• Landing Page
  • Shop
  • Contact
  • Privacy Policy
  • Login
  • Register
Upgrade
TrivDaily
">
  • WorldNew
    Pound

    Pound hits 37-year low against dollar

    Palm Trees - WIND

    Hurricane Tracker : Tropical Storm Hurricane Nine has the potential to reach Florida

    Prince of Wales - TrivDaily

    Princess Diana’s title has been passed on to the Duchess of Cambridge

    TrivDaily - King Charles Speech

    3 main points to be gleaned from King Charles first public speech

    Abdul Qadeer Khan: ‘Father of Pakistan’s nuclear bomb’ dies

    Abdul Qadeer Khan: ‘Father of Pakistan’s nuclear bomb’ dies

    The Afghanistan airport explosion came about beneathneath Biden however lines lower back to Trump

    The Afghanistan airport explosion came about beneathneath Biden however lines lower back to Trump

    Hibernian  beat Arsenal 2-1 in first preseason game on Easter Road

    Hibernian beat Arsenal 2-1 in first preseason game on Easter Road

    After a “racist” tweet against England black players, comedian Andrew Lawrence’s agent cancelled his appearance in show.

    After a “racist” tweet against England black players, comedian Andrew Lawrence’s agent cancelled his appearance in show.

    Lionel Messi, Argentina win Copa America over Brazil

    Lionel Messi, Argentina win Copa America over Brazil

    Trending Tags

    • Lifestyle
      UK weather maps show exact date 7cm of snow and 63mph winds to batter Britain

      UK weather maps show exact date 7cm of snow and 63mph winds to batter Britain

      bet365 bonus code: Secure £30 bonus for Atalanta vs Chelsea trip with code SUN365

      bet365 bonus code: Secure £30 bonus for Atalanta vs Chelsea trip with code SUN365

      Crystal Palace into Champions League places as Guehi scores late winner at Fulham

      UK snow maps show 3-day barrage hitting 10 counties with -6C freeze

      UK snow maps show 3-day barrage hitting 10 counties with -6C freeze

      Hundreds of Man Utd fans stuck outside Old Trafford for West Ham clash with turnstile chaos ‘worst ever seen’

      Hundreds of Man Utd fans stuck outside Old Trafford for West Ham clash with turnstile chaos ‘worst ever seen’

      ARTE and Suspilne Ukraine sign an association agreement to strengthen cooperation

      ARTE and Suspilne Ukraine sign an association agreement to strengthen cooperation

      Trending Tags

      • Pandemic
    • Business
      Danger to Life’ as Storm Bram Batters Devon and Cornwall With Flooding and 90mph Winds

      Danger to Life’ as Storm Bram Batters Devon and Cornwall With Flooding and 90mph Winds

      Zelensky Rushes to London as Trump Accuses Him Over Peace Plan and Kremlin Applauds US Pressure

      Zelensky Rushes to London as Trump Accuses Him Over Peace Plan and Kremlin Applauds US Pressure

      Transmasculine Non-Binary Identity Explained As XG’s Cocona Comes Out

      Transmasculine Non-Binary Identity Explained As XG’s Cocona Comes Out

      Damson Idris and Lori Harvey Ignite ‘Back Together’ Speculation After Unexpected PDA at Art Basel Miami

      Damson Idris and Lori Harvey Ignite ‘Back Together’ Speculation After Unexpected PDA at Art Basel Miami

      Chris Hemsworth, Elsa Pataky Divorce Rumours: Wedding Rings Off As Couple ‘Drift Apart’

      Chris Hemsworth, Elsa Pataky Divorce Rumours: Wedding Rings Off As Couple ‘Drift Apart’

      Miss Universe 2025 Scandal: Why Fatima Bosch Refuses to Step Down Amid Claims of a ‘Predetermined’ Victory

      Miss Universe 2025 Scandal: Why Fatima Bosch Refuses to Step Down Amid Claims of a ‘Predetermined’ Victory

      Trending Tags

      • Vaccine
      • Pandemic
    • Entertainment
      Court dismisses £1.5m problem gambling claim against Betfair for second time

      Court dismisses £1.5m problem gambling claim against Betfair for second time

      Sophia Thakur’s Lexicon Is Love

      Sophia Thakur’s Lexicon Is Love

      President Trump awards medals to Sly Stallone, George Strait and more

      President Trump awards medals to Sly Stallone, George Strait and more

      Supplier Supplement: fraudsters, storytelling and technology

      Supplier Supplement: fraudsters, storytelling and technology

      Fred again.. And Blanco Combine On ‘Solo’

      Fred again.. And Blanco Combine On ‘Solo’

