EudorIACyber Intelligence
Monitoraggio operativo Newsletter IT EN
← Torna all'intelligence
Ransomware

Iranian Government-Sponsored APT Cyber Actors Exploiting Microsoft Exchange and Fortinet Vulnerabilities in Furtherance of Malicious Activities

Fonte ufficiale
Sintesi operativa EudorIA

Cosa significa

Priorità 90/100

CISA Cybersecurity Advisories ha pubblicato un advisory sul ransomware Iranian Government-Sponsored APT Cyber Actors Exploiting Microsoft Exchange and Fortinet Vulnerabilities in Furtherance of Malicious Activities. Le misure indicate vanno confrontate con esposizione, identita, segmentazione e capacita di ripristino.

Perché conta

L'advisory descrive attivita ransomware osservate e misure difensive pubblicate da un'autorita. Non prova che il proprio perimetro sia compromesso, ma richiede una verifica prioritaria di esposizione e controlli.

Benefici operativi potenziali

  • Prioritizzazione delle esposizioni Internet e delle vulnerabilita sfruttate
  • Verifica dei controlli su accessi remoti, movimento laterale ed esfiltrazione
  • Validazione documentata della capacita di ripristino
Indicazioni da confermare sul perimetro tecnico e organizzativo del cliente.
Controlli pertinentiVulnerability managementIdentity and access managementNetwork segmentationBackup and recoveryDetection and response
DestinatariITSOCCISOManagement
Centro informazioni

Traduzione in elaborazione

CISA

Il contenuto ufficiale è disponibile nella lingua originale. La versione italiana verrà pubblicata al termine dei controlli automatici.

Testo acquisito dalla fonte

Cybersecurity Advisory Iranian Government-Sponsored APT Cyber Actors Exploiting Microsoft Exchange and Fortinet Vulnerabilities in Furtherance of Malicious Activities Last Revised November 19, 2021 Alert Code AA21-321A Summary Actions to Take Today to Protect Against Iranian State-Sponsored Malicious Cyber Activity • Immediately patch software affected by the following vulnerabilities: CVE-2021-34473, 2018-13379, 2020-12812, and 2019-5591. • Implement multi-factor authentication . • Use strong, unique passwords .v Note: this advisory uses the MITRE Adversarial Tactics, Techniques, and Common Knowledge (ATT&CK®) framework, version 10. See the ATT&CK for Enterprise for all referenced threat actor tactics and techniques. This joint cybersecurity advisory is the result of an analytic effort among the Federal Bureau of Investigation (FBI), the Cybersecurity and Infrastructure Security Agency (CISA), the Australian Cyber Security Centre (ACSC), and the United Kingdom’s National Cyber Security Centre (NCSC) to highlight ongoing malicious cyber activity by an advanced persistent threat (APT) group that FBI, CISA, ACSC, and NCSC assess is associated with the government of Iran. FBI and CISA have observed this Iranian government-sponsored APT group exploit Fortinet vulnerabilities since at least March 2021 and a Microsoft Exchange ProxyShell vulnerability since at least October 2021 to gain initial access to systems in advance of follow-on operations, which include deploying ransomware. ACSC is also aware this APT group has used the same Microsoft Exchange vulnerability in Australia. The Iranian government-sponsored APT actors are actively targeting a broad range of victims across multiple U.S. critical infrastructure sectors, including the Transportation Sector and the Healthcar

Indicatori CISA verificabili

40 valori IOC dalla fonte ufficiale. Non sono una lista di blocco automatica: verificare data, contesto e applicabilita.

