pwshub.com

Multiple Iran groups step up US election influence efforts

Microsoft says Iran's efforts to influence the November US presidential election have gathered pace recently and there are signs that point toward its intent to incite violence against key figures.

"Over the past several months, we have seen the emergence of significant influence activity by Iranian actors," Microsoft said. "Iranian cyber-enabled influence operations have been a consistent feature of at least the last three US election cycles." 

BH-easterly-keynote-2024

US elections have never been more secure, says CISA chief

READ MORE

The Windows maker added: "Iran's operations have been notable and distinguishable from Russian campaigns for appearing later in the election season and employing cyberattacks more geared toward election conduct than swaying voters. Recent activity suggests the Iranian regime – along with the Kremlin – may be equally engaged in election 2024."

Multiple state-sponsored groups and those whose affiliations are unknown are thought to be involved, each with their own objectives and methods. The group Microsoft tracks as Sefid Flood, for example, has been laying the groundwork for influence operations since March 2024.

Microsoft didn't go into detail about what this staging activity entailed, but Sefid Flood is known for impersonating social and political activist groups with a view to undermining trust in officials and election systems themselves.

It's perhaps why the US has been so adamant recently that its elections are safer than they've ever been. CISA director Jen Easterly spoke on the topic at Black Hat this week, saying the infrastructure is sound, but influence operations, namely from Russia, are a concern due to their improving sophistication.

Sefid Flood may look to use its impersonations as a means to "stoke chaos", Microsoft said, and its operations "may go as far as intimidation, doxxing, or violent incitement targeting political figures or social/political groups."

On the state-sponsored side of things, Mint Sandstorm and Peach Sandstorm are both run by Iranian intelligence, the Islamic Revolutionary Guard Corps (IRGC). As recently as June 2024, Mint Sandstorm was caught trying to spear-phish a presidential campaign official using a former senior advisor's account the group compromised. The email contained a link that could have allowed the IRGC to intercept the official's traffic.

Just days before, on June 13, Mint Sandstorm also tried – and failed – to access the account of a former presidential candidate. While there's no definitive proof this activity was election-related, the timing of it being so close to the targeting of the aforementioned official suggests it might be.

The group is also known for targeting political figures for reasons other than elections – it has been doing so for years – so no firm conclusions can be drawn officially.

A month earlier in May, its IRGC cousin, Peach Sandstorm, embarked on a wide password spraying mission that helped it gain access to a user account at a county-level government in a US swing state. It didn't actually do a great deal with that access so it may not have been election-related and instead more of a dumb-luck result, but Microsoft noted the county, located in a known swing state, had recently experienced a "race-related controversy" that made national news. 

The description is too broad and racism too rife in the US to even draw any kind of conclusions here – it could have been in one of multiple possible states as many fit that description.

Fake news

It was part of Russia's recent attempts to influence the Paris Olympics and Iran has also been observed setting up phony news outlets in an apparent attempt to engage voters on each side of the political divide.

One site has been online and active since 2022, "covering" the US mid-terms. EvenPolitics publishes around 10 articles a week and is run by Storm-2035, which also has various other sites set up to influence audiences in Arabic, English, French, and Spanish languages. Microsoft names groups "Storm-X" when they're under active development.

  • Georgia's voter portal gets a crash course in client versus backend input validation
  • Meta will use your social media posts to train its AI. Europe gets an opt out
  • Andrew Tanenbaum honored for pioneering MINIX, the OS hiding in a lot of computers
  • World's top AI chatbots have no problem parroting Russian disinformation

Nio Thinker was created in October 2023 to cover the Israel-Hamas conflict, but recently shifted to target left-leaning US voters with sarcastic, anti-Trump tirades. It does have some real zingers to be fair, calling the Republican candidate/felon an "opioid-pilled elephant in the MAGA china shop" and a "raving mad litigiosaur."

Savannah Time, on the other hand, seeks out conservative audiences with pieces on Republican politics and topics such as gender-based issues.

"Microsoft Threat Analysis Center has not observed significant social media amplification of these sites as of yet, though it is possible they will begin closer to election day," the report [PDF] reads.

The frequency with which the sites are updated suggests that the pro-Iran actors are dedicating a decent amount of resources to the endeavor, although AI is helping them out a smidge.

"Examination of webpage source code and indicators in the articles themselves suggest the sites' operators are likely using SEO plugins and other generative AI-based tools to create article titles, keywords, and to automatically rephrase stolen content in a way that drives search engine traffic to their sites while obfuscating the content's original source," Microsoft said. ®

Source: theregister.com

Related stories
1 week ago - Cybersecurity researchers found new Iranian hacker networks targeting U.S. political campaigns. Kurt “CyberGuy" Knutsson reveals what you need to know and how to protect yourself.
1 month ago - Editor's Choice: The Tonal smart home gym is effective but expensive. Here's what it's like to use it.
2 weeks ago - Pellet grills have a lot of moving parts that need to be maintained to keep churning out delicious foods.
1 month ago - US politicians and Israeli officials among the top targets for the IRGC’s cyber unit Google has joined Microsoft in publishing intel on Iranian cyber influence activity following a recent uptick in attacks that led to data being leaked...
1 month ago - 12 on X and one on Instagram caught in the crackdown OpenAI has banned ChatGPT accounts linked to an Iranian crew suspected of spreading fake news on social media sites about the upcoming US presidential campaign.…
Other stories
58 minutes ago - As an Amazon Prime member, not only do you get a free Grubhub+ membership, you can also score $10 off your first $15 order.
58 minutes ago - Amazon's second Prime Day event of 2024 is still a few weeks away, but there are some bargains you can score now.
58 minutes ago - YouTube will roll out a new generative AI video tool named Veo later this year that'll allow creators to create 6-second clips with nothing more...
2 hours ago - FBI Director hails successful action but calls it “just one round in a much longer fight.”
2 hours ago - SocialAI takes the social media "filter bubble" to an extreme with 100% fake interactions.