• Skip to primary navigation
  • Skip to main content
  • Skip to primary sidebar
  • Skip to footer

My TechDecisions

  • Best of Tech Decisions
  • Topics
    • Video
    • Audio
    • Mobility
    • Unified Communications
    • IT Infrastructure
    • Network Security
    • Physical Security
    • Facility
    • Compliance
  • RFP Resources
  • Resources
  • Podcasts
  • Project of the Week
  • About Us
    SEARCH
IT Infrastructure, Network Security, News

Report: Iranian Hacking Group Exploiting VPN Vulnerabilities

Cybersecurity experts say a hacking group suspected to be an Iranian state-sponsored entity is selling access to compromised corporate networks.

September 3, 2020 Zachary Comeau Leave a Comment

Cybersecurity Risk

Cybersecurity experts say a hacking group suspected to be an Iranian state-sponsored entity is selling access to compromised organization networks.

The group, code named Pioneer Kitten, has been active since at least 2017 and is focused on gaining and maintaining access to entities possessing sensitive information of likely intelligence interest to the Iranian government,” cybersecurity firm CrowdStrike wrote in a blog.

Pioneer Kitten, which also goes by PARISITE, UNC757 and Fox Kitten, relies on exploits of remote external services on internet-facing assets and open-source tooling to get initial access to victims, according to CrowdStrike.

The adversary is particularly interested in exploits related to VPNs and network appliances, including CVE-2019-11510, CVE-2019-19781, and most recently CVE-2020-5902; reliance on exploits such as these lends to an opportunistic operational model. 

PIONEER KITTEN’s namesake operational characteristic is its reliance on SSH tunneling, through open-source tools such as Ngrok and the adversary’s custom tool SSHMinion, for communication with implants and hands-on-keyboard activity via Remote Desktop Protocol (RDP).

Read Next: NYT Publishes Inside Account of Massive Twitter Hack

In July, an individual associated with the group was observed trying to sell access to compromised networks on an underground internet forum. Information from the victims’ networks would be of “significant intelligence value” to Iran’s government, CrowdStrike reports.

However, CrowdStrike doesn’t believe Iran sanctioned the activity, since the commercial sale of the access would have negative impacts on intelligence collection.

Targets included organizations in North America and Israel, including technology, government, defense, healthcare, aviation, media, academic, engineering, consulting, professional services, chemical, manufacturing, financial services, insurance and retail.

However, the areas of most interest are technology, government, defense and healthcare. The group could be casting a wide net in a move to diversify its revenue stream, CrowdStrike says.

ZDNet reports that other cybersecurity firms have observed the group breaching network devices using the same vulnerabilities, planting backdoors and providing access to other hacking groups.

If you enjoyed this article and want to receive more valuable industry content like this, click here to sign up for our digital newsletters!

Tagged With: Cybersecurity

Related Content:

  • Cloud, SASE, Aryaka How the Cloud is Redefining Media Production and…
  • Singlewire Software mass notification interview Singlewire Software on Mass Notification Solutions
  • URI catchbox 1 Catchbox Plus: The Mic Solution That Finally Gave…
  • Engaging virtual meeting with diverse participants discussing creative ideas in a bright office space during daylight hours Diversified Survey: Workplace AV Tech is Falling Short,…

Free downloadable guide you may like:

  • Practical Design Guide for Office SpacesPractical Design Guide for Office Spaces

    Recent Gartner research shows that workers prefer to return to the office for in-person meetings for relevant milestones, as well as for face-to-face time with co-workers. When designing the office spaces — and meeting spaces in particular — enabling that connection between co-workers is crucial. But introducing the right collaboration technology in meeting spaces can […]

Reader Interactions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Latest Downloads

Practical Design Guide for Office Spaces
Practical Design Guide for Office Spaces

Recent Gartner research shows that workers prefer to return to the office for in-person meetings for relevant milestones, as well as for face-to-fa...

New Camera Can Transform Your Live Production Workflow
New Camera System Can Transform Your Live Production Workflow

Sony's HXC-FZ90 studio camera system combines flexibility and exceptional image quality with entry-level pricing.

Creating Great User Experience and Ultimate Flexibility with Clickshare

Working and collaborating in any office environment today should be meaningful, as workers today go to office for very specific reasons. When desig...

View All Downloads

Would you like your latest project featured on TechDecisions as Project of the Week?

Apply Today!

More from Our Sister Publications

Get the latest news about AV integrators and Security installers from our sister publications:

Commercial IntegratorSecurity Sales

AV-iQ

Footer

TechDecisions

  • Home
  • Welcome to TechDecisions
  • Contact Us
  • Comment Guidelines
  • RSS Feeds
  • Twitter
  • Facebook
  • Linkedin

Free Technology Guides

FREE Downloadable resources from TechDecisions provide timely insight into the issues that IT, A/V, and Security end-users, managers, and decision makers are facing in commercial, corporate, education, institutional, and other vertical markets

View all Guides
TD Project of the Week

Get your latest project featured on TechDecisions Project of the Week. Submit your work once and it will be eligible for all upcoming weeks.

Enter Today!
Emerald Logo
ABOUTCAREERSAUTHORIZED SERVICE PROVIDERSYour Privacy ChoicesTERMS OF USEPRIVACY POLICY

© 2025 Emerald X, LLC. All rights reserved.