Iranian meddling in U.S. election shows new skills. But is it really Iran? – Haaretz.com
The email coercing Democrats in Florida to vote for President Donald Trump seemed legitimate at first. It was sent from an apparently official email account, was personally addressed and even included the recipients home address. However, less than a day after the email was purportedly sent by far-right group the Proud Boys, U.S. officials revealed it to be part of an Iranian campaign to interfere in the U.S. election.
The influence campaign which also targeted voters in Alaska, Pennsylvania and Arizona showed a new level of Iranian sophistication, according to three Israeli cyberexperts who spoke with Haaretz and are knowledgeable about how hackers from the Islamic Republic operate.
They all say the bogus email marks a new type of cyberoffensive by Iran, but add that it raises further questions.
The case also highlights how difficult it is to attribute such cyberattacks nowadays, just as the United States ramps up its efforts to fight attempts by Russia, China and Iran to meddle in the November 3 election.
Last Wednesday, U.S. Director of National Intelligence John Ratcliffe said Russia and Iran have both tried to interfere in next weeks election.
The announcement followed a string of other statements by U.S. intelligence and law enforcement officials in recent weeks, revealing attempts past and present to undermine Americas voting system. These came through cyberattacks on voting networks and infrastructure, and disinformation campaigns. Though officials believe Russia is the bigger threat, both Russia and Iran are acting with what officials say is the clear intent to undermine the integrity of the electoral process.
Something new
According to Israeli web intelligence expert Dana Segev Moyal, the Proud Boys operation was different and more complex than past campaigns attributed to Iran.
Most of what we know publicly about previous attacks attributed to Iran is that they were usually either more complex technologically for example, cyberattacks on infrastructure or, when they were social influence campaigns, they tended to focus on spreading disinformation on social media.
Segev Moyal, who focuses on disinformation and has studied Irans past activities in this area, says were seeing something new this time: Weve never seen an email campaign targeting voters of a specific state with a specific message from a very specific organization, she notes.
We've got more newsletters we think you'll find interesting.
Please try again later.
The email address you have provided is already registered.
At minimum, this shows a pretty detailed understanding of American politics. I doubt your average Israeli or Iranian knows who the Proud Boys are. You need to do research and follow American politics closely. The extremist group made headlines after the first presidential debate, when President Trump refused to denounce it.
Boaz Dolev, a cybersecurity expert whose ClearSky firm has revealed Iranian cyberattacks and disinformation campaigns in recent years, agrees. He calls it a very rare attack.
What makes the attack so unique, according to both experts, is that it was actually quite simple from a technological perspective, but very complex in strategic terms.
Contrary to what people think, this attack doesnt actually require any hacking, Segev Moyal explains. Voter registration details are available online if you know how to find them. Whats interesting here is that they fused and corroborated different types of data to mount an influence campaign. Thats just not the type of planning weve seen up till now, she says.
In 2018, Dolevs ClearSky revealed a massive Iranian disinformation campaign. However, that operation was more in line with what we would term fake news and included a network of more than 70 pseudo-media outlets that covertly spread Iranian state propaganda in 15 different countries a far cry from the complex and hyper-targeted influence campaign now being attributed to them.
Though both experts say its hard to draw a direct line between the email campaign and Iran at least based on the information currently available they state that, much like Russia, Irans capabilities and techniques are always changing, making it that much harder to prove.
Dolev offers one recent example that surprised him: A few weeks ago, his firm revealed an Iranian cyberoperation in Israel that tried to pass itself off as a criminal (as opposed to state) offensive. Operation Quicksand, as it was labeled, also showed new modes of operation that hadnt previously been linked to Iran.
Theres a certain chain of attribution people in the world of cybersecurity know how to do, he explains. You can link a certain technology or technique to a certain team, and you can link that team back to certain states.
