WaterISAC Navigation
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
Home Posts CISA Advisory – Iran-based Cyber Actors Enabling Ransomware Attacks on U.S. Organizations
Become a Member

Log in

  • Upcoming Events
  • Resource Center
  • Tools
  • Webcasts
  • Contaminant Databases
  • Community Partners
  • About
  • Log in

  • My Account

  • Logout

  • Report Incident
  • Contact Us
  • NRWA Signup
  • WaterISAC Champions
More Resources

CISA Advisory – Iran-based Cyber Actors Enabling Ransomware Attacks on U.S. Organizations

Author: Chase Snow

Created: Thursday, August 29, 2024 - 17:49

Categories: Cybersecurity, Federal & State Resources, Security Preparedness

CISA, the FBI, and the Department of Defense Cyber Crime Center (DC3) have issued a joint Cybersecurity Advisory: “Iran-based Cyber Actors Enabling Ransomware Attacks on U.S. Organizations.” The advisory aims to alert network defenders about ongoing threats from a group of Iran-based cyber actors known to the private sector as Pioneer Kitten, Parisite, Rubidium, and Lemon Sandstorm. As late as August 2024, this group has been targeting U.S. and foreign organizations in multiple sectors, including education, finance, healthcare, and defense, as well as local government entities. It is believed the groups methods aim to gain network access to collaborate with ransomware affiliates while also conducting computer network exploitation (CNE) activities to support the Government of Iran.

The timing of this advisory coincides with additional research on Iranian-based cyber threats. Notably, yesterday, Microsoft published its report on Peach Sandstorm and Google Cloud’s Mandiant published a report on an Iranian counterintelligence operation.

CISA and partners encourage critical infrastructure organizations to review and implement the mitigations provided in this joint advisory to reduce the likelihood and impact of ransomware incidents. For more information on Iranian state-sponsored threat actor activity, see CISA’s Iran Cyber Threat Overview and Advisories page. 

See #StopRansomware along with the updated #StopRansomware Guide for additional guidance on ransomware protection, detection, and response. Visit CISA’s Cross-Sector Cybersecurity Performance Goals for more information on the CPGs, including additional recommended baseline protections.

Related Resources

Tip of the Week – May 14, 2026

May 14, 2026 in Cybersecurity, Security Preparedness
Members Only

(TLP:AMBER+STRICT) Situation Report: Heightened Threat Environment – Potential Retaliation by Iranian Threat Actors Following U.S. Strikes on Iran (Updated May 14, 2026)

May 14, 2026 in Cybersecurity, OT-ICS Security, Physical Security, Security Preparedness

(TLP:CLEAR) Non-Human Identities (NHIs) Are Growing Faster Than Most Security Programs

May 14, 2026 in Cybersecurity, Security Preparedness

Become a Member
FAQs
About
Report Incident

Terms & Conditions
Privacy Policy
AI Policy
Contact Us

LinkedIn

1250 I Street NW, Suite 350
Washington, DC 20005
1-866-H2O-ISAC (1-866-426-4722)
© 2026 WaterISAC. All Rights Reserved.

Toggle the Widgetbar