logo

Iranian hackers work with ransomware gangs to extort breached orgs

ID: 871eeb56-0b51-56b6-95ae-5959788c65b9

STIX ID: report--871eeb56-0b51-56b6-95ae-5959788c65b9

Feed Name: Bleeping Computer

Threat Score
90/100

Date Published: 2024-08-28

Date Updated: 2026-04-20

Author: Sergiu Gatlan

...
...

A joint advisory from CISA, the FBI, and the Defense Department details Iran-linked APT 'Pioneer Kitten' (aka Fox Kitten / UNC757 / Parisite) targeting U.S. defense, education, finance, and healthcare sectors: actors are scanning for and exploiting high-severity CVEs (e.g., CVE-2024-24919, CVE-2024-3400, and historically CVE-2019-19781/CVE-2022-1388), selling domain admin/full-domain access on cyber marketplaces, and directly collaborating with ransomware affiliates (NoEscape, Ransomhouse, ALPHV/BlackCat) to monetize access and extort victims.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.