A U.S. court has granted Microsoft the authority to seize domain names in order to take down a phishing campaign run by a notorious group of Iranian hackers.
In a poston Microsoft’s official blog,Randy Spears Archives Customer Security & Trust VP Tom Burt shared details from the now unsealed caseit filed in the U.S. District Court for Washington D.C against the hacker group called Phosphorus. The group is also known under the names APT 35, Charming Kitten, and Ajax Security Team.
Microsoft’s Digital Crimes Unit was allowed to take control of 99 domains in order to stop the hackers’ attacks. Domains such as outlook-verify.net, yahoo-verify.net, and verification-live.com were being used in spear-phishing campaigns by the Iranian hackers.
Spear-phishing is a method of attack that relies on social engineering, where a hacker tricks an individual or group into believing that they are a trusted source through an email or web address. The hacker then uses that trust to obtain passwords or other sensitive information from their target.
Phosphorus targeted U.S. businesses and government agencies as well as activists and journalists. As Techcrunchpoints out, former U.S. Air Force intelligence officer turned spy Monica Witt reportedly has connections to the hacker group. Witt defected to Iran and is currently a fugitive wanted by the FBI for alleged espionage. It is believedthat Witt provided the Iranian hackers with intelligence regarding U.S. officials and her former colleagues. Using this information, the hackers can more accurately pinpoint their spear-phishing campaigns against certain individuals.
According to Microsoft, Phosphorus would send a link containing malicious software under the guise of a friendly source, sometimes even posing as a target’s contact on social media. The hackers would be able to use that software to access the victim’s computer. The group also deployed another attack using the now Microsoft-controlled domain names to trick its targets into thinking there was a security risk flagged on their Outlook or Yahoo account. Upon clicking on the phishing link, the target would be prompted to login to their account, effectively providing their password to the hackers.
This isn’t the first time a U.S. court granted Microsoft the authority to take control of domain names connected to phishing campaigns. Last year, a federal court injunction allowed Microsoft to seize domains deployed by hackers that infringe on the company’s trademarks. Microsoft used that authorityto terminate spear-phishing campaigns set up my the Russian hacker group known as Fancy Bear, which was targeting U.S. politicians, Congressional staffers, and think tanks.
Topics Cybersecurity Microsoft
Facebook isn't getting that much TV money, so it will just start selling TV adsKelly Clarkson's 'Hamilton Mixtape' cover will wreck you in the best wayDave Chappelle to host postWhat Twitter is doubling down on amid all the cutbacksCool Cub: Kris Bryant was suave as could be while making the final out of World Series Game 7Dave Chappelle to host postHindu priests are now helping to combat child marriage in NepalXiaomi is making a LegoMan proposes to girlfriend in front of huge freshwater crocodileTV has the most LGBTQ characters in its historyDave Chappelle to host postU.S. government prepares for Election Day cyber attacksIndian government issues 24'Overwatch' World Cup: 8 teams battle for their countries' gloryApple slashes prices on USBThe chunky Samsung Gear S3 smartwatch costs more than an Apple WatchA 'Pen Pineapple Apple Pen' cafe has opened in TokyoApple slashes prices on USBAn ode to the Cleveland Indians, the true World Series underdogKendall Jenner dressed like Paris Hilton for her 21st birthday Even the best passwords are no match for this simple hack Tesla's autonomous trucks will move in platoons, report says HBO offered hackers a 'bounty payment' of $250,000 last month New TV show is basically the 'Masterchef' of LEGO That 'Fallout' board game borrows from the series in clever ways Microsoft's Windows 10 Pro for Workstations update is for power users This guy missed his high school so much he recreated it on Minecraft Miami Heat become first NBA team with mobile You may want to hold off buying that Microsoft Surface I know, I know ... I'm using Instagram all wrong and I don't care Nintendo's detachable controller design draws accusations of patent infringement 2 Chainz kicks off tour in pink 'trap wheelchair' after breaking his leg Autistic child gets surprise gift after shop runs out of his favourite shoes Your selfies won't look like shit anymore with an Android phone Netflix's 'Atypical' struggles to keep up with its star Samsung's Galaxy Note 8 might copy iPhone's pressure A massive wildfire has been burning in Greenland for more than a week Here's how to see other planets during the total solar eclipse 'Star Wars: The Last Jedi' might pit Laura Dern against Carrie Fisher Man reinvents how to eat ice cream with clever thermos hack
0.974s , 10136.4140625 kb
Copyright © 2025 Powered by 【Randy Spears Archives】,Unobstructed Information Network