Iran Launches Brutal Cyber Attacks on Critical Infrastructure

Published:

Cyber Warriors Conclave — nine editions, one cyber safe nation

Iranian Threat Actor Campaign Targets Critical Infrastructure Acces

Security agencies from the United States, along with international partners, have issued a warning about an ongoing Iranian cyber campaign that targets critical infrastructure through brute-force attacks. This campaign, which has been active for over a year, aims to compromise various sectors including healthcare, government, IT, engineering, and energy.

The FBI, CISA, NSA, and cybersecurity agencies from Canada and Australia have highlighted the need for organizations to enhance their security measures by ensuring strong passwords and implementing a second form of authentication on all accounts. The threat actors behind this campaign are selling access to compromised infrastructure to cybercriminals.

The advisory follows recent reports of Iranian threat actors targeting political organizations to undermine confidence in U.S. democratic institutions. Additionally, there have been instances of these threat actors selling critical infrastructure access to ransomware groups.

The Iranian threat actors have been employing brute-force techniques like password spraying and MFA ‘push bombing’ to gain access to user accounts within organizations. They then proceed to obtain sensitive information and credentials to facilitate further access.

Among the targeted systems are Microsoft 365, Azure, and Citrix, where the threat actors exploit vulnerabilities to register their devices with MFA and gain persistent access. They also utilize VPN services, Remote Desktop Protocol, and various tools to extract credentials and information from compromised networks.

The advisory includes indicators of compromise to help organizations detect and prevent brute-force attacks, as well as specific file hashes associated with the Iranian campaign. Notably, one of the identified file hashes had gone undetected by the majority of security tools before the advisory was issued.

Security teams are urged to remain vigilant against such cyber threats and monitor their systems for any signs of malicious activity.Enhanced security measures are crucial in mitigating the risks posed by these Iranian threat actors targeting critical infrastructure.

Cyber Warriors Conclave Chapter X — Beyond the Ballroom

Related articles

Recent articles

US Senator Requests NSA Guidance on Best Practices for VPN Use Against Foreign Surveillance

A prominent US senator is urging the National Security Agency (NSA) to provide public guidance on best practices for using virtual private networks (VPNs)...

Cisco Patches Critical Nexus 9000 Vulnerability Allowing Remote Code Execution as Root

Cisco has released patches to address a critical security flaw affecting 10 Silicon One-based Nexus 9000 switches that could allow an unauthenticated, remote attacker...

BREEZE COMET Threat Actor Targets Brazilian Financial Sector with Sophisticated Attacks

BREEZE COMET: A Rising Threat to Brazil's Financial Sector In 2024, Mandiant began investigating a series of cyber compromises targeting Brazilian financial services, retail, and...

Dropbox Reports Compromise of 5,000 Accounts Due to Legacy Login Vulnerability

Dropbox has reported that approximately 5,000 accounts were compromised last month due to a legacy login vulnerability associated with Lenovo IDs. This breach allowed...