Iranian Cyber-Activities in the Context of Regional Rivalries and International Tensions
Total Page:16
File Type:pdf, Size:1020Kb
CSS CYBER DEFENSE PROJECT Hotspot Analysis: Iranian cyber-activities in the context of regional rivalries and international tensions Zürich, May 2019 Version 1 Risk and Resilience Team Center for Security Studies (CSS), ETH Zürich Iranian cyber-activities in the context of regional rivalries and international tensions Authors: Marie Baezner © 2019 Center for Security Studies (CSS), ETH Zürich Contact: Center for Security Studies Haldeneggsteig 4 ETH Zürich CH-8092 Zürich Switzerland Tel.: +41-44-632 40 25 [email protected] www.css.ethz.ch Analysis prepared by: Center for Security Studies (CSS), ETH Zürich ETH-CSS project management: Tim Prior, Head of the Risk and Resilience Research Group Myriam Dunn Cavelty, Deputy Head for Research and Teaching, Andreas Wenger, Director of the CSS Disclaimer: The opinions presented in this study exclusively reflect the authors’ views. Please cite as: Baezner, Marie (2019): Hotspot Analysis: Iranian cyber-activities in context of regional rivalries and international tensions, May 2019, Center for Security Studies (CSS), ETH Zürich. 1 Iranian cyber-activities in the context of regional rivalries and international tensions Table of Contents 1 Introduction 4 2 Background and chronology 5 3 Description 9 3.1 Attribution and actors 9 Iranian APTs 9 Iranian patriotic hackers 11 Western actors 12 3.2 Targets 12 Iranian domestic targets 12 Middle East 12 Other targets 13 3.3 Tools and techniques 13 Distributed Denial of Service (DDoS) attacks 13 Fake personas, social engineering and spear phishing 13 Malware 13 4 Effects 14 4.1 Social effects 14 4.2 Economic effects 15 4.3 Technological effects 15 Low technical sophistication of Iranian APTs 15 Stuxnet as a turning point 16 4.4 International effects 16 Iranian use of cyber-operations as asymmetrical warfare technique 16 Proxy wars with regional rivals in physical and cyber realms 16 The JCPOA and cyber-activities 17 Iranian international influence campaigns 17 5 Policy Consequences 18 5.1 Improving cybersecurity 18 5.2 Information sharing 18 5.3 Building awareness of Iranian influence campaigns 18 5.4 Monitoring of US – Iran relations 18 6 Annex 1 19 7 Annex 2 25 8 Annex 3 26 9 Glossary 27 10 Abbreviations 28 11 Bibliography 29 2 Iranian cyber-activities in the context of regional rivalries and international tensions hard-disk contents and rendered computers useless. Executive Summary Iranian APTs have used a mix of freely available, commercial and custom-made malware to compromise their targets and steal relevant information. Iranian Targets: Multiple industries, government patriotic hackers have also played a significant role in institutions, Non-Governmental cyberspace, but their actions have been primarily 1 Organizations (NGOs) in Western and limited to DDoS attacks. However, Stuxnet and Flame Middle Eastern states and Iranian are evidence that the US and Israel have targeted the dissidents in Iran and abroad. Islamic Republic. 2 Tools: Distributed Denial of Service (DDoS), Effects fake personas on social media for spear The social effects of cyber-activities in Iran phishing and malware. consist of control over internet content and the Effects: Surveillance of Iranian opposition, surveillance of opposition figures as part of economic costs due to destructive governmental control over the information sphere. cyberattacks and DDoS attacks, low sophistication but efficient enough Iranian authorities strictly regulate websites that are cyberattacks, Stuxnet as wakeup call for accessible on Iranian territory by censoring websites the international community, cyber- judged to be contrary to Islamic values. Opposition operations as asymmetrical warfare figures’ activities are also closely monitored on the technique, proxy wars transposed to internet. cyberspace, decrease of malicious cyber- Economic effects comprise the economic costs of activities after the signature of the Joint the various cyberattacks attributed to Iranian APTs and Comprehensive Plan Of Action (JCPOA) patriotic hackers. Companies in the Middle East have and Iranian actors conducting influence had to replace damaged computers after destructive campaigns. attacks, and US banks have had to bear the financial Timeframe: From mid-2000s and still ongoing. costs of DDoS attacks. One technology effect concerns the low Iran is an important actor in the Middle East. The sophistication of Iranian APTs’ cyberattacks, which has country stands out from its neighbors because of its not prevented them from achieving their strategic goals. history, economy and religion. Due to these differences, Another technological effect consists of the fact that Iran’s neighbors and parts of the international Stuxnet constituted