Thursday, June 1, 2023
LetsAskBinu.com
  • Home
  • Cybersecurity
  • Cyber Threats
  • Hacking
  • Protection
  • Networking
  • Malware
  • Fintech
  • Internet Of Things
No Result
View All Result
LetsAskBinu.com
No Result
View All Result
Home Cybersecurity

Iranian Hackers Blocked After Gaining Access to 2020 Municipal Election Infrastructure

Researcher by Researcher
April 25, 2023
in Cybersecurity
0
U.S. Government Grapples With Cyber Incident Reporting Pain Points
189
SHARES
1.5k
VIEWS
Share on FacebookShare on Twitter


After an Iranian-based adversary gained access to a city’s local infrastructure that would be used to report the results of voting for the 2020 elections, U.S. government agencies worked together to quickly shut down the attackers before they could carry out any further attack.

The attack was launched by a known Iranian actor called Pioneer Kitten, said government officials with the Cyber National Mission Force (CNMF), with the Department of Defense, and Cybersecurity and Infrastructure Security Agency (CISA), with the Department of Homeland Security, at a Monday session at RSA. Pioneer Kitten’s campaign was first detected on the unnamed jurisdiction by CNMF while executing a cyber intelligence, surveillance and reconnaissance mission in foreign space.

“To be clear, this isn’t the infrastructure involved in casting a vote, it isn’t involved in counting a vote, but our concern is always that some type of website defacement or DDoS – something that took the website down or defaced the website, say on the night of the election – could make it look like the vote had been tampered with when that’s absolutely not true,” said U.S. Army Maj. Gen. William Hartman, commander with the CNMF, while discussing coordination efforts between U.S. agencies conducting offensive and defensive cyber operations.

Pioneer Kitten, which has been active since at least 2017, has been observed using SSH tunneling and exploits related to VPNs and network appliances in order to access sensitive data. The group has previously targeted North America organizations, including ones in the technology, government, defense, healthcare and manufacturing sectors. In 2020, the group was seen advertising access to compromised networks on an underground forum.

As previous U.S. election cycles have proved, the security challenges facing elections are multi-pronged and include disinformation campaigns aimed at swaying voter opinions, disruptive cybercriminal activity like ransomware or DDoS attacks targeting election-related infrastructure and espionage attacks.

Election security became a national priority when APT28 and APT29 stole data from several targets in the 2016 U.S. presidential election, including the Democratic National Committee, and leaked a large number of related emails online.

Then during the 2020 U.S. presidential election cycle, phishing attacks were detected targeting people and organizations associated with both the Trump and Biden campaigns. The threat actors involved during that election cycle included Strontium, a threat group operating from Russia, Zirconium, operating from China, and Phosphorus, operating from Iran.

After the discovery of the 2020 compromise by Pioneer Kitten, CISA notified the impacted jurisdiction and offered support, while the CNMF carried out cyber operations that ensured the threat actor no longer had access to the network. The main concern was that the impact of a potential cyberattack related to any sort of voting infrastructure could sow doubt over the accuracy of the election, the officials said.

“We were concerned with systems that could weigh on the perception of a potential compromise and that’s why this work was so important, so critical to get ahead of this activity and ensure that the victim’s jurisdiction had all they needed to make sure their systems were safe, secure and resilient well in advance of the election occuring,” said Eric Goldstein, executive assistant director at CISA.

Election security continues to be a concern for private sector and government officials, and during the 2022 November midterm elections, Mandiant said they assessed with “moderate confidence” that cyber threat activity would cause disruptions and divisiveness. Last year, an FBI alert also warned that in 2021 U.S. election officials and other state and local government officials had received invoice-themed phishing emails aiming to steal their credentials in what was described as a “coordinated, ongoing effort to target US election officials.”

Hartman and Goldstein cited several other examples of CNMF and CISA working together to assist in the disruption of large-scale cyber operations by threat actors, including responses to the targeting of three unnamed federal agencies, the SolarWinds attack and the Hafnium threat group exploiting Microsoft Exchange vulnerabilities.

CNMF supports U.S. Cyber Command across various national priorities like election security, ransomware and espionage campaigns. CISA, meanwhile, has offered support, tools and free training for the state and local officials accountable for safeguarding election infrastructure that must work with limited resources and capacity.

This collaboration is important for securing election infrastructure: “We want to make sure we are supporting [state and local] officials, but also working to get ahead of adversaries,” said Goldstein. “Ideally we can get ahead of negative events before they happen.”



