AA24-290A Iranian Cyber Actors Brute Force and Credential Access Activity Compromises Critical Infrastructure Organizations
What it means
MISP EudorIA ha pubblicato l'advisory "AA24-290A Iranian Cyber Actors Brute Force and Credential Access Activity Compromises Critical Infrastructure Organizations". Occorre verificarne l'applicabilita rispetto a prodotti e servizi in uso.
Why it matters
Un advisory attendibile puo richiedere verifiche, aggiornamenti o mitigazioni, ma l'applicabilita va confermata sul perimetro reale.
Recommended actions
- Verificare tecnologie, versioni e servizi interessati nel proprio inventario.
- Consultare la fonte originale prima di pianificare la mitigazione.
Text acquired from the source
Evento MISP pubblicato con TLP:CLEAR: AA24-290A Iranian Cyber Actors Brute Force and Credential Access Activity Compromises Critical Infrastructure Organizations. Report from - [URL rimossa] (1728762435) AA24-290A Related topics: Cybersecurity Best Practices, Multifactor Authentication, Organizations and Cyber Safety ## **Summary** The Federal Bureau of Investigation (FBI), the Cybersecurity and Infrastructure Security Agency (CISA), the National Security Agency (NSA), the Communications Security Establishment Canada (CSE), the Australian Federal Police (AFP), and Australian Signals Directorate's Australian Cyber Security Centre (ASD's ACSC) are releasing this joint Cybersecurity Advisory to warn network defenders of Iranian cyber actors’ use of brute force and other techniques to compromise organizations across multiple critical infrastructure sectors, including the healthcare and public health (HPH), government, information technology, engineering, and energy sectors. The actors likely aim to obtain credentials and information describing the victim’s network that can then be sold to enable access to cybercriminals. Since October 2023, Iranian actors have used brute force, such as password spraying, and multifactor authentication (MFA) ‘push bombing’ to compromise user accounts and obtain access to organizations. The actors frequently modified MFA registrations, enabling persistent access. The actors performed discovery on the compromised networks to obtain additional credentials and identify other information that could be used to gain
- Source
- MISP EudorIA
- Publishing entity
- MISP EudorIA
- Entity type
- Intelligence community
- Area
- Global
- Original language
- it · translation not needed
- Publication
- 30/07/2026 02:52
- Sharing
- TLP:CLEAR
- Indicators reported by the source
- 76
- IOCs indexed for lookup
- 0 values within the retention period
- IOCs available in the STIX feed
- 75Last sharing verification: 2026-09-26T04:09:07.175904+00:00
- MISP event
- b891b584-a5bb-48d5-9b70-95cd02ac544c
- Classification
- undefined