      Moonstone Rings: A Timeless Addition to Your Jewelry Collection

      Moonstone Rings: A Timeless Addition to Your Jewelry Collection

      The six Latin American markets the betting industry should keep an eye on

      The six Latin American markets the betting industry should keep an eye on

      Denmark backs “Banko Bill” to set rules of radio & walkie-talkie bingo

      Denmark backs “Banko Bill” to set rules of radio & walkie-talkie bingo

      Peru escalates dispute of Dina’s tax encroachment 

      Peru escalates dispute of Dina’s tax encroachment 

      Trending Tags

      • Sports
        Dusty May: No. 2 Michigan ‘Deserves’ to Be No. 1 After Dominating Villanova

        Dusty May: No. 2 Michigan ‘Deserves’ to Be No. 1 After Dominating Villanova

        AJ Dybantsa’s Career Night, Robert Wright III’s GW Lifts No. 10 BYU Past Clemson

        AJ Dybantsa’s Career Night, Robert Wright III’s GW Lifts No. 10 BYU Past Clemson

        Gen Z Trades Doomscrolling for Real-World Sweat: Key Takeaways from Strava’s 12th Year in Sport Report

        Gen Z Trades Doomscrolling for Real-World Sweat: Key Takeaways from Strava’s 12th Year in Sport Report

        Eagles at Chargers Live Updates | Monday Night Football

        Eagles at Chargers Live Updates | Monday Night Football

        Stake Canada App — Download, Legality, Features & How-To (2025)

        Stake Canada App — Download, Legality, Features & How-To (2025)

        Buccaneers’ NFC South Chances Take Massive Hit After Loss to Saints

        Buccaneers’ NFC South Chances Take Massive Hit After Loss to Saints

        Dallas Cowboys may have found a late-round gem in WR Ryan Flournoy

        Dallas Cowboys may have found a late-round gem in WR Ryan Flournoy

        Cowboys 2025 rookie report: Rookie class was flat in battle against the Lions

        Cowboys 2025 rookie report: Rookie class was flat in battle against the Lions

        Rockets’ Kevin Durant Latest to Score 31K Career Points During Win vs. Suns

        Rockets’ Kevin Durant Latest to Score 31K Career Points During Win vs. Suns

        Trending Tags

        • Travel
          Football’s biggest names including Mbappe and Haaland rally behind Mohamed Salah after Liverpool axe

          Football’s biggest names including Mbappe and Haaland rally behind Mohamed Salah after Liverpool axe

          Man Utd face Premier League bogey side and Arsenal travel to former winners as full FA Cup Third Round draw revealed

          Man Utd face Premier League bogey side and Arsenal travel to former winners as full FA Cup Third Round draw revealed

          Finding stillness in Kyoto: My solo journey through Japan’s most peaceful retreats

          Finding stillness in Kyoto: My solo journey through Japan’s most peaceful retreats

          Saudi giants enquire about Liverpool star Salah

          Saudi giants enquire about Liverpool star Salah

          Christmas chaos warning as staff set to strike at major UK airport

          Christmas chaos warning as staff set to strike at major UK airport

          How volcanic eruptions brought the Black Death to Europe

          How volcanic eruptions brought the Black Death to Europe

          Trending Tags

          • Technology

            Trending Tags

            • Real Estate

              Trending Tags

              No Result
              View All Result
              • WorldNew
                Pound

                Pound hits 37-year low against dollar

                Palm Trees - WIND

                Hurricane Tracker : Tropical Storm Hurricane Nine has the potential to reach Florida

                Prince of Wales - TrivDaily

                Princess Diana’s title has been passed on to the Duchess of Cambridge

                TrivDaily - King Charles Speech

                3 main points to be gleaned from King Charles first public speech

                Abdul Qadeer Khan: ‘Father of Pakistan’s nuclear bomb’ dies

                Abdul Qadeer Khan: ‘Father of Pakistan’s nuclear bomb’ dies

                The Afghanistan airport explosion came about beneathneath Biden however lines lower back to Trump

                The Afghanistan airport explosion came about beneathneath Biden however lines lower back to Trump

                Hibernian  beat Arsenal 2-1 in first preseason game on Easter Road

                Hibernian beat Arsenal 2-1 in first preseason game on Easter Road

                After a “racist” tweet against England black players, comedian Andrew Lawrence’s agent cancelled his appearance in show.

                After a “racist” tweet against England black players, comedian Andrew Lawrence’s agent cancelled his appearance in show.

