{"id":44013,"date":"2021-11-18T16:00:37","date_gmt":"2021-11-18T16:00:37","guid":{"rendered":"https:\/\/www.microsoft.com\/security\/blog\/?p=101943"},"modified":"2021-11-18T16:00:37","modified_gmt":"2021-11-18T16:00:37","slug":"iranian-targeting-of-it-sector-on-the-rise","status":"publish","type":"post","link":"https:\/\/www.threatshub.org\/blog\/iranian-targeting-of-it-sector-on-the-rise\/","title":{"rendered":"Iranian targeting of IT sector on the rise"},"content":{"rendered":"<p>Iranian threat actors are increasing attacks against IT services companies as a way to access their customers\u2019 networks. This activity is notable because targeting third parties has the potential to exploit more sensitive organizations by taking advantage of trust and access in a supply chain. Microsoft has observed multiple Iranian threat actors targeting the IT services sector in attacks that aim to steal sign-in credentials belonging to downstream customer networks to enable further attacks. The Microsoft Threat Intelligence Center (MSTIC) and Digital Security Unit (DSU) assess this is part of a broader espionage objective to compromise organizations of interest to the Iranian regime.<\/p>\n<p>Until July 2021, Microsoft had observed relatively little history of Iranian actors attacking Indian targets. As India and other nations rise as major IT services hubs, more nation state actors follow the supply chain to target these providers\u2019 public and private sector customers around the world matching nation state interests.<\/p>\n<p>To date this year, Microsoft has issued more than 1,600 notifications to over 40 IT companies in response to Iranian targeting, compared to 48 notifications in 2020, making this a significant increase from years past (Figure 1). The focus of several Iranian threat groups on the IT sector particularly spiked in the last six months \u2013 roughly 10-13% of our notifications were related to Iranian threat activity in the last six months, compared to two and a half percent in the six months prior (Figure 2). Most of the targeting is focused on IT services companies based in India, as well as several companies based in Israel and United Arab Emirates. Although different in technique from other recent supply chain attacks, these attacks represent another example of how nation state actors are increasingly targeting supply chains as indirect vectors to achieve their objectives.<\/p>\n<p><img decoding=\"async\" loading=\"lazy\" class=\"alignnone wp-image-101952\" src=\"https:\/\/www.microsoft.com\/security\/blog\/uploads\/securityprod\/2021\/11\/Fig1-notifications-sent-to-IT-services.png\" alt=\"Column chart showing number of notifications for 2019, 2020, and 2021\" width=\"700\" height=\"351\" srcset=\"https:\/\/www.microsoft.com\/security\/blog\/uploads\/securityprod\/2021\/11\/Fig1-notifications-sent-to-IT-services.png 902w, https:\/\/www.microsoft.com\/security\/blog\/uploads\/securityprod\/2021\/11\/Fig1-notifications-sent-to-IT-services-300x150.png 300w, https:\/\/www.microsoft.com\/security\/blog\/uploads\/securityprod\/2021\/11\/Fig1-notifications-sent-to-IT-services-768x385.png 768w\" sizes=\"auto, (max-width: 700px) 100vw, 700px\"><\/p>\n<p><em>Figure 1: Number of notifications sent to IT Services related to Iran-based actor targeting<\/em><\/p>\n<p><img decoding=\"async\" loading=\"lazy\" class=\"alignnone wp-image-101955\" src=\"https:\/\/www.microsoft.com\/security\/blog\/uploads\/securityprod\/2021\/11\/Fig2-percentage-notifications-sent-to-IT-services.png\" alt=\"Column chart showing percentages of notifications for 4 quarters starting Oct-Dec 2020\" width=\"700\" height=\"351\" srcset=\"https:\/\/www.microsoft.com\/security\/blog\/uploads\/securityprod\/2021\/11\/Fig2-percentage-notifications-sent-to-IT-services.png 902w, https:\/\/www.microsoft.com\/security\/blog\/uploads\/securityprod\/2021\/11\/Fig2-percentage-notifications-sent-to-IT-services-300x150.png 