CYBER ALERT: Iranian cyber actors’ brute force and credential access activity compromises critical infrastructure
Since October 2023, Iranian actors have used brute force, such as password spraying, and multi-factor authentication (MFA) ‘push bombing’ to compromise user accounts and obtain access to organizations. The actors frequently modified MFA registrations, enabling persistent access.