Omani Government Targeted in Blatant Iranian-Nexus Cyberespionage
ID: ad97026f-37d0-554a-a6f9-82da075c7545
STIX ID: report--ad97026f-37d0-554a-a6f9-82da075c7545
Feed Name: securityonline.info
Hunt Intelligence found an unprotected VPS in the UAE exposing an active intrusion campaign targeting Oman’s Ministry of Justice and Legal Affairs: attackers deployed a custom webshell (mersaltest.mjla.gov.om), maintained C2 access with operator sessions as recently as April 10, 2026, and exfiltrated over 26,000 Ministry user records plus judicial case data and SAM/SYSTEM registry hives; the infrastructure and TTPs overlap with Iranian state-nexus actors (notably APT34/MuddyWater) and were hosted on RouterHosting alongside related diaspora media and censorship-circumvention tooling.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
