TechBizWebTechBizWeb

    Subscribe to Updates

    Get the latest news about Technology and Business from all around the web..

    What's Hot

    Amazon says it has ‘hundreds’ of Rivian electric vans making deliveries in the US

    November 7, 2022

    Ryanair swings to first-half profit and raises passenger forecast

    November 7, 2022

    Devialet brings its sci-fi design aesthetics to a $790 portable speaker

    November 7, 2022
    Facebook Twitter Instagram
    • About Us
    • Privacy Policy
    • Guest Post
    • Terms
    • Contact
    Facebook Twitter Instagram
    TechBizWebTechBizWeb
    Subscribe
    • Home
    • Technology

      Amazon says it has ‘hundreds’ of Rivian electric vans making deliveries in the US

      November 7, 2022

      Devialet brings its sci-fi design aesthetics to a $790 portable speaker

      November 7, 2022

      Elon Musk’s response to fake verified Elon Twitter accounts: a new permanent ban policy for impersonation

      November 7, 2022

      The iPhone 14 Pro and Pro Max will come with ‘longer wait times’ due to factory lockdown

      November 6, 2022

      Meta’s reportedly planning to lay off ‘thousands’ of workers this week

      November 6, 2022
    • Business
    • Cyber Security
      National Security News

      List of 620 Russian spies, featuring one alleged agent at the centre of one of the biggest personal scandals in Wall Street history.

      September 24, 2022

      Cybersecurity ranked most serious enterprise risk in 2022

      August 31, 2022

      Registration open for CISA virtual summit on K-12 school safety

      August 31, 2022

      What do the Trickbot leaks reveal about Russian cybercrime?

      August 31, 2022

      What cybersecurity measures do CISOs outsource?

      August 30, 2022
    • Blockchain
    • Vulnerabilities
    • Social Engineering
    • Malware
    • Cyber Security Alerts
    TechBizWebTechBizWeb
    Home»Cyber Security»The Rise and Fall of Ashiyane – Iran’s Foremost Hacker Forum
    Cyber Security

    The Rise and Fall of Ashiyane – Iran’s Foremost Hacker Forum

    January 16, 2019Updated:January 16, 2019No Comments6 Mins Read
    Facebook Twitter Pinterest LinkedIn Tumblr WhatsApp
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Have you been attacked? Digitpol the global investigation firm can help you, visit Digitpol’s website to learn more.


    A new study from Recorded Future’s Insikt Group looks at the rise and fall of Ashiyane — Iran’s first and foremost security forum — and its figurehead, Behrooz Kamalian. Ashiyane was shut down in August 2018, and some of its former hacker members have migrated to other forums, notably the Persian Tools Forum and VBIran.ir.

    According to Recorded Future’s researchers, Iran’s hacking scene is a complex mix of government-sponsored contractors. The most prominent feature in modern Iranian history is its tendency to employ proxies for extra-national activities; such as Hezbollah against Israel and Yemen rebels against Saudi Arabia. It follows that the obvious route for foreign cyber-attacks would also involve proxies in the form of contractors frequently drawn from the hacking forums, rather than directly employed military personnel (a route frequently used by China).

    For many years, Ashiyane — formed out of the Ashiyane Digital Security Team founded and run by Behrooz Kamalian (sometimes known as the ‘father of Iranian hacking’) — was the foremost hacker forum.

    “When asked about Ashiyane Digital Security Team’s possible involvement with Iranian state-sponsored efforts,” reports Insikt, “Behrooz has claimed that while Ashiyane Forum operates independently and spontaneously, they cooperate with Iranian military apparatuses in advising and improving security, and ‘have always operated in the framework of the goals of the state’.”

    But the Iranian picture painted by Insikt is confused and confusing. This may partly be due to Iran’s late arrival to international hacking. Since the Stuxnet incident (2010), it is well known that the state has sought to improve its cyber capabilities; but the natural condition still responsive rather than proactive. In 2011, writes Insikt, “One member of the Ashiyane Digital Security Team participated in an IRGC-led [Iranian Revolutionary Guard Corps] distributed denial-of-service (DDoS) campaign against U.S. financial institutions in December 2011, lasting over 176 days.”

