WASHINGTON: Iranian hackers have become increasingly aggressive and sophisticated, moving from disrupting and defacing US websites to engaging in cyber espionage, security experts say.
According to Silicon Valley-based cybersecurity company FireEye Inc, a group called the Ajax Security Team has become the first Iranian hacking group known to use custom-built malicious software to launch espionage campaigns.
Ajax is behind an ongoing series of attacks on US defense companies and has also targeted Iranians who are trying to circumvent Tehran’s Internet censorship efforts, FireEye said on Tuesday.
Many security experts have said that Iran is behind a series of denial-of-service attacks that have disrupted the online banking operations of major US financial institutions over the past few years.
“I’ve grown to fear a nation state that would never go toe-to-toe with us in conventional combat that now suddenly finds they can arrest our attention with cyber attacks,” Michael Hayden, former director of the CIA and the National Security Agency, told the Reuters Cybersecurity Summit on Monday.
Security experts say Iranian hackers stepped up their campaigns against foreign targets in the wake of the Stuxnet attack on Tehran’s nuclear program in 2010. The Stuxnet computer virus is widely believed to have been launched by the US and prompted Iran to ramp up its own cyber programs.
FireEye researcher Nart Villeneuve said his company is monitoring several Iranian hacking groups and that Ajax seems to have the most advanced methods.
“What we are seeing overall is a larger trend in the Iran hacker community to switch to more subtle espionage campaigns from attacks that make a lot of noise and are designed to attract attention for a particular cause or a particular group,” he told the Reuters summit on Tuesday.
According to FireEye, Ajax was formed by two hackers known as “HUrr!c4nE!” and “Cair3x,” and began by defacing websites. The group became increasingly political after Stuxnet.


