Cyber Threat Intelligence

Incident Analysis - Cyberwar: Israel โ€“ Iran

2024.04.30

๐Ÿ”ŽINCIDENT ANALYSIS - Cyber war: Israel โ€“ Iran (April 2024)

S2W is releasing threat analysis reports for regions seeking information on dark web threats. Following our examination of the MENA region in the previous report, our April issue focuses on analyzing ํ•ด์‹œํƒœ๊ทธcyber war incidents between ํ•ด์‹œํƒœ๊ทธIsrael and ํ•ด์‹œํƒœ๊ทธIran.

โœ… Executive Summary:

- Following the Israel-Iran outbreak in April 2024, the volume of messages referencing both countries surged significantly among threat actors on Telegram.

- The 'ํ•ด์‹œํƒœ๊ทธGhost of Palestine' emerged as the most active threat actor group mentioning both 'Israel' and 'Iran' through their ํ•ด์‹œํƒœ๊ทธTelegram channel. While they cited 'Iran' in support of the country, they also referenced 'Israel' to encourage other threat actors to target its infrastructure, attributing malicious actions against Iran.

- Other threat actors on Telegram channels exhibit similar behavior to the 'Ghost of Palestine,' prominently targeting Israel while disseminating messages in support of Iran.

- Despite the Israel-Iran outbreak, the number of postings on Darkweb hacking forums did not significantly increase. However, the 'Government' sector was the most affected industry for both countries.

- In case of Israel, threat actors were observed attempting to sell access to government servers and documents extracted from the 'Ministry of Defense.'

- The Iranian governmental agency 'ํ•ด์‹œํƒœ๊ทธBehdasht' was targeted by a threat actor who joined a Darkweb hacking forum in April 2024. Apart from this incident, the threat actor did not make any other postings.

๐Ÿง‘โ€๐Ÿ’ป Report authors: Analysts Sunhyung Shim and Jay Oh

๐Ÿ‘‰ For any inquiries, please contact us: https://s2w.inc/en/contact


*The full report is available upon request.