Skip to main content

China hackers found to have compromised Iran entities for months

A Chinese hacking group targeted multiple Iranian government bodies in 2022 using advanced malware, according to an industry report. 

This photo taken on August 4, 2020 shows Prince, a member of the hacking group Red Hacker Alliance who refused to give his real name, using a website that monitors global cyberattacks on his computer at their office in Dongguan, China's southern Guangdong province. (Photo by NICOLAS ASFOURI/AFP via Getty Images)
This photo taken on Aug. 4, 2020, shows Prince, a member of the hacking group Red Hacker Alliance who refused to give his real name, using a website that monitors global cyberattacks on his computer at their office in Dongguan, China's southern Guangdong province. — Photo by NICOLAS ASFOURI/AFP via Getty Images

Chinese hacking group Playful Taurus aimed cyber attacks at Iranian government platforms from July to December of 2022, according to a report published Wednesday by American cybersecurity company Palo Alto Networks.

The company’s analysis suggests that four entities of the Iranian government's infrastructure have been compromised by what is known as an advanced persistent threat (APT), or cyberattack campaign with the goal to mine sensitive data.

Among the group's targets were Iran’s Foreign Ministry and Natural Resource Organization, read the findings from Palo Alto Networks' threat intelligence team called Unit 42. 

Mohamed Amine Belarbi, the CEO of Cypherleak, a cyber risk monitoring platform based in Dubai and Delaware, saw the attack as means to steal intelligence information and not necessarily to damage the Iranian infrastructure.  

SUBSCRIBER EXCLUSIVE

Continue reading this exclusive analysis

Original reporting and analysis unavailable elsewhere. Subscribe to AL-MONITOR to read this story and access everything we publish