Iranian hackers are going after critical infrastructure sector passwords, agencies caution
ID: dbd5e563-8693-5b3b-94d2-8da1a519df14
STIX ID: report--dbd5e563-8693-5b3b-94d2-8da1a519df14
Feed Name: CyberScoop
Threat Score
Iranian-affiliated cyber actors have been conducting sustained brute-force and credential-access attacks since October against healthcare, government, IT, energy and engineering sectors, using password spraying, trial-and-error attempts and MFA "push bombing" to gain and retain access; agencies warn the stolen credentials are sold on criminal forums and may be used or brokered to ransomware and other malicious operators.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
