logo

Iranian Cyber Actors’ Brute Force and Credential Access Activity Compromises Critical Infrastructure Organizations

ID: 76e502a5-2d68-5468-af45-3ac3aa2e0b87

STIX ID: report--76e502a5-2d68-5468-af45-3ac3aa2e0b87

Feed Name: CISA Cybersecurity Advisories

Threat Score
90/100

Date Published: 2024-09-30

Date Updated: 2026-04-19

Author: CISA

...
...

This joint advisory from U.S. and allied agencies warns that Iranian cyber actors have used brute-force techniques (password spraying), MFA push-bombing, MFA registration manipulation, Kerberoasting, RDP lateral movement, and LOTL tools to gain persistent access to Microsoft 365/Azure/Citrix and other environments across multiple critical infrastructure sectors; it includes MITRE ATT&CK mappings, IOCs (file hashes, numerous IP addresses, device models), detection guidance, and recommended mitigations such as phishing-resistant MFA and stronger password policies.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.