Ultima verifica: 2026-09-26T06:00:39.554315+00:00

Scarica STIX 2.1
TipoIndicatore (non cliccabile)File
urlhttps://github[.]com/fatedier/frp/releases/download/v0[.]34[.]3/frp_0[.]34[.]3_windows_amd64[.]zip
urlhttps://github[.]com/fatedier/frp/releases/download/v0[.]33[.]0/frp_0[.]33[.]0_windows_amd64[.]zip
MD51a44368eb5bf68688ba4b4357bdc874fMicrosoftOutlookUpdater.bat
SHA-1fa36febfd5a5ca0b3a1b19005b952683a7188a13MicrosoftOutlookUpdater.bat
SHA-2563a08d0cb0ff4d95ed0896f22f4da8755525c243c457ba6273e08453e0e3ac4c4MicrosoftOutlookUpdater.bat
SHA-51270aa89449eb5da1d84b70d114ef9d24cb74751ce12d12c783251e51775c89fdce61b4265b43b1d613114d6a85e9c75927b706f39c576dbb036079c7e8caf28b2MicrosoftOutlookUpdater.bat
MD547333937109f86ba292dc44cd3676f80MicrosoftOutlookUpdater.xml
SHA-1a8674983a45bd88a4d11bcfd686c2bf8182831a0MicrosoftOutlookUpdater.xml
SHA-256ac72790230817e6a72ef3a95b5f1f27144e56082606c425ad14c1f3d2fb2c5bdMicrosoftOutlookUpdater.xml
SHA-512a03f0d73136cbcacaea5c8f7607f4a09f2df9030d30735db2e033da668353636e0fcf7a2aa0b81691a6d7c30cfa67ec9707f7456615e007c025242dbfb6bccf0MicrosoftOutlookUpdater.xml
ipv4-addr154[.]16[.]192[.]70
email-addrnosterrmann[@]protonmail[.]com
email-addrnosterrmann[@]mail[.]com
email-addrwearehere[@]secmail[.]pro
email-addrsar_addr[@]protonmail[.]com
MD526f330dadcdd717ef575aa5bfcdbe76aFrps.exe
SHA-1c4160aa55d092cf916a98f3b3ee8b940f2755053Frps.exe
SHA-256d7982ffe09f947e5b4237c9477af73a034114af03968e3c4ce462a029f072a5aFrps.exe
SSDEEP196608:/qTLyGAlLrOt8enYfrhkhBnfY0NIPvoOQiE:GLHiLrSfY5voOFrps.exe
MD5e64064f76e59dea46a0768993697ef2fConnector3.exe
SHA-16a6fb59dda237d86d776ec3aa89e02af4a6d2e9aConnector3.exe
SHA-256604e7cee9b32160c8e1b4159536e9e50bccc033d36fc8010160a2aea432191e0Connector3.exe
MD5af2d86042602cbbdcc7f1e8efa6423f9GoogleChangeManagement.xml
SHA-1cdcd97f946b78831a9b88b0a5cd785288dc603c1GoogleChangeManagement.xml
SHA-2564c691ccd811b868d1934b4b8e9ed6d5db85ef35504f85d860e8fd84c547ebf1dGoogleChangeManagement.xml
SHA-5126473dac67b75194deeaef37103bba17936f6c16ffcd2a7345a5a46756996fad748a97f36f8fd4be4e1f264ece313773cc5596099d68e71344d8135f50e5d8971GoogleChangeManagement.xml
MD5aa40c49e309959fa04b7e5ac111bb770MicrosoftOutlookUpdateSchedule.xml
SHA-1f1d90e10e6e3654654e0a677763c9767c913f8f0MicrosoftOutlookUpdateSchedule.xml
SHA-2565c818fe43f05f4773ad20e0862280b0d5c66611bb12459a08442f55f148400a6MicrosoftOutlookUpdateSchedule.xml
SHA-512e55a86159f2e869dcdb64fdc730da893718e20d65a04071770bd32cae75ff8c34704bdf9f72ef055a3b362759ede3682b3883c4d9bcf87013076638664e8078eMicrosoftOutlookUpdateSchedule.xml
MD51444884faed804667d8c2bfa0d63ab13MicrosoftOutLookUpdater.exe
SHA-195e045446efb8c9983ebfd85e39b4be5d92c7a2aMicrosoftOutLookUpdater.exe
SHA-256c51fe5073bd493c7e8d83365aace3f9911437a0f2ae80042ba01ea46b55d2624MicrosoftOutLookUpdater.exe
SHA-5126451077b99c5f8ecc5c0ca88fe272156296beb91218b39ae28a086dba5e7e39813f044f9af0fedbb260941b1cd52fa237c098cbf4b2a822f08e3e98e934d0ecfMicrosoftOutLookUpdater.exe
ipv4-addr162[.]55[.]137[.]20
ipv4-addr91[.]214[.]124[.]143
MD5b90f05b5e705e0b0cb47f51b985f84dbAudio.exe or frpc.exe
SHA-15bd0690247dc1e446916800af169270f100d089bAudio.exe or frpc.exe
SHA-25628332bdbfaeb8333dad5ada3c10819a1a015db9106d5e8a74beaaf03797511aaAudio.exe or frpc.exe
SSDEEP98304:MeOuFco2Aate8mjOaFEKC8KZ1F4ANWyJXf/X+g4:MeHFV2AatevjOaDC8KZ1xNWy93UAudio.exe or frpc.exe

Provenienza

Allegato ufficiale CISA · 2021-11-18T21:37:42Z

SHA-512: a950675ee40c9026fb45312afab31c501904f21f2fb262837690618e5897b2f7a29b7cac68e9dbfb5be72fc5a36265755f17ea2f7997e87f77da4df2f0ff42f9

Fonte
CISA Cybersecurity Advisories
Entità pubblicatrice
CISA
Tipo entità
Autorità nazionale
Area
North America · US
Lingua originale
en · traduzione in preparazione
Pubblicazione
19/11/2021 13:00
Condivisione
TLP:CLEAR
MITRE ATT&CK
T1053.005, T1136.001, T1136.002, T1190, T1486, T1560.001, T1588.001, T1588.002
CVE
CVE-2021-34473, CVE-2018-13379, CVE-2020-12812, CVE-2019-5591
Classificazione
Critica
Paese indicato
US
Perimetro tecnico

Prodotti e versioni interessati

Verifica in corso
Informazione non ancora acquisita.

Il collector verificherà NVD e gli advisory vendor ufficiali disponibili.

Azione indicata dalla fonte

Verificare e correggere con priorita i sistemi Internet-facing indicati dalla fonte; applicare MFA resistente al phishing, segmentazione e backup offline immutabili con prove di ripristino.

Riferimenti tecnici ufficiali

Apri la fonte originale