City
Epaper

Iranian hackers breach VPN servers of several firms globally

By IANS | Updated: February 17, 2020 11:15 IST

Cybersecurity researchers have spotted a widespread hacking by Iranian groups who compromised VPN (virtual private network) servers, planted bugs or 'backdoors' and succeeded in gaining access to the networks of numerous companies and organisations around the world.

Open in App

London, Feb 17 Cybersecurity researchers have spotted a widespread hacking by Iranian groups who compromised VPN (virtual private network) servers, planted bugs or 'backdoors' and succeeded in gaining access to the networks of numerous companies and organisations around the world.

During the last quarter of 2019, the research team from the UK-based ClearSky uncovered a widespread Iranian offensive campaign which it called the "Fox Kitten Campaign".

"This campaign is being conducted in the last three years against dozens of companies and organisations in Israel around the world," the company said in a statement on Sunday.

"Through the campaign, the attackers succeeded in gaining access and persistent foothold in the networks of numerous companies and organisations from the IT, telecommunication, oil and gas, aviation, government and security sectors around the world," it added.

Aside from malware, the campaign enfolds an entire infrastructure dedicated to ensuring the long-lasting capability to control and fully access the targets chosen by the Iran.

The campaign infrastructure was used to develop and maintain access routes to the targeted organisations and steal valuable information from the targeted organisations.

"Hackers maintained a long-lasting foothold at the targeted organisations and breach additional companies through supply-chain attacks."

The campaign was conducted by using a variety of offensive tools, most of which open-source code-based and some self-developed.

The Iranian APT groups have succeeded to penetrate and steal information from dozens of companies around the world in the past three years.

The most successful and significant attack vector used by the Iranian advanced persistent threat (APT) groups in the last three years has been the exploitation of known vulnerabilities in systems with unpatched VPN and RDP services, in order to infiltrate and take control over critical corporate information storages.

After breaching the organisations, the attackers usually maintain a foothold and operational redundancy by installing and creating several more access points to the core corporate network.

As a result, identifying and closing one access point does not necessarily deny the capability to carry on operations inside the network.

"Iranian APT groups have developed good technical offensive capabilities and are able to exploit one-day vulnerabilities in relatively short periods of time," said the researchers.

ClearSky observed Iranian groups exploiting VPN flaws within hours after the bugs had been publicly disclosed.

According to a ZDNet report, Iranian hackers have targeted Pulse Secure, Fortinet, Palo Alto Networks, and Citrix VPNs to hack into large companies.

 

( With inputs from IANS )

Open in App

Related Stories

EntertainmentMilind Soman says OTT platforms are giving 90s actors a new lease of opportunities

InternationalJapan PM Takaichi's Cabinet approval rating falls to 67.5 per cent amid Taiwan remarks

BusinessSimta Astrix Opens its New Experience Centre in Hyderabad, Showcasing the Best in Windows, Doors, and Interiors

LifestyleChristmas 2025 Special Cake Recipe: How to Make a Delicious Chocolate Cake at Home

InternationalFacts back Hasina's claim of law-and-order collapse under Yunus government: former Indian diplomat Mahesh Sachdev

टेकमेनिया Realted Stories

TechnologyReady to launch BlueBird Block-2 satellite on December 24: ISRO

TechnologyIndia-New Zealand FTA: PM Modi, Luxon aim to double bilateral trade over 5 years

TechnologyNorth Korea-backed hackers launch cyber attack using computer files

TechnologyIndia’s capital market infra generates over Rs 700 billion revenue in FY25: Report

TechnologyMeditation a scientific tool for stress management, neuroplasticity: MDNIY