CyberzSOC

Publication detail
← Back to advisories & guidance

Iranian Cyber Actors’ Brute Force and Credential Access Activity Compromises Critical Infrastructure Organizations ↗ source

October 16, 2024 NSA Advisory
Co-sealed by: AFP, ASD/ACSC, CCCS, CISA, CSE, FBI, NIST, NSA

Summary

The actors likely aim to obtain credentials and information describing the victim’s network that can then be sold to enable access to cybercriminals. Since October 2023, Iranian actors have used brute force, such as password spraying, and multifactor authentication (MFA) ‘push bombing’ to compromise user accounts and obtain access to organizations. The actors frequently modified MFA registrations, enabling persistent access. The actors performed discovery on the compromised networks to obtain additional credentials and identify other information that could be used to gain additional points of access. The authoring agencies assess the Iranian actors sell this information on cybercriminal forums to actors who may use the information to conduct additional This advisory provides the actors’ tactics, techniques, and procedures (TTPs) and indicators of compromise (IOCs).

News Coverage

No coverage found in monitored research blogs or news feeds.

CVEs Referenced in This Publication

CVECVSSAffected
CVE-2020-1472 5.5 Medium Microsoft Netlogon Microsoft's Netlogon Remote Protocol (MS-NRPC) contains a privilege escalation vulnerability when an attacker establishes a vulnerable Netlogon secur…

Extracted from the publication text. Each CVE links to its tracked detail page.

Vendors Named in This Publication

Each vendor links to its Known Exploited Vulnerabilities catalog page. Only vendors that appear in the KEV catalog are listed, either because the publication cites one of their KEV entries or because it names them directly.