Iranian meddling in U.S. election shows new skills. But is it really Iran? – Haaretz.com
The email coercing Democrats in Florida to vote for President Donald Trump seemed legitimate at first. It was sent from an apparently official email account, was personally addressed and even included the recipients home address. However, less than a day after the email was purportedly sent by far-right group the Proud Boys, U.S. officials revealed it to be part of an Iranian campaign to interfere in the U.S. election.
The influence campaign which also targeted voters in Alaska, Pennsylvania and Arizona showed a new level of Iranian sophistication, according to three Israeli cyberexperts who spoke with Haaretz and are knowledgeable about how hackers from the Islamic Republic operate.
They all say the bogus email marks a new type of cyberoffensive by Iran, but add that it raises further questions.
The case also highlights how difficult it is to attribute such cyberattacks nowadays, just as the United States ramps up its efforts to fight attempts by Russia, China and Iran to meddle in the November 3 election.
Last Wednesday, U.S. Director of National Intelligence John Ratcliffe said Russia and Iran have both tried to interfere in next weeks election.
The announcement followed a string of other statements by U.S. intelligence and law enforcement officials in recent weeks, revealing attempts past and present to undermine Americas voting system. These came through cyberattacks on voting networks and infrastructure, and disinformation campaigns. Though officials believe Russia is the bigger threat, both Russia and Iran are acting with what officials say is the clear intent to undermine the integrity of the electoral process.
Something new
According to Israeli web intelligence expert Dana Segev Moyal, the Proud Boys operation was different and more complex than past campaigns attributed to Iran.
Most of what we know publicly about previous attacks attributed to Iran is that they were usually either more complex technologically for example, cyberattacks on infrastructure or, when they were social influence campaigns, they tended to focus on spreading disinformation on social media.
Segev Moyal, who focuses on disinformation and has studied Irans past activities in this area, says were seeing something new this time: Weve never seen an email campaign targeting voters of a specific state with a specific message from a very specific organization, she notes.
We've got more newsletters we think you'll find interesting.
Please try again later.
The email address you have provided is already registered.
At minimum, this shows a pretty detailed understanding of American politics. I doubt your average Israeli or Iranian knows who the Proud Boys are. You need to do research and follow American politics closely. The extremist group made headlines after the first presidential debate, when President Trump refused to denounce it.
Boaz Dolev, a cybersecurity expert whose ClearSky firm has revealed Iranian cyberattacks and disinformation campaigns in recent years, agrees. He calls it a very rare attack.
What makes the attack so unique, according to both experts, is that it was actually quite simple from a technological perspective, but very complex in strategic terms.
Contrary to what people think, this attack doesnt actually require any hacking, Segev Moyal explains. Voter registration details are available online if you know how to find them. Whats interesting here is that they fused and corroborated different types of data to mount an influence campaign. Thats just not the type of planning weve seen up till now, she says.
In 2018, Dolevs ClearSky revealed a massive Iranian disinformation campaign. However, that operation was more in line with what we would term fake news and included a network of more than 70 pseudo-media outlets that covertly spread Iranian state propaganda in 15 different countries a far cry from the complex and hyper-targeted influence campaign now being attributed to them.
Though both experts say its hard to draw a direct line between the email campaign and Iran at least based on the information currently available they state that, much like Russia, Irans capabilities and techniques are always changing, making it that much harder to prove.
Dolev offers one recent example that surprised him: A few weeks ago, his firm revealed an Iranian cyberoperation in Israel that tried to pass itself off as a criminal (as opposed to state) offensive. Operation Quicksand, as it was labeled, also showed new modes of operation that hadnt previously been linked to Iran.
Theres a certain chain of attribution people in the world of cybersecurity know how to do, he explains. You can link a certain technology or technique to a certain team, and you can link that team back to certain states.
What I can tell you about the Iranians is that the last time we came out and said it was them [in Operation Quicksand], at first I didnt think it was them, because technologically it showed they had taken a step forward in terms of their actual capabilities. It was a professional job that I hadnt seen in this context before. But then you get some more information that allows you to make the attribution.