What I can tell you about the Iranians is that the last time we came out and said it was them [in Operation Quicksand], at first I didnt think it was them, because technologically it showed they had taken a step forward in terms of their actual capabilities. It was a professional job that I hadnt seen in this context before. But then you get some more information that allows you to make the attribution.
In the case of the Proud Boys email campaign, it was Reuters and the United States that made the attribution with the help of information provided by Google and Microsoft. All the experts Haaretz spoke with said that without reviewing the actual information, they couldnt independently confirm or deny the attributions veracity.
As Dolev puts it, experts in his field are constantly updating and revising their assumptions about what certain players can or cant do. So now we know Iran is an agent that has better technological capabilities than we had previously thought, he says, referring to Operation Quicksand.
Nonetheless, he says, when it comes to disinformation campaigns, most of their capabilities are actually basic even if their cyberoffensives against organizations have been stepped up and are better than we initially thought.
In this case, though, as Segev Moyal explains, the operation was actually complex: In addition to finding all the [voter] emails and cross-referencing all the different data sets, they also had to find a Proud Boys server that was vulnerable and actually produce an email campaign.
Proud Iranian boys?
The few details made public about how the email campaign was traced back to Iran show how complex such operations can be both for the perpetrator and those trying to thwart them.
According to Reuters, it was a series of dumb mistakes that revealed the attacks origins. For example, one of the emails sent out (there were a number in the campaign) included a video that purported to show how the hackers managed to obtain voter registration details. A few lines of code viewable in the video, as well as an IP address that was not blurred out, were traced back to websites and techniques previously used by Iran.
However, its exactly this type of slapdash error that also prompts questions. For instance, some reports have shown screen captures of the email. In one of them, theres a glaring typo in the subject line: Voteing with an e, Segev Moyal says. Its strange that someone would make such a big effort but then make such a silly mistake, she adds.
A third expert, who spoke on condition of anonymity due to the sensitivity of their work and the issue, added that certain aspects of the operation actually look more similar to Russian operations.
This appears to be a scenario also examined by the United States: Either they made a dumb mistake or wanted to get caught, said a senior U.S. government official who spoke to Reuters when the story broke last week. But they added: Were not concerned about this activity being some kind of false flag due to other supporting evidence. This was Iran.
Segev Moyal notes that this is not something we can say is definitely not Iran they can do that but there are also others who do such things. However, both she and Dolev refuse to call into question the American findings, saying that without further information, they simply cannot know for certain.
For Segev Moyal, one possible explanation is that, oftentimes, such campaigns are not really intended to succeed but merely to sow distrust and help create the sense that the U.S. electoral process is exposed to manipulation.
In this case, the video itself was also posted online. Social media analytics firm Graphika told Reuters that two Twitter accounts began posting links to the video last Tuesday evening and attempted to attract the attention of some media and political organizations. One account described itself as Trumps Soldier and shared a link to the video with the comment: It seems they hacked [the] voting system.
This also highlights how much the disinformation efforts piggyback statements being pushed out by the U.S. president himself.
When you look at this as an influence campaign that wants to sway public opinion, this could make sense, Segev Moyal says. This was not really a cyberattack on voter infrastructure no one, for example, is suggesting [the Iranians] or the Russians can alter the election results themselves.
From this perspective, the true goal of the email campaign was perhaps to fuel the narrative that Americas electoral system is exposed.
For Dolev, one of the most interesting aspects of the attack was the U.S. response and the governments decision to reveal the operation so quickly.
This is a new American policy and were also seeing it in regards to the Russians, he says, citing recent indictments against hackers operating for the GRU (the Russian armys intelligence branch). By revealing the operations, Dolev adds, the United States is in a sense fighting back, as publicity can counter the effectiveness of such influence campaigns.
During an influence campaign, the target countrys goal can be to respond as publicly as possible, Segev Moyal says. It helps restore public confidence, and show that everything is under control and voting systems have not actually been compromised. Like the operation itself, this type of response also aims at hearts and minds.
