logo

Iranian-Nexus Operation Against Oman's Government: 12 Ministries Hit and 26,000 Citizen Records Exposed

ID: b59a0c18-172d-5955-9153-54e5a880c086

STIX ID: report--b59a0c18-172d-5955-9153-54e5a880c086

Feed Name: Hunt.io Blog

Threat Score
90/100

Date Published: 2026-05-06

Date Updated: 2026-07-16

...
...

A publicly accessible VPS (172.86.76.127) hosted a live intrusion campaign targeting Omani government agencies—chiefly the Ministry of Justice and Legal Affairs—containing C2 servers, webshells (hc2.aspx, health_check_t.aspx), exploit/tooling scripts (ProxyShell, DNN SSRF, Chisel, GodPotato), and exfiltrated data including ~26,596 DNN user records and registry hives. The attacker used a Python HTTP-based C2 and PowerShell beacon to poll for commands and staged harvested databases and credentials on the server; surrounding hosting infrastructure and TTPs align with Iranian-nexus operators, though no firm group attribution is made.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.