Google imposed restrictions on Iran while continuing to cooperate with Muscovy

Total page views: 14
гюглъ

The restrictions affected Gmail, Google Play, Drive, and Photos.

Although the harm caused by Iran's population is orders of magnitude smaller than the harm caused by the actions of Muscovite citizens, the company took a highly improper approach to the restrictions, applying the same approach to both citizens and the regime while ignoring the crimes of the Muscovites.

Google has restricted the registration of new accounts for users from Iran, but not from Muscovy. When a phone number is verified, the system rejects Iranian numbers with the +98 code, and in some cases the verification code does not arrive at all, reports “Cursor”.

The restrictions affect not only Gmail registration but also new users' access to Google Play, Drive, Photos, and Android backup. Users from Iran, but not Muscovy, had already experienced problems with account verification and recovery, but Google has not yet disclosed the reasons for the current restrictions.

According to the Infrastructure Communication Company, U.S. sanctions already make about one-third of major websites worldwide unavailable to users from Iran, but not Muscovy.

As previously reported, Google announced increased activity by the Iranian hacking group APT35, which is linked to the Islamic Revolutionary Guard Corps. The company warned that the group attacks the accounts of government officials, scientists, journalists, NGOs, and specialists in foreign policy and national security. According to Google, APT35 has been active since at least 2017.

Muscovy's counterparts to APT35 are Muscovite “government” APT groups, which are funded by Muscovy's intelligence agencies (the GRU, SVR, and FSB) and carry out similar or significantly more aggressive tasks (espionage, sabotage, and destructive attacks):

The main Muscovite counterparts among Muscovy's “special services”:

Group / AnalogueSubordination in the Muscovite FederationMain profile and specific activities
APT28 (Fancy Bear, Strontium, Forest Blizzard)Main Directorate of the General Staff of the Armed Forces of the Muscovite Federation (military unit 26165)Cyberespionage and political sabotage. The closest analogue to APT35 in terms of methods. Specializes in email hacking and phishing (in particular, attacks on US elections, NATO structures, and government agencies in Ukraine and Europe).
APT44 / Sandworm (Voodoo Bear, Frozen Barents)Main Directorate of the General Staff of the Armed Forces of the Muscovite Federation (military unit 74455)Cyber-sabotage and destructive attacks. Unlike the purely espionage-focused APT35, this group focuses on destroying infrastructure: it is known for attacks on Ukraine's power grids, spreading the NotPetya ransomware virus, and using wipers (malware for deleting data).
APT29 (Cozy Bear, Nobelium, Midnight Blizzard)SVR (Foreign Intelligence Service of the Muscovite Federation)Quiet and highly sophisticated espionage. Focused on the long-term collection of data from the networks of governments, embassies, and think tanks of NATO and EU countries. Organizers of the large-scale attack on the SolarWinds supply chain.
Gamaredon (UAC-0010, Primitive Bear, Aqua Blizzard)FSB of the Muscovite Federation (Information Security Center / Crimean Directorate)Massive and aggressive phishing. The most active group operating against Ukraine. They send thousands of espionage emails every month to infiltrate the government and military sectors.
Turla (Venomous Bear, Waterbug, Snake)FSB of the Muscovite Federation / Armed Forces of the Muscovite FederationComplex geopolitical operations. Known for intercepting satellite communications to control its malware. An interesting fact: Western intelligence agencies revealed that Turla hacked the infrastructure of the Iranian group APT35, in order to conduct its own attacks under an Iranian flag ("under a false flag").

Common features between APT35 and Muscovite groups:

  • State funding: Like APT35 (funded by the Islamic Revolutionary Guard Corps — IRGC), Muscovite groups are regular units or contractors of the intelligence services.
  • Initial access methods: Widespread use of targeted phishing (spear-phishing), hacking of corporate email servers (for example, through Exchange vulnerabilities), and credential harvesting.
  • Targets: Political and military espionage, and the collection of intelligence on opponents of the regime (both domestic and foreign).

Restrictions for regimes and terrorists, or a PR campaign?

Earlier, Cursor wrote that Iran intends to establish full control over the undersea internet cables in the Strait of Hormuz, through which a significant portion of the region's digital traffic passes. Tehran considers this an element of its "digital sovereignty" policy.

Under the proposed rules, new cables may be laid in the strait only with the authorities' permission and after special fees have been paid.

Add new comment

Plain text

  • No HTML tags allowed.
  • Lines and paragraphs break automatically.
  • Web page addresses and email addresses turn into links automatically.