FBI: Iran working with ransomware gangs for attacks in US, Azerbaijan, UAE and Israel
ID: 1ef7e2c3-08d0-58bb-a289-7cbab11426b1
STIX ID: report--1ef7e2c3-08d0-58bb-a289-7cbab11426b1
Feed Name: The Record from Recorded Future News
U.S. federal agencies warn that Iranian government-linked actors have conducted a multi-year campaign targeting education, finance, healthcare, defense and government entities across multiple countries, gaining and maintaining access to networks, stealing sensitive data, and collaborating with ransomware affiliates (e.g., NoEscape, Ransomhouse, AlphV). The advisory highlights repeated exploitation of internet-facing assets and specific vulnerabilities (including CVE-2024-3400, CVE-2024-24919, CVE-2022-1388, CVE-2019-19781, CVE-2023-3519), common tradecraft (Shodan scanning, account creation, disabling security), and their practice of selling or sharing access with criminal operators while sometimes conducting direct extortion or data-leak operations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
