logo

Initial access techniques used by Iran-based threat actors

ID: ef8bff8c-b656-51bd-a22b-0a522993fe37

STIX ID: report--ef8bff8c-b656-51bd-a22b-0a522993fe37

Feed Name: Sophos Blogs

Threat Score
85/100

Date Published: 2026-03-13

Date Updated: 2026-04-30

...
...

This CTU analysis summarizes the preferred initial-access techniques used by Iranian-linked threat actors since 2020—spearphishing (attachments, links, third-party services), exploitation of public-facing applications (e.g., Fortinet, Exchange, VMware/Log4Shell), password spraying and cloud account takeover, abuse of legitimate RMM tools, use of external remote services (VPN/RDP), and exploitation of default/weak credentials—mapping each to MITRE ATT&CK IDs and offering defensive recommendations such as phishing-resistant MFA, prompt patching, credential hygiene, and monitoring for anomalous authentication.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.