Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (Cyborg)
  • No Skin
Collapse
Brand Logo

CIRCLE WITH A DOT

  1. Home
  2. Uncategorized
  3. I've already had questions from a FinServ client about Iran replicating Operation Ababil (2012-2013 DDoS targeting FS orgs).

I've already had questions from a FinServ client about Iran replicating Operation Ababil (2012-2013 DDoS targeting FS orgs).

Scheduled Pinned Locked Moved Uncategorized
6 Posts 3 Posters 0 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • malwarejake@infosec.exchangeM This user is from outside of this forum
    malwarejake@infosec.exchangeM This user is from outside of this forum
    malwarejake@infosec.exchange
    wrote last edited by
    #1

    I've already had questions from a FinServ client about Iran replicating Operation Ababil (2012-2013 DDoS targeting FS orgs).

    My assessment is that is not likely to happen. Iran has limited capacity for cyberattacks and given the current situation, they have MUCH higher priorities for cyberattacks. Realistically, they are FAR more likely to use their limited cyber resources for intelligence collection instead of destructive attacks that would have limited impacts. They are likely unable to perform another Shamoon-style attack either, since that requires significant prepositioning. In any case, it's unlikely they have enough prepositioning in US orgs (especially FS) to create that type of impact.

    One other note, is that FS orgs are in a much different position today to deal with any DDoS attacks that Iranian-linked threat actors might attempt. Operation Ababil was a wakeup call for the whole industry and they've definitely become more resilient to DDoS in the last decade+ since.

    krypt3ia@infosec.exchangeK realn2s@infosec.exchangeR 2 Replies Last reply
    0
    • malwarejake@infosec.exchangeM malwarejake@infosec.exchange

      I've already had questions from a FinServ client about Iran replicating Operation Ababil (2012-2013 DDoS targeting FS orgs).

      My assessment is that is not likely to happen. Iran has limited capacity for cyberattacks and given the current situation, they have MUCH higher priorities for cyberattacks. Realistically, they are FAR more likely to use their limited cyber resources for intelligence collection instead of destructive attacks that would have limited impacts. They are likely unable to perform another Shamoon-style attack either, since that requires significant prepositioning. In any case, it's unlikely they have enough prepositioning in US orgs (especially FS) to create that type of impact.

      One other note, is that FS orgs are in a much different position today to deal with any DDoS attacks that Iranian-linked threat actors might attempt. Operation Ababil was a wakeup call for the whole industry and they've definitely become more resilient to DDoS in the last decade+ since.

      krypt3ia@infosec.exchangeK This user is from outside of this forum
      krypt3ia@infosec.exchangeK This user is from outside of this forum
      krypt3ia@infosec.exchange
      wrote last edited by
      #2

      @malwarejake it’s the proxy terrorist cells that are more problematic.

      malwarejake@infosec.exchangeM 1 Reply Last reply
      0
      • malwarejake@infosec.exchangeM malwarejake@infosec.exchange

        I've already had questions from a FinServ client about Iran replicating Operation Ababil (2012-2013 DDoS targeting FS orgs).

        My assessment is that is not likely to happen. Iran has limited capacity for cyberattacks and given the current situation, they have MUCH higher priorities for cyberattacks. Realistically, they are FAR more likely to use their limited cyber resources for intelligence collection instead of destructive attacks that would have limited impacts. They are likely unable to perform another Shamoon-style attack either, since that requires significant prepositioning. In any case, it's unlikely they have enough prepositioning in US orgs (especially FS) to create that type of impact.

        One other note, is that FS orgs are in a much different position today to deal with any DDoS attacks that Iranian-linked threat actors might attempt. Operation Ababil was a wakeup call for the whole industry and they've definitely become more resilient to DDoS in the last decade+ since.

        realn2s@infosec.exchangeR This user is from outside of this forum
        realn2s@infosec.exchangeR This user is from outside of this forum
        realn2s@infosec.exchange
        wrote last edited by
        #3

        @malwarejake
        Sorry, dummy question.
        FS orgs?
        Financial service?

        malwarejake@infosec.exchangeM 1 Reply Last reply
        0
        • realn2s@infosec.exchangeR realn2s@infosec.exchange

          @malwarejake
          Sorry, dummy question.
          FS orgs?
          Financial service?

          malwarejake@infosec.exchangeM This user is from outside of this forum
          malwarejake@infosec.exchangeM This user is from outside of this forum
          malwarejake@infosec.exchange
          wrote last edited by
          #4

          @realn2s Yeah, financial services.

          realn2s@infosec.exchangeR 1 Reply Last reply
          0
          • krypt3ia@infosec.exchangeK krypt3ia@infosec.exchange

            @malwarejake it’s the proxy terrorist cells that are more problematic.

            malwarejake@infosec.exchangeM This user is from outside of this forum
            malwarejake@infosec.exchangeM This user is from outside of this forum
            malwarejake@infosec.exchange
            wrote last edited by
            #5

            @krypt3ia Yes - that and IRGC QF.

            1 Reply Last reply
            0
            • malwarejake@infosec.exchangeM malwarejake@infosec.exchange

              @realn2s Yeah, financial services.

              realn2s@infosec.exchangeR This user is from outside of this forum
              realn2s@infosec.exchangeR This user is from outside of this forum
              realn2s@infosec.exchange
              wrote last edited by
              #6

              @malwarejake
              🙏🏻

              1 Reply Last reply
              1
              0
              • R relay@relay.infosec.exchange shared this topic
              Reply
              • Reply as topic
              Log in to reply
              • Oldest to Newest
              • Newest to Oldest
              • Most Votes


              • Login

              • Login or register to search.
              • First post
                Last post
              0
              • Categories
              • Recent
              • Tags
              • Popular
              • World
              • Users
              • Groups