Iranian cyber actors’ brute force and credential access activity compromises critical infrastructure
ID: 03ad12d0-c373-5e80-ab65-4b40ea7e59d2
STIX ID: report--03ad12d0-c373-5e80-ab65-4b40ea7e59d2
Date Published: 2024-10-17
Date Updated: 2026-07-25
Author: Australian Cyber Security Centre (ACSC)
This joint advisory from FBI, CISA, NSA, CSE, AFP, and ASD/ACSC warns that Iranian cyber actors have been conducting widespread brute-force and MFA fatigue campaigns since October 2023 to obtain credentials and persistent access across healthcare, government, IT, engineering, and energy sectors; the actors register MFA devices, abuse SSPR and Okta, use VPN exit nodes, enumerate AD/Kerberos, move laterally via RDP, and have been observed connecting to Cobalt Strike C2 and exfiltrating files for sale—agencies provide mapped MITRE ATT&CK TTPs, IOCs, and mitigation guidance (strong passwords and secondary authentication).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