Here is the original post:
Iranian meddling in U.S. election shows new skills. But is it really Iran? - Haaretz.com
- Iran says German-Iranian died before execution was reported - BBC.com - November 5th, 2024 [November 5th, 2024]
- Iran is now dangerously vulnerable to the consequences of another attack on Israel - Business Insider - November 5th, 2024 [November 5th, 2024]
- Federal agencies say Russia and Iran are ramping up influence campaigns targeting US voters - The Associated Press - November 5th, 2024 [November 5th, 2024]
- Three sentenced to death in Iran over killing of top nuclear scientist - Al Jazeera English - November 5th, 2024 [November 5th, 2024]
- Russia launches Soyuz rocket with dozens of satellites, including two from Iran - Reuters - November 5th, 2024 [November 5th, 2024]
- Full-scale war in Middle East involving Israel and Iran likely, say most Europeans in poll - The Guardian - November 5th, 2024 [November 5th, 2024]
- Iran executes a Jewish citizen convicted of murder following a dispute over money - ABC News - November 5th, 2024 [November 5th, 2024]
- US says Iranian-American held in Iran as tensions high following Israeli attack on country - The Associated Press - November 5th, 2024 [November 5th, 2024]
- An Iranian-American journalist is believed to be held by Iran as tensions remain high after an Israeli attack, US says - ABC News - November 5th, 2024 [November 5th, 2024]
- Iran Issues Fresh Threats Against Israel, U.S. - Foundation for Defense of Democracies - November 5th, 2024 [November 5th, 2024]
- Iran arrests female university student who stripped to her underwear in protest over dress code enforcement - CBS News - November 5th, 2024 [November 5th, 2024]
- Oil prices settle up slightly on Iran worries, but prices down for week - Reuters - November 5th, 2024 [November 5th, 2024]
- Two members of Iran's Revolutionary Guards killed in helicopter crash - FRANCE 24 English - November 5th, 2024 [November 5th, 2024]
- Iran wants to hold region hostage with retaliation op - analysis - The Jerusalem Post - November 5th, 2024 [November 5th, 2024]
- Iran slams destabilizing presence as US sends B-52 bombers to region - The Times of Israel - November 5th, 2024 [November 5th, 2024]
- Woman strips off clothes at Iran university in apparent protest, reports say - Reuters - November 5th, 2024 [November 5th, 2024]
- Iran says two French detainees held in good conditions - Reuters - November 5th, 2024 [November 5th, 2024]
- Reformist clerics imply Iran should back two-state solution for Israel and Palestine - The Guardian - November 5th, 2024 [November 5th, 2024]
- Iran to use bigger warheads in attack on Israel - JNS.org - November 5th, 2024 [November 5th, 2024]
- Will Iran Withdraw from the Nuclear Non-Proliferation Treaty? - War On The Rocks - November 5th, 2024 [November 5th, 2024]
- From Iran to Turkey, how the Middle East is bracing for US elections - Al-Monitor - November 5th, 2024 [November 5th, 2024]
- Iran Rejects Nuclear Weapons but Will 'Defend Itself by All Means' - Newsweek - November 5th, 2024 [November 5th, 2024]
- Iran vows strong and complex attack against Israel in retaliation for strikes - New York Post - November 5th, 2024 [November 5th, 2024]
- US said to warn Iran it wont be able to restrain Israel if Tehran attacks again - The Times of Israel - November 5th, 2024 [November 5th, 2024]
- The Houthis couldn't have built their most dangerous weapons without help from Iran and others, UN experts find - Business Insider - November 5th, 2024 [November 5th, 2024]
- Iran detains woman who stripped to her underwear at university in apparent protest - ABC News - November 4th, 2024 [November 4th, 2024]
- Iran executes Jewish Iranian man after settlement aimed at saving him was rejected - The Times of Israel - November 4th, 2024 [November 4th, 2024]
