Latest News

Iranian hackers have been hacking VPN servers to plant backdoors in companies around the world
Friday, February 21, 2020 IST
Iranian hackers have been hacking VPN servers to plant backdoors in companies around the world

Iranian hackers have targeted Pulse Secure, Fortinet, Palo Alto Networks, and Citrix VPNs to hack into large companies.

 
 

2019 will be remembered as the year when major security bugs were disclosed in a large number of enterprise VPN servers, such as those sold by Pulse Secure, Palo Alto Networks, Fortinet, and Citrix.
 
A new report published today reveals that Iran's government-backed hacking units have made a top priority last year to exploit VPN bugs as soon as they became public in order to infiltrate and plant backdoors in companies all over the world.
 
According to a report from cyber-security firm ClearSky, Iranian hackers have targeted companies "from the IT, Telecommunication, Oil and Gas, Aviation, Government, and Security sectors."
 
SOME ATTACKS HAPPENED HOURS AFTER PUBLIC DISCLOSURE
 
The report comes to dispel the notion that Iranian hackers are not sophisticated, and less talented than their Russian, Chinese, or North Korean counterparts.
 
ClearSky says that "Iranian APT groups have developed good technical offensive capabilities and are able to exploit 1-day vulnerabilities in relatively short periods of time."
 
In some instances, ClearSky says it observed Iranian groups exploiting VPN flaws within hours after the bugs been publicly disclosed.
 
*APT stands for advanced persistent threat and is a term often used to describe nation-state hacking units
 
ClearSky says that in 2019, Iranian groups were quick to weaponize vulnerabilities disclosed in the Pulse Secure "Connect" VPN (CVE-2019-11510), the Fortinet FortiOS VPN (CVE-2018-13379), and Palo Alto Networks "Global Protect" VPN (CVE-2019-1579).
 
Attacks against these systems began last summer, when details about the bugs were made public, but they've also continued in 2020.
 
Furthermore, as details about other VPN flaws were made public, Iranian groups also included these exploits in their attacks (namely CVE-2019-19781, a vulnerability disclosed in Citrix "ADC" VPNs).
 
HACKING CORPORATE TARGETS TO PLANT BACKDOORS
 
According to the ClearSky report, the purpose of these attacks is to breach enterprise networks, move laterally throughout their internal systems, and plant backdoors to exploit at a later date.
 
While the first stage (breaching) of their attacks targeted VPNs, the second phase (lateral movement) involved a comprehensive collection of tools and techniques, showing just how advanced these Iranian hacking units have become in recent years.
 
For example, hackers abused a long-known technique to gain admin rights on Windows systems via the "Sticky Keys" accessibility tool [1, 2, 3, 4].
 
They also exploited open-sourced hacking tools like JuicyPotato and Invoke the Hash, but they also used legitimate sysadmin software like Putty, Plink, Ngrok, Serveo, or FRP.
 
Furthermore, in the case where hackers didn't find open source tools or local utilities to help in their attacks, they also had the knowledge to develop custom malware. ClearSky says it found tools like:
 
STSRCheck - Self-developed databases and open ports mapping tool.
POWSSHNET - Self-developed backdoor malware for RDP-over-SSH tunneling.
Custom VBScripts - Scripts to download TXT files from the command-and-control (C2or C&C) server and unify these files into a portable executable file.
Socket-based backdoor over cs.exe - An EXE file used to open a socket-based connection to a hardcoded IP address.
Port.exe - Tool to scan predefined ports for an IP address.
 

 
 

 
MULTIPLE GROUPS ACTING AS ONE
 
Another revelation from the ClearSky report is that Iranian groups also appear to be collaborating and acting as one, something that has not been seen in the past.
 
Previous reports on Iranian hacking activities detailed different clusters of activity, usually the work of one singular group.
 
The ClearSky report highlights that the attacks against VPN servers across the world appear to be the work of at least three Iranian groups -- namely APT33 (Elfin, Shamoon), APT34 (Oilrig), and APT39 (Chafer).
 
THE TREAT OF DATA-WIPING ATTACKS
 
Currently, the purpose of these attacks appears to perform reconnaissance and plant backdoors for surveillance operations.
 
However, ClearSky fears that access to all of these infected enterprise networks could also be weaponized in the future to deploy data-wiping malware that can sabotage companies and take down networks and business operations.
 
Such scenarios are possible and very plausible. Since September 2019, two new strains of data-wiping malware (ZeroCleare and Dustman) have been discovered and linked back to Iranian hackers.
 
Furthermore, ClearSky also doesn't rule out that the Iranian hackers might exploit access to these breached companies for supply chain attacks against their clients.
 
