CISA Alert AA22-257A Iranian Islamic Revolutionary Guard Corps-Affiliated Cyber Actors Exploiting Vulnerabilities for Data Extortion and Disk Encryption for Ransom Operations. [CISA Cybersecurity Alerts]

Published: Sept. 15, 2022, 9:06 p.m.

This joint Cybersecurity Advisory highlights continued malicious cyber activity by advanced persistent threat actors affiliated with the Iranian Government\u2019s Islamic Revolutionary Guard Corps. The IRGC-affiliated actors are actively targeting a broad range of entities, including entities across multiple U.S. critical infrastructure sectors as well as Australian, Canadian, and United Kingdom organizations.\xa0\nAA22-257A Alert, Technical Details, and Mitigations\nAA22-257A.stix\nCISA\u2019s Iran Cyber Threat Overview and Advisories\nFBI\u2019s Iran Threat webpage.\nIranian Government-Sponsored APT Cyber Actors Exploiting Microsoft Exchange and Fortinet Vulnerabilities in Furtherance of Malicious Activities\nTechnical Approaches to Uncovering and Remediating Malicious Activity\nAll organizations should report incidents and anomalous activity to CISA\u2019s 24/7 Operations Center at central@cisa.dhs.gov or (888) 282-0870 and to the FBI via your local FBI field office or the FBI\u2019s 24/7 CyWatch at (855) 292-3937 or CyWatch@fbi.gov.\nLearn more about your ad choices. Visit megaphone.fm/adchoices