Iranian meddling in U.S. election shows new skills. But is it really Iran? – Haaretz.com
The email coercing Democrats in Florida to vote for President Donald Trump seemed legitimate at first. It was sent from an apparently official email account, was personally addressed and even included the recipients home address. However, less than a day after the email was purportedly sent by far-right group the Proud Boys, U.S. officials revealed it to be part of an Iranian campaign to interfere in the U.S. election.
The influence campaign which also targeted voters in Alaska, Pennsylvania and Arizona showed a new level of Iranian sophistication, according to three Israeli cyberexperts who spoke with Haaretz and are knowledgeable about how hackers from the Islamic Republic operate.
They all say the bogus email marks a new type of cyberoffensive by Iran, but add that it raises further questions.
The case also highlights how difficult it is to attribute such cyberattacks nowadays, just as the United States ramps up its efforts to fight attempts by Russia, China and Iran to meddle in the November 3 election.
Last Wednesday, U.S. Director of National Intelligence John Ratcliffe said Russia and Iran have both tried to interfere in next weeks election.
The announcement followed a string of other statements by U.S. intelligence and law enforcement officials in recent weeks, revealing attempts past and present to undermine Americas voting system. These came through cyberattacks on voting networks and infrastructure, and disinformation campaigns. Though officials believe Russia is the bigger threat, both Russia and Iran are acting with what officials say is the clear intent to undermine the integrity of the electoral process.
Something new
According to Israeli web intelligence expert Dana Segev Moyal, the Proud Boys operation was different and more complex than past campaigns attributed to Iran.
Most of what we know publicly about previous attacks attributed to Iran is that they were usually either more complex technologically for example, cyberattacks on infrastructure or, when they were social influence campaigns, they tended to focus on spreading disinformation on social media.
Segev Moyal, who focuses on disinformation and has studied Irans past activities in this area, says were seeing something new this time: Weve never seen an email campaign targeting voters of a specific state with a specific message from a very specific organization, she notes.
We've got more newsletters we think you'll find interesting.
Please try again later.
The email address you have provided is already registered.
At minimum, this shows a pretty detailed understanding of American politics. I doubt your average Israeli or Iranian knows who the Proud Boys are. You need to do research and follow American politics closely. The extremist group made headlines after the first presidential debate, when President Trump refused to denounce it.
Boaz Dolev, a cybersecurity expert whose ClearSky firm has revealed Iranian cyberattacks and disinformation campaigns in recent years, agrees. He calls it a very rare attack.
What makes the attack so unique, according to both experts, is that it was actually quite simple from a technological perspective, but very complex in strategic terms.
Contrary to what people think, this attack doesnt actually require any hacking, Segev Moyal explains. Voter registration details are available online if you know how to find them. Whats interesting here is that they fused and corroborated different types of data to mount an influence campaign. Thats just not the type of planning weve seen up till now, she says.
In 2018, Dolevs ClearSky revealed a massive Iranian disinformation campaign. However, that operation was more in line with what we would term fake news and included a network of more than 70 pseudo-media outlets that covertly spread Iranian state propaganda in 15 different countries a far cry from the complex and hyper-targeted influence campaign now being attributed to them.
Though both experts say its hard to draw a direct line between the email campaign and Iran at least based on the information currently available they state that, much like Russia, Irans capabilities and techniques are always changing, making it that much harder to prove.
Dolev offers one recent example that surprised him: A few weeks ago, his firm revealed an Iranian cyberoperation in Israel that tried to pass itself off as a criminal (as opposed to state) offensive. Operation Quicksand, as it was labeled, also showed new modes of operation that hadnt previously been linked to Iran.
Theres a certain chain of attribution people in the world of cybersecurity know how to do, he explains. You can link a certain technology or technique to a certain team, and you can link that team back to certain states.