                Lionel Messi, Argentina win Copa America over Brazil

                Lionel Messi, Argentina win Copa America over Brazil

                Trending Tags

                • Lifestyle
                  UK weather maps show exact date 7cm of snow and 63mph winds to batter Britain

                  UK weather maps show exact date 7cm of snow and 63mph winds to batter Britain

                  bet365 bonus code: Secure £30 bonus for Atalanta vs Chelsea trip with code SUN365

                  bet365 bonus code: Secure £30 bonus for Atalanta vs Chelsea trip with code SUN365

                  Crystal Palace into Champions League places as Guehi scores late winner at Fulham

                  UK snow maps show 3-day barrage hitting 10 counties with -6C freeze

                  UK snow maps show 3-day barrage hitting 10 counties with -6C freeze

                  Hundreds of Man Utd fans stuck outside Old Trafford for West Ham clash with turnstile chaos ‘worst ever seen’

                  Hundreds of Man Utd fans stuck outside Old Trafford for West Ham clash with turnstile chaos ‘worst ever seen’

                  ARTE and Suspilne Ukraine sign an association agreement to strengthen cooperation

                  ARTE and Suspilne Ukraine sign an association agreement to strengthen cooperation

                  Trending Tags

                  • Pandemic
                • Business
                  Danger to Life’ as Storm Bram Batters Devon and Cornwall With Flooding and 90mph Winds

                  Danger to Life’ as Storm Bram Batters Devon and Cornwall With Flooding and 90mph Winds

                  Zelensky Rushes to London as Trump Accuses Him Over Peace Plan and Kremlin Applauds US Pressure

                  Zelensky Rushes to London as Trump Accuses Him Over Peace Plan and Kremlin Applauds US Pressure

                  Transmasculine Non-Binary Identity Explained As XG’s Cocona Comes Out

                  Transmasculine Non-Binary Identity Explained As XG’s Cocona Comes Out

                  Damson Idris and Lori Harvey Ignite ‘Back Together’ Speculation After Unexpected PDA at Art Basel Miami

                  Damson Idris and Lori Harvey Ignite ‘Back Together’ Speculation After Unexpected PDA at Art Basel Miami

                  Chris Hemsworth, Elsa Pataky Divorce Rumours: Wedding Rings Off As Couple ‘Drift Apart’

                  Chris Hemsworth, Elsa Pataky Divorce Rumours: Wedding Rings Off As Couple ‘Drift Apart’

                  Miss Universe 2025 Scandal: Why Fatima Bosch Refuses to Step Down Amid Claims of a ‘Predetermined’ Victory

                  Miss Universe 2025 Scandal: Why Fatima Bosch Refuses to Step Down Amid Claims of a ‘Predetermined’ Victory

                  Trending Tags

                  • Vaccine
                  • Pandemic
                • Entertainment
                  Court dismisses £1.5m problem gambling claim against Betfair for second time

                  Court dismisses £1.5m problem gambling claim against Betfair for second time

                  Sophia Thakur’s Lexicon Is Love

                  Sophia Thakur’s Lexicon Is Love

                  President Trump awards medals to Sly Stallone, George Strait and more

                  President Trump awards medals to Sly Stallone, George Strait and more

                  Supplier Supplement: fraudsters, storytelling and technology

                  Supplier Supplement: fraudsters, storytelling and technology

                  Fred again.. And Blanco Combine On ‘Solo’

                  Fred again.. And Blanco Combine On ‘Solo’

                  Moonstone Rings: A Timeless Addition to Your Jewelry Collection

                  Moonstone Rings: A Timeless Addition to Your Jewelry Collection

                  The six Latin American markets the betting industry should keep an eye on

                  The six Latin American markets the betting industry should keep an eye on

                  Denmark backs “Banko Bill” to set rules of radio & walkie-talkie bingo

                  Denmark backs “Banko Bill” to set rules of radio & walkie-talkie bingo

                  Peru escalates dispute of Dina’s tax encroachment 

                  Peru escalates dispute of Dina’s tax encroachment 

                  Trending Tags

                  • Sports
                    Dusty May: No. 2 Michigan ‘Deserves’ to Be No. 1 After Dominating Villanova

                    Dusty May: No. 2 Michigan ‘Deserves’ to Be No. 1 After Dominating Villanova

                    AJ Dybantsa’s Career Night, Robert Wright III’s GW Lifts No. 10 BYU Past Clemson

                    AJ Dybantsa’s Career Night, Robert Wright III’s GW Lifts No. 10 BYU Past Clemson

                    Gen Z Trades Doomscrolling for Real-World Sweat: Key Takeaways from Strava’s 12th Year in Sport Report

                    Gen Z Trades Doomscrolling for Real-World Sweat: Key Takeaways from Strava’s 12th Year in Sport Report

                    Eagles at Chargers Live Updates | Monday Night Football

                    Eagles at Chargers Live Updates | Monday Night Football

                    Stake Canada App — Download, Legality, Features & How-To (2025)

