Close Menu
Indo Guard OnlineIndo Guard Online
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
What's Hot

RCE Critical Error RCE Rate 9.9 CVSS in Backup and Replication

June 18, 2025

Google Chrome Zero-Day Cve-2025-2783 is operated by Taxoff to expand Trinper Backdoor

June 17, 2025

Langsmith Bug can expose the Openai keys and users’ data through malicious agents

June 17, 2025
Facebook X (Twitter) Instagram
Facebook X (Twitter) Instagram YouTube
Indo Guard OnlineIndo Guard Online
Subscribe
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
Indo Guard OnlineIndo Guard Online
Home » AI, fake hosting and psychological warfare
Global Security

AI, fake hosting and psychological warfare

AdminBy AdminNovember 1, 2024No Comments4 Mins Read
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link


U.S. and Israeli cybersecurity agencies have issued a new advisory that attributes an Iranian cyber group to the 2024 Summer Olympics and compromised a French commercial supplier of dynamic displays to show messages condemning Israel’s participation in the sporting event.

The activity was anchored to an entity known as Emenet Pasargadwhich the agencies say has been operating under the name Aria Sepehr Ayandehsazan (ASA) since mid-2024. The wider cyber security community tracks it down as Cotton Sandstorm, Haywire Kitten and Marnanbridge.

“The group demonstrated new prowess in its efforts to conduct cyber-enabled information operations through mid-2024 using multiple covert characters, including multiple cyber operations that took place during and targeted the 2024 Summer Olympics — including the compromise of French commercial dynamic display provider,” reports the advisory.

The ASA, the US Federal Bureau of Investigation (FBI), the Treasury Department and Israel’s National Cyber ​​Directorate said they also stole content from IP cameras and used artificial intelligence (AI) software such as Remini AI Photo Enhancer, Voicemod and Murf AI for voice modulation and Appy Pie to generate the image spreading propaganda.

Cyber ​​security

Assessed as part of Iran’s Islamic Revolutionary Guard Corps (IRGC), the threat actor is known for its cyber and influence operations within persons Others include Al-Toufan, Anzu Team, Cyber ​​Cheetahs, Cyber ​​Flood, For Humanity, Menelaus and Market of Data.

One recently noticed tactic involves the use of bogus hosting resellers to provide operational server infrastructure for their own purposes, as well as for an entity in Lebanon to host Hamas-related websites (such as alqassam(.)ps).

“Since approximately mid-2023, ASA has used multiple hosting providers for infrastructure management and obfuscation,” the agencies said. “These two providers are Server Speed ​​(server-speed(.)com) and VPS-agent (vps-agent(.)net).”

“ASA has created its own resellers and purchased server space from European providers, including the Lithuanian company BAcloud and Stark Industries Solutions/PQ Hosting (located in the UK and Moldova, respectively). The ASA then uses these resellers as a front to provide operational servers to its own cyber actors for malicious cyber activities.”

An attack on an unnamed French commercial display vendor took place in July 2024 using a VPS agent infrastructure. He sought to show photo montages criticizing the participation of Israeli athletes in the 2024 Olympic and Paralympic Games.

In addition, the ASA is alleged to have attempted to contact family members of Israeli hostages following the Israel-Hamas war in early October 2023 under the persona Contact-HSTG and to send messages that could “cause additional psychological effects and cause further trauma.”

The threat actor was also linked to another entity known as Cyber ​​Court, which promoted the activities of several self-managed hacktivist cover groups on a Telegram channel and a dedicated website created for the purpose (“cybercourt(.)io”) .

Cyber ​​security

Both domains, vps-agent(.)net and cybercourt(.)io, were seized following a joint law enforcement operation by the US Attorney’s Office for the Southern District of New York (SDNY) and the FBI.

That’s not all. After the start of the war, the ASA is believed to have continued its efforts to count and obtain content from IP cameras in Israel, Gaza and Iran, and to collect information on Israeli fighter pilots and unmanned aerial vehicle (UAV) operators through sites such as knowem.com , facecheck.id, socialcatfish.com, ancestry.com and familysearch.org.

It comes after the US State Department announced a reward of up to $10 million for information leading to the identification or location of people linked to an IRGC-linked hacking group called Shahid Hemmat for attacking critical US infrastructure.

“Shahid Hemmat has been associated with malicious cyber actors targeting the US defense industry and the international shipping sector,” it said. said.

“As a component of the IRGC-CEC (Cyber ​​Electronic Command), Shahid Hemmat is linked to other IRGC-CEC-linked individuals and entities, including Mohammad Bagher Shirinkar, Mahdi Lashgarian, Alireza Shafi Nasab and the front company Emenet Pasargad, Dade Afzar . Arman (DAA) and Mehrsam Andishe Saz Nik (MASN)”.

Did you find this article interesting? Follow us Twitter  and LinkedIn to read more exclusive content we publish.





Source link

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Admin
  • Website

Related Posts

RCE Critical Error RCE Rate 9.9 CVSS in Backup and Replication

June 18, 2025

Google Chrome Zero-Day Cve-2025-2783 is operated by Taxoff to expand Trinper Backdoor

June 17, 2025

Langsmith Bug can expose the Openai keys and users’ data through malicious agents

June 17, 2025

How to protect backups

June 17, 2025

Silver Fox Apt has on target Taiwan with sophisticated GH0Stcringe and Holdinghands Rats Malicious Programs

June 17, 2025

Google warns about scattered spider attacks focused on IT -commander by US insurance firms

June 17, 2025
Add A Comment
Leave A Reply Cancel Reply

Loading poll ...
Coming Soon
Do You Like Our Website
: {{ tsp_total }}

Subscribe to Updates

Get the latest security news from Indoguardonline.com

Latest Posts

RCE Critical Error RCE Rate 9.9 CVSS in Backup and Replication

June 18, 2025

Google Chrome Zero-Day Cve-2025-2783 is operated by Taxoff to expand Trinper Backdoor

June 17, 2025

Langsmith Bug can expose the Openai keys and users’ data through malicious agents

June 17, 2025

How to protect backups

June 17, 2025

Silver Fox Apt has on target Taiwan with sophisticated GH0Stcringe and Holdinghands Rats Malicious Programs

June 17, 2025

Google warns about scattered spider attacks focused on IT -commander by US insurance firms

June 17, 2025

Password “B” in Sitecore XP Sparks Sparks Erriss RCE when deploying businesses

June 17, 2025

Are you forgotten accounts of advertising services that leave you risk?

June 17, 2025
About Us
About Us

Provide a constantly updating feed of the latest security news and developments specific to Indonesia.

Facebook X (Twitter) Pinterest YouTube WhatsApp
Our Picks

RCE Critical Error RCE Rate 9.9 CVSS in Backup and Replication

June 18, 2025

Google Chrome Zero-Day Cve-2025-2783 is operated by Taxoff to expand Trinper Backdoor

June 17, 2025

Langsmith Bug can expose the Openai keys and users’ data through malicious agents

June 17, 2025
Most Popular

In Indonesia, crippling immigration ransomware breach sparks privacy crisis

July 6, 2024

Why Indonesia’s Data Breach Crisis Calls for Better Security

July 6, 2024

Indonesia’s plan to integrate 27,000 govt apps in one platform welcomed but data security concerns linger

July 6, 2024
© 2025 indoguardonline.com
  • Home
  • About us
  • Contact us
  • Privacy Policy

Type above and press Enter to search. Press Esc to cancel.