In the case of the Proud Boys email campaign, it was Reuters and the United States that made the attribution with the help of information provided by Google and Microsoft. All the experts Haaretz spoke with said that without reviewing the actual information, they couldnt independently confirm or deny the attributions veracity.
As Dolev puts it, experts in his field are constantly updating and revising their assumptions about what certain players can or cant do. So now we know Iran is an agent that has better technological capabilities than we had previously thought, he says, referring to Operation Quicksand.
Nonetheless, he says, when it comes to disinformation campaigns, most of their capabilities are actually basic even if their cyberoffensives against organizations have been stepped up and are better than we initially thought.
In this case, though, as Segev Moyal explains, the operation was actually complex: In addition to finding all the [voter] emails and cross-referencing all the different data sets, they also had to find a Proud Boys server that was vulnerable and actually produce an email campaign.
Proud Iranian boys?
The few details made public about how the email campaign was traced back to Iran show how complex such operations can be both for the perpetrator and those trying to thwart them.
According to Reuters, it was a series of dumb mistakes that revealed the attacks origins. For example, one of the emails sent out (there were a number in the campaign) included a video that purported to show how the hackers managed to obtain voter registration details. A few lines of code viewable in the video, as well as an IP address that was not blurred out, were traced back to websites and techniques previously used by Iran.
However, its exactly this type of slapdash error that also prompts questions. For instance, some reports have shown screen captures of the email. In one of them, theres a glaring typo in the subject line: Voteing with an e, Segev Moyal says. Its strange that someone would make such a big effort but then make such a silly mistake, she adds.
A third expert, who spoke on condition of anonymity due to the sensitivity of their work and the issue, added that certain aspects of the operation actually look more similar to Russian operations.
This appears to be a scenario also examined by the United States: Either they made a dumb mistake or wanted to get caught, said a senior U.S. government official who spoke to Reuters when the story broke last week. But they added: Were not concerned about this activity being some kind of false flag due to other supporting evidence. This was Iran.
Segev Moyal notes that this is not something we can say is definitely not Iran they can do that but there are also others who do such things. However, both she and Dolev refuse to call into question the American findings, saying that without further information, they simply cannot know for certain.
For Segev Moyal, one possible explanation is that, oftentimes, such campaigns are not really intended to succeed but merely to sow distrust and help create the sense that the U.S. electoral process is exposed to manipulation.
In this case, the video itself was also posted online. Social media analytics firm Graphika told Reuters that two Twitter accounts began posting links to the video last Tuesday evening and attempted to attract the attention of some media and political organizations. One account described itself as Trumps Soldier and shared a link to the video with the comment: It seems they hacked [the] voting system.
This also highlights how much the disinformation efforts piggyback statements being pushed out by the U.S. president himself.
When you look at this as an influence campaign that wants to sway public opinion, this could make sense, Segev Moyal says. This was not really a cyberattack on voter infrastructure no one, for example, is suggesting [the Iranians] or the Russians can alter the election results themselves.
From this perspective, the true goal of the email campaign was perhaps to fuel the narrative that Americas electoral system is exposed.
For Dolev, one of the most interesting aspects of the attack was the U.S. response and the governments decision to reveal the operation so quickly.
This is a new American policy and were also seeing it in regards to the Russians, he says, citing recent indictments against hackers operating for the GRU (the Russian armys intelligence branch). By revealing the operations, Dolev adds, the United States is in a sense fighting back, as publicity can counter the effectiveness of such influence campaigns.
During an influence campaign, the target countrys goal can be to respond as publicly as possible, Segev Moyal says. It helps restore public confidence, and show that everything is under control and voting systems have not actually been compromised. Like the operation itself, this type of response also aims at hearts and minds.