                    Stake Canada App — Download, Legality, Features & How-To (2025)

                    Buccaneers’ NFC South Chances Take Massive Hit After Loss to Saints

                    Buccaneers’ NFC South Chances Take Massive Hit After Loss to Saints

                    Dallas Cowboys may have found a late-round gem in WR Ryan Flournoy

                    Dallas Cowboys may have found a late-round gem in WR Ryan Flournoy

                    Cowboys 2025 rookie report: Rookie class was flat in battle against the Lions

                    Cowboys 2025 rookie report: Rookie class was flat in battle against the Lions

                    Rockets’ Kevin Durant Latest to Score 31K Career Points During Win vs. Suns

                    Rockets’ Kevin Durant Latest to Score 31K Career Points During Win vs. Suns

                    Trending Tags

                    • Travel
                      Football’s biggest names including Mbappe and Haaland rally behind Mohamed Salah after Liverpool axe

                      Football’s biggest names including Mbappe and Haaland rally behind Mohamed Salah after Liverpool axe

                      Man Utd face Premier League bogey side and Arsenal travel to former winners as full FA Cup Third Round draw revealed

                      Man Utd face Premier League bogey side and Arsenal travel to former winners as full FA Cup Third Round draw revealed

                      Finding stillness in Kyoto: My solo journey through Japan’s most peaceful retreats

                      Finding stillness in Kyoto: My solo journey through Japan’s most peaceful retreats

                      Saudi giants enquire about Liverpool star Salah

                      Saudi giants enquire about Liverpool star Salah

                      Christmas chaos warning as staff set to strike at major UK airport

                      Christmas chaos warning as staff set to strike at major UK airport

                      How volcanic eruptions brought the Black Death to Europe

                      How volcanic eruptions brought the Black Death to Europe

                      Trending Tags

                      • Technology

                        Trending Tags

                        • Real Estate

                          Trending Tags

                          No Result
                          View All Result
                          TrivDaily
                          No Result
                          View All Result
                          Home Technology

                          Ex-IDF cyber chief on Iran, Scattered Spider, and why social engineering worries him more than 0-days

                          Ferhan Rana by Ferhan Rana
                          July 20, 2025
                          in Technology
                          Reading Time:3 mins read
                          31.4k 317
                          A A
                          0
                          Ex-IDF cyber chief on Iran, Scattered Spider, and why social engineering worries him more than 0-days
                          29.7k
                          SHARES
                          33.8k
                          VIEWS
                          Share on FacebookShare on Twitter
                          ">

                          Interview Scattered Spider and Iranian government-backed cyber units have more in common than a recent uptick in hacking activity, according to Ariel Parnes, a former colonel in the Israeli Defense Forces’ cyber unit 8200.

                          Both the financially motivated crew and Tehran’s APT groups excel at social engineering attacks, and are proof positive that cybercriminals don’t necessarily need to use zero-days to inflict damage.

                          “One of the famous cases in Israel was with an insurance company,” Parnes, co-founder and COO at cloud threat detection and response firm Mitiga, told The Register.

                          He’s referring to an Iranian hack-and-leak operation in late 2020 against Israeli insurance company Shirbit, which insured employees of Israel’s Defense Ministry — although it’s worth noting that Scattered Spider also had a more recent run of digital intrusions into American insurance firms.

                          An Iran government-backed group “stole data, leveraging social engineering and one day vulnerabilities,” Parnes said. After stealing the Shirbit files, which included Israelis’ private information, the crew dumped them all online.

                          “The power of the attack, more than anything else, was the psychological impact of it,” Parnes continued. “It’s the fact that they were able to get their hands on sensitive data from citizens of Israel, some of them working in the government, and then they amplified that through social media and other tools. This is their modus operandi. It’s not just about the real impact, but rather the amplification of it.”

                          While their cyber campaigns against Israeli targets haven’t slowed in the subsequent years, Iranian groups have also used these same tactics against Western organizations and government officials: spear-phishing intent on stealing credentials, social engineering including setting up fake LinkedIn personas, breaking into US water and fuel systems and then doing nothing with the access — but then making it into a big deal on social media.

                          You don’t need to be a superpower, you don’t need to be the NSA with zero days, you just need to have the skills to understand how the organization that you’re targeting operates

                          “And now generative AI introduces capabilities in being able to master social engineering, both in quality and quantity,” Parnes said. “If you’re an attacker and you have your target, let’s say, a bank in the US, you need to do reconnaissance, gather intelligence on the target, and then build an attack that is relevant to the audience. Generative AI saves years of investment in the reconnaissance phase.”

                          AI-based systems can generate complete reports about targeted individuals, their interests, memberships in personal and professional organizations, colleagues and friends — all from scraping potential victims’ social media pages, he opined.

