HomeSecurityIranian hackers sell access to critical infrastructure as brokers

Iranian hackers sell access to critical infrastructure as brokers

Iranian hackers are breaching critical infrastructure to collect credentials and network data that can be sold on criminal forums to enable cyberattacks by other malicious actors.

See also: US: Warns about Chinese hackers “Typhoon”

Iranian hackers

Government agencies in the US, Canada and Australia believe that Iranian hackers are acting as initial access brokers and using brute force to gain access to critical infrastructure in the healthcare and public health (HPH), government, information technology, engineering and energy sectors.

An advisory published by the U.S. Cybersecurity Intelligence Agency (CISA) describes the latest activity and methods used by Iranian hackers to compromise networks and collect data that would provide additional access points to critical infrastructure.

The notice is co-signed by the Federal Bureau of Investigation (FBI), CISA, the National Security Agency (NSA), Communications Security Establishment Canada (CSE), the Australian Federal Police (AFP) and the ASD's ACSC.

After the identification stage, malicious actors aim to gain persistent access to the target network, often using brute force techniques.

See also: ScarCruft spreads RokRAT malware via Windows Zero-Day

Monitoring activity involves collecting more credentials, escalating privileges, and learning about compromised systems and the network, which allows them to move laterally and identify other access and exploitation points.

Iranian hackers sell access to critical infrastructure as brokers

Government agencies have not discovered all the methods used in such attacks, but they have found that in some, hackers use password spraying to access valid user and group accounts.

Another method observed was MFA fatigue where cybercriminals bombard a target's mobile phone with access requests to overwhelm the user until they approve the login attempt, either by mistake or simply to stop notifications.

In addition to critical infrastructure, Iranian hackers also used some yet-to-be-determined methods to gain initial access to Microsoft 365, Azure , and Citrix.

Once they gain access to an account, threat actors typically attempt to enroll devices in the organization's MFA system.

See also: Casio confirms data breach by Underground

Brute force attacks are a security breach method that uses an automated system to guess all possible combinations of a password until the correct one is found. This approach can be very time-consuming, especially if the password is long and includes a variety of characters. Brute force attacks are common due to their simplicity and effectiveness, especially in cases where strong security measures have not been implemented. However, there are methods to protect against these attacks, such as using more complex and secure passwords, limiting login attempts , and implementing multi-factor authentication.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Source: bleepingcomputer

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS