Close Menu
Technology Mag

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot
    The Biggest AI Companies Met to Find a Better Path for Chatbot Companions

    The Biggest AI Companies Met to Find a Better Path for Chatbot Companions

    November 21, 2025
    Judge wants to fix Google’s ad tech monopoly before it’s too late

    Judge wants to fix Google’s ad tech monopoly before it’s too late

    November 21, 2025
    Sony’s PlayStation Portal just got a rare discount for Black Friday

    Sony’s PlayStation Portal just got a rare discount for Black Friday

    November 21, 2025
    Facebook X (Twitter) Instagram
    Subscribe
    Technology Mag
    Facebook X (Twitter) Instagram YouTube
    • Home
    • News
    • Business
    • Games
    • Gear
    • Reviews
    • Science
    • Security
    • Trending
    • Press Release
    Technology Mag
    Home » How a Group of Israel-Linked Hackers Has Pushed the Limits of Cyberwar
    Security

    How a Group of Israel-Linked Hackers Has Pushed the Limits of Cyberwar

    News RoomBy News RoomJanuary 26, 20244 Mins Read
    Facebook Twitter Pinterest LinkedIn Reddit WhatsApp Email
    How a Group of Israel-Linked Hackers Has Pushed the Limits of Cyberwar

    Predatory Sparrow is distinguished most of all by its apparent interest in sending a specific geopolitical message with its attacks, says Juan Andres Guerrero-Saade, an analyst at cybersecurity firm SentinelOne who has tracked the group for years. Those messages are all variations on a theme: If you attack Israel or its allies, we have the ability to deeply disrupt your civilization. “They’re showing that they can reach out and touch Iran in meaningful ways,” Guerrero-Saade says. “They’re saying, ‘You can prop up the Houthis and Hamas and Hezbollah in these proxy wars. But we, Predatory Sparrow, can dismantle your country piece by piece without having to move from where we are.’”

    Here’s a brief history of Predatory’s short but distinguished track record of hyper-disruptive cyberattacks.

    2021: Train Chaos

    In early July of 2021, computers showing schedules across Iran’s national railway system began to display messages in Farsi declaring the message “long delay because of cyberattack,” or simply “canceled,” along with the phone number of the office of Iran’s Supreme Leader Ali Khamenei, as if to suggest that Iranians call the number for updates or to complain. SentinelOne’s Guerrero-Saade analyzed the malware used in the attack, which he dubbed Meteor Express, and found that the hackers had deployed a three-stage wiping program that destroyed computers’ file systems, locked out users, and then wiped the master boot record that machines use to locate their operating system when they start up. Iran’s Fars radio station reported that the result of the cyberattack was “unprecedented chaos,” but it later deleted that statement.

    Around the same time, computers across the network of Iran’s Ministry of Roads and Urban Development were hit with the wiper tool, too. Analysis of the wiper malware by Israeli security firm CheckPoint revealed that the hackers had likely used different versions of the same tools years earlier while breaking into Iran-linked targets in Syria, in those cases under the guise of a hacker group named for the Hindu god of storms, Indra.

    “Our goal of this cyber attack while maintaining the safety of our countrymen is to express our disgust with the abuse and cruelty that the government ministries and organizations allow to the nation,” Predatory Sparrow wrote in a post in Farsi on its Telegram channel, suggesting that it was posing as an Iranian hacktivist group as it claimed credit for the attacks.

    2021: Gas Station Paralysis

    Just a few months later, on October 26, 2021, Predatory Sparrow struck again. This time, it targeted point-of-sale systems at more than 4,000 gas stations across Iran—the majority of all fuel pumps in the country—taking down the system used to accept payment by gasoline subsidy cards distributed to Iranian citizens. Hamid Kashfi, an Iranian emigré and founder of the cybersecurity firm DarkCell, analyzed the attack but only published his detailed findings last month. He notes that the attack’s timing came exactly two years after the Iranian government attempted to reduce fuel subsidies, triggering riots across the country. Echoing the railway attack, the hackers displayed a message on fuel pump screens with the Supreme Leader’s phone number, as if to blame Iran’s government for this gas disruption, too. “If you look at it from a holistic view, it looks like an attempt to trigger riots again in the country,” Kashfi says, “to increase the gap between the government and the people and cause more tension.”

