A U.S. court has granted Microsoft the authority to seize domain names in order to take down a phishing campaign run by a notorious group of Iranian hackers.
In a poston Microsoft’s official blog, Customer Security & Trust VP Tom Burt shared details from the now unsealed caseit filed in the U.S. District Court for Washington D.C against the hacker group called Phosphorus. The group is also known under the names APT 35, Charming Kitten, and Ajax Security Team.
Microsoft’s Digital Crimes Unit was allowed to take control of 99 domains in order to stop the hackers’ attacks. Domains such as outlook-verify.net, yahoo-verify.net, and verification-live.com were being used in spear-phishing campaigns by the Iranian hackers.
Spear-phishing is a method of attack that relies on social engineering, where a hacker tricks an individual or group into believing that they are a trusted source through an email or web address. The hacker then uses that trust to obtain passwords or other sensitive information from their target.
Phosphorus targeted U.S. businesses and government agencies as well as activists and journalists. As Techcrunchpoints out, former U.S. Air Force intelligence officer turned spy Monica Witt reportedly has connections to the hacker group. Witt defected to Iran and is currently a fugitive wanted by the FBI for alleged espionage. It is believedthat Witt provided the Iranian hackers with intelligence regarding U.S. officials and her former colleagues. Using this information, the hackers can more accurately pinpoint their spear-phishing campaigns against certain individuals.
According to Microsoft, Phosphorus would send a link containing malicious software under the guise of a friendly source, sometimes even posing as a target’s contact on social media. The hackers would be able to use that software to access the victim’s computer. The group also deployed another attack using the now Microsoft-controlled domain names to trick its targets into thinking there was a security risk flagged on their Outlook or Yahoo account. Upon clicking on the phishing link, the target would be prompted to login to their account, effectively providing their password to the hackers.
This isn’t the first time a U.S. court granted Microsoft the authority to take control of domain names connected to phishing campaigns. Last year, a federal court injunction allowed Microsoft to seize domains deployed by hackers that infringe on the company’s trademarks. Microsoft used that authorityto terminate spear-phishing campaigns set up my the Russian hacker group known as Fancy Bear, which was targeting U.S. politicians, Congressional staffers, and think tanks.
Copyright © 2023 Powered by
Microsoft gains control of domains used by Iranian hackers linked to U.S. fugitive-书香门户网
sitemap
文章
57856
浏览
23
获赞
6451
What TechSpot Writers Want in Windows 10
The look on this man's face in Melania Trump's latest tweet is actually perfect
Melania Trump will soon learn that a picture is worth a whole lot more than 1,000 words once it's poSpotify is testing emergency alerts
Spotify appears to be testing an emergency alert — but the whole thing is still in the very eaWhat is the newest Xbox?
You're here because you just can't figure out which Xbox is actually the newest and most powerful onSex toy designers react to the wild sex toy in 'Watchmen'
I admit I don’t know much about Watchmen —the comic book series, the 2009 film, or the nTwitter quickly made a glorious meme out of that massive Oscars mess
What La La Landproducer Jordan Horowitz lost in a Best Picture Academy Award, he gained in memes.JusNature documentarian Sir David Attenborough is now an adorable cartoon
Sir David Attenborough is a renowned documentarian and the golden voice behind such works as PlanetSamsung Galaxy Watch 7 vs. Apple Watch Series 9: What are the differences?
It'stime, terrible pun intended, for a Samsung Galaxy Watch 7 vs. Apple Watch Series 9 face-off. AtMom goes to the bathroom for 45 seconds and returns to find her toddler on a treadmill
If you've been around little kids for even a second, you know their greatest threat is often themselStuff Your Kindle Day Sept. 2024: How to get free books
GET FREE E-BOOKS:Stuff Your Kindle Day officially kicked off on Sept. 5, but hundreds, if not thousawatchOS 11 public beta: 5 new features that should make your life easier
The watchOS 11 public beta launched on Monday, July 15, allowing testers to explore the new featuresBackground check company breached, nearly 3 billion exposed in data theft
You might be affected by one of the biggest data breaches ever and not even know it.A recent class aNew York City blackouts always bring the wildest photos
It's rare to catch New York City, the so-called "city that never sleeps," at rest. Not even SaturdayLyft already met its 2017 goal to expand to 100 new cities
Lyft has already met its major goal for 2017. The ride-hailing company on Thursday launched in 10 neJason Chaffetz and Mitch McConnell are the new 'Hardy Boys' except much worse
Rep. Jason Chaffetz, the chairman of the House Oversight Committee, has been doing a really great jo