Researchers say Iran is using new and more aggressive tools to spy on its citizens. EPA
Researchers say Iran is using new and more aggressive tools to spy on its citizens. EPA
Researchers say Iran is using new and more aggressive tools to spy on its citizens. EPA
Researchers say Iran is using new and more aggressive tools to spy on its citizens. EPA

Iran is using chat apps to spy on its citizens, researchers say


  • English
  • Arabic

Bob Diachenko, a security researcher in Ukraine, spends part of his days searching the internet for troves of data that aren’t secured properly, in order to patch them up so they aren’t exploited by hackers.

Last month, he came across an unsecured server storing information on 42 million messaging accounts, nearly all from Iran and tied to the chat app Telegram.

There were no immediate clues as to who had obtained the data and placed it on the server. There was only a landing page, all black, with the logo of a white eagle and a message in Farsi.

“Welcome to the Hunting System,” it said.

Mr Diachenko said he notified an Iranian cybersecurity agency, and soon after that, the server was taken down.

But before it vanished, other cybersleuths began their own investigations. Ultimately, that led them to a hacking group with an unlikely nickname – Charming Kitten – and a startling conclusion: Mr Diachenko had stumbled across an Iranian government spying operation.

“For more than 10 years, I have been monitoring Iranian cyber-attacks and surveillance, and I have never seen anything like this,” said Amir Rashidi, an Iranian internet security and digital rights researcher, who is based in New York. “They could use this to go after my relatives, my friends, my family.”

The trove of data, portions of which were reviewed by Bloomberg , contained usernames, phone numbers, user biographies, and unique codes – or “hashes” – associated with the accounts stored on the server.

It’s not clear if the data was mostly from Telegram users or from users of unofficial versions of the app that became popular after Telegram was banned in Iran in 2018. Some of the unofficial apps, which use the same source code as Telegram, have been previously linked to Iran’s government.

Either way, the data could be used to clone people’s accounts and spy on private communications, identify people who are using Telegram anonymously, or send out propaganda or disinformation aimed at specific groups, Mr Diachenko said.

Mr Rashidi said Iran was previously known to selectively target and hack particular people’s accounts. But the Hunting System indicates Iranian authorities are using new and more aggressive techniques to collect and analyse huge troves of information about their citizens, he said.

“This is the first time that I have seen evidence that they are trying to analyse the data on a massive scale,” Mr Rashidi said.

Telegram said in an email statement that it believes the data originated from unofficial versions of its app that are used in Iran, which it said could have covertly harvested information about Telegram users from people’s phones.

“The data samples which we were able to study clearly show that the data was collected using third-party apps that stole data from their users,” said Markus Ra, a Telegram spokesman.

“If one of your friends who has your number used a malicious app, your number and username can end up in a database” like the Hunting System, Mr Ra said, “even if you haven’t used that malicious app yourself.”

"For more than 10 years, I have been monitoring Iranian cyber-attacks and surveillance, and I have never seen anything like this," said Amir Rashidi, an Iranian internet security and digital rights researcher, who is based in New York

At least some of the user accounts in the data trove are associated with active users of the official Telegram app, based on a review comparing accounts on the server and on Telegram. Timestamps indicate that some of the Telegram user records were accessed as recently as March 2020.

Iran’s Cyber Police didn’t respond to requests for comment. Amir Nazemi, deputy minister at Iran’s Ministry of Communication and Information Technology, said he filed a complaint about the data breach with Iran’s attorney general’s office. He declined to comment on whether the Cyber Police or other government agencies were involved in the Hunting System.

Mr Diachenko’s discovery of the server was reported in a computer trade publication. Several Iranian security researchers continued delving into the data.

One of them, Mohammad Jorjandi, who lives and works in the US, said he discovered that the server storing the user data had been registered to an office in northwestern Tehran by a person named Manouchehr Hashemloo.

Using online records seen by Bloomberg, Mr Jorjandi determined that Mr Hashemloo was using the same Gmail address used by a well-known hacker tied to the Iranian government. The hacker, who goes by ArYaIeIrAN, has been associated with an alleged Iranian government-sponsored hacking group known as Charming Kitten, which has a history of targeting Iranian dissidents, academics, journalists and human rights activists.

The people who had set up the Hunting System server, Mr Jorjandi concluded, were probably working for the Iranian government.

ClearSky Cyber Security has also previously uncovered several hacking operations perpetrated by ArYaIeIrAN, the alias associated with Mr Hashemloo, and a 2017 report cited the hacker’s Gmail address and linked it to operations carried out by Charming Kitten.

Mr Hashemloo didn’t respond to an email request for comment.