What I can tell you about the Iranians is that the last time we came out and said it was them [in Operation Quicksand], at first I didnt think it was them, because technologically it showed they had taken a step forward in terms of their actual capabilities. It was a professional job that I hadnt seen in this context before. But then you get some more information that allows you to make the attribution.
In the case of the Proud Boys email campaign, it was Reuters and the United States that made the attribution with the help of information provided by Google and Microsoft. All the experts Haaretz spoke with said that without reviewing the actual information, they couldnt independently confirm or deny the attributions veracity.
As Dolev puts it, experts in his field are constantly updating and revising their assumptions about what certain players can or cant do. So now we know Iran is an agent that has better technological capabilities than we had previously thought, he says, referring to Operation Quicksand.
Nonetheless, he says, when it comes to disinformation campaigns, most of their capabilities are actually basic even if their cyberoffensives against organizations have been stepped up and are better than we initially thought.
In this case, though, as Segev Moyal explains, the operation was actually complex: In addition to finding all the [voter] emails and cross-referencing all the different data sets, they also had to find a Proud Boys server that was vulnerable and actually produce an email campaign.
Proud Iranian boys?
The few details made public about how the email campaign was traced back to Iran show how complex such operations can be both for the perpetrator and those trying to thwart them.
According to Reuters, it was a series of dumb mistakes that revealed the attacks origins. For example, one of the emails sent out (there were a number in the campaign) included a video that purported to show how the hackers managed to obtain voter registration details. A few lines of code viewable in the video, as well as an IP address that was not blurred out, were traced back to websites and techniques previously used by Iran.
However, its exactly this type of slapdash error that also prompts questions. For instance, some reports have shown screen captures of the email. In one of them, theres a glaring typo in the subject line: Voteing with an e, Segev Moyal says. Its strange that someone would make such a big effort but then make such a silly mistake, she adds.
A third expert, who spoke on condition of anonymity due to the sensitivity of their work and the issue, added that certain aspects of the operation actually look more similar to Russian operations.
This appears to be a scenario also examined by the United States: Either they made a dumb mistake or wanted to get caught, said a senior U.S. government official who spoke to Reuters when the story broke last week. But they added: Were not concerned about this activity being some kind of false flag due to other supporting evidence. This was Iran.
Segev Moyal notes that this is not something we can say is definitely not Iran they can do that but there are also others who do such things. However, both she and Dolev refuse to call into question the American findings, saying that without further information, they simply cannot know for certain.
For Segev Moyal, one possible explanation is that, oftentimes, such campaigns are not really intended to succeed but merely to sow distrust and help create the sense that the U.S. electoral process is exposed to manipulation.
In this case, the video itself was also posted online. Social media analytics firm Graphika told Reuters that two Twitter accounts began posting links to the video last Tuesday evening and attempted to attract the attention of some media and political organizations. One account described itself as Trumps Soldier and shared a link to the video with the comment: It seems they hacked [the] voting system.
This also highlights how much the disinformation efforts piggyback statements being pushed out by the U.S. president himself.
When you look at this as an influence campaign that wants to sway public opinion, this could make sense, Segev Moyal says. This was not really a cyberattack on voter infrastructure no one, for example, is suggesting [the Iranians] or the Russians can alter the election results themselves.
From this perspective, the true goal of the email campaign was perhaps to fuel the narrative that Americas electoral system is exposed.
For Dolev, one of the most interesting aspects of the attack was the U.S. response and the governments decision to reveal the operation so quickly.
This is a new American policy and were also seeing it in regards to the Russians, he says, citing recent indictments against hackers operating for the GRU (the Russian armys intelligence branch). By revealing the operations, Dolev adds, the United States is in a sense fighting back, as publicity can counter the effectiveness of such influence campaigns.
During an influence campaign, the target countrys goal can be to respond as publicly as possible, Segev Moyal says. It helps restore public confidence, and show that everything is under control and voting systems have not actually been compromised. Like the operation itself, this type of response also aims at hearts and minds.
