A hacking group believed to have ties to Iran has claimed responsibility for a massive cyberattack that exposed information linked to Australia’s $7 billion Land 400 defence program. The group, known as Cyber Toufan, says it accessed the data after breaching several Israeli defence companies.
Cyber Toufan, a pro-Hamas group, shared the stolen material on Telegram. Among the leaked files were images and details about the Australian Defence Force’s (ADF) Land 400 upgrade program, which includes the Redback infantry fighting vehicle being developed by Hanwha Defence Australia, a subsidiary of South Korea’s Hanwha Defence.
Read more…
Source: MSN News
Sign up for the Cyber Security Review Newsletter
The latest cyber security news and insights delivered right to your inbox
Related:
- United Nations calls for moratorium on sale of surveillance tech like NSO Group’s Pegasus
August 13, 2021
The United Nations has called for a moratorium on the sale of “life threatening” surveillance technology and singled out the NSO Group and Israel for criticism. The catalyst for that UN’s action is the recent allegation that NSO Group’s wares have been widely used beyond their intended purpose of national security, and instead put to work ...
- UNC215: Spotlight on a Chinese Espionage Campaign in Israel
August 10, 2021
This blog post details the post-compromise tradecraft and operational tactics, techniques, and procedures (TTPs) of a Chinese espionage group we track as UNC215. While UNC215’s targets are located throughout the Middle East, Europe, Asia, and North America, this report focuses on intrusion activity primarily observed at Israeli entities. This report comes on the heels of the ...
- Black Hat: This is how a naive NSA staffer helped build an offensive UAE security branch
August 4, 2021
What began as an incredible job offer for a naive, young security analyst turned into an explosive case of former US experts unwittingly helping a foreign service create an offensive security branch. Known as Project Raven, a team of over a dozen former US intelligence operatives was poached with promises of job roles that seemed too ...
- ‘DeadRinger’ Targeted Exchange Servers Long Before Discovery
August 4, 2021
Threat actors linked to China exploited the notorious Microsoft Exchange ProxyLogon vulnerabilities long before they were publicly disclosed, in attacks against telecommunications companies aimed at stealing sensitive customer data and maintaining network persistence, researchers have found. Researchers from Cybereason have been tracking multiple cyberespionage campaigns – collectively dubbed “DeadRinger” – since 2017, reporting initially on findings ...
- Here’s 30 servers Russian intelligence uses to fling malware at the West, beams RiskIQ
July 30, 2021
Details of 30 servers thought to be used by Russia’s SVR spy agency (aka APT29) as part of its ongoing campaigns to steal Western intellectual property were made public today by RiskIQ. Russia’s Foreign Intelligence Service “is actively serving malware (WellMess, WellMail) previously used in espionage campaigns targeting COVID-19 research in the UK, US, and Canada,” ...
- DOJ: SolarWinds hackers breached emails from 27 US Attorneys’ offices
July 30, 2021
The US Department of Justice says that the Microsoft Office 365 email accounts of employees at 27 US Attorneys’ offices were breached by the Russian Foreign Intelligence Service (SVR) during the SolarWinds global hacking spree. “The APT is believed to have access to compromised accounts from approximately May 7 to December 27, 2020,” the DOJ said ...