300w, https:\/\/www.microsoft.com\/security\/blog\/uploads\/securityprod\/2021\/11\/Fig2-percentage-notifications-sent-to-IT-services-768x385.png 768w\" sizes=\"auto, (max-width: 700px) 100vw, 700px\"><\/p>\n<p><em>Figure 2: Percentage of notifications per quarter sent to IT Services NSNs related to Iran-based activity<\/em><\/p>\n<p>As with any observed nation state actor activity, Microsoft has directly notified customers that have been targeted or compromised, providing them with the information they need to secure their accounts. Microsoft uses DEV-#### designations as a temporary name given to an unknown, emerging, or a developing cluster of threat activity, allowing MSTIC to track it as a unique set of information until we reach a high confidence about the origin or identity of the actor behind the activity. Once it meets the criteria, a DEV is converted to a named actor.<\/p>\n<h2>Observed activity<\/h2>\n<p>In July 2021, a group that MSTIC tracks as DEV-0228 and assesses as based in Iran compromised a single Israel-based IT company that provides business management software. Based on MSTIC\u2019s assessment, DEV-0228 used access to that IT company to extend their attacks and compromise downstream customers in the defense, energy, and legal sectors in Israel. In September, we detected a separate Iranian group, DEV-0056, compromising email accounts at a Bahrain-based IT integration company that works on IT integration with Bahrain Government clients, who were likely DEV-0056\u2019s ultimate target. DEV-0056 also compromised various accounts at a partially government-owned organization in the Middle East that provide information and communications technology to the defense and transportation sectors, which are targets of interest to the Iranian regime. DEV-0056 maintained persistence at the IT integration organization through at least October.<\/p>\n<p>MSTIC detected a significant increase in these and other Iranian groups targeting IT companies based in India beginning in mid-August. From mid-August to late September, we issued 1,788 nation state notifications (NSNs) across Iranian actors to enterprise customers in India, roughly 80% of which were to IT companies, an exponential rise from the 10 notifications we issued the previous three years in response to previous Iranian targeting. Iranian cyber actors have rarely targeted India, and the lack of pressing geopolitical issues that would have prompted such a shift suggests that this targeting is for indirect access to subsidiaries and clients outside India.<\/p>\n<h3>Credential theft leads to downstream compromise<\/h3>\n<p>DEV-0228 dumped credentials from the on-premises network of an IT provider based in Israel in early July. Over the next two months, the group compromised at least a dozen other organizations, several of which have strong public relations with the compromised IT company. MSTIC assesses at least four (4) of those victims were compromised using the acquired credentials and access from the IT company in the July and August attacks. Here are two such examples:<\/p>\n<ul>\n<li>DEV-0228 operators compromised the on-premises network of a law firm in Israel in August through an account managed by the IT provider via PAExec (a custom version of the Windows Sysinternals tool PsExec).<\/li>\n<\/ul>\n<p><code>Pa.exe&nbsp; \\\\###.##.#.## -u {user name}\\{domain name} -p \"********\" -s cmd.exe<\/code><\/p>\n<ul>\n<li>DEV-0228 operators also compromised a defense company in Israel by signing into an email account provisioned for the same IT provider on the victim\u2019s Office 365 tenant. The attackers likely obtained those credentials from the initial compromise of the IT provider in July.