Hunt.io Maps Infrastructure Linked to Iranian-Aligned Threat Actors

Summary
Hunt.io describes infrastructure-clustering research on Iranian-linked actors, using hosting, file hashes, certificates, and web fingerprints to identify additional servers and domains associated with MuddyWater and Dark Scepter.
Key points
- Hunt.io tracks 19 Iran-linked groups and reports infrastructure totals for actors including MuddyWater, VoidManticore, APT42, APT35, and Infy.
- A MuddyWater-associated open directory led researchers to a second server through a shared FMAPP.exe hash; both exposed offensive tools.
- The second server briefly hosted a Sliver C2 instance. Researchers say it is unclear whether MuddyWater operated it.
- Files on the server included a Python UDP command-and-control tool and a PowerShell dropper that connected to an IP also linked to Tsundere botnet panels.
- Certificate-hostname and webpage-title pivots uncovered additional servers and domains associated with Dark Scepter, an actor reported to overlap APT34; its infrastructure used Cloudflare proxying.
- The article recommends monitoring recurring hosting networks, certificate and TLS fingerprints, spoofed domains, remote-access activity, and suspicious email and authentication behavior.
Article Details
- Attack Vectors
- Recent reporting described exploitation of an Omani government mailbox to deliver malicious Microsoft Word documents to critical infrastructure and government entities worldwide.
- Spear-phishing messages distributed through messaging services directed security and defense-related individuals to spoofed websites for credential theft.
- A multi-stage dropper downloaded JavaScript payloads and runtime dependencies, then communicated with a WebSocket C2 endpoint.
- Exposed directories contained offensive tooling, including a proxy binary used for tunneling and a custom encrypted UDP C2 server.
- CDN proxying obscured C2 origin addresses; reused certificate hostnames and webpage titles exposed related backend infrastructure.
- Defensive Notes
- Monitor VPN and remote-access authentication for anomalous geolocation shifts, ASN changes, and connections associated with high-risk hosting networks.
- Enforce MFA and monitor suspicious emails, OAuth abuse, token replay, and credential-harvesting patterns.
- Scan for typosquatting domains and certificate reuse involving defense, energy, and government keywords.
- Correlate recurring hosting networks, certificate hostnames, webpage titles, and shared file hashes to identify related infrastructure.
- Use JARM and JA4x fingerprint clustering to investigate backend infrastructure reuse behind CDN proxies.
- Treat attribution of the observed Sliver C2 instance cautiously: the article explicitly states that active operation by the suspected group remains unclear.
- The article identifies government agencies, defense contractors, energy and utilities operators, university and policy institutions, and financial services as priority monitoring sectors for U.S. and Israeli organizations.
Indicators of compromise
| Type | Indicator | Context |
|---|---|---|
| DOMAIN | anythingshere[.]shop | Dark Scepter C2 domain listed among hostnames associated with the identified backend infrastructure. |
| DOMAIN | cside[.]site | Dark Scepter C2 domain listed among hostnames associated with the identified backend infrastructure. |
| DOMAIN | footballfans[.]asia | Dark Scepter C2 domain listed among hostnames associated with the identified backend infrastructure. |
| DOMAIN | girlsbags[.]shop | Dark Scepter C2 domain observed during pivoting to additional servers using reused webpages and certificate hostnames. |
| DOMAIN | justweb[.]click | Dark Scepter C2 domain observed during pivoting to additional servers using reused webpages and certificate hostnames. |
| DOMAIN | lecturegenieltd[.]pro | Dark Scepter C2 domain observed during pivoting to additional servers using reused webpages and certificate hostnames. |
| DOMAIN | menclub[.]lt | Dark Scepter C2 domain listed among hostnames associated with the identified backend infrastructure. |
| DOMAIN | musiclivetrack[.]website | Dark Scepter C2 domain listed among hostnames associated with the identified backend infrastructure. |
| DOMAIN | ntcx[.]pro | Dark Scepter C2 domain observed during pivoting to additional servers using reused webpages and certificate hostnames. |
| DOMAIN | retseptik[.]info | Dark Scepter C2 domain observed during pivoting to additional servers using reused webpages and certificate hostnames. |
| DOMAIN | stone110[.]store | Dark Scepter C2 domain listed among hostnames associated with the identified backend infrastructure. |
| DOMAIN | web14[.]info | Dark Scepter C2 domain used as the initial certificate-hostname pivot to locate backend infrastructure. |
