---
title: Iranian APTs Exploit Microsoft Exchange, Fortinet Vulnerabilities
description: CISA releases a joint advisory statement for organizations to be wary of Microsoft and Fortinet vulnerabilities leveraged by Iran-backed cybercriminals.
---

[SecureWorld News ](https://www.secureworld.io/industry-news)

# [Iranian APTs Exploit Microsoft Exchange, Fortinet Vulnerabilities](https://www.secureworld.io/industry-news/iranian-threat-actors)

 Written by [SecureWorld News Team](https://www.secureworld.io/industry-news/author/secureworld-news-team) | Wed | Nov 17, 2021 | 7:35 PM Z

Nation-state hackers with ties to Iran have been exploiting vulnerabilities in Microsoft Exchange, known as ProxyShell, and also Fortinet to break into systems.

The vulnerabilities, which have been spotted as early as March 2021, have allowed the APTs to infect systems with ransomware and more. Also, these attacks have targeted countries around the world.  

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) released a joint statement with the Federal Bureau of Investigation (FBI), Australian Cyber Security Centre (ACSC), and United Kingdom's National Cyber Security Centre (NCSC) in regards to bringing attention to malicious hacking activity.

"The Iranian government-sponsored APT actors are actively targeting a broad range of victims across multiple U.S. critical infrastructure sectors, including the Transportation Sector and the Healthcare and Public Health Sector, as well as Australian organizations. FBI, CISA, ACSC, and NCSC assess the actors are focused on exploiting known vulnerabilities rather than targeting specific sectors. These Iranian government-sponsored APT actors can leverage this access for follow-on operations, such as data exfiltration or encryption, ransomware, and extortion."

## **Iran-backed malicious hacking activity**

CISA reports that the cyberattacks have hit a wide range of industries, including critical infrastructure. 

A few observations of the activity, as told in CISA's statement, include the following: 

- In March 2021, the FBI and CISA observed these Iranian government-sponsored APT actors scanning devices on ports 4443, 8443, and 10443 for Fortinet FortiOS vulnerability [CVE-2018-13379](http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-13379), and enumerating devices for FortiOS vulnerabilities [CVE-2020-12812](http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-12812) and [CVE-2019-5591](http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-5591). The Iranian Government-sponsored APT actors likely exploited these vulnerabilities to gain access to vulnerable networks. Note: for previous FBI and CISA reporting on this activity, refer to Joint Cybersecurity Advisory: [APT Actors Exploit Vulnerabilities to Gain Initial Access for Future Attacks](https://www.ic3.gov/media/news/2021/210402.pdf).
- In May 2021, these Iranian government-sponsored APT actors exploited a Fortigate appliance to access a webserver hosting the domain for a U.S. municipal government. The actors likely created an account with the username `elie` to further enable malicious activity. Note: for previous FBI reporting on this activity, refer to [FBI FLASH: APT Actors Exploiting Fortinet Vulnerabilities to Gain Initial Access for Malicious Activity](https://www.ic3.gov/media/news/2021/210527.pdf).
- In June 2021, these APT actors exploited a Fortigate appliance to access environmental control networks associated with a U.S.-based hospital specializing in healthcare for children. The Iranian government-sponsored APT actors likely leveraged a server assigned to IP addresses `91.214.124[.]143` and `162.55.137[.]20`—which FBI and CISA judge are associated with Iranian government cyber activity—to further enable malicious activity against the hospital’s network. The APT actors accessed known user accounts at the hospital from IP address `154.16.192[.]70`, which FBI and CISA judge is associated with government of Iran offensive cyber activity.
- As of October 2021, these APT actors have leveraged a Microsoft Exchange ProxyShell vulnerability—`CVE-2021-34473`—to gain initial access to systems in advance of follow-on operations.

For a thorough look at the technical details and mitigation tactics, visit the website at [us-cert.cisa.gov/ncas/alerts/aa21-321a](https://us-cert.cisa.gov/ncas/alerts/aa21-321a).

**Resources **

With 2022 just around the corner, have you planned ahead yet for how your organization can prepare to mitigate risks in the New Year? Join SecureWorld for its last event of 2021 on December 2nd, the [West Coast virtual conference](https://events.secureworld.io/details/west-coast-2021/). 

[RELATED: [The FBI's Most Wanted Iranian Nation-State Hackers](https://www.secureworld.io/industry-news/fbi-most-wanted-hackers-iran)] 

[View full post](https://www.secureworld.io/industry-news/iranian-threat-actors)

```json
{
  "@context" : "http://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "SecureWorld News Team"
  },
  "dateModified" : "2021-11-17T20:33:12.471Z",
  "datePublished" : "2021-11-17T19:35:46Z",
  "headline" : "Iranian APTs Exploit Microsoft Exchange, Fortinet Vulnerabilities",
  "image" : {
    "@type" : "ImageObject",
    "height" : 282,
    "url" : "https://info.secureworld.io/hubfs/Blog_images/Iran_cyber_attack_shutterstock_1329004469.jpg",
    "width" : 500
  },
  "mainEntityOfPage" : "https://www.secureworld.io/industry-news/iranian-threat-actors",
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "height" : 60.0,
      "url" : "https://cdn2.hubspot.net/hubfs/2221756/Logos/SWE/SWE_logo_full-long_forWHITEbackgrounds.jpg",
      "width" : 304.46954
    },
    "name" : "SecureWorld News"
  }
}
```