<\/li>\n<\/ul>\n<h3>Custom implant to establish persistence<\/h3>\n<p>DEV-0228 operators used a custom implant to establish persistence on victim hosts and then dumped LSASS. The implant is a custom remote access Trojan (RAT) that uses Dropbox as a command and control (C2) channel and is disguised as <em>RuntimeBroker.exe<\/em> or <em>svchost.exe<\/em>.<\/p>\n<p>Operators staged their tools in a <em>C:\\Windows\\TAPI<\/em> directory on the victim hosts:<\/p>\n<ul>\n<li>C:\\Windows\\TAPI\\lsa.exe<\/li>\n<li>C:\\Windows\\TAPI\\pa.exe<\/li>\n<li>C:\\Windows\\TAPI\\pc.exe (procdump)<\/li>\n<li>C:\\Windows\\TAPI\\Rar.exe<\/li>\n<\/ul>\n<p>Microsoft will continue to monitor DEV-0228 and DEV-0056 activity and implement protections for our customers. The current detections, advanced detections, and IOCs in place across our security products are detailed below.<\/p>\n<h2>Indicators of compromise (IOCs)<\/h2>\n<table width=\"612\">\n<tbody>\n<tr>\n<td width=\"120\">Type<\/td>\n<td width=\"492\">Indicator<\/td>\n<\/tr>\n<tr>\n<td width=\"120\">svchost.exe<\/td>\n<td width=\"492\">2a1044e9e6e87a032f80c6d9ea6ae61bbbb053c0a21b186ecb3b812b49eb03b7<\/td>\n<\/tr>\n<tr>\n<td width=\"120\">svchost.exe<\/td>\n<td width=\"492\">9ab7e99ed84f94a7b6409b87e56dc6e1143b05034a5e4455e8c555dbbcd0d2dd<\/td>\n<\/tr>\n<tr>\n<td width=\"120\">lsa.exe<\/td>\n<td width=\"492\">43109fbe8b752f7a9076eaafa417d9ae5c6e827cd5374b866672263fdebd5ec3<\/td>\n<\/tr>\n<tr>\n<td width=\"120\">wdmsvc.exe<\/td>\n<td width=\"492\">18a072ccfab239e140d8f682e2874e8ff19d94311fc8bb9564043d3e0deda54b<\/td>\n<\/tr>\n<tr>\n<td width=\"120\">Pa.exe (PAExec.exe)<\/td>\n<td width=\"492\">ab50d8d707b97712178a92bbac74ccc2a5699eb41c17aa77f713ff3e568dcedb<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h2>Recommended defenses<\/h2>\n<p>The following guidance can mitigate the techniques described in the threat activity:<\/p>\n<h2>Detections<\/h2>\n<h3>Microsoft 365 Defender<\/h3>\n<p><strong>Antivirus<\/strong><\/p>\n<p>Microsoft Defender Antivirus detects threat components as the following malware:<\/p>\n<ul>\n<li>Backdoor:MSIL\/ShellClient.A<\/li>\n<li>Backdoor:MSIL\/ShellClient.A!dll<\/li>\n<li>Trojan:MSIL\/Mimikatz.BA!MTB<\/li>\n<\/ul>\n<p><strong>Endpoint detection and response (EDR)<\/strong><\/p>\n<p>Alerts with the following titles in the security center can indicate threat activity on the network:<\/p>\n<ul>\n<li>DEV-0228 actor activity<\/li>\n<li>DEV-0056 actor activity<\/li>\n<\/ul>\n<p>The following alerts might indicate threat activity associated with this threat. These alerts, however, can be triggered by unrelated threat activity, but they are listed here for reference:<\/p>\n<ul>\n<li>Suspicious connection to remote service<\/li>\n<li>Possible command-and-control activity<\/li>\n<li>Suspicious access to LSASS service<\/li>\n<li>Sensitive credential memory read<\/li>\n<\/ul>\n<p><img decoding=\"async\" loading=\"lazy\" class=\"alignnone wp-image-101946 size-full\" src=\"https:\/\/www.microsoft.com\/security\/blog\/uploads\/securityprod\/2021\/11\/IrTargetting-M365-Blog-Screenshot-edit.png\" alt=\"Screenshot of Microsoft 365 Defender alert for Sensitive credential memory read\" width=\"1855\" height=\"1112\" srcset=\"https:\/\/www.microsoft.com\/security\/blog\/uploads\/securityprod\/2021\/11\/IrTargetting-M365-Blog-Screenshot-edit.png 1855w, https:\/\/www.microsoft.com\/security\/blog\/uploads\/securityprod\/2021\/11\/IrTargetting-M365-Blog-Screenshot-edit-300x180.png 300w, https:\/\/www.microsoft.com\/security\/blog\/uploads\/securityprod\/2021\/11\/IrTargetting-M365-Blog-Screenshot-edit-1024x614.png 1024w, https:\/\/www.microsoft.com\/security\/blog\/uploads\/securityprod\/2021\/11\/IrTargetting-M365-Blog-Screenshot-edit-768x460.png 768w, https:\/\/www.microsoft.com\/security\/blog\/uploads\/securityprod\/2021\/11\/IrTargetting-M365-Blog-Screenshot-edit-1536x921.png 1536w\" sizes=\"auto, (max-width: 1855px) 100vw, 1855px\"><\/p>\n<p><em>Figure 3: Microsoft 365 Defender alert showing credential dumping activity<\/em><\/p>\n<p>Microsoft 365 Defender correlates related alerts into consolidated <a href=\"https:\/\/docs.microsoft.com\/en-us\/microsoft-365\/security\/defender\/investigate-incidents\">incidents<\/a> to help customers determine with confidence if observed alerts are related to this activity. Customers using the Microsoft 365 Defender portal can view, investigate, and respond to incidents that include any detections related to the activity described in this blog.