{"id":2440,"date":"2024-01-29T17:31:00","date_gmt":"2024-01-29T17:31:00","guid":{"rendered":"https:\/\/www.darkreading.com\/vulnerabilities-threats\/iran-cyber-centers-dodge-sanctions-sell-cyber-operations"},"modified":"2024-01-29T17:31:00","modified_gmt":"2024-01-29T17:31:00","slug":"irans-cyber-centers-dodge-sanctions-to-sell-cyber-operations","status":"publish","type":"post","link":"https:\/\/ddi.mohflo.net\/index.php\/2024\/01\/29\/irans-cyber-centers-dodge-sanctions-to-sell-cyber-operations\/","title":{"rendered":"Iran&#8217;s &#8216;Cyber Centers&#8217; Dodge Sanctions to Sell Cyber Operations"},"content":{"rendered":"<div class=\"media_block\"><a href=\"https:\/\/i0.wp.com\/eu-images.contentstack.com\/v3\/assets\/blt6d90778a997de1cd\/blt9f8274c817b02845\/65982a332243a0040a326b2e\/GagoDesign_Shutterstock-Syria-cyber-crime.jpg?ssl=1\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/01\/irans-cyber-centers-dodge-sanctions-to-sell-cyber-operations.jpg?w=640&#038;ssl=1\" class=\"media_thumbnail\"><\/a><\/div>\n<div><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/01\/irans-cyber-centers-dodge-sanctions-to-sell-cyber-operations.jpg?w=640&#038;ssl=1\" class=\"ff-og-image-inserted\"><\/div>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Public records combined with documents leaked by Iranian anti-government groups suggest that several Middle Eastern cybersecurity firms are part of complex networks of government officials and cybersecurity specialists that have links to the Iranian Revolutionary Guard Corps.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The contractor firms, such as Emen Net Pasargad and Mahak Rayan Afraz (MRA), are responsible for \u2014 or have contributed to \u2014 attacks on democratic processes in Western countries, the targeting of industrial control systems and critical infrastructure, and compromises at major financial institutions, Recorded Future stated in <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a href=\"https:\/\/www.recordedfuture.com\/leaks-and-revelations-irgc-networks-cyber-companies\" target=\"_blank\" class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" rel=\"noopener\">a recent report<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">In the cybersecurity community, the contractors are suspected to be linked to the activities of the Cotton Sandstorm and<\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a href=\"https:\/\/www.darkreading.com\/threat-intelligence\/imperial-kitten-israeli-industry-multiyear-spy-effort\" target=\"_blank\" class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" rel=\"noopener\"> Imperial Kitten <\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">\u2014 also known as Crimson Sandstorm \u2014 threat actors, respectively.&nbsp;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Overall, the research and leaked data highlights networks of contractors and individuals responsible for cyber operations that constitute &#8220;cyber centers&#8221; that link to Iran&#8217;s military and intelligence organizations, Recorded Future stated in the report.&nbsp;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;The leaks portray a long-standing relationship between intelligence and military organizations and Iran-based contractors,&#8221; the report said. &#8220;Public records point to an ever-growing web of front companies connected via individuals known to serve various branches of the IRGC.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The effort to unmask Iran&#8217;s cyber-operations groups comes as the nation&#8217;s military and intelligence agencies ramp up attacks following Hamas&#8217;s terrorist attack on Israeli civilians and Israel&#8217;s ongoing military operations in Gaza. In December, pro-Iran hackers <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a href=\"https:\/\/www.darkreading.com\/ics-ot-security\/pro-iran-attackers-access-multiple-water-facility-controllers\" target=\"_blank\" class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" rel=\"noopener\">breached multiple water facilities across Western countries<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> using Israeli-made programmable logic controllers and <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a href=\"https:\/\/www.darkreading.com\/ics-ot-security\/iran-threatens-israel-critical-infrastructure-polonium-proxy\" target=\"_blank\" class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" rel=\"noopener\">targeted Israeli critical infrastructure<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">. In mid-December, Israel officials claimed that Iran had breached a hospital, <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a href=\"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/israel-blames-iran-for-hospital-data-breach\" target=\"_blank\" class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" rel=\"noopener\">stealing 500 gigabytes of medical data<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">.&nbsp;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The US had previously <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a href=\"https:\/\/www.darkreading.com\/vulnerabilities-threats\/us-sanctions-iran-apt-cyberattack-activity\" target=\"_blank\" class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" rel=\"noopener\">sanctioned groups connected to Iranian intelligence<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, following cyberattacks on critical infrastructure in the US and European countries. As a result of the sanctions, several contractors in Iran have shut down, but experts expect them to restart under different names, says Rafe Pilling, director of threat research for the Secureworks&#8217; Counter Threat Unit (CTU).&nbsp;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;An organization like Emen Net Pasargad [has] essentially rebranded or changed his identity several times,&#8221; he says, adding: &#8220;They [Iran] are leaning more heavily into the use of of cybercrime and hacktivist personas in different parts of the world to kind of protect and obfuscate their identity.&#8221;&nbsp;<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\">Crime and Sanctions<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The cyber center concept, which some anti-government groups refer to as &#8220;khyber centers,&#8221; typically bring together multi-disciplinary groups of hackers and cybersecurity specialists with Iran&#8217;s government organizations. In some cases, they provide certain services, such as access to compromised networks, to other groups, according to members of Recorded Future&#8217;s Insikt threat-intelligence group who asked not to be named.