Site navigation

Sharp Rise in Brute-Force Cyber-Attacks from Middle East

Tom Quinn

,

Iran brute force
Findings suggest Western firms and CNI operators remain prime targets for renewed hostility.

Security researchers at Barracuda have identified an 88% spike in brute-force attacks targeting SonicWall and FortiGate devices originating from the Middle East, accounting for over half of all incidents seen by the SOC over February and March.

While most attempts were unsuccessful, either blocked outright or aimed at invalid usernames, Barracuda warned that the attackers are on an aggressive campaign of scanning and testing perimeter devices, significantly raising the risk of compromise. 

Though there is no direct evidence linking these cyber-attacks to any specific state, and they may simply have been routed through servers in the region, the uptick coincides with the conflict between the US, Israel, and Iran, which has already fuelled anxiety over cyber threats.

Last month, researchers from Sophos warned that Iranian‑linked groups have stepped up their use of social engineering tactics like spearphishing, along with large-scale password-spraying campaigns and the exploitation of weak credentials to target IT and OT environments.

As with Barracuda’s analysis, Sophos found an uptick in attacks directed at newly disclosed or unpatched vulnerabilities in public-facing applications, including in Fortinet FortiOS and Microsoft Exchange ProxyShell. 

Added to that, analysts at Palo Alto Networks’ Unit 42 reported an increased risk of wiper attacks targeting both enterprise and consumer sectors, which, unlike ransomware, are designed to permanently delete or destroy data. 


Recommended reading


Coupled with Barracuda’s threat brief, this suggests that, despite a fragile ceasefire now in place, weeks of intense conflict have left the digital landscape highly volatile, with Western firms and CNI organisations among the most likely targets for renewed hostility.

Last week, the US security services issued a joint advisory warning that Iran-backed threat actors had targeted internet-facing OT devices across critical infrastructure, including water utilities and energy networks.

That followed news last month that US medtech Stryker had suffered a “global network disruption” to its Microsoft environment after a cyberattack claimed by Iran-linked hacking groups in apparent retaliation for a strike on an Iranian school.

Tom Quinn

Staff Writer, DIGIT

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data