    Similarly — and possibly with Russian cyber assistance — Iran is believed to have developed the original Shamoon wiper that it used against what it considers to be American interests in the area; that is the Saudi Aramco oil company.

    Before Stuxnet, it appears that the greater part of Iranian hacking revolved around web defacements and religious propaganda. However, in 2009, the Iranian government issued a directive to blacklist all hacking sites — probably in response to the Iranian Green Movement (which at the time prompted fears or hopes of an ‘Iranian Spring’). 

    Behrooz Kamalian seems to have deep ties with the Iranian government. “Ashiyane Forum was one of the only hacking forums that remained,” writes Insikt, “and according to Insikt Group’s source, the Iranian hacking community speculated that Kamalian essentially struck a sole-source deal with the Iranian government. Ashiyane Forum had become the primary forum connecting to the new generation of Iranian hackers.”

    It was Stuxnet, one year later, that seems to have re-ignited government tolerance of private hackers. Throughout the post-Stuxnet period, the Iranian government has tolerated the hacking expeditions of the hacker forums, especially where they align with the national interests, culture and religion of the country — and Ashiyane was the primary forum and primary source of private hackers.

    Over the last decade, Ashiyane grew to a total of around 20,000 active users. Insikt’s analysis over this period suggests that the greater part of the content of the forum focused on web exploitation. “Cross-site scripting, DDoS attacks, SQL, and other browser-based code injections have been the primary subjects since the forumís inception,” it writes. Over the last four years, Android exploits have been included, mirroring the growth of Android devices from 26% of the device market in 2014 to 37% in 2015.

    The top hacker tools advertised on the forum in 2015 included Android RATs (AndroRAT and Dendroid RAT), and the Citroni ransomware. In 2016, emphasis shifted to exploits for consumer electronics, Android devices (including DroidJack), PC trojan njRAT, and USB malware. “PoisonTap became popular, as did questions about DDoS and SQL injection attacks,” writes Insikt. In 2017, queries on Linux products and enterprise content management were added to the mix. This is the stuff of standard hacker forums, probably indicating a consistent stream of new members registering.

    But it is after this that the history suddenly gets confused. On March 12, 2018, the official Ashiyane Digital Security Team channel stated that the Iranian court had ordered them to shut down all their activities until further notice. Insikt speculates that the forum was engaged in operating illegal gambling websites — an offense punishable by death or life imprisonment. In 2013, a leak of a portion of the Ashiyane database did indeed indicate a link to online gambling.

    The Ashiyane Forum suddenly disappeared on August 5, 2018. There was no explanation. It has been suggested that Kamalian had been arrested and imprisoned. This may be true, but if so, he had been released by early November. On November 8 he posted an Instagram video where an Iranian actor thanked him for regaining access to his compromised Instagram account. Kamalian seems to be rebuilding his position as a whitehat hacker helping celebrities.

    It is difficult to believe that the closure of Ashiyane and the rebranding of Kamalian indicate a withdrawal from international cyber activity by Iran. Nevertheless, something seems to be happening. Insikt’s Levi Gundert — a former special agent for the Secret Service and FBI and now vice president of intelligence and risk at Recorded Future — told SecurityWeek that it is possible that Kamalian could still be engaged in more nefarious activities under a different name; and that if so, it is possible that western intelligence will sooner or later recognize him. In the meantime, Insikt hasn’t observed the emergence of any central figure with the same level of notoriety.

    Concurrent with this, a high-profile example of Iranian activity is the recent U.S. indictment of two Iranian citizens for operating the SamSam ransomware. This is interesting because SamSam seems to be pure criminal profit-driven activity rather than the typical retaliatory official response to events. If government-sponsored it could possibly be in retaliation for President Trump’s withdrawal from the Iran Nuclear Agreement, but there is no clear linkage.