Another Iranian security researcher said that Mr Hashemloo was “a known person in security and hacker society” in Iran whose “name was on many Iran government cyber operations”. The researcher, who lives in Iran and requested anonymity because of safety concerns, said the Hunting System was probably a portal for Iran’s Cyber Police agency, which was set up in 2011 in part to target dissident groups and government critics.

Charming Kitten’s hacking exploits have been documented by researchers for several years.

In its 2017 report, ClearSky documented that Charming Kitten had created fake news websites – including one named britishnews.com – and tried to hack the computers of journalists, human rights activists and researchers based in Europe and the Middle East.

Last year, ClearSky said the same group of hackers had attempted to break into the email accounts of current and former US officials, people involved with the current US presidential campaign, journalists covering global politics and prominent Iranians living outside Iran.

“We have strong evidence to believe Charming Kitten is a state-sponsored” hacking group in Iran, said Ohad Zaidenberg, the company’s lead cyber intelligence researcher.

Mr Zaidenberg said he hadn’t assessed who was behind the Hunting System. But in the past, he said, the Charming Kitten group had targeted Telegram users. The group had previously set up a malicious website that was designed to look like a Telegram login page, he said.

For years, Iranians have used Telegram as a means to communicate using encryption to protect private messages. The app also allows users to join groups where they can find out about news that is censored by state media in the country.

After a ban on Telegram, some Iranians circumvented it by using software such as virtual private networks, which allowed them to bypass the country’s block on the Telegram website, according to Mr Rashidi.

Others began downloading unofficial versions of Telegram, called Hotgram and Telegram Gold, which rely on the same underlying code as the official app but aren’t operated by Telegram.

Security experts suspected that the unofficial apps may have been developed by the Iranian government as a means to monitor the country’s citizens.

In May 2019, Nassrollah Pezhmanfar, a member of Iran’s parliament, confirmed those suspicions, stating that Telegram Gold and Hotgram were sponsored by Iran’s intelligence and communication ministries, which he said had spent about $90 million (Dh330m) to create them.

“It was obvious that they were connected to authorities in Iran,” said Mahsa Alimardani, a researcher who specialises in Iran at the Oxford Internet Institute. “They were censoring content on the platforms and seeking to centralise control over users.”

Neither Telegram Gold or Hotgram responded to an email message seeking comment.

Telegram has warned Iranians against using the unofficial apps. Last year,they were removed from the Google Play Store because of security concerns.

“Unfortunately, despite our warnings, people in Iran are still using unverified apps,” said the Telegram spokesman. “Apps like Hotgram or Telegram Gold are very likely to be connected to this.”

In numbers: China in Dubai

The number of Chinese people living in Dubai: An estimated 200,000

Number of Chinese people in International City: Almost 50,000

Daily visitors to Dragon Mart in 2018/19: 120,000

Daily visitors to Dragon Mart in 2010: 20,000

Percentage increase in visitors in eight years: 500 per cent

The%20Afghan%20connection
%3Cp%3EThe%20influx%20of%20talented%20young%20Afghan%20players%20to%20UAE%20cricket%20could%20have%20a%20big%20impact%20on%20the%20fortunes%20of%20both%20countries.%20Here%20are%20three%20Emirates-based%20players%20to%20watch%20out%20for.%0D%3Cbr%3E%20%0D%3Cbr%3E%3Cstrong%3EHassan%20Khan%20Eisakhil%3C%2Fstrong%3E%0D%3Cbr%3EMohammed%20Nabi%20is%20still%20proving%20his%20worth%20at%20the%20top%20level%20but%20there%20is%20another%20reason%20he%20is%20raging%20against%20the%20idea%20of%20retirement.%20If%20the%20allrounder%20hangs%20on%20a%20little%20bit%20longer%2C%20he%20might%20be%20able%20to%20play%20in%20the%20same%20team%20as%20his%20son%2C%20Hassan%20Khan.%20The%20family%20live%20in%20Ajman%20and%20train%20in%20Sharjah.%0D%3Cbr%3E%20%0D%3Cbr%3E%3Cstrong%3EMasood%20Gurbaz%3C%2Fstrong%3E%0D%3Cbr%3EThe%20opening%20batter%2C%20who%20trains%20at%20Sharjah%20Cricket%20Academy%2C%20is%20another%20player%20who%20is%20a%20part%20of%20a%20famous%20family.%20His%20brother%2C%20Rahmanullah%2C%20was%20an%20IPL%20winner%20with%20Kolkata%20Knight%20Riders%2C%20and%20opens%20the%20batting%20with%20distinction%20for%20Afghanistan.%0D%3Cbr%3E%20%0D%3Cbr%3E%3Cstrong%3EOmid%20Rahman%3C%2Fstrong%3E%0D%3Cbr%3EThe%20fast%20bowler%20became%20a%20pioneer%20earlier%20this%20year%20when%20he%20became%20the%20first%20Afghan%20to%20represent%20the%20UAE.%20He%20showed%20great%20promise%20in%20doing%20so%2C%20too%2C%20playing%20a%20key%20role%20in%20the%20senior%20team%E2%80%99s%20qualification%20for%20the%20Asia%20Cup%20in%20Muscat%20recently.%0D%3Cbr%3E%3C%2Fp%3E%0A
MATCH INFO

