The Jerusalem Post
Jpost search icon google-icon iphone
  Set as Homepage
Tue, May 21, 2013   12 Sivan, 5773
newspapers magazines
 
    • Breaking News
    • Diplomacy & Politics
    • Defense
    • National
    • Mideast
    • Syria
    • Iran
    • World
    • Business
    • Sports
    • Health & Science
    • Environment
  • Video
  • Opinion
    • Columnists
    • Editorials
    • Op-Eds
    • Letters
  • Jewish World
  • Lifestyle
    • Arts & Culture
    • Food & Wine
    • Travel
  • Features
    • Insights & Features
    • Week in review
    • On the Web
    • Shalva Superheroes
    • Obama in Israel
  • Blogs
    • In the news
    • Judaism
    • From the Middle East
    • Lifestyle
    • Aliya
    • Science and Technology
  • JPost Apps
    • iPhone app
    • iPad app
    • Android app
    • Twitter
    • Facebook
    • RSS feeds
    • JPost Toolbar
    • JPost Newsletter
    • JPost Alert
  • Premium Zone
    • The Jerusalem Report
    • The Experts
    • 20 Questions
    • e-paper
    • Ivrit
    • Christian Edition
    • Dash
    • Magazine
    • Metro
    • In Jerusalem
  • French
    • Politique & Social
    • Affaires Palestiniennes
    • Diplomatie & Monde
    • Art & Culture
    • Israel
  • Green Israel
JPost Learn Hebrew  
Advertise with us  
Nefesh Guided Aliyah  
Eldan  
AFMDA  
Africa Israel Group  
Isram Group  
Kupat Ha  
JPost Twitter  
JPost Facebook  
Classifieds  
         
 
 
    
Breaking News
 
 
  • JPost.com
  • International
 

Researchers: Cyber spying is expanding in Iran

By REUTERS
08/29/2012 16:44
Tweet

Even after security experts below operations' cover, cyber espionage campaign widens, according to research firm that discovered Mahdi Trojan.

Stuxnet Virus
Stuxnet Virus Photo: Courtesy

BOSTON - The scope of a cyber espionage campaign targeting Iran and other parts of the Middle East has widened, even after security experts blew the operation's cover last month, according to the research firm that discovered the Mahdi Trojan.

Israeli security company Seculert said that it has identified about 150 new Mahdi victims over the past six weeks as the developers of the virus have changed the code to evade detection from anti-virus programs. That has brought the total number of infections found so far to nearly 1,000, the bulk of them in Iran.

  • 'Israel among top 3 in cyber attack defense'
  • IDF graduates first ‘Cyber Defenders’ class

"These guys continue to work," Seculert Chief Technology Officer Aviv Raff said via telephone from the company's headquarters in Israel.

The decision to keep the operation running implies that Mahdi's operators were not particularly worried about getting caught, said Roel Schouwenberg, a senior researcher with Kaspersky Lab, which has collaborated with Seculert in analyzing Mahdi.

Schouwenberg said that some viruses are designed for stealth because they become useless if they are discovered. He pointed to the Stuxnet Trojan that targeted Iran's nuclear program in 2010. After that customer-built virus was uncovered by a security researcher in Belarus, authorities in Iran discovered it in a uranium enrichment facility that it had targeted.

Click here for full Jpost coverage of the Iranian threat

Mahdi is a "less professional" operation that runs on technology built with widely available software, according to Schouwenberg.

"If the quality of your operation is not that high, then maybe you don't care about being discovered," he said. "But the scary thing is that it can still be effective."

The Mahdi Trojan lets remote attackers steal files from infected PCs and monitor emails as well as instant messages, Seculert and Kaspersky said. It can also record audio, log keystrokes and take screen shots of activity on those computers.

The firms said they believed multiple gigabytes of data have been uploaded from targeted machines.

Targets of Mahdi include critical infrastructure firms, engineering students, financial services firms and government embassies located in five Middle Eastern countries, with the majority of the infections in Iran, according to the two security firms.

The bulk of the new victims were in Iran, which is where most infections have occurred to date, according to Seculert, though a few were identified in the United States and Germany.

The two firms have declined to identify specific victims.

Raff said that he suspects the campaign is being run by hacker activists, or "hactivists," who are either funded by a government or provide information they collect to a nation for ideological reasons. He declined to say which country might be involved.

