Investigation Details Intrusion Targeting 12 Omani Government Entities, With 26,000 Records Extracted

· Original article ↗

Summary

An exposed server revealed tooling and logs from an intrusion targeting Omani government entities. Evidence shows access to the Ministry of Justice and Legal Affairs and extraction of more than 26,000 user records, judicial data, and registry hives.

Key points

  • An open directory on a VPS exposed campaign files, C2 code, session logs, and stolen data.
  • Recovered scripts mapped activity against 12 Omani government entities; confirmed C2 sessions and data extraction centered on the Ministry of Justice and Legal Affairs.
  • A webshell provided command execution. DNN vulnerability scripts suggest CVE-2025-32372 as a possible access route, but the report says this is unconfirmed.
  • The operator extracted 26,596 DNN user records, judicial and committee data, and Windows SAM and SYSTEM registry hives.
  • The toolkit included Python C2 servers, a PowerShell beacon, Chisel tunneling, and GodPotato privilege escalation; Defender blocked an attempted scheduled-task persistence method.
  • Logs show operator sessions on April 10, 2026. Tooling and targeting overlap with Iranian-nexus groups, but the researchers did not attribute the campaign to a specific group.

Article Details

Attack Vectors
  • Password brute-force attempts targeted government portals; recovered tooling also included Exchange password spraying and MSSQL brute-forcing.
  • ProxyShell exploit scripts targeted two government mail servers that appeared vulnerable. The recovered files did not establish successful exploitation.
  • Scripts targeting a DotNetNuke SSRF vulnerability suggest a possible initial-access path, but the article could not confirm it.
  • A deployed ASPX webshell provided command execution inside the Ministry of Justice and Legal Affairs network.
  • Recovered scripts covered SQL injection, database extraction, Oracle APEX/ORDS attacks, Citrix exploitation, portal enumeration, authentication reconnaissance, and national ID IDOR vulnerabilities.
  • Post-compromise tooling supported privilege escalation, reflective payload execution, credential extraction, HTTP command-and-control, tunneling, and data exfiltration.
Defensive Notes
  • Defender blocked creation of a persistence task named MicrosoftEdgeUpdate; the operator did not retry that task.
  • A separate recovered script attempted to forcibly disable antivirus, but the article did not establish that it succeeded.
  • An earlier privilege-escalation execution approach was reportedly flagged, after which a subsequent script adopted reflective in-memory loading.
  • The exposed C2 server logged all inbound POST requests, including scanner and opportunistic exploitation traffic; those requests should not automatically be treated as victim beacon activity.
  • The article did not confirm a connection between every neighboring infrastructure indicator and the government intrusion, and did not attribute the operation to a specific named group.