    Noticeably, neither of the indicted Iranians appear in Dancho Danchev’s publication today of ‘Iran’s Most Wanted Cybercriminals’. Gundert simply told SecurityWeek, “We cannot currently comment on Iranian government affiliations between Faramarz Shahi Savandi and Mohammad Mehdi Shah Mansouri.”

    Related: Iran-Linked DNS Hijacking Attacks Target Organizations Worldwide 

    Related: Iran Hackers Hunt Nuke Workers, US Officials 

    Related: Iran-Linked Espionage Group Continues Attacks on Middle East 

    Related: Iran-Linked Hackers Use Just-in-Time Creation of Weaponized Attack Docs 

    view counter

    Kevin Townsend is a Senior Contributor at SecurityWeek. He has been writing about high tech issues since before the birth of Microsoft. For the last 15 years he has specialized in information security; and has had many thousands of articles published in dozens of different magazines – from The Times and the Financial Times to current and long-gone computer magazines.

    Previous Columns by Kevin Townsend:
    Tags:



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

    Related Posts

    National Security News

    List of 620 Russian spies, featuring one alleged agent at the centre of one of the biggest personal scandals in Wall Street history.

    September 24, 2022 Cyber Security

    Cybersecurity ranked most serious enterprise risk in 2022

    August 31, 2022 Cyber Security

    Registration open for CISA virtual summit on K-12 school safety

    August 31, 2022 Cyber Security

    What do the Trickbot leaks reveal about Russian cybercrime?

    August 31, 2022 Cyber Security

    What cybersecurity measures do CISOs outsource?