| IPV4 | 157[.]20[.]182[.]49 | Offensive-tooling directory sharing FMAPP.exe with the MuddyWater-profile server; later exposed Sliver C2 on port 31337, with operator attribution uncertain. |
| IPV4 | 185[.]236[.]25[.]119 | WebSocket C2 contacted by reset.ps1 on port 3001; also identified as hosting Tsundere botnet panels on ports 80 and 3000. |
| IPV4 | 185[.]76[.]79[.]125 | Additional Dark Scepter-linked server sharing webpage titles and TLS certificate characteristics with the identified infrastructure. |
| IPV4 | 209[.]74[.]87[.]100 | Open-directory server listed in the MuddyWater actor profile; hosted offensive artifacts including FMAPP.exe. |
| IPV4 | 38[.]180[.]239[.]161 | Actor-controlled Dark Scepter infrastructure identified through certificate-hostname pivoting behind Cloudflare. |
| IPV4 | 92[.]243[.]65[.]243 | Additional Dark Scepter-linked server identified through the reused 'Wonders Above' webpage title and related certificate hostnames. |
| SHA256 | e25892603c42e34bd7ba0d8ea73be600d898cadc290e3417a82c04d6281b743b | SHA-256 of FMAPP.exe, a proxy binary used for tunneling; pivoting on this artifact connected two offensive-tooling directories. |
MITRE ATT&CK
T1056.003 · Web Portal CaptureAPT35 used spoofed websites to steal credentials from recipients of its spear-phishing messages.T1059.001 · PowerShellTameCat is described as a PowerShell-based backdoor, and reset.ps1 is a multi-stage PowerShell dropper and installer.T1071.001 · Web ProtocolsUpon execution, reset.ps1 communicated with 185.236.25[.]119 on port 3001 using WebSockets.T1090.002 · External ProxyDark Scepter used Cloudflare to proxy C2 infrastructure and obscure origin IP addresses.T1095 · Non-Application Layer Protocoludp_3.0.py implemented a custom UDP command-and-control server communicating over port 1269.T1102.002 · Bidirectional CommunicationInfy used Telegram-based C2 with updated Foudre and Tonnerre variants.T1105 · Ingress Tool Transferreset.ps1 downloaded JavaScript payloads and Node.js runtime dependencies.T1566.001 · Spearphishing AttachmentReporting linked VoidManticore to delivery of malicious Microsoft Word documents through an exploited Omani government mailbox.T1566.003 · Spearphishing via ServiceAPT35 distributed spear-phishing messages through WhatsApp to security and defense-related individuals.T1572 · Protocol TunnelingFMAPP.exe, found in linked open directories, served as a proxy binary and tunneling component.T1573.001 · Symmetric Cryptographyudp_3.0.py used a lightweight symmetric cipher for its C2 communications.
Threat Actors
APT35Tracked with 79 IPs, 2,211 hosts, and 67 SHA-256 hashes. Used WhatsApp spear-phishing and spoofed websites to steal credentials from security and defense-related individuals.APT42Explicitly also known as Charming Cypress or Mint Sandstorm. Tracked with 54 IPs, 233 hosts, and 44 SHA-256 hashes; recent activity involved TameCat targeting senior defense and government officials.Charming CypressExplicitly identified as another name for APT42, also known as Mint Sandstorm.Dark ScepterDescribed as a recently identified actor overlapping APT34, identified parenthetically as OilRig. Certificate and webpage pivots revealed its C2 infrastructure behind Cloudflare.InfyTracked with 18 IPs, 53 hosts, and 58 SHA-256 hashes. Observed using updated Foudre and Tonnerre variants and Telegram-based C2 against Iranian dissidents and regional government entities.Mango SandstormExplicitly identified as another name for MuddyWater, whose infrastructure showed recurring use of NameCheap and Hosterdaddy Private Limited.MuddyWaterAlso referred to as Mango Sandstorm and MuddyWater APT. Hunt.io lists 264 IPs, 432 hosts, and 128 related SHA-256 hashes; infrastructure pivots uncovered offensive tooling and possible use of publicly available malware.MuddyWater APTName used for MuddyWater in the article; also referred to as Mango Sandstorm.OilRigName given parenthetically for APT34, with which Dark Scepter is reported to overlap.VoidManticoreTracked with 13 IPs, one host, and 91 SHA-256 hashes. Recent reporting described use of an exploited Omani government mailbox to deliver malicious Word documents.
Malware
Foudrehosts, and 58 SHA-256 hashes. Following recent campaign shifts, the group has been observed using updated Foudre and Tonnerre variants to target Iranian dissidents and regional government entities, leveragingTameCatlinks to 54 IPs, 233 total hosts, and 44 SHA-256 hashes. Analysis of recent campaigns introduces TameCat, a modular, PowerShell-based backdoor used to target senior defense and government officials.TonnerreSHA-256 hashes. Following recent campaign shifts, the group has been observed using updated Foudre and Tonnerre variants to target Iranian dissidents and regional government entities, leveraging Telegram-based C2 toTsunderewith 185.236.25[.]119:3001 using websockets. This IP is identified as high risk in Hunt due to login to Tsundere botnet panels on ports 80 and 3000.
