EudorIACyber Intelligence
Monitoraggio operativo Newsletter IT EN
← Torna all'intelligence
Ransomware

Iranian Government-Sponsored Actors Conduct Cyber Operations Against Global Government and Commercial Networks

Fonte ufficiale
Sintesi operativa EudorIA

Cosa significa

Priorità 95/100

CISA Cybersecurity Advisories ha pubblicato un advisory sul ransomware Iranian Government-Sponsored Actors Conduct Cyber Operations Against Global Government and Commercial Networks. La fonte descrive vulnerabilita o tecniche gia osservate in attacchi e richiede una verifica prioritaria.

Perché conta

L'advisory descrive attivita ransomware osservate e misure difensive pubblicate da un'autorita. Non prova che il proprio perimetro sia compromesso, ma richiede una verifica prioritaria di esposizione e controlli.

Benefici operativi potenziali

  • Prioritizzazione delle esposizioni Internet e delle vulnerabilita sfruttate
  • Verifica dei controlli su accessi remoti, movimento laterale ed esfiltrazione
  • Validazione documentata della capacita di ripristino
Indicazioni da confermare sul perimetro tecnico e organizzativo del cliente.
Controlli pertinentiVulnerability managementIdentity and access managementNetwork segmentationBackup and recoveryDetection and response
DestinatariITSOCCISOManagement
Centro informazioni

Traduzione in elaborazione

CISA

Il contenuto ufficiale è disponibile nella lingua originale. La versione italiana verrà pubblicata al termine dei controlli automatici.

Testo acquisito dalla fonte

Cybersecurity Advisory Iranian Government-Sponsored Actors Conduct Cyber Operations Against Global Government and Commercial Networks Last Revised February 24, 2022 Alert Code AA22-055A Summary Actions to Take Today to Protect Against Malicious Activity * Search for indicators of compromise. * Use antivirus software. * Patch all systems. * Prioritize patching known exploited vulnerabilities . * Train users to recognize and report phishing attempts . * Use multi-factor authentication . Note: this advisory uses the MITRE Adversarial Tactics, Techniques, and Common Knowledge (ATT&CK®) framework, version 10. See the ATT&CK for Enterprise for all referenced threat actor tactics and techniques. The Federal Bureau of Investigation (FBI), the Cybersecurity and Infrastructure Security Agency (CISA), the U.S. Cyber Command Cyber National Mission Force (CNMF), and the United Kingdom’s National Cyber Security Centre (NCSC-UK) have observed a group of Iranian government-sponsored advanced persistent threat (APT) actors, known as MuddyWater, conducting cyber espionage and other malicious cyber operations targeting a range of government and private-sector organizations across sectors—including telecommunications, defense, local government, and oil and natural gas—in Asia, Africa, Europe, and North America. Note: MuddyWater is also known as Earth Vetala, MERCURY, Static Kitten, Seedworm, and TEMP.Zagros. MuddyWater is a subordinate element within the Iranian Ministry of Intelligence and Security (MOIS).[ 1 ] This APT group has conducted broad cyber campaigns in support of MOIS objectives since approximately 2018. MuddyWater actors are positioned both to provide stolen data and accesses to the Iranian government and to share these with other malicious cyber actors. MuddyWater actors are

Indicatori CISA verificabili

81 valori IOC dalla fonte ufficiale. Non sono una lista di blocco automatica: verificare data, contesto e applicabilita.

