Iran-based Cyber Actors Enabling Ransomware Attacks on US Organizations
ID: f3cb6a8b-bd4d-50d1-8fc1-3283a02fa6dc
STIX ID: report--f3cb6a8b-bd4d-50d1-8fc1-3283a02fa6dc
Feed Name: CISA Cybersecurity Advisories
The FBI, CISA, and DC3 released a joint advisory describing an Iran-linked cyber actor (Pioneer Kitten / Fox Kitten / xplfinder / Br0k3r) that exploits unpatched VPNs, firewalls, and networking appliances (multiple CVEs) to deploy webshells and backdoors, steal sensitive data for state-directed objectives, and monetize access by collaborating with ransomware affiliates; the advisory provides mapped MITRE ATT&CK TTPs, IOCs (IPs, domains, bitcoin addresses, TOX identifiers), and detailed mitigations and reporting guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
