Skip to content
TrackPodcasts
technologyMar 12, 202615:56

Iranian Cyberwarfare Is Ramping Up...

About this episode

Here is what to expect

Get every episode summarized

Each time The Deep Dive Radio Show and Nick's Nerd News publishes, we email you a written briefing from the transcript — the topics, who appeared, and any specific claims, with the ad reads skipped.

Email me new episodes

Free for 3 shows. No card needed.

Hosts & guests

Transcript ready

180 searchable segments. Every word is indexed and playable.

Iranian Cyberwarfare Is Ramping Up...

The Deep Dive Radio Show and Nick's Nerd News

0:00
15:56

Full transcript

The Deep Dive Radio Show and Nick's Nerd NewsIranian Cyberwarfare Is Ramping Up.... Machine-transcribed; use the interactive transcript above to jump the player to any line.

Iranian cyber warfare is ramping up. Here's what to expect. I'm Nick Espinoza, your chief security fanatic, and let's dive in. Now, Jason Lalji and Sam Sabin of Axios had a pretty good primer on this that I'm going to be cribbing from before we dive deeper. And if you didn't know, Iranian actors both state-linked and loosely affiliated have a long history of cyber attacks against the United States. However, the US and Israel are now using similar tactics as well. And this past Wednesday, a cyber attack allegedly linked to Iran-aligned hackers disrupted operations at Striker. If you don't know who Striker is, they're a major medical technology company in the United States. Striker did confirm in a statement that's experiencing a, quote, global network disruption to our Microsoft environment, end quote. But they haven't seen any types of ransomware or malware as of now. And they believe that the incident is contained, quote, unquote. So this is basically the same hacking group on that claimed on XAKA Twitter

that it had also hacked US-based payments firm, Verifone. Verifone did come out though and say that they found no evidence of a breach and no service disruptions whatsoever. And if you didn't know, Israel last week carried out a wide-scale strike targeting a collection of military sites in Tehran that allegedly housed the headquarters of the Iranian Islamic Revolutionary Guard Corps. This is according to the IDF or Israeli Defense Forces on X. The IDF also claimed that the headquarters, the IRGC's cyber and electronic headquarters and its intelligence directorate were among the military outposts that were hit in this strike. Therefore, an attempt to cripple cyber operations or at least coordination by the Iranians. However, Iran has been under a near-total internet blackout since the first US and Israeli strikes began, which limits the flow of information coming out of that country. Iran, aligned hackers and self-described activist groups have increased activity against entities in the Middle East, the United States,

and parts of Asia following the February 28 air strikes. And that is according to CrowdStrike, also according to CrowdStrike HydroKitten, a group that operates on behalf of the IRGC has indicated plans to target the financial sector. You might have read about that and heard about that as well, and we're going to be talking about that a little bit more in depth. Researchers from Palo Alto Networks' Unit 42 also reported that dozens of pro-Iranian activist groups say that essentially they have launched several cyber attacks since February 28th targeting critical infrastructure. These groups have claimed responsibility for attacks against Israeli payment systems, the shutdown of Kuwaiti government websites, and incidents affecting online services at airports. Pro-Russian political hackers, interestingly enough, called NoName 05716, teamed up with Iranian activists on March 2nd to target Israeli defense and municipal organizations, including defense contractor Elbet Systems. We've been getting reports that essentially the

Russians have been assisting the Iranians as they are allies with telemetry and information on how to strike or hit both US and Israeli targets, whether it's cyber or kinetic. The same Russian activists also claim they broke into Israeli water management and other industrial control systems, but researchers have not been able to verify those claims as of now. Israel and US have also been launching cyber attacks as well. Israel hacked a popular Iranian prayer app to send notifications of potentially millions of Iranian phones last month, urging the country's military personnel to defect from the regime. Iranian state media has also reported that news sites, including the state news agency IRNA, were hijacked to display articles about the cyber attacks and discredit the regime. And Israel for the record has had persistence within Iranian networks for some time. The Israeli military had access to quote-unquote nearly all of the traffic cameras in Tehran and in partnership with the CIA, Israel used the

cameras to target the air strike that killed Ayatollah Ali Hamani, Iran's supreme leader. General Dan Kane, chair of the Joint Chiefs, said that US cyber command and space command were also among the quote first movers and quote during the initial strike against Iran last month. This is a very common tactic. The Russians also use this against Ukraine prior to their kinetic invasion by attempting to knock out banking institutions, critical infrastructure, all of that, to try and panic the society destabilize currency, all those different kinds of things. And so thanks again to Axios for that primer. But I wanted to dive a bit deeper though, because the United States has a massive attack surface area and that should be cause for concern. So here are the ways that Iran could basically attack the United States, but also Israel and actually any adversary using cyber offensive tools. So first up is obviously power grid attacks, right? Their hackers could attempt to break into systems that control electricity distribution or generation. And if

