logo

Iran-based Cyber Actors Enabling Ransomware Attacks on US Organizations

ID: f3cb6a8b-bd4d-50d1-8fc1-3283a02fa6dc

STIX ID: report--f3cb6a8b-bd4d-50d1-8fc1-3283a02fa6dc

Feed Name: CISA Cybersecurity Advisories

Threat Score
90/100

Date Published: 2024-08-23

Date Updated: 2026-04-19

Author: CISA

...
...

The FBI, CISA, and DC3 released a joint advisory describing an Iran-linked cyber actor (Pioneer Kitten / Fox Kitten / xplfinder / Br0k3r) that exploits unpatched VPNs, firewalls, and networking appliances (multiple CVEs) to deploy webshells and backdoors, steal sensitive data for state-directed objectives, and monetize access by collaborating with ransomware affiliates; the advisory provides mapped MITRE ATT&CK TTPs, IOCs (IPs, domains, bitcoin addresses, TOX identifiers), and detailed mitigations and reporting guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.