The Federal Bureau of Investigation (FBI) recently issued a notification (PIN) to warn private industry organizations and companies about a new threat. According to the FBI, Iranian hackers are attempting to purchase stolen data belonging to American businesses.
See also: Iranian hackers attack ISPs with new enhanced malware

Iranian hackers are trying to buy information available for sale on hacking forums and marketplaces, with the aim of carrying out attacks against American organizations.
US organizations whose data has been stolen and leaked online in the past are at risk, according to the FBI. US authorities fear an attack on entities in critical industries.
See also: Turkish hacker RootAyyildiz hacks WikiLeaks online store
“Criminals have shown interest in leaked datasets in various places, including web forums and the dark web. The FBI believes that Iranian hackers may attempt to leverage information from these leaked datasets, such as network information and email correspondence, to conduct their own attacks against U.S. organizations,” the FBI alert states. “This attacker has also shown interest in gaining unauthorized access to SCADA systems using common default passwords.”

The FBI is urging organizations that have suffered data breaches in the past to reset passwords, strengthen the security of their systems, and warn their employees about potential attacks.
See also: Hackers breached Aruba Central with stolen access key
The FBI also published information on tactics, techniques, and procedures (TTPs) associated with Iranian hackers, such as the use of auto-exploiter tools to create a network of compromised WordPress sites for possible use as an RDP-scanning botnet, etc. The attackers are also exploiting the Kentico Content Management System (CVE-2019-10068) and have used SQLmap to bypass Web Application Firewalls.
Source: Security Affairs
