreter sessions to Insoft infrastructure\" title=\"Meterpreter sessions to Insoft infrastructure\"><\/p>\n<p class=\"ContentImage-Link\">Meterpreter sessions connecting to the Insoft infrastructure with partially blacked-out source IPs.<\/p>\n<\/div>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">In each hack, the attackers also thank and &#8220;shout out&#8221; many hacker aliases, but they are so generic that they are hard to attribute. (Look up how many security researchers and hackers have the handle <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><span class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_italic\">Raz0r<\/span><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">.) Interestingly, they also use a variation of the Anonymous tagline, &#8220;We are Anonymous. We are Legion. We do not forgive. We do not forget. Expect us<\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><span class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_italic\">,&#8221;<\/span><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> instead opting for &#8220;expecc us. respekk us.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Looking at the evidence, it&#8217;s unlikely that Nebula, while effectively being pro-Ukrainian, is controlled by the SSSCIP or the IT Army of Ukraine. That it would go after a medical target isn&#8217;t aligned with the IT Army of Ukraine&#8217;s philosophy.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">In October, the International Committee of the Red Cross (ICRC) released its <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a href=\"https:\/\/blogs.icrc.org\/law-and-policy\/2023\/10\/04\/8-rules-civilian-hackers-war-4-obligations-states-restrain-them\/\" target=\"_blank\" class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" rel=\"noopener\">rules for cyberwarfare<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> during a conflict, which effectively amounts to avoiding or minimizing harm to civilian targets, sticking to military targets, and avoiding medical-related targets. On its <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a href=\"https:\/\/t.me\/s\/itarmyofukraine2022?q=icrc\" target=\"_blank\" class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" rel=\"noopener\">Telegram channel<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> on Oct. 11, the IT Army of Ukraine responded with a short statement, saying: &#8220;We&#8217;ve intuitively adhered to these rules even before they were introduced, for instance, never attacking healthcare or humanitarian sectors.&#8221; (As a side note, the Russian hacker group Killnet&#8217;s answer to a question about the ICRC rules was, &#8220;Why should we listen to the ICRC?&#8221;)<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Since the Raykasoft hack, Nebula has returned to Russian targets. In the first two weeks of November, it took down Refactor-ICS and Insoft, both Russian IT companies.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Looking at the overall picture, it seems that Nebula, being a pro-Ukrainian splinter entity, has merely been opportunistic in its targeting. It&#8217;s taken advantage of weak infrastructure to fire a warning shot to Iran \u2014 counter to the IT Army of Ukraine&#8217;s current targeting philosophy. While Iranian support of Russia is well known, for now cyber activity against Iranian assets (at least from Ukraine) remains a one-off. We&#8217;ll have to keep an eye on this development to see if it mutates into a more sustained trend against wider Iranian Infrastructure.<\/span><\/p>\n<p><a href=\"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/who-is-behind-pro-ukrainian-cyberattacks-iran\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>COMMENTARY Ukrainian cyber forces have attacked Russian infrastructure and assets<\/p>\n","protected":false},"author":12,"featured_media":2335,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1],"tags":[809],"class_list":["post-2334","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-dark-reading"],"featured_image_urls":{"full":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/01\/who-is-behind-pro-ukrainian-cyberattacks-on-iran.jpg?fit=1800%2C1200&ssl=1",1800,1200,false],"thumbnail":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/01\/who-is-behind-pro-ukrainian-cyberattacks-on-iran.jpg?resize=150%2C150&ssl=1",150,150,true],"medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/01\/who-is-behind-pro-ukrainian-cyberattacks-on-iran.jpg?fit=300%2C200&ssl=1",300,200,true],"medium_large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/01\/who-is-behind-pro-ukrainian-cyberattacks-on-iran.jpg?fit=640%2C427&ssl=1",640,427,true],"large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/01\/who-is-behind-pro-ukrainian-cyberattacks-on-iran.jpg?fit=640%2C427&ssl=1",640,427,true],"1536x1536":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/01\/who-is-behind-pro-ukrainian-cyberattacks-on-iran.jpg?fit=1536%2C1024&ssl=1",1536,1024,true],"2048x2048":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/01\/who-is-behind-pro-ukrainian-cyberattacks-on-iran.jpg?fit=1800%2C1200&ssl=1",1800,1200,true],"chromenews-featured":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/01\/who-is-behind-pro-ukrainian-cyberattacks-on-iran.jpg?fit=1024%2C683&ssl=1",1024,683,true],"chromenews-large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/01\/who-is-behind-pro-ukrainian-cyberattacks-on-iran.jpg?resize=825%2C575&ssl=1",825,575,true],"chromenews-medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/01\/who-is-behind-pro-ukrainian-cyberattacks-on-iran.jpg?resize=590%2C410&ssl=1",590,410,true]},"author_info":{"display_name":"Dark Reading","author_link":"https:\/\/ddi.mohflo.net\/index.php\/author\/darkreading\/"},"category_info":"<a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/uncategorized\/\" rel=\"category tag\">Uncategorized<\/a>","tag_info":"Uncategorized","comment_count":"0","jetpack_featured_media_url":"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/01\/who-is-behind-pro-ukrainian-cyberattacks-on-iran.jpg?fit=1800%2C1200&ssl=1","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/2334","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/comments?post=2334"}],"version-history":[{"count":0,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/2334\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media\/2335"}],"wp:attachment":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media?parent=2334"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/categories?post=2334"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/tags?post=2334"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}