Barcelona 2
Suarez (10'), Messi (52')

Real Madrid 2
Ronaldo (14'), Bale (72')

UAE%20SQUAD
%3Cp%3EMuhammad%20Waseem%20(captain)%2C%20Aayan%20Khan%2C%20Aryan%20Lakra%2C%20Ashwanth%20Valthapa%2C%20Asif%20Khan%2C%20Aryansh%20Sharma%2C%20CP%20Rizwaan%2C%20Hazrat%20Billal%2C%20Junaid%20Siddique%2C%20Karthik%20Meiyappan%2C%20Rohan%20Mustafa%2C%20Vriitya%20Aravind%2C%20Zahoor%20Khan%20and%20Zawar%20Farid.%3C%2Fp%3E%0A

Various Artists 
Habibi Funk: An Eclectic Selection Of Music From The Arab World (Habibi Funk)
​​​​​​​

The specs
  • Engine: 3.9-litre twin-turbo V8
  • Power: 640hp
  • Torque: 760nm
  • On sale: 2026
  • Price: Not announced yet
The%20specs%3A%202024%20Mercedes%20E200
%3Cp%3E%3Cstrong%3EEngine%3A%20%3C%2Fstrong%3E2.0-litre%20four-cyl%20turbo%20%2B%20mild%20hybrid%0D%3Cbr%3E%3Cstrong%3EPower%3A%20%3C%2Fstrong%3E204hp%20at%205%2C800rpm%20%2B23hp%20hybrid%20boost%0D%3Cbr%3E%3Cstrong%3ETorque%3A%20%3C%2Fstrong%3E320Nm%20at%201%2C800rpm%20%2B205Nm%20hybrid%20boost%0D%3Cbr%3E%3Cstrong%3ETransmission%3A%20%3C%2Fstrong%3E9-speed%20auto%0D%3Cbr%3E%3Cstrong%3EFuel%20consumption%3A%20%3C%2Fstrong%3E7.3L%2F100km%0D%3Cbr%3E%3Cstrong%3EOn%20sale%3A%20%3C%2Fstrong%3ENovember%2FDecember%0D%3Cbr%3E%3Cstrong%3EPrice%3A%20%3C%2Fstrong%3EFrom%20Dh205%2C000%20(estimate)%3C%2Fp%3E%0A
UAE currency: the story behind the money in your pockets
RESULTS

Mumbai Indians 181-4 (20 ovs)
Kolkata Knight Riders 168-6 (20ovs)

Mumbai won by 13 runs

Rajasthan Royals 152-9 (20 ovs)
Kings XI Punjab 155-4 (18.4 ovs)

Kings XI Punjab won by 6 wickets

Profile of Udrive

Date started: March 2016

Founder: Hasib Khan

Based: Dubai

Employees: 40

Amount raised (to date): $3.25m – $750,000 seed funding in 2017 and a Seed round of $2.5m last year. Raised $1.3m from Eureeca investors in January 2021 as part of a Series A round with a $5m target.

The burning issue

The internal combustion engine is facing a watershed moment – major manufacturer Volvo is to stop producing petroleum-powered vehicles by 2021 and countries in Europe, including the UK, have vowed to ban their sale before 2040. The National takes a look at the story of one of the most successful technologies of the last 100 years and how it has impacted life in the UAE.

Part three: an affection for classic cars lives on

Read part two: how climate change drove the race for an alternative 

Read part one: how cars came to the UAE

If you go

Flights

Emirates flies from Dubai to Phnom Penh with a stop in Yangon from Dh3,075, and Etihad flies from Abu Dhabi to Phnom Penh with its partner Bangkok Airlines from Dh2,763. These trips take about nine hours each and both include taxes. From there, a road transfer takes at least four hours; airlines including KC Airlines (www.kcairlines.com) offer quick connecting flights from Phnom Penh to Sihanoukville from about $100 (Dh367) return including taxes. Air Asia, Malindo Air and Malaysian Airlines fly direct from Kuala Lumpur to Sihanoukville from $54 each way. Next year, direct flights are due to launch between Bangkok and Sihanoukville, which will cut the journey time by a third.

The stay

Rooms at Alila Villas Koh Russey (www.alilahotels.com/ kohrussey) cost from $385 per night including taxes.

