logo

Omani Government Targeted in Blatant Iranian-Nexus Cyberespionage

ID: ad97026f-37d0-554a-a6f9-82da075c7545

STIX ID: report--ad97026f-37d0-554a-a6f9-82da075c7545

Feed Name: securityonline.info

Threat Score
85/100

Date Published: 2026-05-07

Date Updated: 2026-05-07

Author: Ddos

...
...

Hunt Intelligence found an unprotected VPS in the UAE exposing an active intrusion campaign targeting Oman’s Ministry of Justice and Legal Affairs: attackers deployed a custom webshell (mersaltest.mjla.gov.om), maintained C2 access with operator sessions as recently as April 10, 2026, and exfiltrated over 26,000 Ministry user records plus judicial case data and SAM/SYSTEM registry hives; the infrastructure and TTPs overlap with Iranian state-nexus actors (notably APT34/MuddyWater) and were hosted on RouterHosting alongside related diaspora media and censorship-circumvention tooling.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.