Threat Intelligence Brief
Curated summary with source attribution
Source: securityaffairs.com
Threat Risk: High
Victim: Global academic institutions, government agencies, and private corporations
Incident: A multi-year cyber espionage campaign involving the theft of intellectual property and corporate data.
Impact: Theft of 31TB of data and over $20 million in victim remediation and investigation costs.
Attacker: Mabna Institute (linked to Iran’s IRGC)
Analysis: The Mabna Institute utilized password spraying and credential theft to compromise thousands of accounts globally, bridging the gap between state-sponsored espionage and criminal monetization. By stealing over 31 terabytes of academic data and targeting corporate entities, the actors demonstrated a persistent ability to infiltrate diverse sectors. This campaign highlights the high value threat actors place on intellectual property and the vulnerability of academic environments.
Recommendations: Enforce mandatory multi-factor authentication (MFA) for all institutional and corporate accounts.; Implement robust monitoring to detect and block password spraying and credential stuffing attempts.; Conduct regular audits of account permissions and monitor for large-scale unauthorized data egress.
Source: Security Affairs
Editorial note: this post summarizes third-party reporting and links to the original source.
View Original Source