Iran-backed hackers blamed for major LA transit breach – Claril Noticias

Iranian state-backed hackers working for the Ministry of Intelligence and State Security (MOIS) were behind a disruptive cyberattack on the Los Angeles transit system in March, according to a report released on Tuesday by Israeli cybersecurity firm Gambit Security.

The findings, which shed light on the sophisticated digital campaign targeting the Los Angeles County Metropolitan Transportation Authority (LACMTA), were first reported by Reuters following the publication of Gambit’s analysis.

The Illusion of Grassroots Hacktivism

During the initial March breach, a self-proclaimed hacktivist collective calling itself “Ababil of Minab” claimed responsibility for infiltrating the transit network. The group asserted that it had successfully exfiltrated and subsequently erased critical data from LACMTA’s internal systems. The moniker “Ababil of Minab” is a direct reference to a historical US air strike on an Iranian school in the city of Minab, an incident that resulted in the deaths of more than 175 people, the majority of whom were children.

However, researchers have debunked the group’s independent status. In their detailed report, Gambit Security clarified that this is not a newly formed, independent entity, but rather a front for state-sponsored operations. TechCrunch reached out to Ababil of Minab for comment, but received no response.

Forensic Links to Iranian Intelligence

Tracking the Digital Footprint

Gambit Security’s assessment relies on concrete forensic evidence linking the LACMTA intrusion to previous cyber campaigns associated with Tehran. This digital footprint aligns with malicious activities attributed to the MOIS by the Israel National Cyber Directorate. Beyond the United States, Gambit’s investigation tracked similar state-sponsored attacks targeting corporate networks in Israel, Saudi Arabia, and Turkey.

A Pattern of Deceptive Front Groups

If these findings are validated, Ababil of Minab represents the latest addition to a growing list of state-controlled personas operating under the guise of independent hacktivists. A prominent parallel is “Handala”, another suspected Iranian front group that recently targeted Stryker, a major US medical technology firm. That attack resulted in the wiping of thousands of corporate systems and employee devices.

var playerInstance_jwplayer_6a7a0d5927075 = jwplayer( “jwplayer_6a7a0d5927075” );
playerInstance_jwplayer_6a7a0d5927075.setup({
playlist: “https://cdn.jwplayer.com/v2/media/lv0GaEwB”,
});

Escalating Cyber Warfare Against Critical Infrastructure

In the wake of the Stryker security breach, federal authorities intervened, with the FBI seizing two primary web domains operated by Handala. Concurrently, the US Department of Justice formally accused the Iranian government of directing the group’s disruptive operations.

Cyber operations linked to Iran have surged significantly following recent military tensions, including US and Israeli air strikes targeting Iranian territory earlier this year. This escalating digital threat prompted a joint warning in April from a coalition of US federal agencies, highlighting a concerted effort by Iranian actors to compromise Western critical infrastructure.

By Claril

Leave a Reply

Your email address will not be published. Required fields are marked *