- Israel says it conducted a ground raid in Syria and seized a Syrian citizen connected to Iran - PBS NewsHour - November 4th, 2024 [November 4th, 2024]
- Iran said planning to use more powerful weapons in next attack on Israel - The Times of Israel - November 4th, 2024 [November 4th, 2024]
- The Longer Iran Waits to Attack Israel, the More Risks It Takes - Haaretz - November 4th, 2024 [November 4th, 2024]
- Iran's enemies will receive crushing response - Khamenei - BBC.com - November 4th, 2024 [November 4th, 2024]
- Iran fears Trump win would bring Israeli strikes on nuclear sites, Western sanctions - The Times of Israel - November 4th, 2024 [November 4th, 2024]
- Israel says it carried out ground raid into Syria, seizing a Syrian citizen connected to Iran - The Associated Press - November 4th, 2024 [November 4th, 2024]
- Israel Iran war Live Updates: IDF says it eliminated Hezbollah commander Abu Ali Rida - The Times of India - November 4th, 2024 [November 4th, 2024]
- Iran plans strong and complex attack on Israel as Khamenei vows 'harsh retaliation' | What we know so far | Today News - Mint - November 4th, 2024 [November 4th, 2024]
- 'Orders to come from Iran': Iraqi militias pose growing risk to Israel - expert - The Jerusalem Post - November 4th, 2024 [November 4th, 2024]
- Iraq trying to reel in Iran-backed groups to prevent confrontation with Israel - The Times of Israel - November 4th, 2024 [November 4th, 2024]
- Iran warns of 'crushing response' following Israeli airstrikes as Pentagon announces plans to bolster US presence in the Middle East - Business... - November 4th, 2024 [November 4th, 2024]
- Khamenei aide warns Iran may review nuclear doctrine if facing existential threat - The Times of Israel - November 4th, 2024 [November 4th, 2024]
- Iran Is Freaked: The Air Force Is Sending B-52 Bombers Much Closer - The National Interest Online - November 4th, 2024 [November 4th, 2024]
- Israel at War Day 394 | Report: Iran's Army Will Participate in 'Strong and Complex' Attack on Israel - Haaretz - November 4th, 2024 [November 4th, 2024]
- Iran says airspace remains open - The Jerusalem Post - November 4th, 2024 [November 4th, 2024]
- UN experts say Houthis exploited Gaza war to boost regional status, aided by Iran - The Times of Israel - November 4th, 2024 [November 4th, 2024]
- Netanyahu tells U.S. that Israel will strike Iranian military, not nuclear or oil, targets, officials say - The Washington Post - October 16th, 2024 [October 16th, 2024]
- Opinion | Its Time for America to Get Real With Iran and Israel - The New York Times - October 16th, 2024 [October 16th, 2024]
- Iran says it will respond decisively if Israel attacks, asks UN to intervene - The Times of Israel - October 16th, 2024 [October 16th, 2024]
- US warns Iran to stop plotting against Trump, says US official - Reuters - October 16th, 2024 [October 16th, 2024]
- Iran working to control oil spill off Kharg Island, says IRNA - Reuters - October 16th, 2024 [October 16th, 2024]
- Israel said to decide on targets it could strike in Iran: Now a matter of time - The Times of Israel - October 16th, 2024 [October 16th, 2024]
- Israel will respond to Iran based on national interest - Netanyahu - BBC.com - October 16th, 2024 [October 16th, 2024]
- Israel Tells U.S. It Will Limit Its Expected Strike on Iran to Military Targets, Officials Say - The New York Times - October 16th, 2024 [October 16th, 2024]
- Israeli arrested for plot to kill local scientist in exchange for $100K from Iran - The Times of Israel - October 16th, 2024 [October 16th, 2024]
- Israel is ready to strike Iran with attack expected before US election: report - New York Post - October 16th, 2024 [October 16th, 2024]
