Iranian Cyber Actors Target Critical Infrastructure

Red | Attack Report

Iranian cyber actors have been targeting critical infrastructure sectors, such as healthcare, government, and energy, using brute force attacks like password spraying and MFA "push bombing" to gain access. They modify MFA registrations to maintain persistent access and conduct network reconnaissance to steal additional credentials. Their methods include exploiting vulnerabilities like Zerologon and using VPNs to mask their activities. The stolen credentials are often sold to cybercriminals, posing a serious threat to organizations.

Reduce real exposure. Not just vulnerability volume.