                          “And that allows me to be significantly more effective in this first step than if I needed to do all of that manually,” Parnes said.

                          Plus, AI makes it much easier to craft phishing emails, phony documents, and even spoofed websites that look and sound real. “So it makes this attack significantly more scalable — Google said Iranian threat actors were using Gemini for these purposes,” he added. “This is what worries me more than zero-days.”

                          “You don’t need to be a superpower, you don’t need to be the NSA with zero days, you just need to have the skills to understand how the organization that you’re targeting operates, who the actors are, what processes and procedures understand people, understand language, understand culture, and this is it.”

                          • Google to Iran: Yes, we see you using Gemini for phishing and scripting. We’re onto you
                          • Iranian ransomware crew reemerges, promises big bucks for attacks on US or Israel
                          • That WhatsApp from an Israeli infosec expert could be a Iranian phish
                          • Ex-NSA bad-guy hunter listened to Scattered Spider’s fake help-desk calls: ‘Those guys are good’

                          Scattered Spider, perhaps even more so than Iranian spies, has mastered social engineering and they’ve got a built-in advantage when it comes to attacking American and British orgs because they are native speakers, who know the language and the culture.

                          “Scattered Spider is an example of how powerful social engineering can be,” Parnes said, adding that he wouldn’t be surprised to see some level of collaboration between the financially motivated gang and Tehran’s state-sponsored crews along the lines of Iran’s Pioneer Kitten working with ALPHV/BlackCat and other ransomware-as-a-service gangs.

                          Plus, there are already indications that state-linked attackers are adding ransomware to their toolkits.

                          “Scattered Spider harvests identities, and they sell them to whoever wants to buy them, so Iran threat actors could use them in their campaigns,” Parnes said. “It all ends up in Iranians being able to do much more with their rather rudimentary capabilities.”

                          Neither Iran nor Scattered Spider “have the most advanced cyber weapons,” he added. “But maybe they don’t need it.” ®

                          ">

                          Interview Scattered Spider and Iranian government-backed cyber units have more in common than a recent uptick in hacking activity, according to Ariel Parnes, a former colonel in the Israeli Defense Forces’ cyber unit 8200.

                          Both the financially motivated crew and Tehran’s APT groups excel at social engineering attacks, and are proof positive that cybercriminals don’t necessarily need to use zero-days to inflict damage.

                          “One of the famous cases in Israel was with an insurance company,” Parnes, co-founder and COO at cloud threat detection and response firm Mitiga, told The Register.

                          He’s referring to an Iranian hack-and-leak operation in late 2020 against Israeli insurance company Shirbit, which insured employees of Israel’s Defense Ministry — although it’s worth noting that Scattered Spider also had a more recent run of digital intrusions into American insurance firms.

                          An Iran government-backed group “stole data, leveraging social engineering and one day vulnerabilities,” Parnes said. After stealing the Shirbit files, which included Israelis’ private information, the crew dumped them all online.

                          “The power of the attack, more than anything else, was the psychological impact of it,” Parnes continued. “It’s the fact that they were able to get their hands on sensitive data from citizens of Israel, some of them working in the government, and then they amplified that through social media and other tools. This is their modus operandi. It’s not just about the real impact, but rather the amplification of it.”

                          While their cyber campaigns against Israeli targets haven’t slowed in the subsequent years, Iranian groups have also used these same tactics against Western organizations and government officials: spear-phishing intent on stealing credentials, social engineering including setting up fake LinkedIn personas, breaking into US water and fuel systems and then doing nothing with the access — but then making it into a big deal on social media.

                          You don’t need to be a superpower, you don’t need to be the NSA with zero days, you just need to have the skills to understand how the organization that you’re targeting operates

                          “And now generative AI introduces capabilities in being able to master social engineering, both in quality and quantity,” Parnes said. “If you’re an attacker and you have your target, let’s say, a bank in the US, you need to do reconnaissance, gather intelligence on the target, and then build an attack that is relevant to the audience. Generative AI saves years of investment in the reconnaissance phase.”

                          AI-based systems can generate complete reports about targeted individuals, their interests, memberships in personal and professional organizations, colleagues and friends — all from scraping potential victims’ social media pages, he opined.

                          “And that allows me to be significantly more effective in this first step than if I needed to do all of that manually,” Parnes said.

                          Plus, AI makes it much easier to craft phishing emails, phony documents, and even spoofed websites that look and sound real. “So it makes this attack significantly more scalable — Google said Iranian threat actors were using Gemini for these purposes,” he added. “This is what worries me more than zero-days.”

                          “You don’t need to be a superpower, you don’t need to be the NSA with zero days, you just need to have the skills to understand how the organization that you’re targeting operates, who the actors are, what processes and procedures understand people, understand language, understand culture, and this is it.”

