IRIDIUM is a nation-state group conducting long-term cyberespionage against diplomatic and military networks in Five Eyes countries.
Analyst brief
IRIDIUM is a nation-state threat actor conducting a multi-year cyberespionage campaign targeting sensitive government, diplomatic, and military resources in Five Eyes countries (Australia, Canada, New Zealand, the United Kingdom, and the United States). This actor is focused on compromising high-value state assets, with attacks on parliamentary bodies being a key component of their operations. Defenders should prioritize monitoring for long-term, targeted intelligence-gathering activities directed at diplomatic and military networks.
IRIDIUM
unknown
Resecurity’s research indicates that the attack on Parliament is a part of a multi-year cyberespionage campaign orchestrated by a nation-state actor whom we are calling IRIDIUM. This actor targets sensitive government, diplomatic, and military resources in the countries comprising the Five Eyes intelligence alliance (which includes Australia, Canada, New Zealand, the United Kingdom and the United States)
Which countries' institutions does the IRIDIUM threat actor target?+
IRIDIUM targets government, diplomatic, and military institutions in the countries of the Five Eyes intelligence alliance (Australia, Canada, New Zealand, the United Kingdom, and the United States).
What should defenders focus on against IRIDIUM's activities?+
Defenders should prioritize monitoring for anomalies in diplomatic and military networks and remain vigilant against long-term, targeted intelligence-gathering activities aimed at high-value state assets.