HT TECH wants to start sending you push notifications. Click allow to subscribe

'Dumb mistake' exposed Iranian hand behind fake Proud Boys US election emails: Sources

Attribution to Iranian hackers does not necessarily mean a group is working at the behest of the government there. Iranian officials denied the US allegations.

By: REUTERS
Updated on: Aug 20 2022, 23:42 IST
US Director of National Intelligence John Ratcliffe said Russia and Iran have both tried to interfere in the campaign for the November 3 election.  (Pixabay)

Government analysts and private sector investigators were able to rapidly attribute to Iranian hackers a wave of thousands of threatening emails aimed at US voters because of mistakes made in a video attached to some of the messages, according to four people familiar with the matter.

Those failures provided a rare opportunity for the US government to identify and publicly announce blame for a malicious cyber operation in a matter of days, something that usually requires months of technical analysis and supporting intelligence.

You may be interested in

Mobiles Tablets Laptops
OnePlus 10 Pro
  • Volcanic Black
  • 8 GB RAM
  • 128 GB Storage
₹47,999
Check details
48% OFF
Samsung Galaxy S22 Plus
  • Green
  • 8 GB RAM
  • 128 GB Storage
₹44,890₹85,999
Buy now
48% OFF
Samsung Galaxy S22
  • Green
  • 8 GB RAM
  • 128 GB Storage
₹44,890₹85,999
Buy now
7% OFF
Google Pixel 7 5G
  • Obsidian
  • 8 GB RAM
  • 128 GB Storage
₹40,990₹43,999
Buy now
7% OFF
Microsoft Surface Pro 8 8PV 00029
  • Graphite Black
  • 16 GB DDR4 RAM
  • 256 GB SSD
₹139,999₹149,999
Buy now
47% OFF
Microsoft Surface 4 5UI 00049
  • Platinum Silver
  • 8 GB DDR4 RAM
  • 256 GB SSD
₹98,000₹186,500
Buy now
6% OFF
Microsoft Surface Go THH 00023
  • Platinum
  • 8 GB DDR4 RAM
  • 128 GB SSD
₹94,799₹100,999
Buy now
2% OFF
Microsoft Surface Pro 7 Plus TFM 00013
  • Platinum
  • 8 GB RAM
  • 128 GB SSD
₹78,990₹80,999
Buy now
Xiaomi Pad 6
  • Mist Blue
  • 6 GB RAM
  • 128 GB Storage
₹25,999
Check details
55% OFF
Lenovo Tab M10 5G
  • Abyss Blue
  • 6 GB RAM
  • 128 GB Storage
₹20,999₹47,000
Buy now
32% OFF
Realme Pad 2
  • Imagination Grey
  • 6 GB RAM
  • 128 GB Storage
₹19,674₹28,999
Buy now
Honor Pad X9
  • Gray
  • 4 GB RAM
  • 128 GB Storage
₹16,998
Check details

"Either they made a dumb mistake or wanted to get caught," said a senior US government official, who asked not to be identified. "We are not concerned about this activity being some kind of false flag due to other supporting evidence. This was Iran."

Attribution to Iranian hackers does not necessarily mean a group is working at the behest of the government there. Iranian officials denied the US allegations.

"These accusations are nothing more than another scenario to undermine voter confidence in the security of the US election, and are absurd," said Alireza Miryousefi, spokesman for Iran's mission to the United Nations in New York.

On Wednesday, US Director of National Intelligence John Ratcliffe said Russia and Iran have both tried to interfere in the campaign for the November 3 election. US intelligence agencies are still analyzing exactly who in Iran commanded the operation and its intent, three of the sources said.

Within hours of the video being circulated this week, which purported to come from an American far-right group known as The Proud Boys, intelligence officials and major email platform providers, such as Google and Microsoft, began closely analysing computer code that appeared in the hackers' video.

Also Read: Facebook sees uptick in Proud Boys content after presidential debate

While the emails, which demanded that voters change their party affiliation to the Republican Party and vote for President Donald Trump or "we will come after you," appeared to come from an official-looking Proud Boys email address, the address was inauthentic, security analysts said. The Proud Boys denied they were behind the messages.

How security analysts used intelligence from the video to attribute the email scheme has not been previously reported.

A Microsoft spokesperson declined to comment on the company's collaboration with law enforcement. A Google statement on Wednesday night said the activity was "linked to Iran." A Google spokesperson said on Thursday the company was in contact with the FBI.

Attempts to blur

Despite attempts to blur aspects of the video to hide their identity, the hackers were unable to obfuscate all of the incriminating information, the sources said.