successful, they could cause blackouts, disrupt power to things like hospitals, factories, manufacturing cities, all these kinds of things as well. Water and wastewater is another way that they could attack us as well. I've done multiple segments on just the massive vulnerabilities that the 50,000 plus water and wastewater districts in the United States have. And so that is important because water treatment plants rely on computerized control systems attackers could manipulate these systems and shut down the water supply or contaminate treatment processes or cause service disruptions. We saw it back in 2021, 2022. Somebody tried to introduce high quantities of lie into the drinking water of Oldsmart, Florida, population 15,000 or so, which would have been a first mass casualty event due to hacking. So that's a very real and very serious issue that the United States faces. On top of it, oil and gas infrastructure could get hit pipelines refineries, fuel distribution networks are all controlled by industrial computers. We all saw just the absolute panic on the eastern seaboard when basically Russian cut out hit

and shut down colonial pipeline back in I want to say it was around 2020 or so. So obviously, that's a very real possibility because we could disrupt the basically the gasoline supply temporary shutdown, temporarily shut down parts of the energy sector. That would be a massively critical one as well. Also, we have a ton of banking and financial systems around the world, the U.S. in particular. So Iranian groups have historically targeted banks and financial institutions. I've talked about this before. Iranians were actually wanted and arrested by the FBI for trying to knock out Wall Street, like literally Wall Street. So the goal would be obviously to disrupt things like online banking, delay transactions, and eventually cause a public panic if possible. In other words, imagine if Chase and City and all the big banks and I think it's something like the five top banks are like 80% of the, you know, run 80% of the financial institutions. If those were to go down in some way, shape, or form, and people couldn't get access to your money, we might see panics runs on banks, all of those different kinds of things. On top of it,

there's a vast amount of telecommunications networks in the United States, cell phone carriers, internet providers. This is essentially infrastructure that we rely on every single day. You are not watching this or listening to this without telecommunications network in your life, not to mention everything else, including bank transactions. You name it. So a successful attack could disrupt phone service, slow internet access, you know, and more. On top of it, hospitals and health care systems are large, large surface areas as well. And there are several of them within the United States. Hospitals heavily rely on digital systems for patient records and medical devices alike. Cyberattacks could disrupt care, could delay surgeries, could lock access to critical data. We have literally seen hospitals ransomed where they have to divert ambulances and people have died. So this is a huge one as well. We have a large array of transportation imports around the world as well. The United States is no slouch in this, airports, shipping ports, rail systems, logistics networks. All of these are very heavily automated now. So an attack of delay shipments,

halt port operations, disrupt airline scheduling. It could be an absolute and complete mess. Then there's industrial control systems. Factories and infrastructure rely on ICS or industrial control systems to run equipment. So Iranian cyber groups have in the past specifically targeted these systems to disrupt manufacturing or critical services. So it's very possible that they would do it again. And we will talk about what is possible and probable here. On top of it, we just have the plain old denial of service or distributed denial of service attacks, DDoS, basically flooding website and network traffic with flooding websites and networks with massive amounts of traffic until essentially they crash or they lock up. So government sites, bank websites, media outlets could be possibly knocked offline temporarily. The cloud flares and the other CDNs or content delivery networks are going to have one heck of a time if they're seeing massive amounts of bandwidth flooding across essentially there's content delivery networks as they're delivering everything from government websites to the media channels to the YouTube's of the world. So we'll see what happens

there. Then there's data theft in data destruction. This is something that we've seen coming out of a lot of countries including Russia as well. But their attackers may steal sensitive information or wipe computer systems entirely. The goal oftentimes is either intelligence gathering or operational disruption. But in basically a cyber warfare situation they may not necessarily be going for scraping data or copying data out. They may simply just try to destroy the data to slow or disrupt operations for whatever entity they're hitting. On top of it, there's a standard fishing and social engineering. Iran has been very, very successful at this over the years. So they might be able to trick an employee into giving up a password or clicking a malicious link. It's one of the most common ways that attackers get into systems. And then there's a disinformation and psychological operations that could be associated with this because we have an overreliance on technology in modern society. So cyber campaigns could spread false information online. They could create panic or distrust or mistrust. These operations are designed to essentially weaken public confidence

