EudorIACyber Intelligence
Operational monitoring Newsletter IT EN
← Back to intelligence
Ransomware

Iranian Government-Sponsored APT Cyber Actors Exploiting Microsoft Exchange and Fortinet Vulnerabilities in Furtherance of Malicious Activities

Official source
EudorIA operational summary

What it means

Priority 90/100

CISA Cybersecurity Advisories ha pubblicato un advisory sul ransomware Iranian Government-Sponsored APT Cyber Actors Exploiting Microsoft Exchange and Fortinet Vulnerabilities in Furtherance of Malicious Activities. Le misure indicate vanno confrontate con esposizione, identita, segmentazione e capacita di ripristino.

Why it matters

L'advisory descrive attivita ransomware osservate e misure difensive pubblicate da un'autorita. Non prova che il proprio perimetro sia compromesso, ma richiede una verifica prioritaria di esposizione e controlli.

Potential operational benefits

  • Prioritizzazione delle esposizioni Internet e delle vulnerabilita sfruttate
  • Verifica dei controlli su accessi remoti, movimento laterale ed esfiltrazione
  • Validazione documentata della capacita di ripristino
Indications to confirm against the customer's technical and organisational perimeter.
Relevant controlsVulnerability managementIdentity and access managementNetwork segmentationBackup and recoveryDetection and response
AudienceITSOCCISOManagement
Information centre

Translation in progress

CISA

The official content is available in the original language. The Italian version will be published once automated checks are complete.

Text acquired from the source

Cybersecurity Advisory Iranian Government-Sponsored APT Cyber Actors Exploiting Microsoft Exchange and Fortinet Vulnerabilities in Furtherance of Malicious Activities Last Revised November 19, 2021 Alert Code AA21-321A Summary Actions to Take Today to Protect Against Iranian State-Sponsored Malicious Cyber Activity • Immediately patch software affected by the following vulnerabilities: CVE-2021-34473, 2018-13379, 2020-12812, and 2019-5591. • Implement multi-factor authentication . • Use strong, unique passwords .v Note: this advisory uses the MITRE Adversarial Tactics, Techniques, and Common Knowledge (ATT&CK®) framework, version 10. See the ATT&CK for Enterprise for all referenced threat actor tactics and techniques. This joint cybersecurity advisory is the result of an analytic effort among the Federal Bureau of Investigation (FBI), the Cybersecurity and Infrastructure Security Agency (CISA), the Australian Cyber Security Centre (ACSC), and the United Kingdom’s National Cyber Security Centre (NCSC) to highlight ongoing malicious cyber activity by an advanced persistent threat (APT) group that FBI, CISA, ACSC, and NCSC assess is associated with the government of Iran. FBI and CISA have observed this Iranian government-sponsored APT group exploit Fortinet vulnerabilities since at least March 2021 and a Microsoft Exchange ProxyShell vulnerability since at least October 2021 to gain initial access to systems in advance of follow-on operations, which include deploying ransomware. ACSC is also aware this APT group has used the same Microsoft Exchange vulnerability in Australia. The Iranian government-sponsored APT actors are actively targeting a broad range of victims across multiple U.S. critical infrastructure sectors, including the Transportation Sector and the Healthcar

Indicatori CISA verificabili

40 valori IOC dalla fonte ufficiale. Non sono una lista di blocco automatica: verificare data, contesto e applicabilita.

