Iranian State Hackers Facilitate Ransomware Gangs as Access Middlemen

Published:

Cyber Warriors Conclave — nine editions, one cyber safe nation

Iranian Cyber Actors Collaborate with Ransomware Groups to Target U.S. and Allies: Warning from FBI, CISA, and DC3

A shadowy group of Iranian cyber actors has been exposed by a joint warning from the FBI, CISA, and the Department of Defense Cyber Crime Center (DC3), revealing their involvement in access brokering for ransomware gangs. These state-sponsored operatives, known as “Pioneer Kitten” and other aliases, have been collaborating with ransomware affiliates to target critical sectors in the U.S. and its allies since 2017.

The Iranian actors have intensified their activities over the years, focusing on sectors such as education, finance, healthcare, and defense, as well as government entities. By selling access to ransomware groups like NoEscape and BlackCat, they enable more effective ransomware attacks and share in the profits received in cryptocurrency.

Moreover, these actors have been exploiting vulnerabilities in widely-used networking devices to gain initial access and maintain persistence within victim networks. They have also engaged in hack-and-leak campaigns, targeting countries like Israel to cause political and social disruption.

To combat these threats, organizations are advised to review their logs for malicious IP addresses, apply patches to known vulnerabilities, and validate security controls against the MITRE ATT&CK framework. Increased vigilance is crucial across all sectors, as the collaboration between Iranian cyber actors and ransomware groups blurs the line between cybercrime and state-sponsored espionage. National security remains at risk, making it imperative for entities to stay vigilant against evolving cyber threats.

Cyber Warriors Conclave Chapter X — Beyond the Ballroom

Related articles

Recent articles

Supply Chain Attacks Target Developer Tools and CI/CD Pipelines, Research Reveals

In recent years, supply chain attacks have evolved dramatically, shifting from targeting finished software to infiltrating the very tools and code that developers use...

NordVPN Alerts Android Users to Malware Posing as Ryanair, Emirates, and Qatar Airways Apps

NordVPN has issued a warning to Android users about a sophisticated malware campaign that impersonates over 65 well-known brands, including Ryanair, Emirates, and Qatar...

AliExpress Exposed for Using Inaudible Sounds to Fingerprint Browser Visitors

AliExpress has come under scrutiny for employing an outdated method of browser fingerprinting that utilizes inaudible sounds to track visitors. This technique, which exploits...

ReliaQuest Confirms Targeting by ShinyHunters in Limited Social Engineering Attack

Cybersecurity firm ReliaQuest has confirmed being targeted by hackers affiliated with the notorious ShinyHunters group, but claims the impact of the attack was limited. ReliaQuest...