On April 6, 2018, a hacker group named JHT launched a cyber attack on the internet infrastructure in Iran and Russia, causing disruptions in internet access in both countries. In a message tweeted by Iran's Minister of Communications and Information Technology, the hackers mentioned their non-interference in their country's elections alongside the American flag. This attack, which could have been easily prevented by updating two Cisco software programs, attracted significant attention from various media outlets, both Persian and non-Persian, sparking discussions about its nature. This article addresses three important questions regarding this cyber attack. What was the cause of this attack? As mentioned above, Iran and other countries could have easily prevented this cyber attack by updating the Smart Install feature in two Cisco IOS Software and Cisco IOS XE programs. On March 27, 2018, Cisco, one of the largest producers and providers of hardware and software for internet infrastructure, reported a severe security vulnerability in its two software programs and urged all users to update them promptly. However, officials and various individuals in Iran and other countries using these two software programs did not take this warning seriously until the day of the cyber attack, which was April 7. How did this attack work? This security vulnerability essentially allowed the attacker to reset the router settings to default and display a desired message to the victim. In the attack carried out by the JHT group, the router's configuration file named startup-config was rewritten, and then the router was restarted. With this change, the hackers disrupted the network, which in this case was Iran's internet network, and displayed the message shown in the image above to the network administrators of the attacked networks. What was the hackers' motivation? Answering this question is quite difficult, but according to an interview conducted by the Motherboard website with the JHT hacking group, the hackers cited their main reason as being 'tired' of state-sponsored hackers attacking the U.S. and other countries. Additionally, JHT claimed that before launching the attack, they had examined and resolved the Cisco software issue in other countries such as the U.S., the U.K., and Canada, and then began their attack to ensure that only a few countries like Iran and Russia experienced disruptions in internet connectivity. What lessons can be learned from this attack? Only one important and fundamental lesson can be drawn from this attack: the continuous updating of various software and tools; so that whenever a new version of software is released, it should be updated without delay. To start, check all the software you are using right now to ensure they are up to date.
What Was the Internet Disruption Incident in Iran?
On April 6, 2018, the hacker group JHT attacked Iran's internet infrastructure, causing significant disruptions. The attack was preventable through timely software updates from Cisco, which were ignored by many users. This incident highlights the critical importance of maintaining updated software to prevent cyber vulnerabilities.
👥 Key Players
📰 What Happened
On April 6, 2018, the hacker group JHT launched a cyber attack that disrupted internet access in Iran and Russia by exploiting a known vulnerability in Cisco software. The attack was preventable, as the vulnerability had been publicly reported just days prior.
- The attack was executed by resetting router settings to default and displaying a message to network administrators.
- JHT claimed their motivation was to retaliate against state-sponsored hacking activities.
💡 Why It Matters
📚 Background
Cybersecurity is a growing concern globally, with state-sponsored and independent hacking becoming increasingly common. This incident illustrates the vulnerabilities inherent in internet infrastructure.
🏷️ Entities Mentioned
Translated from the original and edited for English readers. View original source →
Translation confidence: 85%