Iranian-linked hackers collaborate with ransomware affiliates, feds say
ID: be5d977a-3d09-522c-b5a6-80472ec7d16a
STIX ID: report--be5d977a-3d09-522c-b5a6-80472ec7d16a
Feed Name: CyberScoop
Threat Score
U.S. agencies warn that Iranian-linked APT Pioneer Kitten (Lemon Sandstorm) has been acting as an access broker for ransomware affiliates including ALPHV/BlackCat, seeking initial network access in education, finance, healthcare, and defense, using tools like Shodan and targeting Ivanti VPNs and Citrix NetScaler devices; the group also conducts separate espionage activity against Israel and Azerbaijan.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
