At CyberwarCon on November 21, Microsoft security researcher Ned Moran presented his findings that show a shift in the activity of the Iranian hacker group APT33.
Iranian hackers have carried out some of the most disruptive acts of digital sabotage in the last decade. These hackers typically wipe out entire computer networks in waves of cyberattacks across the Middle East and occasionally the United States. However, one of Iran’s most active hacker groups appears to have shifted focus, targeting the physical control systems used in electric utilities, oil refineries, and manufacturing.
According to a recent article from Wired.com, the hackers’ motivation—and which industrial control systems they’ve already breached—remains unclear. Moran speculates the group is seeking to gain a foothold to carry out cyberattacks with physically disruptive effects. “They’re going after these producers and manufacturers of control systems, but I don’t think they’re the end targets,“ says Moran. ”They’re looking to inflict some pain on someone’s critical infrastructure that makes use of these control systems.”
Moran compares Iran’s disruptive cyberattacks to the acts of physical sabotage the United States has accused Iran of carrying out. Both destabilize and intimidate regional adversaries—and the former will do so even more if their hackers can add physical effects to the already damaging digital effects.
Sources:
A notorious Iranian hacking crew is targeting industrial control systems. (2019, November, 23). Retrieved from arstechnica.com/information-technology/2019/11/a-notorious-iranian-hacking-crew-is-targeting-industrial-control-systems/