The video showed the hackers' computer screen as they typed in commands and pretended to hack a voter registration system. Investigators noticed snippets of revealing computer code, including file paths, file names and an internet protocol (IP) address.

Security analysts found that the IP address, hosted through an online service called Worldstream, traced back to previous Iranian hacking activity, the sources said.

Analysts then cross-referenced those clues left in the video with data from other intelligence streams, including communications interceptions, the government official said.

"This public disclosure of attribution to Iran by the government has been done with breakneck speed, compared to the usual process that takes months and often years," said Dmitri Alperovitch, a co-founder and former CTO of cybersecurity company CrowdStrike.

Also Read: Hackers have infiltrated many of Washington state’s agencies

Two cybersecurity experts, who spoke on condition of anonymity because they were not authorized to talk to the press, independently said they had seen Iranian hackers use infrastructure from Dutch-based Worldstream to launch cyberattacks in recent months.

Worldstream's chief legal operations officer Wouter van Zwieten said in a statement that the account associated with the IP in question was suspended after Reuters got in touch and that the Dutch National Cyber Security Center was looking into the matter.

"They've just informed us that the particular IP address is now officially registered by them and ready for investigation under Dutch Law," van Zwieten said. The National Cyber Security Center confirmed that Worldstream had been in touch and that it had logged the case but declined further comment.

Van Zwieten said the server used by the hackers was only commissioned on October 6 and had not drawn any complaints until now. The company said it had no access to the content on its servers.

In addition to sending thousands of emails to voters in states including Florida, the hackers also attempted to share links to the video via fake accounts on Facebook and Twitter.

Social media analytics firm Graphika said two Twitter accounts began posting links to the video on Tuesday evening and attempted to get the attention of some media and political organisations.

One account described itself as "Trump's Soldier" and shared a link to the video with the comment "It seems they hacked voting system."

A Twitter spokeswoman said: "We acted quickly to proactively and permanently suspend a small number of accounts and limit the sharing of media-specific to this coordinated campaign."

Facebook said: "We disrupted an attempt by a single fake account to seed information related to what appears to be an influence operation primarily focused on spreading false claims via email."

Catch all the Latest Tech News, Mobile News, Laptop News, Gaming news, Wearables News , How To News, also keep up with us on ,Twitter, Facebook, , and Instagram. For our latest videos, subscribe to our YouTube channel.

First Published Date: 23 Oct, 08:34 IST

Sale

Mobiles Tablets Laptops
5% OFF
Google Pixel 7A
  • Charcoal
  • 8 GB RAM
  • 128 GB Storage
₹41,990₹43,999
Buy now
48% OFF
Samsung Galaxy S23 FE
  • Mint
  • 8 GB RAM
  • 128 GB Storage
₹41,944₹79,999
Buy now
13% OFF
Samsung Galaxy A55
  • Awesome Iceblue
  • 8 GB RAM
  • 128 GB Storage
₹39,999₹45,999
Buy now
4% OFF
Samsung Galaxy S24 Ultra
  • Titanium Black
  • 12 GB RAM
  • 256 GB Storage
₹129,999₹134,999
Buy now
57% OFF
Lenovo Tab M10 5G
  • Abyss Blue
  • 6 GB RAM
  • 128 GB Storage
₹19,999₹47,000
Buy now
38% OFF
Realme Pad 2
  • Imagination Grey
  • 6 GB RAM
  • 128 GB Storage
₹17,999₹28,999
Buy now
21% OFF
Samsung Galaxy Tab S9 5G 256GB
  • Graphite
  • 8 GB RAM
  • 256 GB Storage
₹88,858₹113,098
Buy now
6% OFF
Apple iPad Pro 11 2022
  • Silver
  • 8 GB RAM
  • 128 GB Storage
₹105,999₹112,900
Buy now
23% OFF
Infinix INBook X1 Neo XL22 Laptop Intel Celeron Quad Core 8 GB 256 GB SSD Windows 11
  • Blue
  • 4 GB RAM
  • 128 GB SSD
₹22,990₹29,990
Buy now
37% OFF
Asus ROG Strix Scar 15 G532LW AZ056T Laptop
  • Black
  • 16 GB RAM
  • 1 TB SSD
₹146,200₹231,990
Buy now
24% OFF
Asus ROG Strix G15 G513RC HN063W Laptop
  • Electro Punk
  • 16 GB RAM
  • 512 GB SSD
₹66,500₹86,990
Buy now
37% OFF
Asus Zenbook 14 OLED UX3402VA KN541WS Laptop
  • Ponder Blue
  • 16 GB RAM
  • 512 GB SSD
₹85,990₹135,990
Buy now
NEXT ARTICLE BEGINS