Here is the original post:
Iranian meddling in U.S. election shows new skills. But is it really Iran? - Haaretz.com
- Iran's Pezeshkian says Tehran seeks peace, but will not bow to coercion - Reuters - November 7th, 2025 [November 7th, 2025]
- IAEA chief says Iran still capable of building nuclear weapons | Iran International - - November 7th, 2025 [November 7th, 2025]
- Cultural Genocide and the Kurdish Struggle in Iran - Genocide Watch - November 7th, 2025 [November 7th, 2025]
- Iran Fears Gen-Z: Why the Regime Is Ratcheting Up Propaganda - National Council of Resistance of Iran - NCRI - November 7th, 2025 [November 7th, 2025]
- Iran plotted to kill Israeli ambassador to Mexico, US and Israeli officials say - The Times of Israel - November 7th, 2025 [November 7th, 2025]
- Iran planned to kill Israeli envoy to Mexico this year - JNS.org - November 7th, 2025 [November 7th, 2025]
- Iran: Protest in Ahvaz Following Shocking Self-Immolation of 20-Year-Old Ahmad Baldi - National Council of Resistance of Iran - NCRI - November 7th, 2025 [November 7th, 2025]
- Iran says open to negotiation but will not give up nuclear - The Jerusalem Post - November 7th, 2025 [November 7th, 2025]
- Marginalization of the Baloch in Iran - Genocide Watch - November 7th, 2025 [November 7th, 2025]
- Pezeshkian: Iran seeks peace, but wont give up its nuclear and missile programs - The Times of Israel - November 7th, 2025 [November 7th, 2025]
- Jewish Iranian-American sentenced to prison in Iran for visiting Israel 13 years ago - Jewish Telegraphic Agency - November 7th, 2025 [November 7th, 2025]
- Iran News in Brief November 7, 2025 - National Council of Resistance of Iran - NCRI - November 7th, 2025 [November 7th, 2025]
- After its drone success, Iran's next breakout hit could come from the sea - Tehran Times - November 7th, 2025 [November 7th, 2025]
- Surviving 903 Days of Torture and Sexual Assault by Iran-Backed Shia Militias - IranWire - November 7th, 2025 [November 7th, 2025]
- Iran Arrests Baha'is in Wave of Raids Across Multiple Provinces - IranWire - November 7th, 2025 [November 7th, 2025]
- Trump says Iran has asked about lifting US sanctions - - November 7th, 2025 [November 7th, 2025]
- Iran unveils monument to ancient victory in show of post-war defiance - RFI - November 7th, 2025 [November 7th, 2025]
- Iran condemns Israels breach of truce and strikes on Lebanon - Tehran Times - November 7th, 2025 [November 7th, 2025]
- Iran: US Citizen Hekmati, 70, Sentenced to 4 Years Over Trip to Israel in 2012 - EA WorldView - November 7th, 2025 [November 7th, 2025]
- Iran submits three films to 1st Open Eurasian Film Award Diamond Butterfly - Tehran Times - November 7th, 2025 [November 7th, 2025]
- IDF reveals Hamas ties to Iran, UNRWA, Al Jazeera, stolen aid in collection of documents - The Jerusalem Post - November 7th, 2025 [November 7th, 2025]
- Iran unveils monument to ancient victory in show of post-war defiance - Homenewshere.com - November 7th, 2025 [November 7th, 2025]
- Iranian-American poets son arrested over Detroit terror plot | Iran International - - November 7th, 2025 [November 7th, 2025]
- Average age of first-time mothers in Iran continues to rise - Tehran Times - November 7th, 2025 [November 7th, 2025]
- Iran planned to assassinate Israel's ambassador to Mexico, but the attempt was thwarted - US official - - November 7th, 2025 [November 7th, 2025]
- Between Mediation and Advocacy: Omans Shifting Role in Gulf-Iran Relations - orfonline.org - November 7th, 2025 [November 7th, 2025]
- Not if they say we will bomb you: Pezeshkian says Iran seeks peace, but wont abandon nuke programme - WION - November 7th, 2025 [November 7th, 2025]
