Original release date: November 17, 2021
CISA, the Federal Bureau of Investigation (FBI), the Australian Cyber Security Centre (ACSC), and the United Kingdom’s National Cyber Security Centre (NCSC) have released a joint Cybersecurity Advisory highlighting ongoing malicious cyber activity by an advanced persistent threat (APT) group that FBI, CISA, ACSC, and NCSC assess is associated with the government of Iran. FBI and CISA have observed this Iranian government-sponsored APT exploit Fortinet and Microsoft Exchange ProxyShell vulnerabilities to gain initial access to systems in advance of follow-on operations, which include deploying ransomware.
Joint Cybersecurity Advisory AA21-321A provides observed tactics and techniques, as well as indicators of compromise that FBI, CISA, ACSC, and NCSC assess are likely associated with this Iranian government-sponsored APT activity. FBI, CISA, ACSC, and NCSC urge critical infrastructure organizations to apply the recommendations listed in the advisory to mitigate risk of compromise from Iranian government-sponsored cyber actors.
CISA also recommends reviewing its Iran Cyber Threat Overview and other Iran-related Advisories.
This product is provided subject to this Notification and this Privacy & Use policy.
Systems Affected Microsoft Windows Systems Overview Microsoft has released a Security Bulletin…
Systems Affected Microsoft Windows Systems Overview Microsoft has released a Security Bulletin…
Systems Affected Microsoft Windows Systems Overview A new variant of the MyDoom…
Systems Affected Microsoft Windows systems; specifically, some versions of the following programs: Microsoft Windows…
Systems Affected These vulnerabilities affect the following versions of Microsoft Internet Explorer: Microsoft Internet Explorer…
Systems Affected Applications and systems that use the libpng library. Overview Several vulnerabilities exist in…
This website uses cookies.