Cyber experts warn Iranian hackers becoming more aggressive

Ajax is first hacking group known to use custom-built malware for espionage

Last updated:
1 MIN READ

Washington: Iranian hackers have become increasingly aggressive and sophisticated, moving from disrupting and defacing US websites to engaging in cyber espionage, security experts say.

According to Silicon Valley-based cybersecurity company FireEye Inc, a group called the Ajax Security Team has become the first Iranian hacking group known to use custom-built malicious software to launch espionage campaigns.

Ajax is behind an ongoing series of attacks on US defence companies and has also targeted Iranians who are trying to circumvent Tehran’s internet censorship efforts, FireEye said in a report to be published on Tuesday.

Many security experts have said that Iran is behind a series of denial-of-service attacks that have disrupted the online banking operations of major US banks over the past few years.

“I’ve grown to fear a nation state that would never go toe-to-toe with us in conventional combat that now suddenly finds they can arrest our attention with cyber attacks,” Michael Hayden, former director of the CIA and the National Security Agency, told the Reuters Cybersecurity Summit on Monday.

Security experts say Iran-ian hackers stepped up their campaigns against foreign targets in the wake of the Stuxnet attack on Tehran’s nuclear programme in 2010. The Stuxnet computer virus is widely believed to have been launched by the United States.

According to FireEye, the Ajax Security Team was formed by hackers known as “HUrr!c4nE!” and “Cair3x,” and began by defacing websites. The group became increasingly political after Stuxnet, FireEye researcher Nart Villeneuve said.

Leonard Moodispaw, chief executive of cybersecurity firm KEYW Corp, said that for now, Iranian hackers appeared to be increasingly spying and stealing money but not launching Stuxnet-like destructive attacks.

— Reuters

Sign up for the Daily Briefing

Get the latest news and updates straight to your inbox