Iranian hackers work with ransomware gangs to extort breached orgs
ID: 871eeb56-0b51-56b6-95ae-5959788c65b9
STIX ID: report--871eeb56-0b51-56b6-95ae-5959788c65b9
Feed Name: Bleeping Computer
A joint advisory from CISA, the FBI, and the Defense Department details Iran-linked APT 'Pioneer Kitten' (aka Fox Kitten / UNC757 / Parisite) targeting U.S. defense, education, finance, and healthcare sectors: actors are scanning for and exploiting high-severity CVEs (e.g., CVE-2024-24919, CVE-2024-3400, and historically CVE-2019-19781/CVE-2022-1388), selling domain admin/full-domain access on cyber marketplaces, and directly collaborating with ransomware affiliates (NoEscape, Ransomhouse, ALPHV/BlackCat) to monetize access and extort victims.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