<\/p>\n<h2>Advanced hunting queries<\/h2>\n<h3>Microsoft Sentinel<\/h3>\n<p>The indicators of compromise (IoCs) included in this blog post can be used by Microsoft Sentinel customers for detection purposes using the queries detailed below.<\/p>\n<p><strong>Command Line Activity November 2021<\/strong><\/p>\n<p>This hunting query looks for process command line activity related to observed activity. The query uses additional data from Microsoft Defender for Endpoint to generate a risk score associated with each result. Hosts with higher risk events should be investigated first.<\/p>\n<p><a href=\"https:\/\/github.com\/azure\/azure-sentinel\/blob\/master\/Hunting%20Queries\/MultipleDataSources\/Dev-0056CommandLineActivityNovember2021.yaml\">https:\/\/github.com\/azure\/azure-sentinel\/blob\/master\/Hunting%20Queries\/MultipleDataSources\/Dev-0056CommandLineActivityNovember2021.yaml<\/a><\/p>\n<p><strong>FilePath\/Hashes query November 2021<\/strong><\/p>\n<p>This hunting query looks for file paths\/hashes related to observed activity as detailed in this blog.<\/p>\n<p><a href=\"https:\/\/github.com\/Azure\/Azure-Sentinel\/tree\/master\/Detections\/MultipleDataSources\/Dev-0228FilePathHashesNovember2021.yaml\">https:\/\/github.com\/Azure\/Azure-Sentinel\/tree\/master\/Detections\/MultipleDataSources\/Dev-0228FilePathHashesNovember2021.yaml<\/a><\/p>\n<p>In addition to these queries, there are equivalent queries that use the Advanced SIEM Information Model (ASIM) to look for the same activity.<\/p>\n<p><a href=\"https:\/\/github.com\/Azure\/Azure-Sentinel\/tree\/master\/Hunting%20Queries\/ASimProcess\/imProcess_Dev-0056CommandLineActivityNovember2021-ASIM.yaml\">https:\/\/github.com\/Azure\/Azure-Sentinel\/tree\/master\/Hunting%20Queries\/ASimProcess\/imProcess_Dev-0056CommandLineActivityNovember2021-ASIM.yaml<\/a><\/p>\n<p><a href=\"https:\/\/github.com\/Azure\/Azure-Sentinel\/tree\/master\/Detections\/ASimFileEvent\/imFileEvent_Dev-0228FilePathHashesNovember2021-ASIM.yaml\">https:\/\/github.com\/Azure\/Azure-Sentinel\/tree\/master\/Detections\/ASimFileEvent\/imFileEvent_Dev-0228FilePathHashesNovember2021-ASIM.yaml<\/a><\/p>\n<h3>Microsoft 365 Defender<\/h3>\n<p>To locate malicious activity related to the activity described in this blog, customers can run the following queries in Microsoft 365 Defender or Microsoft Defender for Endpoint.<\/p>\n<p><strong>Identify use of PAExec in your environment<\/strong><\/p>\n<p>Look for <em>PAExec.exe<\/em> process executions in your environment. <a href=\"https:\/\/security.microsoft.com\/v2\/advanced-hunting?query=H4sIAAAAAAAAA5WQvQrCQBCEpxZ8hyOVgvoGVv6AIGplKyHGJJDkJBf8AfHZ_e7UJtjIsrvD7O3OcHOluqhQQt-pkQ3IEQv4VLVasFFfPT3oV-WwDWm0ZK8EbRSrCsxUT2qkM0yqG5lo8kERE8um6ejswz3HLYvaijyBtnCFMrLmVvm31i-_NXdbDTr6M3BFxMyPWgdF_zqHcToE_s6WV_J7GdV7MPh8e3LMRsHLGOzVvj8aaUi8AIcrwsVkAQAA&amp;timeRangeId=month\">Run query<\/a><u>. <\/u><\/p>\n<p><code>DeviceProcessEvents<br \/>|&nbsp;where&nbsp;FileName&nbsp;=~&nbsp;\"paexec.exe\"&nbsp;or&nbsp;ProcessVersionInfoOriginalFileName&nbsp;=~&nbsp;\"paexec.exe\"<br \/>|&nbsp;where&nbsp;not(ProcessCommandLine&nbsp;has_any(\"program&nbsp;files\",&nbsp;\"-service\"))<\/code><\/p>\n<p><strong>Identify files created in the Windows\\Tapi directory<\/strong><\/p>\n<p>Look for files created in the Windows\\Tapi directory. <a