    The attack immediately led to long lines at gas stations across Iran that lasted days. But Kashfi argues that the gas station attack, despite its enormous effects, represents one where Predatory Sparrow demonstrated actual restraint. He inferred, based on detailed data uploaded by Iranian incident responders to the malware repository VirusTotal, that the hackers had enough access to the gas stations’ payment infrastructure to have destroyed the entire system, forcing manual reinstallation of software at gas stations or even reissuing of subsidy cards. Instead, they merely wiped the point-of-sale systems in a way that would allow relatively quick recovery.

    Share. Facebook Twitter Pinterest LinkedIn WhatsApp Reddit Email
    Previous ArticleReminder: Amazon Prime Video is getting ads next week
    Next Article The seven dirty words you can’t say with AI

    Related Posts

    Vaping Is ‘Everywhere’ in Schools—Sparking a Bathroom Surveillance Boom

    Vaping Is ‘Everywhere’ in Schools—Sparking a Bathroom Surveillance Boom

    November 21, 2025
    A Major Leak Spills a Chinese Hacking Contractor’s Tools and Targets

    A Major Leak Spills a Chinese Hacking Contractor’s Tools and Targets

    November 21, 2025
    A Simple WhatsApp Security Flaw Exposed 3.5 Billion Phone Numbers

    A Simple WhatsApp Security Flaw Exposed 3.5 Billion Phone Numbers

    November 20, 2025
    Mexico City Is the Most Video-Surveilled Metropolis in the Americas

    Mexico City Is the Most Video-Surveilled Metropolis in the Americas

    November 20, 2025
    This Is the Platform Google Claims Is Behind a ‘Staggering’ Scam Text Operation

    This Is the Platform Google Claims Is Behind a ‘Staggering’ Scam Text Operation

    November 19, 2025
    DOJ Issued Seizure Warrant to Starlink Over Satellite Internet Systems Used at Scam Compound

    DOJ Issued Seizure Warrant to Starlink Over Satellite Internet Systems Used at Scam Compound

    November 19, 2025
    Our Picks
    Judge wants to fix Google’s ad tech monopoly before it’s too late

    Judge wants to fix Google’s ad tech monopoly before it’s too late

    November 21, 2025
    Sony’s PlayStation Portal just got a rare discount for Black Friday

    Sony’s PlayStation Portal just got a rare discount for Black Friday

    November 21, 2025
    This Quest 3S Bundle Is  Off and Includes a Game and Gift Card

    This Quest 3S Bundle Is $50 Off and Includes a Game and Gift Card

    November 21, 2025
    You can now try the Xbox Full Screen Experience on any PC, laptop, or tablet

    You can now try the Xbox Full Screen Experience on any PC, laptop, or tablet

    November 21, 2025
    • Facebook
    • Twitter
    • Pinterest
    • Instagram
    • YouTube
    • Vimeo
    Don't Miss
    Nothing’s Android 16 update puts a progress bar on the back of your phone News

    Nothing’s Android 16 update puts a progress bar on the back of your phone

    By News RoomNovember 21, 2025

    Nothing’s Android 16-powered update brings a bunch of new features to its phones, including its…

    Press a button and this SSD will self-destruct with all your data

    Press a button and this SSD will self-destruct with all your data

    November 21, 2025
    The US Needs an Open Source AI Intervention to Beat China

    The US Needs an Open Source AI Intervention to Beat China

    November 21, 2025
    Apple’s new limited edition iPhone grip is all about accessibility

    Apple’s new limited edition iPhone grip is all about accessibility

    November 21, 2025
    Facebook X (Twitter) Instagram Pinterest
    • Privacy Policy
    • Terms of use
    • Advertise
    • Contact
    © 2025 Technology Mag. All Rights Reserved.

    Type above and press Enter to search. Press Esc to cancel.