Ultima verifica: 2026-09-26T04:30:40.022274+00:00

Scarica STIX 2.1
TipoIndicatore (non cliccabile)File
urlhttp://95[.]181[.]161[.]49:80/index[.]php?id=
ipv4-addr192[.]210[.]191[.]188
ipv4-addr185[.]141[.]27[.]248
ipv4-addr185[.]141[.]27[.]143
ipv4-addr185[.]118[.]164[.]21
ipv4-addr185[.]117[.]75[.]34
ipv4-addr185[.]25[.]51[.]108
ipv4-addr164[.]132[.]237[.]65
ipv4-addr95[.]181[.]161[.]50
ipv4-addr89[.]163[.]252[.]232
ipv4-addr88[.]119[.]171[.]213
ipv4-addr80[.]85[.]158[.]49
ipv4-addr46[.]166[.]129[.]159
ipv4-addr45[.]142[.]212[.]61
MD55763530f25ed0ec08fb26a30c04009f1index.exe
SHA-12a6ddf89a8366a262b56a251b00aafaed5321992index.exe
SHA-256bf090cf7078414c9e157da7002ca727f06053b39fa4e377f9a0050f2af37d3a2index.exe
ipv4-addr192[.]210[.]226[.]128
ipv4-addr45[.]153[.]231[.]104
MD515fa3b32539d7453a9a85958b77d4c95gram_app.exe
SHA-111d594f3b3cf8525682f6214acb7b7782056d282gram_app.exe
SHA-256b75208393fa17c0bcbc1a07857686b8c0d7e0471d00a167a07fd0d52e1fc9054gram_app.exe
ipv4-addr95[.]181[.]161[.]49
ipv4-addr5[.]199[.]133[.]149
ipv4-addr88[.]119[.]170[.]124
ipv4-addr185[.]183[.]96[.]44
ipv4-addr185[.]183[.]96[.]7
ipv4-addr185[.]45[.]192[.]228
ipv4-addr45[.]142[.]213[.]17
ipv4-addr87[.]236[.]212[.]22

Provenienza

Allegato ufficiale CISA · 2022-02-22T20:49:17Z

SHA-512: e824f52fbfec8291e6844e90d8a4666483305356fd02ff38b3ab3af8ffa2c0df6f15b3453dcfbb4a71b3128e1fb5c3a5908c3164843716900edc44830ece013a

TipoIndicatore (non cliccabile)File
MD5a27655d14b0aabec8db70ae08a623317
SHA-18344f2c1096687ed83c2bbad0e6e549a71b0c0b1
SHA-25612db8bcee090521ecf852bf215ce3878737517a22ef1f2ff9bdec7cba8d0d3aa
MD5218d4151b39e4ece13d3bf5ff4d1121b
SHA-128e799d9769bb7e936d1768d498a0d2c7a0d53fb
SHA-2562471a039cb1ddeb826f3a11f89b193624d89052afcbee01205dc92610723eb82
ipv4-addr185[.]183[.]96[.]7
MD5860f5c2345e8f5c268c9746337ade8b7
SHA-16c55d3acdc2d8d331f0d13024f736bc28ef5a7e1
SHA-2569d50fcb2c4df4c502db0cac84bef96c2a36d33ef98c454165808ecace4dd2051
MD5cec48bcdedebc962ce45b63e201c0624
SHA-181f46998c92427032378e5dead48bdfc9128b225
SHA-256dd7ee54b12a55bcc67da4ceaed6e636b7bd30d4db6f6c594e9510e1e605ade92
MD5a65696d6b65f7159c9ffcd4119f60195
SHA-1570f7272412ff8257ed6868d90727a459e3b179e
SHA-256b5b1e26312e0574464ddef92c51d5f597e07dba90617c0528ec9f494af7e8504
MD54a022ea1fd2bf5e8c0d8b2343a230070
SHA-189df0feca9a447465d41ac87cb45a6f3c02c574d
SHA-256e7baf353aa12ff2571fc5c45184631dc2692e2f0a61b799e29a1525969bf2d13
MD56c084c8f5a61c6bec5eb5573a2d51ffb
SHA-161608ed1de56d0e4fe6af07ecba0bd0a69d825b8
SHA-2567e7545d14df7b618b3b1bc24321780c164a0a14d3600dbac0f91afbce1a2f9f4
ipv4-addr185[.]117[.]75[.]34
MD5a0421312705e847a1c8073001fd8499c
SHA-13204447f54adeffb339ed3e00649ae428544eca3
SHA-2569cb79736302999a7ec4151a43e93cd51c97ede879194cece5e46b4ff471a7af7
ipv4-addr192[.]210[.]191[.]188
MD5a16f4f0c00ca43d5b20f7bc30a3f3559
SHA-194e26fb2738e49bb70b445315c0d63a5d364c71b
SHA-2565bcdd422089ed96d6711fa251544e2e863b113973db328590cfe0457bfeb564f
ipv4-addr185[.]183[.]96[.]44
MD5c0c2cd5cc018e575816c08b36969c4a6
SHA-147a4e0d466bb20cec5d354e56a9aa3f07cec816a
SHA-256b1e30cce6df16d83b82b751edca57aa17795d8d0cdd960ecee7d90832b0ee76c
ipv4-addr185[.]118[.]164[.]21
MD537fa9e6b9be7242984a39a024cade2d5
SHA-10211569091b96cffab6918e18ccc97f4b24d88d4
SHA-25642ca7d3fcd6d220cd380f34f9aa728b3bb68908b49f04d04f685631ee1f78986
MD50431445d6d6e5802c207c8bc6a6402ea
SHA-13765c1ad8a1d936aad88255aef5d6d4ce24f94e8
SHA-2563098dd53da40947a82e59265a47059e69b2925bc49c679e6555d102d1c6cbbc8
MD5b0ab12a5a4c232c902cdeba421872c37
SHA-1a8e7659942cc19f422678181ee23297efa55fa09
SHA-256026868713d60e6790f41dc7046deb4e6795825faa903113d2f22b644f0d21141
MD5e182a861616a9f12bc79988e6a4186af
SHA-169840d4c4755cdab01527eacbb48577d973f7157
SHA-256c2badcdfa9b7ece00f245990bb85fb6645c05b155b77deaf2bb7a2a0aacbe49e
MD5b3504546810e78304e879df76d4eec46
SHA-1d02d93b707ac999fde0545792870a2b82dc3a238
SHA-256f10471e15c6b971092377c524a0622edf4525acee42f4b61e732f342ea7c0df0
ipv4-addr88[.]119[.]170[.]124
MD56cef87a6ffb254bfeb61372d24e1970a
SHA-1e21d95b648944ad2287c6bc01fcc12b05530e455
SHA-2564b2862a1665a62706f88304406b071a5c9a6b3093daadc073e174ac6d493f26c
MD5cb84c6b5816504c993c33360aeec4705
SHA-19f212961d1de465c20e84f3c4d8ac0302e02ce37
SHA-256d77e268b746cf1547e7ed662598f8515948562e1d188a7f9ddb8e00f4fd94ef0
ipv4-addr5[.]199[.]133[.]149