                          • Google to Iran: Yes, we see you using Gemini for phishing and scripting. We’re onto you
                          • Iranian ransomware crew reemerges, promises big bucks for attacks on US or Israel
                          • That WhatsApp from an Israeli infosec expert could be a Iranian phish
                          • Ex-NSA bad-guy hunter listened to Scattered Spider’s fake help-desk calls: ‘Those guys are good’

                          Scattered Spider, perhaps even more so than Iranian spies, has mastered social engineering and they’ve got a built-in advantage when it comes to attacking American and British orgs because they are native speakers, who know the language and the culture.

                          “Scattered Spider is an example of how powerful social engineering can be,” Parnes said, adding that he wouldn’t be surprised to see some level of collaboration between the financially motivated gang and Tehran’s state-sponsored crews along the lines of Iran’s Pioneer Kitten working with ALPHV/BlackCat and other ransomware-as-a-service gangs.

                          Plus, there are already indications that state-linked attackers are adding ransomware to their toolkits.

                          “Scattered Spider harvests identities, and they sell them to whoever wants to buy them, so Iran threat actors could use them in their campaigns,” Parnes said. “It all ends up in Iranians being able to do much more with their rather rudimentary capabilities.”

                          Neither Iran nor Scattered Spider “have the most advanced cyber weapons,” he added. “But maybe they don’t need it.” ®

                          ">

                          Interview Scattered Spider and Iranian government-backed cyber units have more in common than a recent uptick in hacking activity, according to Ariel Parnes, a former colonel in the Israeli Defense Forces’ cyber unit 8200.

                          Both the financially motivated crew and Tehran’s APT groups excel at social engineering attacks, and are proof positive that cybercriminals don’t necessarily need to use zero-days to inflict damage.

                          “One of the famous cases in Israel was with an insurance company,” Parnes, co-founder and COO at cloud threat detection and response firm Mitiga, told The Register.

                          He’s referring to an Iranian hack-and-leak operation in late 2020 against Israeli insurance company Shirbit, which insured employees of Israel’s Defense Ministry — although it’s worth noting that Scattered Spider also had a more recent run of digital intrusions into American insurance firms.

                          An Iran government-backed group “stole data, leveraging social engineering and one day vulnerabilities,” Parnes said. After stealing the Shirbit files, which included Israelis’ private information, the crew dumped them all online.

                          “The power of the attack, more than anything else, was the psychological impact of it,” Parnes continued. “It’s the fact that they were able to get their hands on sensitive data from citizens of Israel, some of them working in the government, and then they amplified that through social media and other tools. This is their modus operandi. It’s not just about the real impact, but rather the amplification of it.”

                          While their cyber campaigns against Israeli targets haven’t slowed in the subsequent years, Iranian groups have also used these same tactics against Western organizations and government officials: spear-phishing intent on stealing credentials, social engineering including setting up fake LinkedIn personas, breaking into US water and fuel systems and then doing nothing with the access — but then making it into a big deal on social media.

                          You don’t need to be a superpower, you don’t need to be the NSA with zero days, you just need to have the skills to understand how the organization that you’re targeting operates

                          “And now generative AI introduces capabilities in being able to master social engineering, both in quality and quantity,” Parnes said. “If you’re an attacker and you have your target, let’s say, a bank in the US, you need to do reconnaissance, gather intelligence on the target, and then build an attack that is relevant to the audience. Generative AI saves years of investment in the reconnaissance phase.”

                          AI-based systems can generate complete reports about targeted individuals, their interests, memberships in personal and professional organizations, colleagues and friends — all from scraping potential victims’ social media pages, he opined.

                          “And that allows me to be significantly more effective in this first step than if I needed to do all of that manually,” Parnes said.

                          Plus, AI makes it much easier to craft phishing emails, phony documents, and even spoofed websites that look and sound real. “So it makes this attack significantly more scalable — Google said Iranian threat actors were using Gemini for these purposes,” he added. “This is what worries me more than zero-days.”

                          “You don’t need to be a superpower, you don’t need to be the NSA with zero days, you just need to have the skills to understand how the organization that you’re targeting operates, who the actors are, what processes and procedures understand people, understand language, understand culture, and this is it.”

                          • Google to Iran: Yes, we see you using Gemini for phishing and scripting. We’re onto you
                          • Iranian ransomware crew reemerges, promises big bucks for attacks on US or Israel
                          • That WhatsApp from an Israeli infosec expert could be a Iranian phish
                          • Ex-NSA bad-guy hunter listened to Scattered Spider’s fake help-desk calls: ‘Those guys are good’

                          Scattered Spider, perhaps even more so than Iranian spies, has mastered social engineering and they’ve got a built-in advantage when it comes to attacking American and British orgs because they are native speakers, who know the language and the culture.