href=\"https:\/\/security.microsoft.com\/v2\/advanced-hunting?query=H4sIAAAAAAAAA3NhSGUoY8hkSAbSbkA6B0i7AkVSGfIYShiKGRQYeBm4GGqAdDlDBlC0CIgVgCrzgSpTwPwAhkSgygygaAaQBdLhwKDE4MxgxRDDEA40MQ-oLh-ouxjID2FwBKr3BMoDAHEPI4l4AAAA&amp;timeRangeId=month\">Run query<\/a><u>. <\/u><\/p>\n<p><code>DeviceFileEvents<br \/>|&nbsp;where&nbsp;FolderPath&nbsp;has&nbsp;@\"C:\\Windows\\TAPI\"<\/code><\/p>\n<p><strong>Suspicious PowerShell commands<\/strong><\/p>\n<p>Look for suspicious PowerShell process execution. <a href=\"https:\/\/security.microsoft.com\/v2\/advanced-hunting?query=H4sIAAAAAAAAA5WQy0oDQRBFz1rwH5ohyATyQFCz18SVSCALl6JxzAQmmWQSfEA-PqdbnYW7UFTX7Vu3qrp6TMEHS-bGKQ11QjttIl-wZi8OnHPGwfhJKdvo4Z_-TrzSXqx548Ge66QqZXY8J_6bnIwhW_mhlUGvqfRG_M6IC_M9ccaj1XsGPBk71nV5dUZl359X_ek68j0uufaMeODsqFioKemnTGZ1SFPiHvlJL48z7pN-xW1iCm64Ymb_JmkXKsJv9em_UmnxV_pmajbtXnHPr_aWt_eudgT13J3gtgEAAA&amp;timeRangeId=month\">Run query. <\/a><\/p>\n<p><code>DeviceProcessEvents<br \/>| where ProcessCommandLine has_any(\"\/q \/c color f7&amp;\", \"Net.We$()bClient\", \"$b,15,$b.Length-15\") or<br \/>(ProcessCommandLine has \"FromBase64String\" and ProcessCommandLine has_all(\"-nop\", \"iex\", \"(iex\"))<\/code><\/p>\n<p> READ MORE <a href=\"https:\/\/www.microsoft.com\/security\/blog\/2021\/11\/18\/iranian-targeting-of-it-sector-on-the-rise\/\">HERE<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Microsoft has observed multiple Iranian threat actors targeting the IT services sector in attacks that aim to steal sign-in credentials belonging to downstream customer networks to enable further attacks.<br \/>\nThe post Iranian targeting of IT sector on the rise appeared first on Microsoft Security Blog. READ MORE HERE&#8230;<\/p>\n","protected":false},"author":2,"featured_media":44014,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"colormag_page_layout":"default_layout","footnotes":""},"categories":[276],"tags":[347,7221,9237,9245],"class_list":["post-44013","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-microsoft-secure","tag-cybersecurity","tag-microsoft-security-intelligence","tag-microsoft-threat-intelligence-center-mstic","tag-nation-state-actor"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.8 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Iranian targeting of IT sector on the rise 2026 | ThreatsHub Cybersecurity News<\/title>\n<meta name=\"description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.threatshub.org\/blog\/iranian-targeting-of-it-sector-on-the-rise\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Iranian targeting of IT sector on the rise 2026 | ThreatsHub Cybersecurity News\" \/>\n<meta property=\"og:description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.threatshub.org\/blog\/iranian-targeting-of-it-sector-on-the-rise\/\" \/>\n<meta property=\"og:site_name\" content=\"ThreatsHub Cybersecurity News\" \/>\n<meta property=\"article:published_time\" content=\"2021-11-18T16:00:37+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.microsoft.com\/security\/blog\/uploads\/securityprod\/2021\/11\/Fig1-notifications-sent-to-IT-services.png\" \/>\n<meta name=\"author\" content=\"TH Author\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@threatshub\" \/>\n<meta name=\"twitter:site\" content=\"@threatshub\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"TH Author\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"8 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/iranian-targeting-of-it-sector-on-the-rise\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/iranian-targeting-of-it-sector-on-the-rise\\\/\"},\"author\":{\"name\":\"TH Author\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\"},\"headline\":\"Iranian targeting of IT sector on the