Iranian intelligence service behind hack of LA transit system, researchers say
Iranian intelligence service operatives, known as Ababil of Minab, were responsible for a significant cyberattack targeting the Los Angeles County Metropolitan Transportation Authority (LACMTA). The group, linked to the Ministry of Intelligence and Security of Iran (MOIS), exfiltrated data and caused infrastructure damage, utilizing sophisticated techniques to hinder recovery efforts. This attack highlights Iran’s expanding cyber capabilities and its targeting of critical infrastructure.
The attack on the LACMTA, attributed to Ababil of Minab, involved the exfiltration of data and the deliberate destruction of the transit system’s infrastructure. Researchers at Gambit Security identified a clear connection between the group and the Ministry of Intelligence and Security of Iran (MOIS) based on forensic evidence from prior Iran-backed cyber operations. The group employed advanced techniques, including custom exfiltration tooling and multi-layered attacks on virtualization, storage, and backup systems, to maximize disruption and prevent system restoration. This approach demonstrates a sophisticated understanding of IT infrastructure and a focus on denial-of-service capabilities.