                          “Scattered Spider is an example of how powerful social engineering can be,” Parnes said, adding that he wouldn’t be surprised to see some level of collaboration between the financially motivated gang and Tehran’s state-sponsored crews along the lines of Iran’s Pioneer Kitten working with ALPHV/BlackCat and other ransomware-as-a-service gangs.

                          Plus, there are already indications that state-linked attackers are adding ransomware to their toolkits.

                          “Scattered Spider harvests identities, and they sell them to whoever wants to buy them, so Iran threat actors could use them in their campaigns,” Parnes said. “It all ends up in Iranians being able to do much more with their rather rudimentary capabilities.”

                          Neither Iran nor Scattered Spider “have the most advanced cyber weapons,” he added. “But maybe they don’t need it.” ®

                          ">

                          Interview Scattered Spider and Iranian government-backed cyber units have more in common than a recent uptick in hacking activity, according to Ariel Parnes, a former colonel in the Israeli Defense Forces’ cyber unit 8200.

                          Both the financially motivated crew and Tehran’s APT groups excel at social engineering attacks, and are proof positive that cybercriminals don’t necessarily need to use zero-days to inflict damage.

                          “One of the famous cases in Israel was with an insurance company,” Parnes, co-founder and COO at cloud threat detection and response firm Mitiga, told The Register.

                          He’s referring to an Iranian hack-and-leak operation in late 2020 against Israeli insurance company Shirbit, which insured employees of Israel’s Defense Ministry — although it’s worth noting that Scattered Spider also had a more recent run of digital intrusions into American insurance firms.

                          An Iran government-backed group “stole data, leveraging social engineering and one day vulnerabilities,” Parnes said. After stealing the Shirbit files, which included Israelis’ private information, the crew dumped them all online.

                          “The power of the attack, more than anything else, was the psychological impact of it,” Parnes continued. “It’s the fact that they were able to get their hands on sensitive data from citizens of Israel, some of them working in the government, and then they amplified that through social media and other tools. This is their modus operandi. It’s not just about the real impact, but rather the amplification of it.”

                          While their cyber campaigns against Israeli targets haven’t slowed in the subsequent years, Iranian groups have also used these same tactics against Western organizations and government officials: spear-phishing intent on stealing credentials, social engineering including setting up fake LinkedIn personas, breaking into US water and fuel systems and then doing nothing with the access — but then making it into a big deal on social media.

                          You don’t need to be a superpower, you don’t need to be the NSA with zero days, you just need to have the skills to understand how the organization that you’re targeting operates

                          “And now generative AI introduces capabilities in being able to master social engineering, both in quality and quantity,” Parnes said. “If you’re an attacker and you have your target, let’s say, a bank in the US, you need to do reconnaissance, gather intelligence on the target, and then build an attack that is relevant to the audience. Generative AI saves years of investment in the reconnaissance phase.”

                          AI-based systems can generate complete reports about targeted individuals, their interests, memberships in personal and professional organizations, colleagues and friends — all from scraping potential victims’ social media pages, he opined.

                          “And that allows me to be significantly more effective in this first step than if I needed to do all of that manually,” Parnes said.

                          Plus, AI makes it much easier to craft phishing emails, phony documents, and even spoofed websites that look and sound real. “So it makes this attack significantly more scalable — Google said Iranian threat actors were using Gemini for these purposes,” he added. “This is what worries me more than zero-days.”

                          “You don’t need to be a superpower, you don’t need to be the NSA with zero days, you just need to have the skills to understand how the organization that you’re targeting operates, who the actors are, what processes and procedures understand people, understand language, understand culture, and this is it.”

                          • Google to Iran: Yes, we see you using Gemini for phishing and scripting. We’re onto you
                          • Iranian ransomware crew reemerges, promises big bucks for attacks on US or Israel
                          • That WhatsApp from an Israeli infosec expert could be a Iranian phish
                          • Ex-NSA bad-guy hunter listened to Scattered Spider’s fake help-desk calls: ‘Those guys are good’

                          Scattered Spider, perhaps even more so than Iranian spies, has mastered social engineering and they’ve got a built-in advantage when it comes to attacking American and British orgs because they are native speakers, who know the language and the culture.

                          “Scattered Spider is an example of how powerful social engineering can be,” Parnes said, adding that he wouldn’t be surprised to see some level of collaboration between the financially motivated gang and Tehran’s state-sponsored crews along the lines of Iran’s Pioneer Kitten working with ALPHV/BlackCat and other ransomware-as-a-service gangs.

                          Plus, there are already indications that state-linked attackers are adding ransomware to their toolkits.

