Iranian cyber actors have been targeting critical infrastructure sectors, such as healthcare, government, and energy, using brute force attacks like password spraying and MFA “push bombing” to gain access. They modify MFA registrations to maintain persistent access and conduct network reconnaissance to steal additional credentials. Their methods include exploiting vulnerabilities like Zerologon and using VPNs to mask their activities. The stolen credentials are often sold to cybercriminals, posing a serious threat to organizations.
What’s new on HivePro
Get through updates and upcoming events, and more directly in your inbox