Provenienza

Allegato ufficiale CISA · 2022-02-22T15:55:39Z

SHA-512: cc1ed7b579904d7dfb2639af7064301f5573a0111fcfdd5d836c138ba0df78eb23440e083a91d0feff717ed60472d22e64ad050fe884791dc51a94458e320a9b

Fonte
CISA Cybersecurity Advisories
Entità pubblicatrice
CISA
Tipo entità
Autorità nazionale
Area
North America · US
Lingua originale
en · traduzione in preparazione
Pubblicazione
24/02/2022 13:00
Condivisione
TLP:CLEAR
MITRE ATT&CK
T1001, T1001.001, T1003, T1003.001, T1003.004, T1003.005, T1005, T1016, T1027, T1027.003, T1027.004, T1033, T1036, T1036.005, T1041, T1047, T1049, T1053.005, T1057, T1059, T1059.001, T1059.003, T1059.005, T1059.006, T1059.007, T1071, T1071.001, T1082, T1083, T1087, T1087.002, T1090, T1090.002, T1102, T1102.002, T1104, T1105, T1113, T1132, T1132.001, T1132.002, T1137, T1137.001, T1140, T1203, T1204, T1204.001, T1204.002, T1218, T1218.003, T1218.005, T1218.011, T1219, T1480, T1486, T1518, T1518.001, T1547.001, T1548.002, T1552, T1552.001, T1555, T1555.003, T1559, T1559.001, T1559.002, T1560, T1560.001, T1562, T1562.001, T1566, T1566.001, T1566.002, T1572, T1574.002, T1583, T1583.006, T1588, T1588.002, T1589, T1589.002
CVE
CVE-2020-1472, CVE-2020-0688, CVE-2017-0199
Classificazione
Critica
Paese indicato
US
Perimetro tecnico

Prodotti e versioni interessati

Verifica in corso
Informazione non ancora acquisita.

Il collector verificherà NVD e gli advisory vendor ufficiali disponibili.

Azione indicata dalla fonte

Verificare e correggere con priorita i sistemi Internet-facing indicati dalla fonte; applicare MFA resistente al phishing, segmentazione e backup offline immutabili con prove di ripristino.

Riferimenti tecnici ufficiali

Apri la fonte originale