Hunt.io Maps Infrastructure Linked to Iranian-Aligned Threat Actors

· Original article ↗

Summary

Hunt.io describes infrastructure-clustering research on Iranian-linked actors, using hosting, file hashes, certificates, and web fingerprints to identify additional servers and domains associated with MuddyWater and Dark Scepter.

Key points

  • Hunt.io tracks 19 Iran-linked groups and reports infrastructure totals for actors including MuddyWater, VoidManticore, APT42, APT35, and Infy.
  • A MuddyWater-associated open directory led researchers to a second server through a shared FMAPP.exe hash; both exposed offensive tools.
  • The second server briefly hosted a Sliver C2 instance. Researchers say it is unclear whether MuddyWater operated it.
  • Files on the server included a Python UDP command-and-control tool and a PowerShell dropper that connected to an IP also linked to Tsundere botnet panels.
  • Certificate-hostname and webpage-title pivots uncovered additional servers and domains associated with Dark Scepter, an actor reported to overlap APT34; its infrastructure used Cloudflare proxying.
  • The article recommends monitoring recurring hosting networks, certificate and TLS fingerprints, spoofed domains, remote-access activity, and suspicious email and authentication behavior.

Article Details

Attack Vectors
  • Recent reporting described exploitation of an Omani government mailbox to deliver malicious Microsoft Word documents to critical infrastructure and government entities worldwide.
  • Spear-phishing messages distributed through messaging services directed security and defense-related individuals to spoofed websites for credential theft.
  • A multi-stage dropper downloaded JavaScript payloads and runtime dependencies, then communicated with a WebSocket C2 endpoint.
  • Exposed directories contained offensive tooling, including a proxy binary used for tunneling and a custom encrypted UDP C2 server.
  • CDN proxying obscured C2 origin addresses; reused certificate hostnames and webpage titles exposed related backend infrastructure.
Defensive Notes
  • Monitor VPN and remote-access authentication for anomalous geolocation shifts, ASN changes, and connections associated with high-risk hosting networks.
  • Enforce MFA and monitor suspicious emails, OAuth abuse, token replay, and credential-harvesting patterns.
  • Scan for typosquatting domains and certificate reuse involving defense, energy, and government keywords.
  • Correlate recurring hosting networks, certificate hostnames, webpage titles, and shared file hashes to identify related infrastructure.
  • Use JARM and JA4x fingerprint clustering to investigate backend infrastructure reuse behind CDN proxies.
  • Treat attribution of the observed Sliver C2 instance cautiously: the article explicitly states that active operation by the suspected group remains unclear.
  • The article identifies government agencies, defense contractors, energy and utilities operators, university and policy institutions, and financial services as priority monitoring sectors for U.S. and Israeli organizations.

Indicators of compromise

TypeIndicatorContext
DOMAINanythingshere[.]shopDark Scepter C2 domain listed among hostnames associated with the identified backend infrastructure.
DOMAINcside[.]siteDark Scepter C2 domain listed among hostnames associated with the identified backend infrastructure.
DOMAINfootballfans[.]asiaDark Scepter C2 domain listed among hostnames associated with the identified backend infrastructure.
DOMAINgirlsbags[.]shopDark Scepter C2 domain observed during pivoting to additional servers using reused webpages and certificate hostnames.
DOMAINjustweb[.]clickDark Scepter C2 domain observed during pivoting to additional servers using reused webpages and certificate hostnames.
DOMAINlecturegenieltd[.]proDark Scepter C2 domain observed during pivoting to additional servers using reused webpages and certificate hostnames.
DOMAINmenclub[.]ltDark Scepter C2 domain listed among hostnames associated with the identified backend infrastructure.
DOMAINmusiclivetrack[.]websiteDark Scepter C2 domain listed among hostnames associated with the identified backend infrastructure.
DOMAINntcx[.]proDark Scepter C2 domain observed during pivoting to additional servers using reused webpages and certificate hostnames.
DOMAINretseptik[.]infoDark Scepter C2 domain observed during pivoting to additional servers using reused webpages and certificate hostnames.
DOMAINstone110[.]storeDark Scepter C2 domain listed among hostnames associated with the identified backend infrastructure.
DOMAINweb14[.]infoDark Scepter C2 domain used as the initial certificate-hostname pivot to locate backend infrastructure.
IPV4157[.]20[.]182[.]49Offensive-tooling directory sharing FMAPP.exe with the MuddyWater-profile server; later exposed Sliver C2 on port 31337, with operator attribution uncertain.
IPV4185[.]236[.]25[.]119WebSocket C2 contacted by reset.ps1 on port 3001; also identified as hosting Tsundere botnet panels on ports 80 and 3000.
IPV4185[.]76[.]79[.]125Additional Dark Scepter-linked server sharing webpage titles and TLS certificate characteristics with the identified infrastructure.
IPV4209[.]74[.]87[.]100Open-directory server listed in the MuddyWater actor profile; hosted offensive artifacts including FMAPP.exe.
IPV438[.]180[.]239[.]161Actor-controlled Dark Scepter infrastructure identified through certificate-hostname pivoting behind Cloudflare.
IPV492[.]243[.]65[.]243Additional Dark Scepter-linked server identified through the reused 'Wonders Above' webpage title and related certificate hostnames.
SHA256e25892603c42e34bd7ba0d8ea73be600d898cadc290e3417a82c04d6281b743bSHA-256 of FMAPP.exe, a proxy binary used for tunneling; pivoting on this artifact connected two offensive-tooling directories.

