CISA reported that Iran-based threat actors exploited known vulnerabilities in enterprise VPN products to gain initial access to victim networks, using exposed remote access infrastructure as a foothold for broader intrusion activity. The campaign highlighted the risk from unpatched perimeter devices and showed how state-linked operators can move from internet-facing appliances into internal environments, targeting organizations in the United States and elsewhere.
A later CISA advisory said Iranian government-sponsored APT actors compromised a U.S. federal network and deployed a cryptominer alongside a credential harvester, indicating both opportunistic monetization and sustained access objectives. The activity tied together exploitation of public-facing weaknesses, credential collection, and post-compromise tooling, underscoring how Iranian operators have combined VPN exploitation with follow-on persistence and abuse inside victim networks.

TTPs, infrastructure, and targeting history in one profile.
2 events from the most recent confirmed update back to the earliest known activity.
CISA later disclosed that Iranian government-sponsored APT actors compromised a federal civilian executive branch network. The intrusion included deployment of a cryptocurrency miner and a credential harvester on the victim environment.
CISA reported that Iran-based threat actors were exploiting known VPN vulnerabilities to gain initial access to networks in the United States and elsewhere. The activity involved targeting unpatched internet-facing appliances and using the access for follow-on intrusion activity.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.