Source link

Related articles

Spring Framework Flaw Exploited in Mirai Malware Attacks

Threat Actors Exploit Critical Zyxel Flaw in Botnet Attacks

June 1, 2023
Cisco Acquiring Armorblox for Predictive and Generative AI Technology

Cisco Acquiring Armorblox for Predictive and Generative AI Technology

June 1, 2023
Tags: AccessblockedElectionGainingHackersinfrastructureIranianMunicipal
Share76Tweet47

Related Posts

Spring Framework Flaw Exploited in Mirai Malware Attacks

Threat Actors Exploit Critical Zyxel Flaw in Botnet Attacks

June 1, 2023
0

Threat actors are exploiting a critical-severity Zyxel flaw in order to add vulnerable devices to a Mirai botnet variant. While...

Cisco Acquiring Armorblox for Predictive and Generative AI Technology

Cisco Acquiring Armorblox for Predictive and Generative AI Technology

June 1, 2023
0

Cisco on Wednesday announced that it’s acquiring California-based cybersecurity firm Armorblox for its artificial intelligence (AI) technology. Armorblox specializes in...

8 best practices for securing your Mac from hackers in 2023

8 best practices for securing your Mac from hackers in 2023

June 1, 2023
0

Best practices for securing your Mac against potential hacks and security vulnerabilities include enabling the firewall, using strong passwords and...

ZuoRAT Malware Found Hitting Home Routers

New SeroXen RAT Emerges | Decipher

June 1, 2023
0

Security researchers are tracking a new fileless RAT named SeroXen that has the capability to evade many EDR systems and...

Sentra Raises $30 Million for DSPM Technology

Chrome 114 Released With 18 Security Fixes

May 31, 2023
0

Google this week announced the release of Chrome 114 to the stable channel with a total of 18 security fixes...

Load More
  • Trending
  • Comments
  • Latest
This Week in Fintech: TFT Bi-Weekly News Roundup 08/02

This Week in Fintech: TFT Bi-Weekly News Roundup 15/03

March 15, 2022
QNAP Escalation Vulnerability Let Attackers Gain Administrator Privileges

QNAP Escalation Vulnerability Let Attackers Gain Administrator Privileges

March 15, 2022
Supply chain efficiency starts with securing port operations

Supply chain efficiency starts with securing port operations

March 15, 2022
A first look at threat intelligence and threat hunting tools

A first look at threat intelligence and threat hunting tools

March 15, 2022
Beware! Facebook accounts being hijacked via Messenger prize phishing chats

Beware! Facebook accounts being hijacked via Messenger prize phishing chats

0
Shoulder surfing: Watch out for eagle‑eyed snoopers peeking at your phone

Shoulder surfing: Watch out for eagle‑eyed snoopers peeking at your phone

0
Remote work causing security issues for system and IT administrators

Remote work causing security issues for system and IT administrators

0
Elementor WordPress plugin has a gaping security hole – update now – Naked Security

Elementor WordPress plugin has a gaping security hole – update now – Naked Security

0
Spring Framework Flaw Exploited in Mirai Malware Attacks

Threat Actors Exploit Critical Zyxel Flaw in Botnet Attacks

June 1, 2023
All eyes on APIs: Top 3 API security risks and how to mitigate them

All eyes on APIs: Top 3 API security risks and how to mitigate them

June 1, 2023
Cisco Acquiring Armorblox for Predictive and Generative AI Technology

Cisco Acquiring Armorblox for Predictive and Generative AI Technology

June 1, 2023
This Week in Fintech: TFT Bi-Weekly News Roundup 08/02

This Week in Fintech: TFT Bi-Weekly News Roundup /

June 1, 2023

Recent Posts

Spring Framework Flaw Exploited in Mirai Malware Attacks

Threat Actors Exploit Critical Zyxel Flaw in Botnet Attacks

June 1, 2023
All eyes on APIs: Top 3 API security risks and how to mitigate them

All eyes on APIs: Top 3 API security risks and how to mitigate them

June 1, 2023
Cisco Acquiring Armorblox for Predictive and Generative AI Technology

Cisco Acquiring Armorblox for Predictive and Generative AI Technology

June 1, 2023

Categories

  • Cyber Threats
  • Cybersecurity
  • Fintech
  • Hacking
  • Internet Of Things
  • LetsAskBinuBlogs
  • Malware
  • Networking
  • Protection

Tags

Access attack Attacks banking BiWeekly bug Cisco cloud code critical Cybersecurity Data Digital exploited financial Fintech Flaw flaws Google Group Hackers Krebs Latest launches malware Microsoft million Network News open patches Payments platform Ransomware RoundUp security Software Stories TFT Threat Top vulnerabilities vulnerability warns Week

© 2022 Lets Ask Binu All Rights Reserved

No Result
View All Result
  • Home
  • Cybersecurity
  • Cyber Threats
  • Hacking
  • Protection
  • Networking
  • Malware
  • Fintech
  • Internet Of Things

© 2022 Lets Ask Binu All Rights Reserved