Iran Cyberattacks Targeting US Companies Imminent, Experts Warn
Top cybersecurity experts say they expect to see Iran retaliate against the U.S. for the killing of General Qassem Soleimani by launching cyberattacks against major U.S. businesses.
Top cybersecurity experts say they expect to see Iran retaliate against the U.S. for the killing of General Qassem Soleimani by launching cyberattacks against major U.S. businesses.
“We’ve really opened Pandora’s box on this one,” said Tom Kellermann, head cybersecurity strategist at VMware Carbon Black. “You have to appreciate he is now a martyr, the three days of mourning are now over, and there are numbers sympathetic Iranians that work in tech and live in cities around the world that could raise their weapon — their weapon being their laptop.”
In an interview with SDxCentral, Kellermann said he expects to see destructive cyberattacks, potentially followed by physical attacks against critical infrastructure in the U.S. “Beginning in the next 24 hours you will see cyberattacks manifesting as a harbinger for kinetics attacks.” He added, “I hope I’m wrong.”
On Jan. 4, two days after the United States killed the Iranian military leader in a drone strike, the U.S. Department of Homeland Security issued a terrorism advisory warning that Iran could carry out cyberattacks “with temporary disruptive effects against critical infrastructure in the United States.”
And late yesterday the department posted another advisory encouraging U.S. companies to “assess and strengthen” their security posture to protect against possible Iranian cyberattacks. These include potential “disruptive and destructive” cyberattacks against financial, energy, and telecommunications organizations, espionage and intellectual property theft, disinformation campaigns, and even bombings.
“Our current assessment is that organizations in the financial, defense, government, and oil and gas sectors are the most likely targets for retaliation activity,” wrote Adam Meyers, VP of intelligence at CrowdStrike, in an email. “We are also monitoring for distributed denial of service (DDoS) activity, as Iran has employed DDoS attacks in the past, as well as other tactics, such as ransomware activity.
In addition to these sectors and attacks, Kellermann added IT service providers and managed security service providers, as well as destructive malware and island hopping — where an attacker infiltrates a vulnerable partner network instead of launching a direct attack against a company — to the list.
“Destructive attacks are going to increase, and if you are a name-brand U.S. corporation or you have a name-brand U.S. corporation as a client, you will be targeted,” he said. “What’s coming is a destructive cyber insurgency.”
VMware Carbon Black has seen a “dramatic evolution” in Iran’s cyber capabilities over the last three years, Kellermann said. Iran’s use of destructive cyberattacks increased 11% year over year, “and the most significant nation-state actor deploying destructive attacks has been Iran,” he added. “This is the first country to leverage a truly virulent destructive attack against one of their adversaries publicly, which was Saudi Arabia.”
Last month IBM’s X-Force threat intelligence team issued a report about a new type of wiper malware used in destructive cyberattacks attacks against industrial and energy companies. IBM said Iran state-sponsored hackers were likely responsible for the ZeroCleare malware, which aims to overwrite the Master Boot Record and disk partitions on Windows-based machines.
“I do think they are going to be creating new forms of wipers that are not limited to Microsoft operating systems,” Kellermann said.
The latest Homeland Security alert includes actions that companies should take to protect themselves from cyberattacks including backing up all critical data, implementing an incident response plan, conducting risk analysis and staff training, monitoring all network traffic, and scanning for vulnerabilities.
Both Kellermann and Meyers echo these recommendations. “CrowdStrike recommends adopting a strong defensive posture, particularly for those organizations in the above-named sectors, and enabling all prevention capabilities possible,” Meyers said.
Kellerman said CEOs need to sit down with their chief information security officers (CISOs) and ask them a series of questions. “Do we have a managed threat detection response firm on call, on contract right now? Are all of our security controls integrated and if not, why not? When was the last time we conducted a cyberthreat hunt, why are we not conducting one right now, and what was the remediation on said cyber hunt? And are we leveraging microsegmentation, and if we are not microsegmenting, what are we doing to stop lateral movement between our infrastructure and our environment?”
Plus, basic security hygiene — like visibility across all devices on a company’s network — is essential. “Don’t tell me you have logs because that’s not sufficient in today’s world,” Kellerman said. “We don’t have much time because it’s a clear and present danger for the U.S. in cyberspace.”