Seculert and Kaspersky dubbed the campaign Mahdi after a term referring to the prophesied redeemer of Islam because evidence suggests the attackers used a folder with that name as they developed the software to run the project.

They also included a text file named mahdi.txt in the malicious software that infected target computers.

  • Send
  • Large
  • Small
  • Print
  • Share
Most Viewed in
1
Israeli restaurateur goes viral with online meltdown
2
S.Korea deploys Israeli missile on border with North
3
UK set to deport radical Muslim cleric to Jordan
4
US discussing religious freedom worries with Israel
JPost Community
Tweet
Cyber Iran Virus Israel Nuclear Stuxnet
Share this article
Tweet
Share
Send
Your comment must be approved by a moderator before being published on JPost.com. Disqus users can post comments automatically.

Comments must adhere to our Talkback policy. If you believe that a comment has breached the Talkback policy, please press the flag icon to bring it to the attention of our moderation team.
JPost Services
conferenceConference
newsletterNewsletter
iphoneMobile Apps
kotelcamKotel Cam
kolboJPost Alert
premiumPremium
JPost TV News  
Mobile Apps  
Bank Hapoalim  
Meir Panim  
Yad Ezra  
Rambam Hospital  
TourLuxe  
Zev Goldstein PLLC  
Penrose Gallery  
JPost Premium Zone  
JPost kotel Camera  
         
 
Israel Focus
JPost TV News
Coming soon to a screen near you!  
Nefesh B'Nefesh Guided Aliyah
Already living in Israel? Enjoy the Benefits of Aliyah!  
Give "Freedom" this Passover
to needy Israeli families. Donate now  
Intelligence Squared
The international debate forum, announces it is coming to Israel  
Bank Hapoalim
Israeli's number one bank  
Jerusalem Post Lite
Lite Edition of the Jerusalem Post for English improvement  
Learn Hebrew with us
Get 10 minutes free personal coaching in Hebrew through phone or Skype  
JPost newspapers
Sign up for the JPost newspapers and receive one month free subscription  
Kosher English Magazine
English language weekly magazine - especially for religious people  
JReport Kindle Edition
Now you can get the Jerusalem Report directly to your Kindle  
JPost Premium Edition
The very best articles are available only in our Premium edition  
Lifestyle Magazine
 
 
Real Estate
Don't Look For a House!
In Israel, our website will do it for you!  
 
Travel
Eldan Rent a Car
20% off all Car Rental Reservations in Israel  
Hertz Car Rental
Special Online Discounts!  
The King David Jerusalem Hotel
One of the world's truly iconic hotels, and a Jerusalem landmark  
 
 
 

Sites Of Interest:

Jerusalem Hotels
KKL-JNF
Poalim Online
BreitBart.com
Our Friends
Jerusalem Attractions
Jerusalem Tours
itraveljerusalem.com

JPost sites:

Learn Hebrew
The Jerusalem Report
Our Magazines
JPost Edition Francaise
Green Israel
Christian World
Jerusalem Post Lite

Services:

JPost Mobile Apps
JPost Premium
JPost Newsletter
JPost Toolbar
JPost News Ticker
JPost RSS feeds
JPost Archives
JPost Alert
JPost Kotel Cam

JPost Conferences:

NYC Conference
Diplomatic Conference

Information:

About Us
Feedback
Staff E-mails
Copyright
Sitemap
News Partners
Advertise with Us
Price List
Statistics
Ad Specs
Terms Of Service
Jpost.com, the online edition of the Jerusalem Post Newspaper - the most read and best-selling English-language newspaper in Israel. For analysis and opinion from Israel, the Jewish World and the Middle East. Jpost.com offers expert and in-depth reporting from Israel, the Jewish World and the Middle East, including diplomacy and defense, the Palestinian-Israeli conflict, the Arab Spring, the Mideast peace process, politics in Israel, life in Jerusalem, Israel's international affairs, Iran and its nuclear program, Syria and the Syrian civil war, Lebanon, the Palestinian Authority, the West Bank and Gaza Strip, Israel's world of business and finance, and Jewish life in Israel and the Diaspora.
 
About Us | Advertise with Us | Subscribe | Premium | Newsletter | RSS | Contact Us
 
All rights reserved © The Jerusalem Post 1995 - 2012