This theory is supported by the fact that earlier this month, the FBI sent out a security alert to the US private sector warning about ongoing attacks against software supply chain companies, "including entities supporting Industrial Control Systems (ICS) for global energy generation, transmission, and distribution." The ICS and energy sector has been a traditional target for Iranian hacking groups in the past.
 
The same FBI alert noted links between malware deployed in these attacks and code previously used by Iran's APT33 group, strongly suggesting that Iranian hackers might be behind these attacks.
 
Furthermore, the attack against Bapco, Bahrain's national oil company, used the same "breach VPN -> move laterally" tactic that ClearSky described in its report.
 
ClearSky now warns that after months of attacks, companies who have finally patched their VPN servers should also scan their internal networks for any signs of compromise.
 
The ClearSky report includes indicators of compromise (IOCs) that security teams can use to scan logs and internal systems for signs of an intrusion by an Iranian group.
 
However, the same flaws have also been exploited by Chinese hackers and multiple ransomware and cryptomining groups.
 
NEW VPN FLAWS
 
Furthermore, taking into account the conclusions of the ClearSky report, we can also expect that Iranian hackers will also pounce on the opportunity to exploit new VPN flaws once they become public. Earlier this week, for example, security researchers published details about six vulnerabilities impacting SonicWall SRA and SMA VPN servers.
 
 

 
 
 
 
 

Related Topics

 
 
 

Trending News & Articles

 Article
Tata Harrier’s 7-seater Version H7X Will Be Quite Different – Report

Tata Harrier’s three-row seat version in works, details out  

Recently posted . 2K views . 0 min read
 

 Article
How to make you car as silent as a Rolls Royce inside

Rolls Royce cars are extremely luxurious. While there are many expensive pieces of equipment in Rolls Royce cars, their most relaxing feature is the silence that ...

Recently posted . 2K views . 2 min read
 

 Article
India's Top 5 Mobile Charger manufacturer Brand 2019

The following list of India's Top 5 Mobile Charger manufacture Brand 2019  

Recently posted . 2K views . 0 min read
 

 Article
Mahindra XUV300 vs Maruti Brezza, Ford EcoSport, Tata Nexon – Price

XUV300 is the latest entrant in the compact SUV segment.

Recently posted . 2K views . 0 min read
 

 
 

More in Electronics & Gadgets

 Article
Google Bans Chinese App Developer With 600 Million Downloads From Play Store: Report

The app developer claims to have over 250 million active users.

Recently posted. 821 views . 0 min read
 

 Article
Vodafone plans $3.5 bn war chest to fight richest Asian

Vodafone Idea plans to raise as much as Rs 25,000 crore ($3.5 billion) via a rights offering to help India’s largest mobile-phone carrier fend off Asia’...

Recently posted. 657 views . 2 min read
 

 Article
Coolpad Cool Play 6 with 6GB of RAM launched in India for Rs 14,999

Coolpad on Sunday launched its latest flagship smartphone, Coolpad Cool Play half-dozen, in India. Priced at Rs fourteen,999, the smartphone are solely on the marke...

Recently posted. 830 views . 18 min read
 

 Video
How train change the track



Recently posted . 972 views
 

 Reviews
2019 Renault Triber review, test drive



Recently posted . 926 views . 70 min read
 

 Article
BSNL Halves Unlimited Calls Rental for Landlines to Rs. 49 a Month for New Subscribers

State-run telecom operator BSNL on Monday halved the monthly rental for unlimited calling from landline to any network on Sundays and night hours to Rs. 49 from Rs....

Recently posted. 553 views . 9 min read
 

 Article
Google removes 2 popular Android apps that enabled click fraud

Google finally took action after eight Cheetah Mobile and Kika Tech apps were allegedly involved in ad fraud last week. The search giant removed CM File manager a...

Recently posted. 827 views . 1 min read
 

 
 
 

   Prashnavali

  Thought of the Day

Without leaps of imagination or dreaming, we lose the excitement of possibilities. Dreaming, after all is a form of planning.
Gloria Steinem

Be the first one to comment on this story

Close
Post Comment
Shibu Chandran
2 hours ago

Serving political interests in another person's illness is the lowest form of human value. A 70+ y old lady has cancer.

November 28, 2016 05:00 IST
Shibu Chandran
2 hours ago

Serving political interests in another person's illness is the lowest form of human value. A 70+ y old lady has cancer.

November 28, 2016 05:00 IST
Shibu Chandran
2 hours ago

Serving political interests in another person's illness is the lowest form of human value. A 70+ y old lady has cancer.

November 28, 2016 05:00 IST
Shibu Chandran
2 hours ago

Serving political interests in another person's illness is the lowest form of human value. A 70+ y old lady has cancer.

November 28, 2016 05:00 IST


ads
Back To Top