Iranian Hackers Acting As Ransomware Access Brokers
ID: 6fb648b3-5705-5f79-b74a-55ce0adb0b37
STIX ID: report--6fb648b3-5705-5f79-b74a-55ce0adb0b37
Feed Name: Cyble Blog
Executive summary: A US government joint advisory details Iran-linked, state-sponsored cyber actors (aliases: Pioneer Kitten, Lemon Sandstorm, xplfinder) that have evolved into access brokers for ransomware affiliates while continuing espionage and hack-and-leak operations; they exploit known vulnerabilities in internet-facing devices (multiple CVEs listed), maintain persistent access using webshells and backdoors, and have observable IOCs (IPs, domains, tunneling tools, and bitcoin addresses) — organizations in critical sectors are urged to patch, monitor for suspicious outbound connections and unauthorized remote-access tools, and review provided MITRE ATT&CK mappings and IOCs for detection and mitigation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