Indicators of compromise

TypeIndicatorContext
DOMAINbrnettlix[.]comDomain listed in the surrounding infrastructure IOC cluster at 172.86.76[.]124; intrusion linkage is unconfirmed.
DOMAINbrttfrixx[.]comDomain listed in the surrounding infrastructure IOC cluster at 172.86.76[.]124; intrusion linkage is unconfirmed.
DOMAINidentificara[.]comDomain listed in the surrounding infrastructure IOC cluster at 172.86.76[.]124; intrusion linkage is unconfirmed.
DOMAINrealprimefix[.]comDomain listed in the surrounding infrastructure IOC cluster at 172.86.76[.]124; intrusion linkage is unconfirmed.
DOMAINregorixa[.]comDomain listed in the neighboring infrastructure IOC cluster associated with a supposed USDT investment platform; intrusion linkage is unconfirmed.
DOMAINsuanefllix[.]comDomain listed in the surrounding infrastructure IOC cluster at 172.86.76[.]124; intrusion linkage is unconfirmed.
DOMAINvaermb[.]comInfrastructure domain containing the C2 hostname and neighboring dubai-# hosts; links between all neighboring hosts and the intrusion remain unconfirmed.
HOSTNAMEdubai-1[.]vaermb[.]comHostname listed in the neighboring infrastructure IOC cluster, resolving to 172.86.76[.]101; intrusion linkage is unconfirmed.
HOSTNAMEdubai-10[.]vaermb[.]comDomain resolving to the exposed staging and C2 server at 172.86.76[.]127.
HOSTNAMEdubai-2[.]vaermb[.]comHostname listed in the neighboring infrastructure IOC cluster, resolving to 172.86.76[.]94; intrusion linkage is unconfirmed.
HOSTNAMEdubai-3[.]vaermb[.]comHostname listed in the neighboring infrastructure IOC cluster, resolving to 172.86.76[.]108; intrusion linkage is unconfirmed.
HOSTNAMEdubai-4[.]vaermb[.]comHostname listed in the neighboring infrastructure IOC cluster, resolving to 172.86.76[.]112; intrusion linkage is unconfirmed.
HOSTNAMEdubai-5[.]vaermb[.]comHostname listed in the neighboring infrastructure IOC cluster, resolving to 172.86.76[.]120; intrusion linkage is unconfirmed.
HOSTNAMEdubai-6[.]vaermb[.]comHostname listed in the neighboring infrastructure IOC cluster, resolving to 172.86.76[.]121; intrusion linkage is unconfirmed.
HOSTNAMEdubai-7[.]vaermb[.]comHostname listed in the neighboring infrastructure IOC cluster, resolving to 172.86.76[.]124; intrusion linkage is unconfirmed.
HOSTNAMEdubai-8[.]vaermb[.]comHostname listed in the neighboring infrastructure IOC cluster, resolving to 172.86.76[.]129; intrusion linkage is unconfirmed.
HOSTNAMEdubai-9[.]vaermb[.]comHostname listed in the neighboring infrastructure IOC cluster, resolving to 172.86.76[.]130; intrusion linkage is unconfirmed.
HOSTNAMEmyjitsi[.]exceptionnotfound[.]irHostname listed in the surrounding infrastructure IOC cluster at 172.86.76[.]108; intrusion linkage is unconfirmed.
HOSTNAMEmyjitsi[.]mrnajafipour[.]irAssociated infrastructure hostname serving a Radio Zamaneh replica; no malicious page code was identified and intrusion linkage is unconfirmed.
HOSTNAMEprice[.]exceptionnotfound[.]irHostname listed in the associated infrastructure IOC cluster at 45.59.114[.]60; intrusion linkage is unconfirmed.
HOSTNAMEs5[.]sideliner[.]irHostname listed in the surrounding infrastructure IOC cluster at 172.86.76[.]112; intrusion linkage is unconfirmed.
HOSTNAMEshop[.]exceptionnotfound[.]irHostname listed in the associated infrastructure IOC cluster at 45.59.114[.]60; intrusion linkage is unconfirmed.
HOSTNAMEtools[.]exceptionnotfound[.]irCloudflare-hosted hostname explicitly listed in the surrounding infrastructure IOC cluster; intrusion linkage is unconfirmed.
IPV4104[.]21[.]27[.]95Cloudflare IP explicitly listed for tools.exceptionnotfound[.]ir in the surrounding infrastructure IOC table; intrusion linkage and exclusive attacker control are unconfirmed.
IPV4172[.]67[.]142[.]35Cloudflare IP explicitly listed for tools.exceptionnotfound[.]ir in the surrounding infrastructure IOC table; intrusion linkage and exclusive attacker control are unconfirmed.
IPV4172[.]86[.]76[.]101Research indicator in the neighboring infrastructure cluster; hosted a #FreeIran conduit page and a Regorixa investment landing page. Intrusion linkage is unconfirmed.
IPV4172[.]86[.]76[.]108IP listed in the neighboring infrastructure IOC cluster, hosting dubai-3 and an .ir hostname; intrusion linkage is unconfirmed.
IPV4172[.]86[.]76[.]112IP listed in the neighboring infrastructure IOC cluster, hosting dubai-4 and s5.sideliner[.]ir; intrusion linkage is unconfirmed.
IPV4172[.]86[.]76[.]120IP listed in the neighboring dubai-# infrastructure IOC cluster; intrusion linkage is unconfirmed.
IPV4172[.]86[.]76[.]121IP listed in the neighboring dubai-# infrastructure IOC cluster; intrusion linkage is unconfirmed.
IPV4172[.]86[.]76[.]124IP listed in the neighboring infrastructure IOC cluster with dubai-7 and several additional domains; intrusion linkage is unconfirmed.
IPV4172[.]86[.]76[.]127Operator staging and C2 server exposing attack scripts, payloads, session logs, and exfiltrated government data.
IPV4172[.]86[.]76[.]129IP listed in the neighboring dubai-# infrastructure IOC cluster; intrusion linkage is unconfirmed.
IPV4172[.]86[.]76[.]130IP listed in the neighboring dubai-# infrastructure IOC cluster; intrusion linkage is unconfirmed.
IPV4172[.]86[.]76[.]94IP listed in the neighboring dubai-# infrastructure IOC cluster; intrusion linkage is unconfirmed.
IPV445[.]59[.]114[.]60Associated infrastructure IP hosting a Radio Zamaneh replica and .ir subdomains; its connection to the government intrusion is unconfirmed.
SHA256ecc3611f7dcbaa53acf44e67de2f10d78a26e03b3c77ba28bbd3ee16b2e66437TLS certificate fingerprint used to connect the associated Swiss server to the UAE infrastructure cluster; not a malware hash.