                          “Scattered Spider harvests identities, and they sell them to whoever wants to buy them, so Iran threat actors could use them in their campaigns,” Parnes said. “It all ends up in Iranians being able to do much more with their rather rudimentary capabilities.”

                          Neither Iran nor Scattered Spider “have the most advanced cyber weapons,” he added. “But maybe they don’t need it.” ®

                          Tags: cyberEx-IDF
                          ">
                          Ferhan Rana

                          Ferhan Rana

                          Related Posts

                          Trump Is Building a ‘U.S. Tech Force’ of 1,000+ Early Career Workers
                          Technology

                          Trump Is Building a ‘U.S. Tech Force’ of 1,000+ Early Career Workers

                          by Ferhan Rana
                          December 16, 2025
                          Trump’s Vile Post About Rob Reiner Has Some Republicans Breaking Ranks
                          Technology

                          Trump’s Vile Post About Rob Reiner Has Some Republicans Breaking Ranks

                          by Ferhan Rana
                          December 16, 2025
                          Nutanix takes another swipe at VMware with sovereign cloud push
                          Technology

                          Nutanix takes another swipe at VMware with sovereign cloud push

                          by Ferhan Rana
                          December 15, 2025
                          Roomba maker iRobot gets cleaned out in Chapter 11
                          Technology

                          Roomba maker iRobot gets cleaned out in Chapter 11

                          by Ferhan Rana
                          December 15, 2025
                          The future of long-term data storage is clear and will last 14 billion years
                          Technology

                          The future of long-term data storage is clear and will last 14 billion years

                          by Ferhan Rana
                          December 14, 2025

                          Premium Content

                          Princess Theodora and Matthew Kumar look so in love in official wedding photos

                          Princess Theodora and Matthew Kumar look so in love in official wedding photos

                          September 29, 2024
                          World of Warcraft‘s Developers Just Made a Huge Leap Forward For Video Game Unionization

                          World of Warcraft‘s Developers Just Made a Huge Leap Forward For Video Game Unionization

                          July 25, 2024
                          Man United vs. Tottenham odds: Free 2025 UEFA Europa League final picks, prediction for Wednesday, May 21

                          Man United vs. Tottenham odds: Free 2025 UEFA Europa League final picks, prediction for Wednesday, May 21

                          May 21, 2025

                          Browse by Category

                          • Business
                          • Crypto
                          • Entertainment
                          • Fashion
                          • Health
                          • Lifestyle
                          • Real Estate
                          • Sports
                          • Technology
                          • Travel
                          • Uncategorized
                          • World

                          Browse by Tags

                          announces Apple Barcelona Beckham Charles Elizabeth Europe Exclusive First George Google Harry health Inside Intel James Jennifer Kelly launches Lewis makes Manchester Markle Meghan Michael Microsoft Middleton people Prince Princess Queen REPORT reveals Review Royal Samsung Shares Taylor Trump Twitter wants WATCH William World Years
                          TrivDaily

                          Get the latest World news and analysis, breaking news, features and special reports from World. Also watch videos from across the Europian continent.

                          Learn more

                          Categories

                          • Business
                          • Crypto
                          • Entertainment
                          • Fashion
                          • Health
                          • Lifestyle
                          • Real Estate
                          • Sports
                          • Technology
                          • Travel
                          • Uncategorized
                          • World

                          Browse by Tag

                          Business (1564) Crypto (1643) Entertainment (1988) Fashion (3) Health (1863) Lifestyle (1890) Real Estate (40) Sports (3100) Technology (3055) Travel (1480) Uncategorized (11) World (23)

                          Recent Posts

                          • Taylor Swift, Travis Kelce Wedding Details Leak: Couple Ditch Rhode Island for New York Ceremony
                          • Louisville Cardinals Basketball transfer portal tracker live updates, news on commits, departures from the program
                          • Allen still confident of a top six finish for Wrexham

                          © 2021 TrivDaily - Developed by ADSA Solutions.

                          Welcome Back!

                          Login to your account below

                          Forgotten Password? Sign Up

                          Create New Account!

                          Fill the forms bellow to register

                          All fields are required. Log In

                          Retrieve your password

                          Please enter your username or email address to reset your password.

                          Log In

                          Add New Playlist

                          • Login
                          • Sign Up
                          • Cart
                          No Result
                          View All Result
                          • Home
                          • Business News
                          • Entertainment News
                          • Lifestyle News
                          • Health News
                          • Tech News
                          • Real Estate News
                          • World News

                          © 2021 TrivDaily - Developed by ADSA Solutions.

                          Are you sure want to unlock this post?
                          Unlock left : 0
                          Are you sure want to cancel subscription?