NEW: Crowdstrike says an Iranian APT is selling access to compromised networks on a hacking forum

-Group (Fox/Pioneer Kitten) is a contractor for the Iranian regime, providing initial access to other Iranian APTs
-Now apparently selling the extra stock

https://www.zdnet.com/article/iranian-hackers-are-selling-access-to-compromised-companies-on-an-underground-forum/
Fox Kitten is the same APT that according to ClearSky has spent most of 2019 and 2020 hacking VPN servers and networking equipment to plant backdoors in corporate networks around the world

Usual targets included:

https://www.clearskysec.com/fox-kitten/ 
Last month, the FBI sent out an alert about the group expanding its targeting to F5 BIG-IP devices, which at the time was the latest and hottest exploit disclosed by security researchers

https://www.zdnet.com/article/fbi-says-an-iranian-hacking-group-is-attacking-f5-networking-devices/
You can follow @campuscodi.
Tip: mention @twtextapp on a Twitter thread with the keyword “unroll” to get a link to it.

Latest Threads Unrolled: