CISA warned that Iranian government-sponsored and Islamic Revolutionary Guard Corps (IRGC)-affiliated cyber actors exploited unpatched Microsoft Exchange and Fortinet vulnerabilities to gain access to victim networks, establish persistence, and conduct follow-on malicious activity. The intrusions targeted internet-facing systems and relied on known vulnerabilities to move from initial compromise into broader enterprise environments, underscoring the continued risk from delayed patching of widely deployed edge and email infrastructure.
U.S. authorities said the activity evolved beyond espionage-style access into data extortion and disk encryption for ransom operations, with the same Iranian-linked operators using compromised networks to steal information and pressure victims for payment. The advisories tie the campaigns to state-backed Iranian actors and describe a pattern in which vulnerability exploitation on exposed systems enabled credential access, lateral movement, and disruptive impact across victim organizations.

TTPs, infrastructure, and targeting history in one profile.
2 events from the most recent confirmed update back to the earliest known activity.
CISA published advisory AA22-257A stating that Iranian Islamic Revolutionary Guard Corps-affiliated cyber actors were exploiting vulnerabilities to steal data, extort victims, and encrypt disks in ransomware-style operations.
CISA published advisory AA21-321A warning that Iranian government-sponsored APT actors were exploiting Microsoft Exchange and Fortinet vulnerabilities to gain access to U.S. networks and conduct follow-on malicious activity.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
4 references tracked. Mallory keeps watching after this page renders.
cisa.gov
Open sourcecisa.gov
Open sourcecisa.gov
Open sourcecisa.gov
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.