a turning point in cybersecurity in community see the Islamic Republic as a regional rival terms of awareness of cyber capabilities. generating tensions in the region. With regard to There were multiple effects of Iranian-related cybersecurity, Iran is also an interesting actor, both as a cyber-activities on the international level. First, Iranian target and as a threat actor. As a target, Iran discovered authorities consider cyber-operations as tools for Stuxnet in its nuclear facility at Natanz in 2010 and is asymmetrical warfare. The Iranian government is aware regularly targeted by the US and Israel. As a threat actor, that it cannot compete with the US or US allies in Iranian Advanced Persistent Threats (APTs) regularly military terms, but cyber-operations give Iran the involve destructive and cyberespionage campaigns, opportunity to harass its adversaries with limited risks of including a recent online influence campaign in the US. retaliation because of low barriers of entry and relative This Hotspot Analysis examines cyber-activities in anonymity. Second, Iran fights proxy wars against its relation to Iran within the context of regional rivalry and regional rivals in both the physical world and in international tensions. The objective of this report is to cyberspace. Third, the number of malicious cyber- understand the dynamics of these cyberspace activities activities between the US and Iran diminished after the in such complex settings. JCPOA was signed and increased again once the US Description withdrew from the agreement. This confirms that state- Due to regional rivalry and international tensions, sponsored cyber-activities are related to events in the Iran has engaged in multiple and diverse cyber-activities. physical realm. Finally, Iranian APTs have been involved While a majority of sources report on APTs that are in online influence campaigns in the US mid-term nebulous and flexible entities with likely ties to the elections to influence political opinion in favor of Iranian Iranian authorities, a minority also reports on actors interests. targeting Iran. The majority of Iranian cyber-activities Policy Consequences consists of espionage targeting various industries, Policy recommendations focus on improving government institutions, NGOs and Iranian dissidents. cybersecurity, sharing information on Iranian APTs, The goal of these campaigns is to gather information raising awareness of influence campaigns and relevant to Iranian authorities. While other cyberattacks monitoring US-Iran relations. have had destructive characteristics in that they wiped 1 Abbreviations are listed in Section 10. 2 Technical terms are explained in a glossary in Section 9. 3 Iranian cyber-activities in the context of regional rivalries and international tensions against industries, government institutions and Non- 1 Introduction Governmental Organizations (NGOs) in Western states Iran is a significant actor in the Middle East and and in the Middle East. Finally, the section looks at tools also in cyberspace. Because of its history, economy, and techniques used in the Iranian context. This section religion and political ambitions, Iran cannot be ignored demonstrates that Iranian patriotic hackers used as a regional power and is considered as a threat by its Distributed Denial of Service (DDoS) attacks, that Iranian neighbors. While access to certain internet content is APTs created fake personas on social media for spear strictly controlled inside Iran, Iranian Advanced phishing campaigns and used a mix of freely available, Persistent Threats (APTs)3 have become infamous for commercial and custom-made malware in their targeting energy companies in neighboring countries cyberattacks, and that Western actors used with destructive malware4 and cyberespionage sophisticated malware against Iranian targets. campaigns. However, Iran is also known for being the Section 4 examines the effects of cyber-activities target of highly sophisticated cyberattacks, the most at the national and international levels. The first famous being Stuxnet, which was jointly developed by subsection analyzes the effects of Iranian authorities’ the US and Israel. control over internet content and online surveillance of This Hotspot Analysis analyzes cyber-activities in dissidents. The second subsection details the economic relation to Iran in the context of its regional rivalry with effects of destructive cyberattacks on energy companies its neighbors and its relationship with the US, which has and the economic effects of DDoS attacks. The third come under renewed strain. In this context, subsection examines the fact that Iranian APTs are not cyberattacks are instruments that states can deploy in technically sophisticated but still manage to achieve case of tensions, whether to defuse heightened tension their