Pro-ISIS hackers are largely unsophisticated, but they are looking for experts, Flashpoint says Credit: Thierry Ehrmann The U.S. and its allies should be concerned about cyberattacks from ISIS-affiliated groups, but the hackers are poorly organized and likely underfunded, at least in the short term, according to a new report.Several pro-ISIS hacking groups announced this month they are joining together to form the United Cyber Caliphate, but the groups seem to have limited abilities, according to a report from security intelligence research group Flashpoint. Still, with new coordination, “even limited success could inflate their notoriety and enable them to continue to grow their capabilities and attract talent,” Flashpoint said.Pro-ISIS hackers have compromised some Twitter accounts, and the groups are focusing on coordinating and elevating their cyberattacks, said Laith Alkhouri, a co-founder at Flashpoint. [ MORE: U.S. cyberwar against ISIS could use methods and tactics criminals use against enterprises ] But “until recently, our analysis of the group’s overall capabilities indicated that they were neither advanced nor did they demonstrate sophisticated targeting,” Alkhouri said in a statement.Before the United Cyber Caliphate, pro-ISIS hackers were divided up into at least five distinct groups that launched their own campaigns, Flashpoint said. So far, pro-ISIS hacking groups have focused on government, banks, and media outlets as their targets, with publicity one of the main goals of the attacks. “These attacks remain relatively novice-level and are mostly attacks of opportunity,” Flashpoint said. “Such attacks include finding and exploiting vulnerabilities in websites owned by … small businesses, and defacing or DDoSing their websites.”The groups will likely continue to launch such attacks of opportunity in the near future, Flashpoint said in the report. But the group has had some success recruiting more sophisticated hackers, and “advanced targeting and exfiltration are not far-fetched if the group is able to recruit outside experts into its fold,” the report said. Groups concerned about ISIS cyberattacks should look for the hacking groups to use deep Web forums as a training ground for ISIS followers with low-level hacking abilities to improve their skills, Flashpoint said.Expect ISIS hackers to download hacking tools from publicly available sources and use a combination of off-the-shelf and custom malware, Flashpoint added. Related content news North Korean hackers mix code from proven malware campaigns to avoid detection Threat actors are combining RustBucket loader with KandyKorn payload to effect an evasive and persistent RAT attack. By Shweta Sharma Nov 28, 2023 3 mins Malware feature How a digital design firm navigated its SOC 2 audit L+R's pursuit of SOC 2 certification was complicated by hardware inadequacies and its early adoption of AI, but a successful audit has provided security and business benefits. By Alex Levin Nov 28, 2023 11 mins Certifications Compliance news GE investigates alleged data breach into confidential projects: Report General Electric has confirmed that it has started an investigation into the data breach claims made by IntelBroker. By Shweta Sharma Nov 27, 2023 3 mins Data Breach opinion A year after ChatGPT’s debut, is GenAI a boon or the bane of the CISO’s existence? You can try to keep the flood of generative AI at bay but embracing it with proper vigilance is likely the best hope to maintain control and prevent the scourge of it becoming shadow AI. By Christopher Burgess Nov 27, 2023 6 mins Generative AI Data and Information Security Security Practices Podcasts Videos Resources Events SUBSCRIBE TO OUR NEWSLETTER From our editors straight to your inbox Get started by entering your email address below. Please enter a valid email address Subscribe