Ultima verifica: 2026-09-26T06:00:39.554315+00:00

Scarica STIX 2.1
TipoIndicatore (non cliccabile)File
urlhttps://github[.]com/fatedier/frp/releases/download/v0[.]34[.]3/frp_0[.]34[.]3_windows_amd64[.]zip
urlhttps://github[.]com/fatedier/frp/releases/download/v0[.]33[.]0/frp_0[.]33[.]0_windows_amd64[.]zip
MD51a44368eb5bf68688ba4b4357bdc874fMicrosoftOutlookUpdater.bat
SHA-1fa36febfd5a5ca0b3a1b19005b952683a7188a13MicrosoftOutlookUpdater.bat
SHA-2563a08d0cb0ff4d95ed0896f22f4da8755525c243c457ba6273e08453e0e3ac4c4MicrosoftOutlookUpdater.bat
SHA-51270aa89449eb5da1d84b70d114ef9d24cb74751ce12d12c783251e51775c89fdce61b4265b43b1d613114d6a85e9c75927b706f39c576dbb036079c7e8caf28b2MicrosoftOutlookUpdater.bat
MD547333937109f86ba292dc44cd3676f80MicrosoftOutlookUpdater.xml
SHA-1a8674983a45bd88a4d11bcfd686c2bf8182831a0MicrosoftOutlookUpdater.xml
SHA-256ac72790230817e6a72ef3a95b5f1f27144e56082606c425ad14c1f3d2fb2c5bdMicrosoftOutlookUpdater.xml
SHA-512a03f0d73136cbcacaea5c8f7607f4a09f2df9030d30735db2e033da668353636e0fcf7a2aa0b81691a6d7c30cfa67ec9707f7456615e007c025242dbfb6bccf0MicrosoftOutlookUpdater.xml
ipv4-addr154[.]16[.]192[.]70
email-addrnosterrmann[@]protonmail[.]com
email-addrnosterrmann[@]mail[.]com
email-addrwearehere[@]secmail[.]pro
email-addrsar_addr[@]protonmail[.]com
MD526f330dadcdd717ef575aa5bfcdbe76aFrps.exe
SHA-1c4160aa55d092cf916a98f3b3ee8b940f2755053Frps.exe
SHA-256d7982ffe09f947e5b4237c9477af73a034114af03968e3c4ce462a029f072a5aFrps.exe
SSDEEP196608:/qTLyGAlLrOt8enYfrhkhBnfY0NIPvoOQiE:GLHiLrSfY5voOFrps.exe
MD5e64064f76e59dea46a0768993697ef2fConnector3.exe
SHA-16a6fb59dda237d86d776ec3aa89e02af4a6d2e9aConnector3.exe
SHA-256604e7cee9b32160c8e1b4159536e9e50bccc033d36fc8010160a2aea432191e0Connector3.exe
MD5af2d86042602cbbdcc7f1e8efa6423f9GoogleChangeManagement.xml
SHA-1cdcd97f946b78831a9b88b0a5cd785288dc603c1GoogleChangeManagement.xml
SHA-2564c691ccd811b868d1934b4b8e9ed6d5db85ef35504f85d860e8fd84c547ebf1dGoogleChangeManagement.xml
SHA-5126473dac67b75194deeaef37103bba17936f6c16ffcd2a7345a5a46756996fad748a97f36f8fd4be4e1f264ece313773cc5596099d68e71344d8135f50e5d8971GoogleChangeManagement.xml
MD5aa40c49e309959fa04b7e5ac111bb770MicrosoftOutlookUpdateSchedule.xml
SHA-1f1d90e10e6e3654654e0a677763c9767c913f8f0MicrosoftOutlookUpdateSchedule.xml
SHA-2565c818fe43f05f4773ad20e0862280b0d5c66611bb12459a08442f55f148400a6MicrosoftOutlookUpdateSchedule.xml
SHA-512e55a86159f2e869dcdb64fdc730da893718e20d65a04071770bd32cae75ff8c34704bdf9f72ef055a3b362759ede3682b3883c4d9bcf87013076638664e8078eMicrosoftOutlookUpdateSchedule.xml
MD51444884faed804667d8c2bfa0d63ab13MicrosoftOutLookUpdater.exe
SHA-195e045446efb8c9983ebfd85e39b4be5d92c7a2aMicrosoftOutLookUpdater.exe
SHA-256c51fe5073bd493c7e8d83365aace3f9911437a0f2ae80042ba01ea46b55d2624MicrosoftOutLookUpdater.exe
SHA-5126451077b99c5f8ecc5c0ca88fe272156296beb91218b39ae28a086dba5e7e39813f044f9af0fedbb260941b1cd52fa237c098cbf4b2a822f08e3e98e934d0ecfMicrosoftOutLookUpdater.exe
ipv4-addr162[.]55[.]137[.]20
ipv4-addr91[.]214[.]124[.]143
MD5b90f05b5e705e0b0cb47f51b985f84dbAudio.exe or frpc.exe
SHA-15bd0690247dc1e446916800af169270f100d089bAudio.exe or frpc.exe
SHA-25628332bdbfaeb8333dad5ada3c10819a1a015db9106d5e8a74beaaf03797511aaAudio.exe or frpc.exe
SSDEEP98304:MeOuFco2Aate8mjOaFEKC8KZ1F4ANWyJXf/X+g4:MeHFV2AatevjOaDC8KZ1xNWy93UAudio.exe or frpc.exe

Provenance

Allegato ufficiale CISA · 2021-11-18T21:37:42Z

SHA-512: a950675ee40c9026fb45312afab31c501904f21f2fb262837690618e5897b2f7a29b7cac68e9dbfb5be72fc5a36265755f17ea2f7997e87f77da4df2f0ff42f9

Source
CISA Cybersecurity Advisories
Publishing entity
CISA
Entity type
National authority
Area
North America · US
Original language
en · translation in preparation
Publication
19/11/2021 13:00
Sharing
TLP:CLEAR
MITRE ATT&CK
T1053.005, T1136.001, T1136.002, T1190, T1486, T1560.001, T1588.001, T1588.002
CVE
CVE-2021-34473, CVE-2018-13379, CVE-2020-12812, CVE-2019-5591
Classification
Critical
Stated country
US
Technical scope

Affected products and versions

Verification in progress
Information not yet acquired.

The collector will check NVD and the available official vendor advisories.

Action indicated by the source

Verificare e correggere con priorita i sistemi Internet-facing indicati dalla fonte; applicare MFA resistente al phishing, segmentazione e backup offline immutabili con prove di ripristino.

Official technical references

Open the original source