Iranian-Nexus Operation Against Oman's Government: 12 Ministries Hit and 26,000 Citizen Records Exposed
ID: b59a0c18-172d-5955-9153-54e5a880c086
STIX ID: report--b59a0c18-172d-5955-9153-54e5a880c086
Feed Name: Hunt.io Blog
A publicly accessible VPS (172.86.76.127) hosted a live intrusion campaign targeting Omani government agencies—chiefly the Ministry of Justice and Legal Affairs—containing C2 servers, webshells (hc2.aspx, health_check_t.aspx), exploit/tooling scripts (ProxyShell, DNN SSRF, Chisel, GodPotato), and exfiltrated data including ~26,596 DNN user records and registry hives. The attacker used a Python HTTP-based C2 and PowerShell beacon to poll for commands and staged harvested databases and credentials on the server; surrounding hosting infrastructure and TTPs align with Iranian-nexus operators, though no firm group attribution is made.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
