DIRECTORY

  • Alerts
  • APTs
  • Blog
  • Books
  • Certifications
  • Cheat Sheets
  • Courses
  • Cyber Briefing
  • CyberDecoded
  • CyberReview
  • CyberStory
  • CyberTips
  • Definitions
  • Domains
  • Entertainment
  • FAQ
  • Frameworks
  • Hardware Tools
  • Incidents
  • Malware
  • News
  • Papers
  • Podcasts
  • Quotes
  • Reports
  • Tools
  • Threats
  • Tutorials
No Result
View All Result
  • Login
  • Register
  • Cyber Citizens
  • Cyber Professionals
  • Institutions
CyberMaterial
Get Help
  • Cyber Citizens
  • Cyber Professionals
  • Institutions
CyberMaterial
No Result
View All Result
Get Help
CyberMaterial
Home Incidents

Iranian Hackers Target Israeli Shipping

May 25, 2023
Reading Time: 2 mins read
in Incidents

Suspected Iranian hackers, identified as the group Tortoiseshell, have targeted multiple shipping and logistics websites in Israel, aiming to gather user information. ClearSky, a Tel Aviv-based cybersecurity company, attributes these attacks to Tortoiseshell, which has been active since at least July 2018. The hackers employed a watering hole attack, compromising websites frequented by the target audience to inject malicious code.

The majority of the affected websites have removed the malicious code, but the attack raises concerns about the ongoing cyber conflict between Iran and Israel, with Iranian actors continually enhancing their capabilities.

The hackers used malicious JavaScript in their recent attack, collecting sensitive data such as IP addresses, screen resolutions, and the URLs of previously visited webpages. They also attempted to determine users’ computer language preferences to customize future attacks. The compromised websites, including SNY Cargo, Depolog, and SZM, were primarily hosted by the uPress hosting service, which was previously targeted by the Iranian group Emennet Pasargad in 2020, resulting in the defacement of thousands of Israeli sites.

The cyber conflict between Israel and Iran has intensified over the past two years, with Iranian state-sponsored actors steadily improving their cyber capabilities. While not as advanced as Russian or Chinese counterparts, Iranian hackers are known to exploit recently disclosed vulnerabilities and employ tailored tools against their targets.

Tortoiseshell, previously involved in supply chain attacks in Saudi Arabia, used the domain jquery-stack[.]online, which mimicked the legitimate JavaScript framework jQuery, to deceive website code checks. ClearSky researchers have observed similar tactics involving domain names impersonating jQuery in a previous Iranian campaign dating back to 2017, employing watering hole attacks.

Read More

Tags: ClearSkyCyberattackHackersincidentsIncidents 2023IranMay 2023Tortoiseshell
4
VIEWS
ADVERTISEMENT

Related Posts

Tesla Data Breach: Investigation Underway

Tesla Data Breach: Investigation Underway

May 26, 2023
Del Monte Data Breach Exposes Information

Del Monte Data Breach Exposes Information

May 26, 2023
Marine Corps Data Breach Investigations

Marine Corps Data Breach Investigations

May 26, 2023
Massive Data Breach Exposes VPN Users

Massive Data Breach Exposes VPN Users

May 26, 2023

More Articles

Alerts

Irish data protection commission fines Meta over 2021 data-scraping leak

November 29, 2022
Entertainment

Nothing to Hide (2017)

March 10, 2021
Cyber101

Mean Time Between Failures (MTBF)

June 21, 2022
Incidents

Researchers Uncover ‘Hermit’ Android Spyware Used in Kazakhstan, Syria, and Italy

June 20, 2022

Security through data

Cybersecurity Domains

  • API Security
  • Business Continuity
  • Career Development
  • Compliance
  • Cryptography
  • HSM
  • KPIs / KRIs
  • Penetration Testing
  • Shift Left
  • Vulnerability Scan

Emerging Technologies

  • 5G
  • Artificial Intelligence
  • Blockchain
  • Cryptocurrency
  • Deepfake
  • E-Commerce
  • Healthcare
  • IoT
  • Quantum Computing

Frameworks

  • CIS Controls
  • CCPA
  • GDPR
  • NIST
  • 23 NYCRR 500
  • HIPAA

Repository

  • Books
  • Certifications
  • Definitions
  • Documents
  • Entertainment
  • Quotes
  • Reports

Threats

  • APTs
  • DDoS
  • Insider Threat
  • Malware
  • Phishing
  • Ransomware
  • Social Engineering

© 2023 | CyberMaterial | All rights reserved.

World’s #1 Cybersecurity Repository

  • About
  • Legal and Privacy Policy
  • Site Map
No Result
View All Result
  • Audience
    • Cyber Citizens
    • Cyber Professionals
    • Institutions
  • Highlights
    • Blog
    • CyberDecoded
    • Cyber Review
    • CyberStory
    • CyberTips
  • Cyber Risks
    • Alerts
    • Attackers
    • Domains
    • Incidents
    • Threats
  • Opportunities
    • Events
    • Jobs
  • Repository
    • Books
    • Certifications
    • Cheat Sheets
    • Courses
    • Definitions
    • Frameworks
    • Games
    • Hardware Tools
    • Memes
    • Movies
    • Papers
    • Podcasts
    • Quotes
    • Reports
  • Report Cyber Incident
  • GET HELP

Subscribe to our newsletter

© 2022 Cybermaterial - Security Through Data .

Welcome Back!

Sign In with Google
Sign In with Linked In
OR

Forgotten Password? Sign Up

Create New Account!

Sign Up with Google
Sign Up with Linked In
OR

All fields are required. Log In

Retrieve your password

Please enter your username or email address to reset your password.

Log In

Add New Playlist

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.