Here is the original post:
Iranian meddling in U.S. election shows new skills. But is it really Iran? - Haaretz.com
- Trump: Iran, scared and with defenses pretty much gone, will make nuclear deal with US - The Times of Israel - February 11th, 2025 [February 11th, 2025]
- Trump Pushes Iran's Economy to the Brink - Newsweek - February 11th, 2025 [February 11th, 2025]
- Trumps Grand Bargain With Iran Shouldnt Abandon Its People - Foreign Policy - February 11th, 2025 [February 11th, 2025]
- Iran loosens import restrictions on foreign cars and iPhones, trying to mask its economic woes - ABC News - February 11th, 2025 [February 11th, 2025]
- VOA Persian: With no new nuclear deal, Iran to remain under maximum pressure, US says - Voice of America - February 11th, 2025 [February 11th, 2025]
- Iran loosens import restrictions on foreign cars and iPhones, trying to mask its economic woes - The Associated Press - February 11th, 2025 [February 11th, 2025]
- Trump says a 'very frightened and nervous' Iran longs for a deal with US | Iran International - - February 11th, 2025 [February 11th, 2025]
- Iran and Turkmenistan Strengthen Energy, Trade Ties - The Media Line - February 11th, 2025 [February 11th, 2025]
- What should a new deal with Iran look like? - Bulletin of the Atomic Scientists - February 11th, 2025 [February 11th, 2025]
- Trump updates Iran peace deal effort to reflect new realities, analysts say - Voice of America - February 11th, 2025 [February 11th, 2025]
- Opinion | China on edge after Trump makes overtures to North Korea and Iran - South China Morning Post - February 11th, 2025 [February 11th, 2025]
- Memorandum on Imposing Maximum Pressure on the Government of the Islamic Republic of Iran, Denying Iran All Paths to a Nuclear Weapon, and Countering... - February 11th, 2025 [February 11th, 2025]
- AmEx closed 30 accounts potentially tied to Iran's government - Reuters - February 11th, 2025 [February 11th, 2025]
- Trump says he prefers nuclear deal with Iran than bombing the hell out of it - The Times of Israel - February 11th, 2025 [February 11th, 2025]
- Iran Makes Threat Over Key World Oil Supply Route - Newsweek - February 11th, 2025 [February 11th, 2025]
- Iran: Strengthening relations with Saudi Arabia is irreversible - Middle East Monitor - February 11th, 2025 [February 11th, 2025]
- 46 Years of tyranny: How Iran's Islamic Revolution betrayed its promises - opinion - The Jerusalem Post - February 11th, 2025 [February 11th, 2025]
- Iran says its ready to negotiate with US, but not under maximum pressure policy - The Times of Israel - February 11th, 2025 [February 11th, 2025]
- Trump used decoy plane over fears of assassination by Iran - The Times - February 11th, 2025 [February 11th, 2025]
- Trump: 'I would like a deal done with Iran' rather than 'bombing the hell out of it' - The Jerusalem Post - February 11th, 2025 [February 11th, 2025]
- Trump says without Iran deal US could 'bomb the hell out of it' - Israel Hayom - February 11th, 2025 [February 11th, 2025]
- Maximum pressure on Iran will boost mainstream VLCC demand, broker BRS says - Lloyd's List - February 11th, 2025 [February 11th, 2025]
- US vows to keep up Iran pressure if no will shown for deal | Iran International - - February 11th, 2025 [February 11th, 2025]
- Anniversary of 1979 Islamic Revolution marked in Iran while Trumps policies shake the region - All Israel News - February 11th, 2025 [February 11th, 2025]
- Iran stages mock arrest of Trump amid reports of Iranian agents in the US - Newsweek - February 11th, 2025 [February 11th, 2025]