rise\",\"datePublished\":\"2021-11-18T16:00:37+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/iranian-targeting-of-it-sector-on-the-rise\\\/\"},\"wordCount\":1442,\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/iranian-targeting-of-it-sector-on-the-rise\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/11\\\/iranian-targeting-of-it-sector-on-the-rise.png\",\"keywords\":[\"Cybersecurity\",\"Microsoft security intelligence\",\"Microsoft Threat Intelligence Center (MSTIC)\",\"nation-state actor\"],\"articleSection\":[\"Microsoft Secure\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/iranian-targeting-of-it-sector-on-the-rise\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/iranian-targeting-of-it-sector-on-the-rise\\\/\",\"name\":\"Iranian targeting of IT sector on the rise 2026 | ThreatsHub Cybersecurity News\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/iranian-targeting-of-it-sector-on-the-rise\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/iranian-targeting-of-it-sector-on-the-rise\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/11\\\/iranian-targeting-of-it-sector-on-the-rise.png\",\"datePublished\":\"2021-11-18T16:00:37+00:00\",\"description\":\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/iranian-targeting-of-it-sector-on-the-rise\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/iranian-targeting-of-it-sector-on-the-rise\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/iranian-targeting-of-it-sector-on-the-rise\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/11\\\/iranian-targeting-of-it-sector-on-the-rise.png\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/11\\\/iranian-targeting-of-it-sector-on-the-rise.png\",\"width\":902,\"height\":452},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/iranian-targeting-of-it-sector-on-the-rise\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Cybersecurity\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/tag\\\/cybersecurity\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"Iranian targeting of IT sector on the rise\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"name\":\"ThreatsHub Cybersecurity News\",\"description\":\"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"alternateName\":\"Threatshub.org\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\",\"name\":\"ThreatsHub.org\",\"alternateName\":\"Threatshub.org\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"width\":432,\"height\":435,\"caption\":\"ThreatsHub.org\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/threatshub\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\",\"name\":\"TH Author\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"caption\":\"TH Author\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Iranian targeting of IT sector on the rise 2026 | ThreatsHub Cybersecurity News","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.threatshub.org\/blog\/iranian-targeting-of-it-sector-on-the-rise\/","og_locale":"en_US","og_type":"article","og_title":"Iranian targeting of IT sector on the rise 2026 | ThreatsHub Cybersecurity News","og_description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","og_url":"https:\/\/www.threatshub.org\/blog\/iranian-targeting-of-it-sector-on-the-rise\/","og_site_name":"ThreatsHub Cybersecurity News","article_published_time":"2021-11-18T16:00:37+00:00","og_image":[{"url":"https:\/\/www.microsoft.com\/security\/blog\/uploads\/securityprod\/2021\/11\/Fig1-notifications-sent-to-IT-services.png","type":"","width":"","height":""}],"author":"TH Author","twitter_card":"summary_large_image","twitter_creator":"@threatshub","twitter_site":"@threatshub","twitter_misc":{"Written by":"TH Author","Est. reading time":"8 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.threatshub.org\/blog\/iranian-targeting-of-it-sector-on-the-rise\/#article","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/iranian-targeting-of-it-sector-on-the-rise\/"},"author":{"name":"TH