- Soroka to receive over $300 million to rebuild after Iran missile strike in June - The Times of Israel - November 3rd, 2025 [November 3rd, 2025]
- Iran: Human rights investigators alarmed by surge in repression and spike in executions following Israeli airstrikes - UN News - November 3rd, 2025 [November 3rd, 2025]
- Iran says wont dismantle missiles, ready for war with Israel - JNS.org - November 3rd, 2025 [November 3rd, 2025]
- Irans Ruling Class Turns on Itself as Crises Deepen - National Council of Resistance of Iran - NCRI - November 3rd, 2025 [November 3rd, 2025]
- Is this the end of Iran's Islamic Revolution? - The Jerusalem Post - November 3rd, 2025 [November 3rd, 2025]
- Dead Sea hotel worker charged with spying for Iran; was asked for intel on Ben Gvir - The Times of Israel - November 3rd, 2025 [November 3rd, 2025]
- Iran's Bitcoin Mining Industry: Inside the World's Fifth-Largest Operation Amid Sanctions and Energy Crisis - Brave New Coin - November 3rd, 2025 [November 3rd, 2025]
- Russian FM says no limits for military cooperation with Iran - Tehran Times - November 3rd, 2025 [November 3rd, 2025]
- Araghchi says Israel duped US on Iran threat, urges Trump to reverse course - - November 3rd, 2025 [November 3rd, 2025]
- Former Israeli Ambassador Warns That Iran, Russia, and China Are Expanding Terror Sleeper Cells Across the US - VINnews - November 3rd, 2025 [November 3rd, 2025]
- In the past 48 hours, the heinous lie that the unlawful Israeli and U.S. bombing of Iran was motivated by an imminent nuclear threat has been... - November 3rd, 2025 [November 3rd, 2025]
- Iran To Build 8 New Nuclear Plants With Russias Help - Eurasia Review - November 3rd, 2025 [November 3rd, 2025]
- At the heart of regional architecture, Iran is inevitable - Tehran Times - November 3rd, 2025 [November 3rd, 2025]
- Iran promises to rebuild bombed nuclear sites "with greater strength" after US strikes - Euromaidan Press - November 3rd, 2025 [November 3rd, 2025]
- We will not be set back: Pezeshkian vows Iran will rebuild its nuclear sites stronger than before - WION - November 3rd, 2025 [November 3rd, 2025]
- Iran banking on Iraq vote to retain regional influence - Citizen Tribune - November 3rd, 2025 [November 3rd, 2025]
- Iran vows to rebuild nuclear facilities 'with greater strength' after US strikes - Trkiye Today - November 3rd, 2025 [November 3rd, 2025]
- UK Parliament Conference Calls For Firm Policy On Iran Amid Surge In Executions OpEd - Eurasia Review - November 3rd, 2025 [November 3rd, 2025]
- Regional Museum of Southeastern Iran, a mirror of Iranian culture, civilization - Tehran Times - November 3rd, 2025 [November 3rd, 2025]
- Charges filed against Tiberias man suspected of spying for Iran - The Times of Israel - November 3rd, 2025 [November 3rd, 2025]
- Repression in Iran worsened after 12-day war with Israel in June, UN probe finds - The Times of Israel - October 31st, 2025 [October 31st, 2025]
- As Renewal of Iran-Israel War Looms, What Lessons Can Be Learned from June? - Middle East Council on Global Affairs - October 31st, 2025 [October 31st, 2025]
- Mediator Egypt urges end to impasse over Iran nuclear inspections - - October 31st, 2025 [October 31st, 2025]
- Faith, knowledge, and steadfastness: Ayatollah Khameneis vision for an independent Iran - Tehran Times - October 31st, 2025 [October 31st, 2025]
- Two men sentenced to 25 years over Iran-backed plot to kill dissident - Reuters - October 31st, 2025 [October 31st, 2025]
- Socioeconomic disparities in urological cancers in iran: a systematic analysis for the Global Burden of Disease study 2019 - BMC Public Health - October 31st, 2025 [October 31st, 2025]
- UN accuses Iran of widespread arrests, abuses after 12-day war with Israel - France 24 - October 31st, 2025 [October 31st, 2025]
