logo

Iranian-linked hackers collaborate with ransomware affiliates, feds say

ID: be5d977a-3d09-522c-b5a6-80472ec7d16a

STIX ID: report--be5d977a-3d09-522c-b5a6-80472ec7d16a

Feed Name: CyberScoop

Threat Score
88/100

Date Published: 2024-08-28

Date Updated: 2026-04-21

Author: Christian Vasquez

...
...

U.S. agencies warn that Iranian-linked APT Pioneer Kitten (Lemon Sandstorm) has been acting as an access broker for ransomware affiliates including ALPHV/BlackCat, seeking initial network access in education, finance, healthcare, and defense, using tools like Shodan and targeting Ivanti VPNs and Citrix NetScaler devices; the group also conducts separate espionage activity against Israel and Azerbaijan.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.