- Iran's president says Trump is trying to bring Iran "to its knees" - CBS News - February 11th, 2025 [February 11th, 2025]
- Hamas leaders defiant in Iran: Palestinians like olive trees, steadfast in their land - analysis - The Jerusalem Post - February 11th, 2025 [February 11th, 2025]
- Khamenei of Iran Denounces Negotiation With U.S. but Seems to Leave Door Ajar - The New York Times - February 7th, 2025 [February 7th, 2025]
- Iranian supreme leader vows to respond in kind if US acts on threats against Iran - The Times of Israel - February 7th, 2025 [February 7th, 2025]
- Iran supreme leader criticizes proposed nuclear talks with US, upending push to negotiation - The Associated Press - February 7th, 2025 [February 7th, 2025]
- Trump says hes given advisers instructions for Iran to be obliterated if it assassinates him - The Associated Press - February 7th, 2025 [February 7th, 2025]
- Trump Issues Sanctions on Iran, Threatens to Obliterate It if Hes Killed - Truthout - February 7th, 2025 [February 7th, 2025]
- Iran's first drone carrier joins the Revolutionary Guards' fleet - Reuters - February 7th, 2025 [February 7th, 2025]
- As Trump Makes Overtures, Iran Weighs Its Next Move - Bloomberg - February 7th, 2025 [February 7th, 2025]
- Iran is willing to give Trump diplomacy 'another chance', senior Iranian official says - Reuters - February 7th, 2025 [February 7th, 2025]
- Iran daily urges Pezeshkian to respond promptly to Trumps overtures - - February 7th, 2025 [February 7th, 2025]
- How Close Is Iran to a Nuclear Weapon as Trump Eyes a Deal? - Bloomberg - February 7th, 2025 [February 7th, 2025]
- Maximum pressure returns as Iran reacts to Trumps offer of talks - Amwaj.media - February 7th, 2025 [February 7th, 2025]
- UN rapporteur urges Iran to halt imminent execution of Kurdish woman - - February 7th, 2025 [February 7th, 2025]
- Iran has never pursued nuclear weapons, says President Pezeshkian - the voice of vietnam - February 7th, 2025 [February 7th, 2025]
- Iran Unveils Drone Carrier Warship in Threat to US - Newsweek - February 7th, 2025 [February 7th, 2025]
- Study debunks nuclear test misinformation following 2024 Iran earthquake - The Hub at Johns Hopkins - February 7th, 2025 [February 7th, 2025]
- Deep Dive: Syria spillover for Iran moving towards the Caucasus - Amwaj.media - February 7th, 2025 [February 7th, 2025]
- Trump says he wants to negotiate a nuclear deal with Iran after imposing maximum pressure - CNBC - February 7th, 2025 [February 7th, 2025]
- Iran says verifying its nuclear programme is an 'easy task' - Reuters - February 7th, 2025 [February 7th, 2025]
- Trump Torpedoed the Iran Nuclear Deal. Now Hes Calling for Another One. - The New York Times - February 5th, 2025 [February 5th, 2025]
- Iran praises US for cutting foreign aid funding as it looks for a Trump message on nuclear talks - The Associated Press - February 5th, 2025 [February 5th, 2025]
- Iran calls for OPEC to unite against potential US oil sanctions - Reuters - February 5th, 2025 [February 5th, 2025]
- Denying US and Israel are planning a strike, Trump says he wants a deal with Iran - The Times of Israel - February 5th, 2025 [February 5th, 2025]
- Sharper: Iran and the Axis of Upheaval - Center for a New American Security - February 5th, 2025 [February 5th, 2025]
- Donald Trump signals wish to hold talks with Iran over nuclear deal - The Guardian - February 5th, 2025 [February 5th, 2025]
- Iran says its foreign policy driven by interests after Trump voices readiness to talk - Reuters - February 5th, 2025 [February 5th, 2025]