Author","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476"},"headline":"Iranian targeting of IT sector on the rise","datePublished":"2021-11-18T16:00:37+00:00","mainEntityOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/iranian-targeting-of-it-sector-on-the-rise\/"},"wordCount":1442,"publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/iranian-targeting-of-it-sector-on-the-rise\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2021\/11\/iranian-targeting-of-it-sector-on-the-rise.png","keywords":["Cybersecurity","Microsoft security intelligence","Microsoft Threat Intelligence Center (MSTIC)","nation-state actor"],"articleSection":["Microsoft Secure"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.threatshub.org\/blog\/iranian-targeting-of-it-sector-on-the-rise\/","url":"https:\/\/www.threatshub.org\/blog\/iranian-targeting-of-it-sector-on-the-rise\/","name":"Iranian targeting of IT sector on the rise 2026 | ThreatsHub Cybersecurity News","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/iranian-targeting-of-it-sector-on-the-rise\/#primaryimage"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/iranian-targeting-of-it-sector-on-the-rise\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2021\/11\/iranian-targeting-of-it-sector-on-the-rise.png","datePublished":"2021-11-18T16:00:37+00:00","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","breadcrumb":{"@id":"https:\/\/www.threatshub.org\/blog\/iranian-targeting-of-it-sector-on-the-rise\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.threatshub.org\/blog\/iranian-targeting-of-it-sector-on-the-rise\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/iranian-targeting-of-it-sector-on-the-rise\/#primaryimage","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2021\/11\/iranian-targeting-of-it-sector-on-the-rise.png","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2021\/11\/iranian-targeting-of-it-sector-on-the-rise.png","width":902,"height":452},{"@type":"BreadcrumbList","@id":"https:\/\/www.threatshub.org\/blog\/iranian-targeting-of-it-sector-on-the-rise\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.threatshub.org\/blog\/"},{"@type":"ListItem","position":2,"name":"Cybersecurity","item":"https:\/\/www.threatshub.org\/blog\/tag\/cybersecurity\/"},{"@type":"ListItem","position":3,"name":"Iranian targeting of IT sector on the rise"}]},{"@type":"WebSite","@id":"https:\/\/www.threatshub.org\/blog\/#website","url":"https:\/\/www.threatshub.org\/blog\/","name":"ThreatsHub Cybersecurity News","description":"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform","publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"alternateName":"Threatshub.org","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.threatshub.org\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.threatshub.org\/blog\/#organization","name":"ThreatsHub.org","alternateName":"Threatshub.org","url":"https:\/\/www.threatshub.org\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","width":432,"height":435,"caption":"ThreatsHub.org"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/threatshub"]},{"@type":"Person","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476","name":"TH Author","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","caption":"TH Author"}}]}},"_links":{"self":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/44013","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/comments?post=44013"}],"version-history":[{"count":0,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/44013\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media\/44014"}],"wp:attachment":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media?parent=44013"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/categories?post=44013"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/tags?post=44013"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}