- Iran says UN watchdog should not express 'unfounded opinions' on nuclear programme - Reuters - October 31st, 2025 [October 31st, 2025]
- Iran participating in 28th Algiers International Book Fair - Tehran Times - October 31st, 2025 [October 31st, 2025]
- Hassan Rouhani wants to be the next Supreme Leader. Iran's hardliners won't have it - thenationalnews.com - October 31st, 2025 [October 31st, 2025]
- Egypt mediates talks between Iran and the IAEA on nuclear program cooperation - Latest news from Azerbaijan - October 31st, 2025 [October 31st, 2025]
- Artist Sheida Soleimani renders story of her parents' escape from Iran - The Business Journals - October 31st, 2025 [October 31st, 2025]
- Niger Joins Haiti, Russia, Iran, and Iraq in the US List of Do Not Travel Urgent Warnings The Hidden Dangers That Could Put Your Life at Risk! -... - October 31st, 2025 [October 31st, 2025]
- IDF, Mossad on alert for Oct. 7-style threat from Iran-backed militias in Iraq - Yahoo - October 31st, 2025 [October 31st, 2025]
- Egypt, Iran, IAEA discuss steps toward peaceful resolution of Tehrans nuclear issue - Trkiye Today - October 31st, 2025 [October 31st, 2025]
- Iran, Russia and the New Zealand insurer that kept their sanctioned oil flowing - Reuters - October 28th, 2025 [October 28th, 2025]
- Iran declares bankruptcy of major bank as country grapples with restored sanctions - The Times of Israel - October 28th, 2025 [October 28th, 2025]
- CSIS Satellite Imagery Analysis Reveals Possible Signs of Renewed Nuclear Activity in Iran - CSIS | Center for Strategic and International Studies - October 28th, 2025 [October 28th, 2025]
- British woman's 'spirits were low' on phone call from Iran prison - BBC - October 28th, 2025 [October 28th, 2025]
- Why is the UN directing tourists into Iran? - The Telegraph - October 28th, 2025 [October 28th, 2025]
- Iran News in Brief October 28, 2025 - National Council of Resistance of Iran - NCRI - October 28th, 2025 [October 28th, 2025]
- Russia says no rift with Iran as row over Moscow role heats up in Tehran | Iran International - - October 28th, 2025 [October 28th, 2025]
- Irans Education System Paralyzed as Regime Diverts Resources to Nuclear and Military Programs - National Council of Resistance of Iran - NCRI - October 28th, 2025 [October 28th, 2025]
- Irans Rappers: Voices of Dissent, Targets of the State - Center for Human Rights in Iran - October 28th, 2025 [October 28th, 2025]
- Satellite images reveal possible renewed nuclear activity in Iran - think tank - - October 28th, 2025 [October 28th, 2025]
- From FATF to Bank Meltdown, Irans Power Factions Clash on Every Front - National Council of Resistance of Iran - NCRI - October 28th, 2025 [October 28th, 2025]
- Political Prisoner on Fifth Day of Hunger Strike in Iran - IranWire - October 28th, 2025 [October 28th, 2025]
- Iran-UAE dispute over three islands in Gulf heats up - The New Arab - October 28th, 2025 [October 28th, 2025]
- Family of British couple detained in Iran issue update after recent court hearing had not gone well - The Independent - October 28th, 2025 [October 28th, 2025]
- Iran Establishes Itself As A Missile Superpower Through Advanced Precision And Hypersonic Technology - Iran - Iran Front Page - IFP News - October 28th, 2025 [October 28th, 2025]
- Iran stresses key role of Islamic unity in face of foreign threats - taghribnews.com - October 28th, 2025 [October 28th, 2025]
- Iran criticizes UN for failure to act on Israeli-imposed war on Tehran - taghribnews.com - October 28th, 2025 [October 28th, 2025]
- As '80s Iran convulsed, L.A. immigrants honed new sounds. This album lauds them - with warnings for today - Los Angeles Times - October 28th, 2025 [October 28th, 2025]