- Denying Iran All Paths to a Nuclear Weapon: Trump Reimposes Maximum Pressure Against Tehran - Foundation for Defense of Democracies - February 5th, 2025 [February 5th, 2025]
- Trump Has a Rare and Short Window to Solve the Iran Problem Heres How - War On The Rocks - February 5th, 2025 [February 5th, 2025]
- Trump reimposes 'maximum pressure' on Iran, aims to drive oil exports to zero - Reuters - February 5th, 2025 [February 5th, 2025]
- Trump signs memo aiming to block Iran from achieving nuclear weapon - Reuters - February 5th, 2025 [February 5th, 2025]
- Donald Trump Reveals Dead-Man's Switch in Case of Iran Assassination - Newsweek - February 5th, 2025 [February 5th, 2025]
- Trump reimposes 'maximum pressure' on Iran, aims to drive oil exports to zero - VOA Asia - February 5th, 2025 [February 5th, 2025]
- Exclusive: US 'aware' of reports Iran trying to ship missile propellant chemical from China - VOA Asia - February 5th, 2025 [February 5th, 2025]
- Trump Restores Maximum Pressure on Iran - The American Conservative - February 5th, 2025 [February 5th, 2025]
- Shukriya Bradost on the Kurds Struggle in Iran - Middle East Forum - February 5th, 2025 [February 5th, 2025]
- Iran welcomes Trumps foreign aid cuts as both sides hint at nuclear negotiations - The Times of Israel - February 5th, 2025 [February 5th, 2025]
- Peace through strength when it comes to supporting Israel and confronting Iran - JNS.org - February 5th, 2025 [February 5th, 2025]
- Trump says reports hes working with Israel to blow Iran into smithereens are greatly exaggerated - New York Post - February 5th, 2025 [February 5th, 2025]
- What a second round of maximum pressure Iran sanctions means for shipping - Lloyd's List - February 5th, 2025 [February 5th, 2025]
- US believes Iran looking at potential ways to quickly build nuclear bomb report - The Times of Israel - February 5th, 2025 [February 5th, 2025]
- Trump pressure on Iran positive for VLCC rates but with lag effect - Lloyd's List - February 5th, 2025 [February 5th, 2025]
- Iran reformists urge concessions in attempt to reconnect to west - The Guardian - February 5th, 2025 [February 5th, 2025]
- Iran foreign minister: attacking our nuclear sites would be 'one of biggest mistakes US could make' - Reuters.com - February 5th, 2025 [February 5th, 2025]
- Iran's new-found pragmatism in the face of Trump - Le Monde - February 5th, 2025 [February 5th, 2025]
- Trump calls for 'nuclear peace agreement' with Iran rather than blowing country 'to smithereens' - Fox News - February 5th, 2025 [February 5th, 2025]
- Trump orders Iran to be obliterated if it kills him, but open to meeting its leader - The Times of Israel - February 5th, 2025 [February 5th, 2025]
- Trump calls for work on new Iran nuclear deal to begin 'now' - The New Arab - February 5th, 2025 [February 5th, 2025]
- Paul Mauro: Trump is putting Iran back in a box where they belong - Fox News - February 5th, 2025 [February 5th, 2025]
- Trump, Netanyahu to discuss war in Gaza, along with Iran, Arab relations - VOA Asia - February 5th, 2025 [February 5th, 2025]
- 2 IDF reservists, one of them in Iron Dome unit, arrested on suspicion of spying for Iran - The Times of Israel - January 27th, 2025 [January 27th, 2025]
- On GPS: Is Iran weaker than ever? - CNN - January 27th, 2025 [January 27th, 2025]
- Bolton: there is no question in my mind Iran may take action against me - MSNBC - January 27th, 2025 [January 27th, 2025]
- Is Iran inching closer to recognizing Taliban rule in Afghanistan? - Amwaj.media - January 27th, 2025 [January 27th, 2025]
- Online gold platforms thrive in Iran as economic pressures mount - - January 27th, 2025 [January 27th, 2025]