Attacks/Breaches
11/29/2012
11:09 AM
Connect Directly
RSS
E-Mail
50%
50%

U.S. Bank Attackers Dispute Iran Ties

Izz ad-Din al-Qassam Cyber Fighters resurface, not with new DDoS takedowns, but a media interview to explain their motives.

Who Is Hacking U.S. Banks? 8 Facts
Who Is Hacking U.S. Banks? 8 Facts
(click image for larger view and for slideshow)
Remember the Muslim hackers behind the "Operation Ababil" attack campaign against Wall Street banks, which saw leading U.S. financial firms' websites disrupted at preannounced days and times?

The group that's claimed responsibility for the attacks -- calling themselves the Izz ad-Din al-Qassam Cyber Fighters -- is back. Thankfully, however, it's only to grant an interview.

After weeks of website takedowns, the last post to the group's Pastebin account, on October 25, 2012, announced that the group was pausing its distributed denial-of-service (DDoS) attacks in honor of the Muslim Eid al-Adha holiday. That represented the culmination of six weeks of attacks that disrupted the websites of numerous firms, including Bank of America, JPMorgan Chase and Wells Fargo.

In classic hacktivist fashion, however, at the same time as it announced the pause, the group promised to grant a media interview. "To commemorate this breezy and blessing day, we will stop our attack operations during the next days. Instead, we are going to have an interview with one of the American media and press about our ideas and positions," read the group's announcement. "Every press volunteer to interview us, send its full specifications and offers to us throughout (alqassamcyberfighter@myway.com)."

[ Symantec says Iranian accounting software is under attack, but Iran disputes the threat. See Malware Corrupts Iranian Financial Databases. ]

Curiously, the interview that resulted from that open offer was apparently granted to Flashpoint Partners, which describes itself as a "consulting and data services enterprise focused on threat actors in cyberspace," and says its "customers and partners" include the Department of Defense, NBC and the Department of Justice.

What revelations does the interview with Flashpoint Partners contain? For starters, the hacktivists reiterated their previous assertions that the targeting of U.S. banks' websites was in retaliation for the release of the Innocence of Muslims film that mocks the founder of Islam. A 13-minute clip of the film was uploaded in September to YouTube, and the group has demanded that the video be removed from the Internet.

The group argued in its interview that the website disruptions were commensurate with the perceived insult. "We have not pursued any hit or destruction in the United States. We have selected the banks because we should have done something proportional to what has happened against us," they said. "In the system where ... religion and sacred things are not honorable, and only material, money and finance have value, this seems a suitable and effective ... [action] and can influence governors and decision makers."

What are the hacktivists' overall political aims? The name of their group apparently references "Izz ad-Din al-Qassam, a Muslim holy man who fought against European forces and Jewish settlers in the Middle East in the 1920s and 1930s," according to The New York Times. But in the interview, the group's representative said the choice of name was apolitical. "We don't have connection with any fractional or political structure," according to the group. "Also we are not aware of nationality composition of our group's members. Our unifying and gathering factor is protesting against insulting sanctities."

U.S. government officials have blamed Iran for sponsoring the banking website disruptions for which the group has claimed credit. But in the interview, the hacktivists disputed that assertion. "We are not dependent on any government. We merely wanted to protest against the insulting movie," they said. "But there are some ones who want to portray this action as political. So they are deflecting the issue to the side of their political leanings."

Interestingly, the group also distanced itself from the Hilf-ol-Fozoul blog, which had suggested that the hacktivist group's attacks were the work of a crowdsourced, Anonymous-like operation. Instead, the Izz ad-Din al-Qassam Cyber Fighters said the only official communications from their group are disseminated via their Pastebin account.

Asked whether or not the group was using botnets to attack service providers and hosting companies, as some security experts have suggested -- and other security experts have disputed -- the group said that "any of [the] technical comments during the attacks have made us doubtful about [the] technical competence of American companies' security consultants" and noted that "many of [the] technical statements about this case are not scientific, reliable or significant."

Has Operation Ababil now run its course? In the interview, the group of "volunteer hackers" threatened that unless the Innocence of Muslims film gets excised from the Internet, it could resume its attacks.

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Flash Poll
Current Issue
Cartoon
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-0972
Published: 2014-08-01
The kgsl graphics driver for the Linux kernel 3.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, does not properly prevent write access to IOMMU context registers, which allows local users to select a custom page table, and consequently write ...

CVE-2014-2627
Published: 2014-08-01
Unspecified vulnerability in HP NonStop NetBatch G06.14 through G06.32.01, H06 through H06.28, and J06 through J06.17.01 allows remote authenticated users to gain privileges for NetBatch job execution via unknown vectors.

CVE-2014-3009
Published: 2014-08-01
The GDS component in IBM InfoSphere Master Data Management - Collaborative Edition 10.0 through 11.0 and InfoSphere Master Data Management Server for Product Information Management 9.0 and 9.1 does not properly handle FRAME elements, which makes it easier for remote authenticated users to conduct ph...

CVE-2014-3302
Published: 2014-08-01
user.php in Cisco WebEx Meetings Server 1.5(.1.131) and earlier does not properly implement the token timer for authenticated encryption, which allows remote attackers to obtain sensitive information via a crafted URL, aka Bug ID CSCuj81708.

CVE-2014-3534
Published: 2014-08-01
arch/s390/kernel/ptrace.c in the Linux kernel before 3.15.8 on the s390 platform does not properly restrict address-space control operations in PTRACE_POKEUSR_AREA requests, which allows local users to obtain read and write access to kernel memory locations, and consequently gain privileges, via a c...

Best of the Web
Dark Reading Radio