MITRE ATT&CK

Threat Actors

APT35Tracked with 79 IPs, 2,211 hosts, and 67 SHA-256 hashes. Used WhatsApp spear-phishing and spoofed websites to steal credentials from security and defense-related individuals.APT42Explicitly also known as Charming Cypress or Mint Sandstorm. Tracked with 54 IPs, 233 hosts, and 44 SHA-256 hashes; recent activity involved TameCat targeting senior defense and government officials.Charming CypressExplicitly identified as another name for APT42, also known as Mint Sandstorm.Dark ScepterDescribed as a recently identified actor overlapping APT34, identified parenthetically as OilRig. Certificate and webpage pivots revealed its C2 infrastructure behind Cloudflare.InfyTracked with 18 IPs, 53 hosts, and 58 SHA-256 hashes. Observed using updated Foudre and Tonnerre variants and Telegram-based C2 against Iranian dissidents and regional government entities.Mango SandstormExplicitly identified as another name for MuddyWater, whose infrastructure showed recurring use of NameCheap and Hosterdaddy Private Limited.MuddyWaterAlso referred to as Mango Sandstorm and MuddyWater APT. Hunt.io lists 264 IPs, 432 hosts, and 128 related SHA-256 hashes; infrastructure pivots uncovered offensive tooling and possible use of publicly available malware.MuddyWater APTName used for MuddyWater in the article; also referred to as Mango Sandstorm.OilRigName given parenthetically for APT34, with which Dark Scepter is reported to overlap.VoidManticoreTracked with 13 IPs, one host, and 91 SHA-256 hashes. Recent reporting described use of an exploited Omani government mailbox to deliver malicious Word documents.

Malware

Vendors

Akton d.o.o.The virtual servers are hosted on Akton d.o.o. (AS25467), and EDIS GmbH (AS57169), respectively. Observed domain names: justweb[.]click, girlsbags[.]shop, lecturegenieltd[.]pro, ntcx[.]pro, and retseptik[.]info.CloudflareReviewing C2 domains linked to Dark Scepter showed Cloudflare being used to proxy infrastructure and obscure origin IP addresses. Cloudflare fronting is common among Iranian-aligned operators, which makes certificateEDIS GmbHThe virtual servers are hosted on Akton d.o.o. (AS25467), and EDIS GmbH (AS57169), respectively. Observed domain names: justweb[.]click, girlsbags[.]shop, lecturegenieltd[.]pro, ntcx[.]pro, and retseptik[.]info.Hosterdaddy Private LimitedAlso referred to as Mango Sandstorm, MuddyWater APT, and other Iranian state-linked groups have displayed a preference for including NameCheap and Hosterdaddy Private Limited (AS136557).Hunt.iointelligence such as ASN patterns, TLS fingerprints, and hosting clusters derived from Hunt.io. While many indicators originate from public reporting, infrastructure scanning and behavioral clusteringLet's Encryptplus the server we started with in the previous query. The new servers share the same webpage and Let's Encrypt certificates with multiple hostnames as seen below:M247 Europe SRLregex to look for all occurrences of web*.info, identifies actor-controlled infrastructure hosted on M247 Europe SRL at 38.180.239[.]161. From the results, we also see several domains listed as hostnames. Some of theseNamecheapAlso referred to as Mango Sandstorm, MuddyWater APT, and other Iranian state-linked groups have displayed a preference for including NameCheap and Hosterdaddy Private Limited (AS136557).

Products

Tools

Countries

Industries

Related Articles