F1 The Movie

Starring: Brad Pitt, Damson Idris, Kerry Condon, Javier Bardem

Director: Joseph Kosinski

Rating: 4/5

EMIRATES'S%20REVISED%20A350%20DEPLOYMENT%20SCHEDULE
%3Cp%3E%3Cstrong%3EEdinburgh%3A%3C%2Fstrong%3E%20November%204%20%3Cem%3E(unchanged)%3C%2Fem%3E%3C%2Fp%3E%0A%3Cp%3E%3Cstrong%3EBahrain%3A%3C%2Fstrong%3E%20November%2015%20%3Cem%3E(from%20September%2015)%3C%2Fem%3E%3B%20second%20daily%20service%20from%20January%201%3C%2Fp%3E%0A%3Cp%3E%3Cstrong%3EKuwait%3A%3C%2Fstrong%3E%20November%2015%20%3Cem%3E(from%20September%2016)%3C%2Fem%3E%3C%2Fp%3E%0A%3Cp%3E%3Cstrong%3EMumbai%3A%3C%2Fstrong%3E%20January%201%20%3Cem%3E(from%20October%2027)%3C%2Fem%3E%3C%2Fp%3E%0A%3Cp%3E%3Cstrong%3EAhmedabad%3A%3C%2Fstrong%3E%20January%201%20%3Cem%3E(from%20October%2027)%3C%2Fem%3E%3C%2Fp%3E%0A%3Cp%3E%3Cstrong%3EColombo%3A%3C%2Fstrong%3E%20January%202%20%3Cem%3E(from%20January%201)%3C%2Fem%3E%3C%2Fp%3E%0A%3Cp%3E%3Cstrong%3EMuscat%3A%3C%2Fstrong%3E%3Cem%3E%20%3C%2Fem%3EMarch%201%3Cem%3E%20(from%20December%201)%3C%2Fem%3E%3C%2Fp%3E%0A%3Cp%3E%3Cstrong%3ELyon%3A%3C%2Fstrong%3E%20March%201%20%3Cem%3E(from%20December%201)%3C%2Fem%3E%3C%2Fp%3E%0A%3Cp%3E%3Cstrong%3EBologna%3A%3C%2Fstrong%3E%20March%201%20%3Cem%3E(from%20December%201)%3C%2Fem%3E%3C%2Fp%3E%0A%3Cp%3E%3Cem%3ESource%3A%20Emirates%3C%2Fem%3E%3C%2Fp%3E%0A
The biog

Hometown: Birchgrove, Sydney Australia
Age: 59
Favourite TV series: Outlander Netflix series
Favourite place in the UAE: Sheikh Zayed Grand Mosque / desert / Louvre Abu Dhabi
Favourite book: Father of our Nation: Collected Quotes of Sheikh Zayed bin Sultan Al Nahyan
Thing you will miss most about the UAE: My friends and family, Formula 1, having Friday's off, desert adventures, and Arabic culture and people
 

A little about CVRL

Founded in 1985 by Sheikh Mohammed bin Rashid, Vice President and Ruler of Dubai, the Central Veterinary Research Laboratory (CVRL) is a government diagnostic centre that provides testing and research facilities to the UAE and neighbouring countries.

One of its main goals is to provide permanent treatment solutions for veterinary related diseases. 

The taxidermy centre was established 12 years ago and is headed by Dr Ulrich Wernery. 

While you're here

Michael Young: Where is Lebanon headed?

Kareem Shaheen: I owe everything to Beirut

Raghida Dergham: We have to bounce back

Fund-raising tips for start-ups

Develop an innovative business concept

Have the ability to differentiate yourself from competitors

Put in place a business continuity plan after Covid-19

Prepare for the worst-case scenario (further lockdowns, long wait for a vaccine, etc.) 

Have enough cash to stay afloat for the next 12 to 18 months

Be creative and innovative to reduce expenses

Be prepared to use Covid-19 as an opportunity for your business

* Tips from Jassim Al Marzooqi and Walid Hanna

Key facilities
  • Olympic-size swimming pool with a split bulkhead for multi-use configurations, including water polo and 50m/25m training lanes
  • Premier League-standard football pitch
  • 400m Olympic running track
  • NBA-spec basketball court with auditorium
  • 600-seat auditorium
  • Spaces for historical and cultural exploration
  • An elevated football field that doubles as a helipad
  • Specialist robotics and science laboratories
  • AR and VR-enabled learning centres
  • Disruption Lab and Research Centre for developing entrepreneurial skills
Benefits of first-time home buyers' scheme
  • Priority access to new homes from participating developers
  • Discounts on sales price of off-plan units
  • Flexible payment plans from developers
  • Mortgages with better interest rates, faster approval times and reduced fees
  • DLD registration fee can be paid through banks or credit cards at zero interest rates