MITRE ATT&CK

T1001.003 · Protocol or Service ImpersonationBeacon exfiltration traffic spoofs a Chrome User-Agent, although polling retains a native PowerShell WebClient identifier.T1003.002 · Security Account ManagerThe operator extracted SAM and SYSTEM registry hives from the victim environment.T1016 · System Network Configuration DiscoveryThe webshell defaults to ipconfig to return the compromised host's network configuration.T1033 · System Owner/User DiscoveryThe webshell defaults to whoami /all, and beacon startup callbacks report the victim username.T1041 · Exfiltration Over C2 ChannelThe HTTP C2 environment supported exfiltration, and extracted government data was recovered from its loot and ejustice directories.T1053.005 · Scheduled TaskThe operator attempted to create a scheduled task named MicrosoftEdgeUpdate for persistence; Defender blocked it.T1059.001 · PowerShellPowerShell extracted database schema and user-table data, and a PowerShell beacon polled the HTTP C2 server.T1059.003 · Windows Command ShellThe recovered hc2.aspx webshell executes supplied commands through cmd.exe /c.T1071.001 · Web ProtocolsThe PowerShell beacon polls an HTTP C2 listener every 30 seconds for commands and returns command results.T1074.001 · Local Data StagingExtracted registry hives were staged in C:\Windows\Temp during the recorded operator session.T1082 · System Information DiscoveryThe webshell defaults to hostname, and beacon startup callbacks report the victim hostname.T1105 · Ingress Tool TransferGodPotato is stored in the C2 server's payload directory and retrieved at runtime for execution in the victim environment.T1110.001 · Password GuessingRecovered activity included password brute-force attempts against the eVisa and State Audit Institution portals and MSSQL brute-forcing scripts.T1110.002 · Password CrackingThe operator extracted stored credentials from aspnet_Membership and attempted to crack the hashes offline.T1110.003 · Password SprayingThe government-targeting script collection included Exchange password spraying.T1132.001 · Standard EncodingThe beacon base64-encodes results and returns them in 1,500-character chunks.T1134.001 · Token Impersonation/TheftThe privilege-escalation script runs GodPotato to abuse SeImpersonatePrivilege.T1190 · Exploit Public-Facing ApplicationRecovered scripts attempted ProxyShell exploitation against government mail servers and targeted a DotNetNuke SSRF flaw; successful initial access through these exploits was not confirmed.T1213 · Data from Information RepositoriesThe operator enumerated and extracted application database records, including judicial data, committee decisions, identity information, and more than 26,000 user records.T1505.003 · Web Shellhealth_check_t.aspx provided persistent command execution inside the Ministry of Justice network; hc2.aspx was recovered from the C2 server.T1562.001 · Disable or Modify ToolsA separate recovered script attempted to forcibly disable antivirus on the compromised system; success was not established.T1620 · Reflective Code LoadingA subsequent privilege-escalation script uses reflective loading to execute the payload in memory rather than on disk.

CVE

Threat Actors

Vendors

Products

CitrixRoyal Court Affairs Citrix exploitation, authentication reconnaissance, and MOF-based executionDefenderto further establish persistence via a scheduled task named MicrosoftEdgeUpdate, but it was blocked by Defender and never retried. It should be noted that a separate script on the server showed an attempt toDotNetNuke/Portals/0/, DotNetNuke's (DNN) default file storage directory. Additional scripts targeting CVE-2025-32372, an SSRF flaw in DNN versions before 9.13.8, point to a likely initial access path, though this cannot beExchangeA dedicated gov[.]om folder included 12 exploit scripts, including Exchange spraying, SQL server escalation, and a reflective execution variant.Joomlascripts covering a range of platforms and vulnerabilities; WAF bypass techniques, Fortinet appliances, Joomla installations, MSSQL brute-forcing, Oracle APEX and ORDS backends, Spring Boot Actuator endpoints, andOracle APEXWAF bypass techniques, Fortinet appliances, Joomla installations, MSSQL brute-forcing, Oracle APEX and ORDS backends, Spring Boot Actuator endpoints, and national ID Insecure Direct Object ReferenceORDSWAF bypass techniques, Fortinet appliances, Joomla installations, MSSQL brute-forcing, Oracle APEX and ORDS backends, Spring Boot Actuator endpoints, and national ID Insecure Direct Object Reference (IDOR)PowerShellcredentials and personal information. Database schema information and user tables were extracted via PowerShell and posted to the loot/ directory.SimpleSAMLphp/ITAPortal_AR/, suggesting a common codebase across both organizations. MJLA's SimpleSAMLphp identity provider, if configured for federated authentication within the same portal infrastructure, represents a single pointSpring Boot ActuatorFortinet appliances, Joomla installations, MSSQL brute-forcing, Oracle APEX and ORDS backends, Spring Boot Actuator endpoints, and national ID Insecure Direct Object Reference (IDOR) vulnerabilities.

Tools

Countries

Industries

Related Articles