Hamid Kashfi
Check @AleeAmini 's post. He has done a remarkable job of analyzing samples from last year's wipe of Iranian banks. I briefly wrote and talked about the operation before, but now that the cat is out of the bag, I guess everyone gets to enjoy the craftsmanship behind it. The blog post covers only the post-exploitation phase and local side of works, jumping from local access to unrestricted firmware and memory. The initial access remains uncovered here, but I strongly believe at least one of the RCEs dell fixed last year was used for gaining initial access to storage devices. The structure and style of tooling and operation is also very similar and hallmarks of the infamous Predatory Sparrows. Details about this overlap will remain TLP gated though. You might remember a glimpse of that from the wiping attack against Iranian gas stations and fuel distribution system, which also attempted soft-bricking POS devices installed on pumps, combined with partial wipe of mid-level management and relay servers. One of the most interesting aspects of these wipers used in Iran, which I believe are first of its kind publicly documented as well, are combining software based wipes with physical disruption of operation of device switches. This is mostly an effort to further block attempts to interrupt the wipe operation by physically switching off or restarting the storage device on-site. That alone buys some extra wipe time, before datacenter operators literally pull the plug on machines. https://aleeamini.com/firmburn-firmware-zero-day-scsi-passthru-burned-iran-banks-hack/