Express Computer
Home  »  News  »  Iranian hackers found using tool to extract 2FA SMS codes

Iranian hackers found using tool to extract 2FA SMS codes

0 180

Researchers at cybersecurity firm Check Point have unravelled an ongoing surveillance operation by Iranian entities who have used multiple tools including an Android backdoor that extracts two-factor authentication (2FA) codes from SMS messages and records the phone’s voice surroundings.

The hacking group, nicknamed Rampant Kitten by Check Point, largely managed to keep the operations under the radar for at least six years.

The hackers have been taking advantage of multiple attack vectors to spy on their victims, attacking victims’ personal computers and mobile devices, and their supposedly private, secure communications via Telegram and other social networks, Check Point said in a blog post on Friday.

According to Check Point, the tools deployed by the hacking group appear to be mainly used against Iranian minorities, anti-regime organisations and resistance movements such as Association of Families of Camp Ashraf and Liberty Residents (AFALR), Azerbaijan National Resistance Organization and Balochistan residents.

Among the different attacks Check Point found were four variants of Windows infostealers intended to steal victims’ personal documents as well as access their Telegram Desktop and KeePass (an open source password manager) account information.

The tool and methods used by the threat actors also included an Android backdoor mentioned earlier and malicious Telegram phishing pages, distributed using fake Telegram service accounts.

“Since most of the targets we identified are Iranian nationals, it appears that in common with other attacks attributed to the Islamic Republic, this might be yet another case in which Iranian threat actors are collecting intelligence on potential opponents to the regime,” said the blog post.

–IANS

Get real time updates directly on you device, subscribe now.

Leave A Reply

Your email address will not be published.

LIVE Webinar

Digitize your HR practice with extensions to success factors

Join us for a virtual meeting on how organizations can use these extensions to not just provide a better experience to its’ employees, but also to significantly improve the efficiency of the HR processes
REGISTER NOW 
India's Leading e-Governance Summit is here!!! Attend and Know more.
Register Now!
close-image
Attend Webinar & Enhance Your Organisation's Digital Experience.
Register Now
close-image
Enable A Truly Seamless & Secure Workplace.
Register Now
close-image
Attend Inida's Largest BFSI Technology Conclave!
Register Now
close-image
Know how to protect your company in digital era.
Register Now
close-image
Protect Your Critical Assets From Well-Organized Hackers
Register Now
close-image
Find Solutions to Maintain Productivity
Register Now
close-image
Live Webinar : Improve customer experience with Voice Bots
Register Now
close-image
Live Event: Technology Day- Kerala, E- Governance Champions Awards
Register Now
close-image
Virtual Conference : Learn to Automate complex Business Processes
Register Now
close-image