833-847-3280
Schedule a Call

Hacking: Phishing, Malware, Password Spraying – DHS warns U.S. about Hackers

Hacking

In late June of 2019, the Department of Homeland Security (DHS) warned US companies of increased malicious cyber-activity, or hacking, from Iranian Hackers.

Consequently, DHS has urged US companies to do everything they can to protect against some of the hackers’ most common hacking practices.

These include data-wiping malware, password spraying, spear phishing, and credential stuffing.

 

What are the common hacking practices?

Data-wiping malware is just like it sounds. It deletes data on compromised systems. The purpose is usually to prevent forensic analysis.

In 2012, Iran utilized this malware scheme to attack major oil companies in Saudi Arabia and Qatar. The companies temporarily forced to stop oil production. This triggered financial losses.

Password Spraying is an attack that mimics brute force attacks.

For example, the hacker will take a commonly used password (“password”) and see how many accounts they can access with it while coming through in the internet.

Spear phishing is a type of social engineering attack where the hacker will send a detailed specific email to someone in an organization attempting to gather information.

For example, an email that comes from the CEO to the head of HR asking for social security numbers.

Credential stuffing is simply a hacker taking known information like usernames and passwords that have been leaked on third-party sites.

They will use this information to gain access to accounts that are being targeting. This is considered targeting password reuse.

An example of this is people who use same password for multiple accounts such as Banking, email, Amazon, and Facebook.

 

What does this mean for the United States?

With the United States now working against Iran, it is likely that U.S. companies will now become targets. Iranian hackers have successfully gone after energy companies in the past.

Most importantly, MainNerve is sure all U.S. industries will be easy targets.  Please take these warnings very seriously. Not only are we attempting to keep U.S., Chinese, and Russian hackers at bay, now we have gained notoriety for Iranian hackers to be placed in the queue.

In conclusion, if you would like to see how your employees react to spear phishing in a controlled way, you can purchase one of our social engineering tests.

We can provide information on who might need a little extra training.

Latest Posts

A transparent image used for creating empty spaces in columns
In today’s digital landscape, cyberattacks are relentless, sophisticated, and increasingly costly. Yet, many government regulations designed to protect sensitive data and critical infrastructure fall short, not because they lack good intentions, but because they fail to explicitly require penetration testing as a standard practice. This regulatory ambiguity…
A transparent image used for creating empty spaces in columns
 Every IT manager knows the drill. You schedule your annual penetration test, the security team arrives, runs their tools, and delivers a comprehensive report detailing vulnerabilities and recommendations. You check the compliance box, file the report, and get back to your daily grind. Fast…
A transparent image used for creating empty spaces in columns
When a major brand like Victoria’s Secret, MGM, or T-Mobile gets hacked, it’s all over the news. These companies are household names, and a breach affecting them often exposes millions of customer records, making it a national, or even global, story. But what about small…
A transparent image used for creating empty spaces in columns
 Choosing a penetration tester isn’t just about credentials or price; it’s about trust, depth, and the results they deliver. In today’s rapidly evolving cybersecurity landscape, selecting the right penetration testing partner is more critical than ever. At MainNerve, we’ve witnessed significant shifts in the…
A transparent image used for creating empty spaces in columns
Cybersecurity threats in 2025 are evolving faster than most organizations can keep pace with. In early 2025, a global financial institution paid out a staggering $75 million following a ransomware attack. The cause? A single, compromised endpoint tied to a legacy application that had gone…
A transparent image used for creating empty spaces in columns
   Targeted retesting focuses only on the vulnerabilities you’ve already remediated. It’s scoped tightly around the affected systems, configurations, or application components that were updated, patched, or re-engineered in response to findings from the original penetration test. This approach offers several key benefits: 1.…
contact

Our Team

Name(Required)
This field is for validation purposes and should be left unchanged.
On Load
Where? .serviceMM
What? Mega Menu: Services