Key Takeaways

  • Lemon Sandstorm breaches internet-facing systems and sells or shares privileged access with ransomware affiliates.
  • Healthcare, education, finance, defense and local government networks remain prominent targets.
  • The campaign reflects a broader convergence of Iranian state interests, cyber espionage and financially motivated extortion.

U.S. cybersecurity and intelligence agencies have detailed how Lemon Sandstorm, an Iran-linked state-sponsored threat actor, obtains access to victim networks and works with ransomware affiliates to monetize those intrusions. The group is also tracked as Pioneer Kitten, Fox Kitten, Parisite, UNC757 and formerly Rubidium.

The Cybersecurity and Infrastructure Security Agency, the Federal Bureau of Investigation and the Department of Defense Cyber Crime Center assessed the activity as consistent with an Iranian state-sponsored operation rather than an independent cybercrime gang. Danesh Novin Sahand, an Iranian information technology company, is likely used as a cover for the activity, according to the agencies.

Lemon Sandstorm’s model is notable because it blurs the traditional boundary between government-backed intrusion campaigns and commercial ransomware. Instead of relying solely on its own file-encrypting payload, Lemon Sandstorm obtains and maintains access, secures domain administrator credentials and then collaborates with affiliates associated with NoEscape, RansomHouse and BlackCat, also known as ALPHV. The Iranian actors receive a share of the proceeds.

That relationship goes beyond a simple handoff. U.S. agencies said the actors work with ransomware affiliates to lock networks and develop extortion strategies. Lemon Sandstorm has also offered full domain control and administrator credentials through underground marketplaces, creating more than one route for converting compromised infrastructure into revenue.

While an initial-access broker may not appear in a ransom note, their activity determines whether an intrusion becomes a business-wide outage. Once administrative privileges are compromised, ransomware affiliates can move laterally, disable defenses, steal information and disrupt recovery systems. Who deployed the final payload matters less to an affected hospital if clinical services and billing systems are unavailable.

Healthcare exposure is particularly concerning. The Sophos State of Ransomware in Healthcare 2024 found that 67% of healthcare organizations were hit by ransomware in 2024, nearly double the 34% recorded in 2021. Iranian threat actors were also identified as the most active actors targeting healthcare organizations during 2024. Lemon Sandstorm’s access-broker role gives ransomware groups another path into institutions already facing staffing, technology and recovery constraints.

The February 2024 Change Healthcare incident illustrates the potential scale, even though it should not be treated as evidence that Lemon Sandstorm enabled that specific intrusion. The attack was tied to BlackCat/ALPHV, one of the ransomware ecosystems named in connection with Lemon Sandstorm’s broader affiliate activity. Approximately 190 million to 192.7 million individuals were affected, while UnitedHealth estimated total costs at $3.09 billion.

Figures from the HHS Office for Civil Rights and subsequent healthcare-sector analyses recorded between 742 and 772 large breaches during 2024, affecting roughly 140 million to 243 million people (source). Differences between totals reflect reporting dates and later revisions, but the direction is clear: healthcare networks offer a large and costly attack surface.

Technically, Lemon Sandstorm often starts with vulnerable remote services exposed to the internet. Exploited flaws include CVE-2019-19781, CVE-2022-1388, CVE-2023-3519, CVE-2024-3400 and CVE-2024-24919. After entry, the actors establish persistence, elevate privileges and deploy remote-access capabilities such as AnyDesk or the open-source Ligolo tunneling tool. Legitimate administration software can complicate detection because some enterprises already permit it for support work.

The operation stretches back to at least 2017. Check Point and ClearSky connected Pioneer Kitten to the Pay2Key hack-and-leak campaign against Israeli businesses in 2020, while leaked documents later linked some activity to Emennet Pasargad. For security leaders, the practical response is to prioritize exposed-edge patching, restrict remote management software, monitor new administrator privileges and plan for incidents in which a state-linked foothold is ultimately monetized by a separate ransomware crew.