The Containment Era is here. →Explore

Executive Summary

In late 2024, security authorities announced a $10 million reward for information regarding the whereabouts of Mohammad Bagher Shirinkar and Fatemeh Sedighian Kashi, key leaders of Shahid Shushtari — a cyber unit operating under Iran’s Islamic Revolutionary Guard Corps Cyber-Electronic Command. Known by threat intelligence analysts as UNC5866, Cotton Sandstorm, and Haywire Kitten, the group targets critical infrastructure sectors, including news, shipping, travel, energy, financial services, and telecom across the U.S., Europe, and the Middle East. Their operations span spear-phishing, malware campaign delivery, and cyberespionage, with significant disruptions and financial damages reported. Notably, the group attempted to influence the 2020 U.S. presidential election and continues its multi-pronged attacks using evolving techniques and new tradecraft.

This incident underscores the persistent and evolving threat posed by nation-state actors targeting both public and private institutions globally. Increased vigilance, timely intelligence sharing, and robust controls around east-west network traffic and encrypted communications are now critical countermeasures as similar attacks escalate.

Why This Matters Now

Iranian nation-state cyber units like Shahid Shushtari are rapidly adapting new tradecraft, directly impacting global critical infrastructure and democratic processes. With an active pace of sophisticated campaigns and the demonstrated ability to bypass traditional defenses, timely situational awareness and enhanced segmentation are urgent for defenders facing similar threats.

Attack Path Analysis

Related CVEs

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

The breach exposed insufficient east-west traffic controls, lack of zero trust segmentation, and limited anomaly-based detection, revealing widespread vulnerabilities in critical infrastructure sectors.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Comprehensive Zero Trust segmentation, cloud-native east-west controls, and egress enforcement could have significantly mitigated adversary movement, limited scope of compromise, and detected exfiltration attempts at multiple points in the attack chain. Cloud Network Security Framework (CNSF) controls, as validated, address lateral movement, data-in-transit protection, policy centralization, real-time threat detection, and cloud perimeter hardening.

Initial Compromise

Control: Cloud Firewall (ACF)

Mitigation: Blocked malicious inbound traffic, thwarting unauthorized external access.

Privilege Escalation

Control: Zero Trust Segmentation

Mitigation: Limited blast radius by restricting unused paths and enforcing least privilege between workloads.

Lateral Movement

Control: East-West Traffic Security

Mitigation: Blocked unauthorized east-west movement between workloads and environments.

Command & Control

Control: Egress Security & Policy Enforcement

Mitigation: Detected and controlled suspicious outbound traffic, disrupting C2 connectivity.

Exfiltration

Control: Encrypted Traffic (HPE) & Inline IPS (Suricata)

Mitigation: Detected, inspected, and blocked data exfiltration attempts in line.

Impact (Mitigations)

Rapid anomaly detection and centralized policy could accelerate response and minimize operational impact.

Impact at a Glance

Affected Business Functions

  • Media Publishing
  • Subscriber Management
Operational Disruption

Estimated downtime: 7 days

Financial Impact

Estimated loss: $500,000

Data Exposure

Personal information of approximately 200,000 subscribers was exposed, including names, email addresses, and subscription details.

Recommended Actions

  • Enforce Zero Trust segmentation with microsegmentation to restrict workload and user access across cloud, regions, and environments.
  • Mandate cloud-native east-west traffic security to detect and prevent lateral movement within cloud networks.
  • Deploy egress policy enforcement and encrypted traffic inspection to control data flows and quickly identify suspicious outbound activity.
  • Leverage continuous anomaly detection and centralized multicloud visibility for rapid detection and incident response to threats.
  • Regularly review cloud IAM permissions and cloud firewall policies to ensure least privilege and reduce exposure from misconfiguration.

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image