logo

Analysis of APT35 infrastructure reveals interest in Egyptian Shipping Companies

ID: adfaab17-0b5c-523e-ad02-dbd9ae0b5845

STIX ID: report--adfaab17-0b5c-523e-ad02-dbd9ae0b5845

Feed Name: SecurityScorecard Blog

Threat Score
85/100

Date Published: 2025-02-24

Date Updated: 2026-04-29

...
...

SecurityScorecard’s STRIKE team identified multiple typosquatted and rogue mail subdomains resolving to infrastructure tied to an Iran-linked APT (C2 IP 136.243.108.14) that forward via CNAME to smtp11.smtplab.com, hosting a Kerio Connect webmail interface likely used for phishing; several legitimate domains appear to have had DNS/subdomain entries created without authorization, the activity is attributed to APT35/Charming Kitten and primarily targets Egypt-based shipping and marine service organizations, and the report recommends brand monitoring and mitigation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.