logo

FBI: Iran working with ransomware gangs for attacks in US, Azerbaijan, UAE and Israel

ID: 1ef7e2c3-08d0-58bb-a289-7cbab11426b1

STIX ID: report--1ef7e2c3-08d0-58bb-a289-7cbab11426b1

Feed Name: The Record from Recorded Future News

Threat Score
88/100

Date Published: 2024-08-28

Date Updated: 2026-05-01

...
...

U.S. federal agencies warn that Iranian government-linked actors have conducted a multi-year campaign targeting education, finance, healthcare, defense and government entities across multiple countries, gaining and maintaining access to networks, stealing sensitive data, and collaborating with ransomware affiliates (e.g., NoEscape, Ransomhouse, AlphV). The advisory highlights repeated exploitation of internet-facing assets and specific vulnerabilities (including CVE-2024-3400, CVE-2024-24919, CVE-2022-1388, CVE-2019-19781, CVE-2023-3519), common tradecraft (Shodan scanning, account creation, disabling security), and their practice of selling or sharing access with criminal operators while sometimes conducting direct extortion or data-leak operations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.