and focus on that more than actually disrupting the systems. So they could be have a full core press. Everything I just talked about is possible for the record. All of those different avenues that they could hit us. But the question becomes what is really probable here? And so if I'm going through this and I'm analyzing essentially their past behavior, their past cyber capabilities, I've been reporting on them for years. And I did my homework here. But I think these are, I would say the five most common things that I think we're going to see. This is what I would be looking out for if I were running political risk quantification. First and foremost, is banking system disruptions through things like denial of service or distributed denial of service attacks. It's being reported, basically by intel agencies that they're going to be focusing on this. Banks are basically gearing up for this. But Iran has previously launched cyber campaigns that have flooded US bank websites with traffic to knock them off line. The goal there isn't to

steal money. It's to basically shut down online banking even if it's temporary to try and cause a panic and instability in financial institutions. I think the next most probable thing here would be attacks on small water utilities because they are wildly undefended. They have not spent money. Local governments usually don't have the cash to give them. And Iran has already targeted water systems in the United States by hacking internet-connected equipment that is used in treatment plants. These facilities often have weak cybersecurity as I mentioned. And so they're very attractive targets that could cause disruption, public fear. I mean, imagine poisoning the water supply for a population or shutting down the water supply to a population until they can manually get it back online in some way, shape, or form. That would be a very serious problem. I think the third most probable attack is data wiping attacks on US companies as well. Iranian hackers have frequently deployed destructive malware that erases essentially computer systems instead of just

stealing data. They use this tactic also to wipe out tens of thousands of computers in the energy sector across the Middle East. So they have a history of doing this. And I think that's very probable. Next up is the spearfishing campaigns. I think against government and defense contractors as well. Iranian cyber groups are well known for sending targeted fishing emails to government agencies, to universities, to defense contractors and all of that. This is one of the reasons why the US military has been ramping up CMMC, the cybersecurity maturity model certification. There are over 300,000 companies in the defense industrial base in the United States. And they all need to get certified in some way, shape, or form. So good cyber hygiene. So there are people aren't falling for this and letting the Iranians or the Chinese or the Russians or whoever in. These attacks are literally designed to steal credentials and then just quietly infiltrate sensitive networks over time to steal information. That said, they could also infiltrate infiltrate and essentially wipe a contractor out. That might be a critical contractor of the war fighting capability of the United

States or Israel or any one of them. And then finally, I think we're also looking at in terms of highest probability psychological operations. So like leaks of sensitive data, defacements of websites, disinformation campaigns, all of those things have been very effective in the age of social media and the algorithms prioritizing anger and political hyperbole over anything else. And Iran often uses cyber attacks to embarrass or intimidate its enemies rather than just destroy infrastructure. So they may leak stolen data, deface websites, propaganda online to create political pressure or undermine public confidence in political leadership. Iran's past cyber strategies have focused for the record less unsophisticated sabotage and more on disruption. They're not as sophisticated as some of the other threat actors out there, but they are very effective at what they know. And so we could be looking at things overarchingly like knocking services offline, targeting weak infrastructure, wiping data, stealing information, spreading

psychological pressure. Like these are things that I think are well within the Iranian capability. And remember, they're doing a lot of this from outside of Iran itself. They have positioned themselves thanks to the cuts for us all over the world to support terror operations and cutouts. And so they're going to get to work. And I think they're going to be harder to find. So it's going to be a massive man hunt basically for to find wherever these people are. They could be sitting in Eastern Europe. They could be sitting in Asia. They could be sitting in the United States. And there's a lot of fear. And intelligence reports about sleeper cells within Iran. And so even if a company is doing things like geoblocking traffic from outside of let's say the United States, for example, if the attackers are inside the United States and using actual infrastructure, not just VPNs to mask their presence, then it's a very real possibility that they could strike and strike very effectively within the United States. So these are the things we need to watch out for. This is going to be an incredibly tense time just given that that there's an actual active war going on. Whatever you call it, war not. I'm not getting into that debate on some antics.

I'm simply saying that the this is how asymmetrical warfare is going to work. I did a past segment on asymmetrical warfare, but this is the specifics to cyber attacks. And so best of luck to us all, we're going to keep our eyes on this. Obviously, and you know, I'll keep you up to date here. So stick around and thanks for listening. And please like share a follow me here on Facebook and Twitter and Nick AESP. And please feel free to subscribe to me at YouTube as well. And as always, stay safe, stay online. And please, please, please, I'm going to say private, secure, and informed. Take care.

More episodes

More from The Deep Dive Radio Show and Nick's Nerd News

View all episodes →