logo

Iranian Hackers Acting As Ransomware Access Brokers

ID: 6fb648b3-5705-5f79-b74a-55ce0adb0b37

STIX ID: report--6fb648b3-5705-5f79-b74a-55ce0adb0b37

Feed Name: Cyble Blog

Threat Score
90/100

Date Published: 2025-03-03

Date Updated: 2026-07-16

...
...

Executive summary: A US government joint advisory details Iran-linked, state-sponsored cyber actors (aliases: Pioneer Kitten, Lemon Sandstorm, xplfinder) that have evolved into access brokers for ransomware affiliates while continuing espionage and hack-and-leak operations; they exploit known vulnerabilities in internet-facing devices (multiple CVEs listed), maintain persistent access using webshells and backdoors, and have observable IOCs (IPs, domains, tunneling tools, and bitcoin addresses) — organizations in critical sectors are urged to patch, monitor for suspicious outbound connections and unauthorized remote-access tools, and review provided MITRE ATT&CK mappings and IOCs for detection and mitigation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.