- Sputnik International
World
Get the latest news from around the world, live coverage, off-beat stories, features and analysis.

Report Finds ‘Growing Number’ of Gmail Hacks Coming From Iran

© AP Photo / Vahid SalemiIranian women use computers at an Internet cafe in central Tehran, Iran
Iranian women use computers at an Internet cafe in central Tehran, Iran - Sputnik International
Subscribe
Iranian hackers set up an “elaborate” phishing operation to target the Iranian diaspora and at least one Western activist, according to report of the University of Toronto’s Citizen Lab.

Nikolai Patrushev, Secretary of the Russian Security Council - Sputnik International
Russia
Cyberattacks on Russian Authorities Increase - Russian Security Council
WASHINGTON (Sputnik) — Hackers from Iran have found a way to get around Gmail’s two-factor authentication system and hack the Iranian diaspora and political dissidents, according to a report published on Thursday by the University of Toronto’s Citizen Lab.

“The ongoing attacks attempt to circumvent the extra protections conferred by two-factor authentication in Gmail, and rely heavily on phone-call based phishing and ‘real time’ login attempts by the attackers,” the report read.

Two-factor authentication is a process where a user sets up not only a password and username, but also another piece of information for an extra layer of security.

According to the report, Iranian hackers have set up an “elaborate” phishing operation to target the Iranian diaspora and at least one Western activist.

Laptop Keyboard - Sputnik International
Surveillance Tool Used by Law Enforcement Vulnerable to Hackers
The report said these “growing number of attacks” point to “extensive knowledge of the targets’ activities, and share infrastructure and tactics with campaigns previously linked to Iranian threat actors.”

In order for these two-factor authentication targeted attacks to succeed, the alleged Iranian hackers must obtain the targets’ password and single-user codes.

According to the report, the alleged Iranian hackers obtain the passwords first through text messages and phishing password reset pages, where they then collect the information and take over the account.

Additionally, the report said the hackers also attempted to gain access to their targets’ Gmail accounts by posing as journalists. In some instances the hackers made calls to users pitching fake business proposals that they would then send to their Gmail with a fake Google Drive link.

Newsfeed
0
To participate in the discussion
log in or register
loader
Chats
Заголовок открываемого материала