Initial access techniques used by Iran-based threat actors
ID: ef8bff8c-b656-51bd-a22b-0a522993fe37
STIX ID: report--ef8bff8c-b656-51bd-a22b-0a522993fe37
Feed Name: Sophos Blogs
This CTU analysis summarizes the preferred initial-access techniques used by Iranian-linked threat actors since 2020—spearphishing (attachments, links, third-party services), exploitation of public-facing applications (e.g., Fortinet, Exchange, VMware/Log4Shell), password spraying and cloud account takeover, abuse of legitimate RMM tools, use of external remote services (VPN/RDP), and exploitation of default/weak credentials—mapping each to MITRE ATT&CK IDs and offering defensive recommendations such as phishing-resistant MFA, prompt patching, credential hygiene, and monitoring for anomalous authentication.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
