Several security agencies from the United States, along with Canada and Australia, have warned about the access of cyber agents from the Islamic Republic to critical infrastructure networks. In a joint advisory released on Wednesday, October 25, by three U.S. security agencies, including the National Security Agency (NSA), the Federal Bureau of Investigation (FBI), and the Cybersecurity and Infrastructure Security Agency (CISA), along with several security agencies from Canada and Australia, the risks posed by Iranian cyber agents against several critical infrastructures have been highlighted. These security agencies announced that cyber attackers from the Islamic Republic have targeted several critical infrastructure sectors, including health, government centers, information technology, engineering, and energy, exposing them to damage. They specified that attackers have attempted to guess common user passwords using methods such as 'brute force' attacks to decrypt sensitive data and 'password spraying' attacks. According to these security agencies from the U.S., Canada, and Australia, the next step for Iranian cyber attackers is to sell stolen information to cybercriminals for further sabotage. The advisory issued by the security agencies suggested strategies to counter the tactics of cyber attackers, including continuous monitoring, enhancing network security accuracy, educating users about cyber threats, and using strong passwords. The advisory warned network security defenders that the harmful actions of Iranian cyber attackers could lead to permanent damage to sensitive systems. Earlier, Microsoft released a report on Tuesday, October 24, regarding digital threats, stating that the governments of Iran, Russia, and China are increasingly relying on criminal networks to conduct cyber espionage and hacking operations against the United States and other countries. According to the Associated Press, the growing collaboration between authoritarian governments and criminal hackers has raised concerns among national security officials and cybersecurity experts. They noted that this indicates increasingly blurred lines between actions by Beijing or the Kremlin aimed at undermining rivals and illegal activities by groups that typically have a greater interest in financial gain. For example, Microsoft analysts found that a criminal hacker group with links to Iran attempted to sell hacked personal information by infiltrating an Israeli dating site or extorting money through it. Microsoft concluded that the hackers had two objectives: to embarrass Israelis and to make money. In another example, inspectors identified a Russian criminal network that infiltrated over 50 electronic devices of the Ukrainian army in July 1403 (2024) and was apparently seeking access to information that could assist Russia's attack on Ukraine, but regardless of any payment that might have been made by Russia, there was no clear financial motive for this group. The Associated Press described this situation as a kind of 'marriage of convenience with benefits for both sides.' The governments of Russia, China, Iran, and North Korea can increase the impact of their cyber activities without additional costs, and criminals also receive new ways to gain more profit and promises of support from governments. Tom Burt, Microsoft's Vice President of Customer Security and Trust, stated, 'We are witnessing this trend towards the combination of nation-state and criminal activities in each of these countries.' He emphasized that although there is currently no evidence that Russia, China, and Iran share their resources or work with common criminal networks, the increasing use of private 'mercenary' hackers indicates how far America's enemies will go in weaponizing the internet. According to Microsoft's review of security threats from August 1402 to July 1403, Russia has focused most of its cyber operations on Ukraine, attempting to infiltrate military and government systems and spread misinformation to undermine support from Ukraine's allies in the war against Russia, while Ukraine has responded with its own cyber efforts, including taking some Russian media offline last week. Networks linked to Russia, China, and Iran have also targeted American voters by using fake websites and social media accounts to spread misleading information about the 1403 elections. Russia targets the campaign of Democratic candidate Kamala Harris, while Iran attempts to counter Republican candidate Donald Trump. U.S. federal officials have also accused the Iranian government of covertly supporting protests in the U.S. against the war in Gaza. Burt believes that as the election day approaches, Russia and Iran will increase the pace of cyber operations targeting the United States. Meanwhile, China has focused on election competitions for Congress or state and local positions, and according to Microsoft's findings, networks linked to Beijing continue to target Taiwan and other countries in the region. A spokesperson for the Chinese embassy in Washington dismissed claims of China's partnership with cybercriminals as unfounded and accused the United States of spreading 'misinformation about so-called Chinese hacking threats.' The governments of Russia and Iran also denied allegations of using cyber operations to target American citizens. Recently, U.S. federal officials announced plans to seize hundreds of domain names used by Russia for cybercriminal operations and hacking. However, the Atlantic Digital Forensics Laboratory found that these domains can be easily and quickly replaced. For example, researchers at this lab noticed 12 websites created to replace several domains seized by the Department of Justice just one day after the seizure, and they continue to operate even after a month.
Western Security Agencies Warn About Cyber Access of Iranian Agents to Critical Infrastructure Networks
Western security agencies have issued a warning about Iranian cyber agents accessing critical infrastructure networks, highlighting their malicious activities targeting sectors like health and energy. The advisory suggests measures to counter these threats, as the collaboration between authoritarian regimes and cybercriminals raises concerns about increased cyber operations against the U.S.
👥 Key Players
⚡ Actions
📰 What Happened
Western security agencies warn of Iranian cyber agents targeting critical infrastructure networks.
- NSA, FBI, CISA announce critical infrastructure networks
- Iranian cyber agents target health, government centers, information technology, engineering, energy
- Iranian cyber attackers attempt sensitive data
💡 Why It Matters
📚 Background
The advisory underscores the serious risks posed by Iranian cyber agents to critical infrastructure.
📝 Key Evidence
🏷️ Entities Mentioned
Translated from the original and edited for English readers. View original source →
Translation confidence: 85%