- Iran Shouldnt Expect Russia to Come Riding to Its Rescue - Carnegie Endowment for International Peace - October 16th, 2024 [October 16th, 2024]
- Jordan tells Iran it will not allow anyone to violate its airspace - The Times of Israel - October 16th, 2024 [October 16th, 2024]
- Iran has a big surprise and is waiting for zero hour, warns senior IRGC officer - Middle East Monitor - October 16th, 2024 [October 16th, 2024]
- Iran cyber attacks against Israel surged after Gaza war started, Microsoft reports - The Times of Israel - October 16th, 2024 [October 16th, 2024]
- Sudans civil war fueled by secret arms shipments from UAE and Iran - The Washington Post - October 16th, 2024 [October 16th, 2024]
- Israel launches new strikes in Beirut despite U.S. warning over scale of attacks on Iran-backed Hezbollah - CBS News - October 16th, 2024 [October 16th, 2024]
- Any retaliation against Iran will be based on national interest, says Israel - The Guardian - October 16th, 2024 [October 16th, 2024]
- Would Iran Close the Strait of Hormuz in a Conflict? - The Maritime Executive - October 16th, 2024 [October 16th, 2024]
- Why The Exiled Crown Prince of Iran Is Urging Israel to 'Take Down' The Tyrannical Regime - CBN.com - October 16th, 2024 [October 16th, 2024]
- Israel has these four options for attacking Iran - The Economist - October 16th, 2024 [October 16th, 2024]
- Iran has a hit list of former Trump aides. The U.S. is scrambling to protect them. - POLITICO - October 14th, 2024 [October 14th, 2024]
- Biden warned Iran that killing Trump would be an act of war: report - Fox News - October 14th, 2024 [October 14th, 2024]
- Harris to Jewish voters: All options on the table to stop Iran from going nuclear - The Times of Israel - October 14th, 2024 [October 14th, 2024]
- Secret Documents Show Hamas Tried to Persuade Iran to Join Its Oct. 7 Attack - The New York Times - October 14th, 2024 [October 14th, 2024]
- Video: Iran warns US that it will retaliate against any future Israel strike - CNN - October 14th, 2024 [October 14th, 2024]
- Iran says it halted indirect talks with US in Oman as it waits for Israeli retaliation - The Times of Israel - October 14th, 2024 [October 14th, 2024]
- EU includes Iran Air in sanctions over missile transfer to Russia - Reuters - October 14th, 2024 [October 14th, 2024]
- US will send a missile defense system and troops to run it to Israel to aid defense against Iran - The Associated Press - October 14th, 2024 [October 14th, 2024]
- Two Israelis arrested for acts of sabotage, plotting assassination for Iran - The Times of Israel - October 14th, 2024 [October 14th, 2024]
- As Israel plots to strike Iran, its choices range from symbolic to severe - The Associated Press - October 14th, 2024 [October 14th, 2024]
- Uncertainty looms over Israels expected Iran strike; rescuers dig through debris in central Beirut - The Washington Post - October 14th, 2024 [October 14th, 2024]
- Iran Issues New Warning: 'We Have No Red Line' - Newsweek - October 14th, 2024 [October 14th, 2024]
- Iran's attacks on Israel suggest ballistic missiles are an overhyped threat - Business Insider - October 14th, 2024 [October 14th, 2024]
- A US missile-defense system, hailed as the world's best, is headed to Israel to counter Iran - Business Insider - October 14th, 2024 [October 14th, 2024]
- 'No red lines' in defending Iran and its interests, foreign minister says - FRANCE 24 English - October 14th, 2024 [October 14th, 2024]
- Iran bans pagers, walkie talkies on planes after blasts targeting Hezbollah members - The Times of Israel - October 14th, 2024 [October 14th, 2024]
- Putin hails very close links with Iran at landmark first meeting with president, as Middle East tensions soar - CNN - October 14th, 2024 [October 14th, 2024]