Stakeholder Message: Iranian Cyber Actors’ Brute Force and Credential Access Activity Compromises Critical Infrastructure Organizations – Joint Cybersecurity Advisory
Source: CISA

CISA, Federal Bureau of Investigation (FBI), National Security Agency (NSA), Canadian Centre for Cyber Security (Cyber Centre) Australian Federal Police (AFP), and Australian Signals Directorate’s Australian Cyber Security Centre (ASD’s ACSC) released a joint Cybersecurity Advisory, Iranian Cyber Actors’ Brute Force and Credential Access Activity Compromises Critical Infrastructure Organizations. This advisory provides known indicators of compromise (IOCs) and tactics, techniques, and procedures (TTPs) used by Iranian actors derived from FBI engagements with entities impacted by this malicious activity.
This advisory provides details on how Iranian actors use valid user and group email accounts to obtain initial access to Microsoft 365, Azure, and Citrix systems. Since October 2023, tactics frequently used by these actors include brute force and password spraying; in some cases, the actors use multi-factor authentication (MFA) fatigue or push bombing. Once in compromised networks, they used discovery, such as living off the land, to obtain additional credentials, escalate privileges and identify other information that could be used to gain additional points of access.
Multiple critical infrastructure sectors, including the healthcare and public health (HPH), government, information technology, engineering, and energy sectors, are being compromised by these Iranian cyber actors.
Recommended mitigations and actions to protect against this Iranian-cyber threat activity in this advisory include use strong passwords for IT helpdesk password management, disable user accounts for personnel who left company, and implement phishing-resistant multifactor authentication (MFA). Organizations are encouraged to review the advisory for complete list of IOCs and TTPs and implement recommended mitigations.
To learn more about the Iranian cyber threat, visit Iran Cyber Threat, on CISA.gov.


