Iran-linked CyberAv3ngers suspected in attacks on Minnesota water systems


Security researchers at Tenable suspect the Iran-linked faux hacktivist outfit CyberAv3ngers was behind the cyberattack that disrupted more than 30 Minnesota water facilities.

Neither state-level nor federal officials have made any claims regarding attribution for the attacks, however, Tenable reckons the operational pattern is consistent with the crew’s previous raids, noting the timing relative to recent government warnings.

The Cybersecurity and Infrastructure Security Agency (CISA) updated an advisory on Iran-linked attackers targeting programmable logic controllers (PLCs) across critical infrastructure on July 22, four days before Minnesota said the attacks targeted its systems.

Read more…
Source:  The Register


Sign up for the Cyber Security Review Newsletter
The latest cyber security news and insights delivered right to your inbox


Related:

  • Overflowing Water Tank Linked to Russian Cyber Attack

    April 19, 2024

    A water tank in Texas overflowed after a cyber attack in January, and a new report is linking the incident to hackers backed by the Russian government. On Jan. 18, city officials in Muleshoe were alerted to an overflowing water tank. When they checked it out, they learned that a software hack had caused a system ...

  • The Fall of LabHost: Law Enforcement Shuts Down Phishing Service Provider

    April 18, 2024

    In late 2021, LabHost (AKA LabRat) emerged as a new PhaaS platform, growing over time to eventually offer dozens of phishing pages targeting banks, high-profile organizations, and other service providers located around the world, but most notably in Canada, the US, and the UK. The popularity of the platform meant that at the time of the ...

  • #StopRansomware: Akira Ransomware summary

    April 18, 2024

    Since March 2023, Akira ransomware has impacted a wide range of businesses and critical infrastructure entities in North America, Europe, and Australia. In April 2023, following an initial focus on Windows systems, Akira threat actors deployed a Linux variant targeting VMware ESXi virtual machines. As of January 1, 2024, the ransomware group has impacted over 250 ...

  • US 911 emergency call line outage resolved in some areas

    April 18, 2024

    Emergency services on the 911 telephone call line were restored late on Wednesday in parts of the United States, officials said, following a widespread outage across all of South Dakota and in parts of Nebraska, Nevada and Texas. Officials in South Dakota, Nevada and Las Vegas said 911 services had been restored, but without identifying the ...

  • From Social Engineering to DMARC Abuse: TA427’s Art of Information Gathering

    April 16, 2024

    Proofpoint researchers track numerous state-sponsored and state-aligned threat actors. TA427 (also known as Emerald Sleet, APT43, THALLIUM or Kimsuky), a Democratic People’s Republic of Korea (DPRK or North Korea) aligned group working in support of the Reconnaissance General Bureau, is particularly prolific in email phishing campaigns targeting experts for insight into US and the Republic of ...

  • DHS: Applications Open for FY24 Targeted Violence and Terrorism Prevention Grants

    April 15, 2024

    WASHINGTON – The Department of Homeland Security (DHS) today released the Fiscal Year (FY) 2024 Targeted Violence and Terrorism Prevention (TVTP) Grant Program Notice of Funding Opportunity (NOFO). Administered by the DHS Center for Prevention Programs and Partnerships (CP3) and the Federal Emergency Management Agency (FEMA), the TVTP Grant Program is the only federal government grant ...