Vendors
Akton d.o.o.The virtual servers are hosted on Akton d.o.o. (AS25467), and EDIS GmbH (AS57169), respectively. Observed domain names: justweb[.]click, girlsbags[.]shop, lecturegenieltd[.]pro, ntcx[.]pro, and retseptik[.]info.CloudflareReviewing C2 domains linked to Dark Scepter showed Cloudflare being used to proxy infrastructure and obscure origin IP addresses. Cloudflare fronting is common among Iranian-aligned operators, which makes certificateEDIS GmbHThe virtual servers are hosted on Akton d.o.o. (AS25467), and EDIS GmbH (AS57169), respectively. Observed domain names: justweb[.]click, girlsbags[.]shop, lecturegenieltd[.]pro, ntcx[.]pro, and retseptik[.]info.Hosterdaddy Private LimitedAlso referred to as Mango Sandstorm, MuddyWater APT, and other Iranian state-linked groups have displayed a preference for including NameCheap and Hosterdaddy Private Limited (AS136557).Hunt.iointelligence such as ASN patterns, TLS fingerprints, and hosting clusters derived from Hunt.io. While many indicators originate from public reporting, infrastructure scanning and behavioral clusteringLet's Encryptplus the server we started with in the previous query. The new servers share the same webpage and Let's Encrypt certificates with multiple hostnames as seen below:M247 Europe SRLregex to look for all occurrences of web*.info, identifies actor-controlled infrastructure hosted on M247 Europe SRL at 38.180.239[.]161. From the results, we also see several domains listed as hostnames. Some of theseNamecheapAlso referred to as Mango Sandstorm, MuddyWater APT, and other Iranian state-linked groups have displayed a preference for including NameCheap and Hosterdaddy Private Limited (AS136557).
Products
Hunt.iointelligence such as ASN patterns, TLS fingerprints, and hosting clusters derived from Hunt.io. While many indicators originate from public reporting, infrastructure scanning and behavioral clusteringMicrosoft Wordinvolves the exploitation of an Omani government mailbox to facilitate the delivery of malicious Microsoft Word documents focusing on critical infrastructure and government entities worldwide.Node.jsreset.ps1: Multi-stage PowerShell dropper and installer, responsible for downloading JavaScript payloads, including Node.js runtime dependencies.TelegramFoudre and Tonnerre variants to target Iranian dissidents and regional government entities, leveraging Telegram-based C2 to bypass defenses.WhatsAppIOCs revealed 79 IPs, 2,211 hosts, and 67 SHA-256 hashes attributed to APT35. This threat actor has used WhatsApp to distribute spear-phishing messages using spoofed websites to steal the credentials of security and
Tools
FMAPP.exeFigure 8: Attack Capture file manager for open directory hosted at 209.74.87[.]100Among the thousands of exposed artifacts on the server was FMAPP.exe, a proxy binary used as a tunneling component.HuntSQLIn this section, we extend that approach using HuntSQL and examine Dark Scepter, a recently identified actor overlapping APT34 (OilRig).Sliverremained accessible until February 26. Several days later, on March 2, our network scans identified a Sliver C2 server on port 31337. The C2's presence was only captured for a single day. It remains unclear whether
Countries
IranTensions between the United States, Israel, and Iran have reached a critical point following a series of diplomatic breakdowns, which led to escalating military exchanges and proxy engagements across the Middle East.IsraelTensions between the United States, Israel, and Iran have reached a critical point following a series of diplomatic breakdowns, which led to escalating military exchanges and proxy engagements across the Middle East.OmanUAEpublicly available malware likely to blend in with cybercriminals. Target-referenced files related to a UAE engineering company found within the .49 directory further strengthened the assessment of campaignUnited StatesTensions between the United States, Israel, and Iran have reached a critical point following a series of diplomatic breakdowns, which led to escalating military exchanges and proxy engagements across the Middle East.
Industries
Critical infrastructurecampaigns ranging from espionage and credential harvesting to ransomware and attacks targeting critical infrastructure.Defensestate-aligned actors have historically targeted energy, financial services, government networks, and defense-related organizations across the U.S., Israel, and allied regions.EducationEnergylong before physical engagement begins. Iranian state-aligned actors have historically targeted energy, financial services, government networks, and defense-related organizations across the U.S., Israel, andEngineeringavailable malware likely to blend in with cybercriminals. Target-referenced files related to a UAE engineering company found within the .49 directory further strengthened the assessment of campaign alignment.Financial Servicesbefore physical engagement begins. Iranian state-aligned actors have historically targeted energy, financial services, government networks, and defense-related organizations across the U.S., Israel, and allied regions.Governmentengagement begins. Iranian state-aligned actors have historically targeted energy, financial services, government networks, and defense-related organizations across the U.S., Israel, and allied regions.Utilitiesentities, the sectors of greatest exposure are government agencies, defense contractors, energy and utilities operators, university and policy institutions, and financial services.