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">US government indictments and sanctions of Iranian individuals and suspected threat actors have been an effective tool and making business more difficult for the cyber-offensive contractors, the Recorded Future report stated. However, the international strategy is unlikely to deter Iran from continuing its cyber operations, according to the firm&#8217;s researchers.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;As it pertains to the current conflict, &#8230; the Islamic Republic is almost certainly framing their support for Hamas and Gazans as a legitimate cause justifying their involvement,&#8221; the researchers stated. &#8220;We have observed examples of persons associated with the Iranian cyber program claiming that sanctions would not deter their activities.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The companies are likely considered to be legitimate commercial entities in Iran, says Pilling.&nbsp;&#8220;The operational model that that Iran uses &#8230; is very much one where they use contractors \u2014 some people refer to them as front companies,&#8221; he says. &#8220;Maybe they do other kind of like quasi-legitimate work in Iran, but they also essentially do government work, which is also probably considered legitimate, and that work just happens to be offensive cyber activity against perceived adversaries of Iran.&#8221;<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\">Not a Unique Business Arrangement<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The Iranian contractors are not alone in their arrangements with government officials. Russia&#8217;s cyber operations are often run by private companies, such as <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a href=\"https:\/\/www.wired.com\/story\/russia-internet-research-agency-disbands\/\" target=\"_blank\" class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" rel=\"noopener\">the Internet Research Agency<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, including <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a href=\"https:\/\/www.darkreading.com\/endpoint-security\/pro-russian-information-operations-escalate-in-ukraine-war\" target=\"_blank\" class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" rel=\"noopener\">massive disinformation campaigns<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> that were launched prior to \u2014 and continue during \u2014 the invasion of Ukraine.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The contractors highlighted in the report are not only profiting from operations in Iran, but also across the border by selling services to other nations, likely including Iraq, Syria, and Lebanon, Recorded Future stated.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;Research on these groups has also highlighted financially motivated activities outside of Iran&#8217;s borders that formalize the exportation of cyber technologies,&#8221; the report stated. &#8220;While public information is still limited on this front, the cases identified in this research suggest that contractors rely on the IRGCQF to penetrate the highest levels of government to engage in presumably lucrative arrangements.&#8221;<\/span><\/p>\n<p><a href=\"https:\/\/www.darkreading.com\/vulnerabilities-threats\/iran-cyber-centers-dodge-sanctions-sell-cyber-operations\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Public records combined with documents leaked by Iranian anti-government groups<\/p>\n","protected":false},"author":12,"featured_media":2441,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1],"tags":[809],"class_list":["post-2440","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-dark-reading"],"featured_image_urls":{"full":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/01\/irans-cyber-centers-dodge-sanctions-to-sell-cyber-operations-scaled.jpg?fit=2560%2C1494&ssl=1",2560,1494,false],"thumbnail":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/01\/irans-cyber-centers-dodge-sanctions-to-sell-cyber-operations-scaled.jpg?resize=150%2C150&ssl=1",150,150,true],"medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/01\/irans-cyber-centers-dodge-sanctions-to-sell-cyber-operations-scaled.jpg?fit=300%2C175&ssl=1",300,175,true],"medium_large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/01\/irans-cyber-centers-dodge-sanctions-to-sell-cyber-operations-scaled.jpg?fit=640%2C373&ssl=1",640,373,true],"large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/01\/irans-cyber-centers-dodge-sanctions-to-sell-cyber-operations-scaled.jpg?fit=640%2C374&ssl=1",640,374,true],"1536x1536":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/01\/irans-cyber-centers-dodge-sanctions-to-sell-cyber-operations-scaled.jpg?fit=1536%2C897&ssl=1",1536,897,true],"2048x2048":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/01\/irans-cyber-centers-dodge-sanctions-to-sell-cyber-operations-scaled.jpg?fit=2048%2C1196&ssl=1",2048,1196,true],"chromenews-featured":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/01\/irans-cyber-centers-dodge-sanctions-to-sell-cyber-operations-scaled.jpg?fit=1024%2C598&ssl=1",1024,598,true],"chromenews-large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/01\/irans-cyber-centers-dodge-sanctions-to-sell-cyber-operations-scaled.jpg?resize=825%2C575&ssl=1",825,575,true],"chromenews-medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/01\/irans-cyber-centers-dodge-sanctions-to-sell-cyber-operations-scaled.jpg?resize=590%2C410&ssl=1",590,410,true]},"author_info":{"display_name":"Dark Reading","author_link":"https:\/\/ddi.mohflo.net\/index.php\/author\/darkreading\/"},"category_info":"<a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/uncategorized\/\" rel=\"category tag\">Uncategorized<\/a>","tag_info":"Uncategorized","comment_count":"0","jetpack_featured_media_url":"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/01\/irans-cyber-centers-dodge-sanctions-to-sell-cyber-operations-scaled.jpg?fit=2560%2C1494&ssl=1","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/2440","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/comments?post=2440"}],"version-history":[{"count":0,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/2440\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media\/2441"}],"wp:attachment":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media?parent=2440"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/categories?post=2440"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/tags?post=2440"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}