    August 30, 2022 Cyber Security

    SIA announces Women in Security Forum scholarship recipients

    August 30, 2022 Cyber Security
    Editors Picks

    Ryanair swings to first-half profit and raises passenger forecast

    November 7, 2022

    Devialet brings its sci-fi design aesthetics to a $790 portable speaker

    November 7, 2022

    Google Cloud Says Running Validator on Solana Blockchain

    November 7, 2022

    European stocks rise as investors boosted by China speculation

    November 7, 2022
    Trending Now

    Evergrande creditors sell ‘Versailles mansion’ plot in Hong Kong

    By techbizweb

    OpenSea Creates Tool for NFT Creators to Enforce Royalties On-Chain

    By techbizweb

    FTSE chairs warn of declining relations with institutional investors

    By techbizweb

    https://www.nationalsportsacademy.com

    slot gacor hari ini

    http://www.inadesfo.org/

    http://www.eueomgbissau.org/

    http://www.congo-mai-mai.net/

    http://www.angelesdelafrontera.org/

    http://fifaworldcup2018schedule.com/

    http://tony4gtrmcr.co.uk/

    http://www.standrewsagreement.org/

    http://www.bob-russell.co.uk/

    http://davidmulholland.co.uk/

    http://railwayhotelenniskillen.com/

    http://www.fantasysportstrades.com/

    http://www.rainleaf-flooring.com

    http://mothersagainstguns.org/

    http://ma-coc.org/

    slot online

    http://www.paradoxmag.com/situs-judi-slot-online-gampang-menang-2021/

    http://www.paradoxmag.com/situs-judi-slot-online-terbaru-2021/

    http://slot-terbaru.net/

    Slot Gacor

    Slot Online

    Situs Slot Gacor

    http://www.appdexterity.com/

    https://cars4kids-deutschland.de/

    https://www.stretchingculture.com/

    https://www.b-123-hp.com/slot-gacor/

    https://denzstaffing.nl/

    https://ezbbqcooking.com/slot-gacor/

    https://www.mbahelp24.com/slot-gacor

    https://minhtanstore.com/slot-jackpot-terbesar/

    https://njbpusupplierdiversity.com/slot-gacor-gampang-menang/

    https://www.floridaspecialtycropfoundation.org/slot-gampang-menang/

    https://childrenscornerpreschool.org/slot-gacor-gampang-menang/

    https://cryptoquoter.com/slot-online-terbaik/

    https://alorkantho24.com/slot-gacor/

    https://ellas.xyz/slot-gacor/

    https://it.dougamatome.xyz/slot-online/

    https://www.daltercume.com/slot-gacor/

    https://josi-ana.dougamatome.xyz/slot88/

    https://josi-ana.dougamatome.xyz/slot-gacor/

    https://fastobserver.com/slot-jackpot-terbesar/

    https://www.planetexperts.com/slot-gacor/

    https://bfsolution.group/slot-bet-kecil/

    https://rustleva.co/slot/

    https://bfsolution.group/slot-bet-kecil/

    https://www.hotelcalimareal.com/togel-online/

    https://anime-game.dougamatome.xyz/slot-gacor-gampang-menang/

    https://anime-game.dougamatome.xyz/togel-online/

    https://bourbonbarrelfoods.com/slot/

    http://suneo39.wp.xdomain.jp/slot/

    https://techbizweb.com/slot-gacor/

    https://www.generalcatalyst.com/18-daftar-slot-gacor-terbaik-gampang-menang-jackpot-hari-ini/

    https://www.hotelcalimareal.com/slot-online/

    https://www.blockgates.io/slot-gacor/

    https://l12.com.br/slot-gacor/

    slot paling gacor

    https://www.donalds-hobby.com/slot-online/

    https://thecryptodirt.com/slot-gacor-hari-ini/

    http://iseta.edu.ar/aulavirtual/app/upload/users/1/1205/my_files/sbobet.html

    http://escuelavirtual.mincit.gov.co/app/upload/users/1/194/my_files/slot.html

    https://www.dev.medecinesfax.org/courses/JUDICASINO/document/slot.html

    http://www.e-archivos.org/cursos/courses/JUDICASINO/document/slot-gacor.html

    http://iesma.com.br/ead/main/upload/users/4/447/my_files/slot.html

    https://www.fundacoop.org/chamilo/app/upload/users/1/1185/my_files/slot.html

    https://fata-aatf.org/eskola/main/upload/users/3/31/my_files/slot.html

    https://uancv.edu.pe/ofinvestigacion/app/upload/users/3/328/my_files/slot-terlengkap.html

    https://micost.edu.my/EL/app/upload/users/2/209/my_files/slot-gacor.html

    https://www.academiacoderdojo.ro/elearningdev/app/upload/users/2/2442/my_files/slot-online.html

    http://campus-cidci.ulg.ac.be/courses/JUDICASINO/document/slot-termurah.html

    https://www.escueladerobotica.misiones.gob.ar/aula-ste/courses/LIVECASINO/document/slot-tergacor.html

    http://ccdipeepccqqfar.usac.edu.gt/chamilo/app/upload/users/3/358/my_files/slot-online.html

    https://cunori.edu.gt/campus/app/upload/users/7/7334/my_files/slot-online.html

    http://u-rus.com.ar/aula/app/upload/users/1/1322/my_files/slot.html

    http://icrodarisoveria.edu.it/chamilo/app/upload/users/1/1855/my_files/slot.html

    https://iestpliliagutierrez.edu.pe/clarolgm/courses/CASINO/document/slot.html

    http://pva.cobach.edu.mx/app/upload/users/7/7379/my_files/slot.html

    http://www.imb-pc-online.edu.gt/PL/app/upload/users/3/373/my_files/slot.html

    http://avcs.upeu.edu.pe/main/upload/users/3333/my_files/slot.html

    https://chamilo.fca.uas.edu.mx/app/upload/users/1/11186/my_files/slot-online/

    TechBizWeb
    Facebook Twitter Instagram Pinterest Vimeo YouTube
    • Home
    • Guest Post
    • About Us
    • Privacy Policy
    • Our Authors
    • Terms and Conditions
    • Contact
    © 2023 Tech Biz Web. Developed by Sawah Dev.

    Type above and press Enter to search. Press Esc to cancel.