FlagThis — Daily Cybersecurity Intelligence Briefing

FILTERING BY: CLEAR FILTER

US DOJ Indictment of Mabna Institute and IRGC for Cyber Espionage

The U.S. Department of Justice has indicted 17 members of the Iran-based Mabna Institute, operating on behalf of the Islamic Revolutionary Guard Corps (IRGC), for a systemic cyber theft campaign. The actors targeted U.S. government agencies and academic institutions via the unauthorized compromise of high-level email accounts and university research databases. The campaign utilized dedicated Command and Control (C2) infrastructure to maintain long-term persistence and exfiltrate sensitive intellectual property (IP) and proprietary research data. The primary objective was the acquisition of strategic data to advance Iranian national interests through targeted espionage.

Coordinated Attack on Minnesota Water Infrastructure Targeting Rockwell Automation and Schneider Electric PLCs

A coordinated cyberattack targeted over 30 Minnesota water and wastewater utilities, leveraging internet-exposed industrial control systems (ICS) via cellular modems. The campaign utilized critical vulnerabilities in Rockwell Automation controllers (CVE-2021-22681, CVE-2023-3595, CVE-2024-6242) and targeted Schneider Electric and Siemens PLCs. Threat actors, attributed to the Iranian-linked CyberAv3ngers (IRGC-CEC), progressed to "Phase 4" capabilities, employing legitimate vendor engineering software to exfiltrate PLC project files and manipulate Add-On Instructions (AOIs) to disable safety protocols. This resulted in operational shutdowns in Braham and transitions to manual operations across multiple municipalities, though no water quality contamination was reported.


LINK COPIED TO CLIPBOARD