- Also known as: Pioneer Kitten, Fox Kitten, UNC757, Parisite, RUBIDIUM, Br0k3r, "xplfinder"
- First observed: 2017
- Believed origin: Iran
- Model: Initial access broker
- Status: Active as of the most recent joint federal advisories (2024–2025)
Origin
Lemon Sandstorm is a threat actor the U.S. government assesses to be linked to the government of Iran, meaning its activity is both espionage and profit-driven cybercrime.
A joint advisory from the FBI, CISA, and the Department of Defense Cyber Crime Center, issued in August 2024, stated, “This group is known in the private sector by the names Pioneer Kitten, Fox Kitten, UNC757, Parisite, RUBIDIUM, and Lemon Sandstorm - the actors also refer to themselves by the moniker Br0k3r, and as of 2024, have been operating under the moniker "xplfinder" in their channels.” Crucially, the agencies did not describe this as a criminal gang acting independently, they stated that, “FBI analysis and investigation indicate the group's activity is consistent with a cyber actor with Iranian state-sponsorship.”
Microsoft's threat intelligence division, in a report on ransomware risk to the U.S. healthcare sector, singled out this group's unusual prominence in 2024's threats, stating that “Iranian threat actors appear to be the most active in targeting healthcare organizations in 2024, and in August 2024, the U.S. government issued a warning to the health sector about an Iran-based threat actor known as Lemon Sandstorm.”
The business model
What makes Lemon Sandstorm different from the other groups is its role in the ransomware supply chain. Rather than deploying its own ransomware payload and negotiating directly with victims, the group specializes in gaining and maintaining unauthorized access to networks, then monetizing that access by handing it off to financially motivated ransomware affiliates, who carry out the actual extortion.
The joint federal advisory described the mechanics in detail, noting that, “The FBI previously observed these actors attempt to monetize their access to victim organizations on cyber marketplaces, with a significant percentage of the group's US-focused cyber activity in furtherance of obtaining and maintaining technical access to victim networks to enable future ransomware attacks. The actors offer full domain control privileges, as well as domain admin credentials, to numerous networks.”
TechTarget's healthcare-security coverage of the same advisory made the downstream consequence clear, “The authoring entities stated that a "significant percentage" of the threat actors' operations against U.S. organizations are intended to develop network access and later collaborate with affiliate actors to deploy ransomware.” That same coverage placed Lemon Sandstorm within a longer operational history than most ransomware crews can claim, “The FBI has been tracking these Iranian cyberthreat actors since their first intrusion attempts against U.S. organizations in 2017, all the way to exploits as recent as August 2024.”
Access techniques
Lemon Sandstorm's initial access methods include exploiting known, often unpatched, vulnerabilities in the network appliances that healthcare organizations rely on for remote access rather than the phishing emails or malicious downloads more commonly associated with financially motivated ransomware affiliates. For instance, the August 2024 joint advisory documented the group scanning for and exploiting internet-facing Check Point Security Gateway devices vulnerable to CVE-2024-24919, a Palo Alto Networks PAN-OS command-injection flaw (CVE-2024-3400), two separate Citrix NetScaler vulnerabilities (CVE-2019-19781 and CVE-2023-3519), and an F5 BIG-IP iControl REST vulnerability (CVE-2022-1388). All of these flaws were perimeter remote-access appliances rather than issues introduced through phishing or drive-by downloads.
TechTarget's coverage of the advisory detailed the group's preferred entry points, noting, “The threat actors often obtain initial access by exploiting a public-facing networking device, such as a Citrix NetScaler.” The focus on internet-facing infrastructure is consistent with the group's documented history, the same coverage noted that, “The latest advisory highlighted similar threat actor activity from a September 2020 joint advisory that focused on Iran-backed hackers such as Pioneer Kitten and UNC757 exploiting known vulnerabilities in VPN connections.”
A separate, follow-up October 2024 advisory explained another technique used by the group, brute-forcing credentials rather than exploiting software flaws. TechTarget's coverage of that advisory explained that “the October 2024 advisory specifically focused on Iranian cyberthreat actors using brute force, such as multifactor authentication "push bombing" to overwhelm users and compromise accounts, as well as password spraying, where a hacker uses one password to attempt to break into other accounts.” That same report confirmed the group's sectoral focus, noting, “The agencies had observed these groups exploiting organizations in the education, healthcare, defense, and finance sectors.”
A geopolitical wildcard
Unlike financially motivated ransomware groups, Lemon Sandstorm's activity appears tied at least partly to Iran's geopolitical posture, meaning its threat level can spike with regional conflict rather than purely criminal opportunism. BankInfoSecurity's coverage of a mid-2025 HHS advisory reported that “U.S. federal authorities warned of increased risk of Iranian cyber and related threats against healthcare and public health sector organizations, including ransomware, distributed denial-of-service, and other attacks, related to that nation's escalated conflicts with Israel and the United States.”
HHS's Administration for Strategic Preparedness and Response, quoted in the same report, was careful to note the absence of confirmed specific targeting while still urging heightened vigilance, "While there is no current evidence of specific targeting against healthcare and public health sector organizations, we know that the sector has historically been the victim of cyberattacks from a wide range of cyber threat actors during periods of conflict... Iranian government-affiliated cyberthreat actors, in particular, have been known to utilize brute force methods, such as password spraying and multi-factor authentication 'push bombing,' to compromise networks and obtain credentials."
DOJ action against the group
Despite years of joint federal advisories naming and detailing this group's tactics, no DOJ indictment, press release, or FBI Most Wanted listing has publicly named a specific individual as a confirmed member of Lemon Sandstorm, Pioneer Kitten, Fox Kitten, or any of its aliases. The FBI and CISA have pointed to an Iranian IT firm, "Danesh Novin Sahand," as a likely corporate cover the group operates behind to enable operations.
Meanwhile, DOJ has brought several indictments against Iranian nationals for tactically similar hacking campaigns, most notably a September 2022 New Jersey indictment charging Mansour Ahmadi, Ahmad Khatibi Aghda, and Amir Hossein Nickaean Ravari with exploiting known vulnerabilities in network devices and carrying out encryption-based extortion against hundreds of U.S. and international victims, and a September 2020 indictment of Behzad Mohammadzadeh and Marwan Abusrour for website defacements tied to Iranian government interests but neither of these charging documents identifies the defendants as members of Lemon Sandstorm or its aliases. In short, the public record shows sustained advisory-level attribution of this activity to Iran and its state apparatus, alongside a pattern of DOJ prosecutions against Iranian hackers using comparable methods, but no official body connects a specific named defendant to this particular group.
Read also: Why ransomware attacks are so successful in healthcare
FAQs
What is an initial access broker?
An initial access broker is a hacker who specializes in breaking into networks and then sells or hands off that access to other criminals, rather than carrying out the final attack themselves.
How is a "state-sponsored" hacking group different from an ordinary cybercriminal gang?
A state-sponsored group operates with the backing, direction, or tacit approval of a national government, combining espionage goals with criminal activity, whereas an ordinary gang is purely profit-driven and independent of any government.
What does CVE mean in the context of a vulnerability?
CVE stands for "Common Vulnerabilities and Exposures," a standardized public identifier assigned to a specific, documented software or hardware security flaw.
Can regional political conflicts affect the intensity of cyberattacks from state-linked groups?
Yes, threat activity from state-affiliated actors can rise during periods of geopolitical tension, since some of these groups' operations serve national interests as well as financial ones.
