Threat Intelligence Report: The Pro-Iran Hacktivist Ecosystem 2026
Moving beyond traditional state-centric APT structures, the pro-Iran coalition of jihadist-aligned collectives, nationalist actors, and opportunistic groups coordinates via Telegram to turn low-cost cyber operations into high-impact psychological warfare. While individual actors primarily rely on technically unsophisticated tradecraft like DDoS-for-hire tools, website defacements, and recycled breach data, their strategic strength lies in speed, visibility, and rapid mobilization alongside real-world kinetic events.
Executive Summary
The cyber environment surrounding the U.S.-Iranian conflict and regional tensions has produced a decentralized wartime cyber ecosystem in service of Iran. It is not a single organized force, instead, it is a loose mix of jihadist-aligned cyber collectives, nationalist actors, and state-adjacent influence networks that converge around shared enemies and geopolitical narratives. This activity has intensified with tensions around the events in Iran and the attacks on regional infrastructure.
The ecosystem operates through Telegram channels and websites, shared target lists, DDoS-for-hire tools, recycled breach data and leak-amplification campaigns. Attack claims and propaganda often appear within hours of kinetic events. This gives actors a deniable auxiliary role while keeping them separate from formal state structures.
Most activity remains technically unsophisticated. DDoS attacks, website defacements, and hack & leak extortion-style messaging with exaggerated claims are more common than verified advanced intrusions. The strategic effect comes less from technical capability than from speed, visibility, and ideological framing that make it into news cycles. In practice these actors use cyber activity as scalable asymmetric information warfare. Even with limited high-end capability, loosely aligned ideological and state-adjacent networks can impose psychological, political, and economic pressure on adversaries during periods of regional crisis.
Iran Aligned Actor Groups
The current pro-Iran and “Axis of Resistance” cyber ecosystem is decentralized, blending hacktivist groups, ideological cyber militias, influence operators, and jihadist cyber propagandists. This ecosystem does not operate as a single command infrastructure, instead functioning as a loose knit cyber mobilization network. Coordination happens through online platforms like Telegram and websites created for dumps of data and propaganda release. All of these are then amplified by social media and news reporting picking up on splashy reports of hack-and-leak operations for the most part.
The groups in this report show how modern cyber conflict is moving beyond traditional espionage toward more influence operations. Much of this activity is built for wartime influence by leveraging public visibility for asymmetric pressure against perceived enemies.
Their primary tradecraft centers on DDoS campaigns, hack-and-leak operations, propaganda amplification, and extortion-style messaging. Targeting is often symbolic, with activity directed against government, telecommunications, healthcare, finance, logistics, and open-source infrastructure that is aligned with, or within the borders of, the enemies of the state they are supporting.
The ecosystem matters less because of proven advanced capability and more because of scale, coordination, and visibility. It can turn low-cost disruption into wartime psychological pressure. Groups such as Handala, 313 Team, Cyber Islamic Resistance, Fatimiyoun/FAD Team, Dark Storm, CJM, Keymous+, DieNet, MONARCH, Killnet, and other coalition actors create the appearance of a broad transnational cyber front. They do this primarily through synchronized propaganda and hacking campaigns.
One notable example of this activity is the May 2026 DDoS campaign against Canonical and Ubuntu infrastructure. This campaign demonstrated how commercial stresser tools and coalition amplification could be used to create outsized disruption against globally important digital platforms.
As tensions rise around the Strait of Hormuz and the wider regional conflict these actors should be treated as deniable asymmetric auxiliaries (e.g. proxies). They may not always demonstrate high-end capability but they can still generate persistent disruption, economic and reputational damage, and psychological instability.
Islamic Cyber Resistance in Iraq / 313 Team
The Islamic Cyber Resistance in Iraq, also known as 313 Team, is one of the most visible Iraqi resistance-branded cyber personas in the pro-Iran ecosystem. Its “313” branding draws from Shia theology and militia culture, giving the group ideological weight inside Iran-aligned media and militia networks.
Operationally, 313 Team focuses on DDoS attacks and website disruption. It also uses Telegram propaganda, symbolic targeting and wartime messaging. The group gained visibility during the aforementioned May 2026 DDoS campaign against Canonical and Ubuntu infrastructure. The campaign affected ubuntu.com, Launchpad package repositories and security APIs update systems as well as related services used by enterprise and cloud environments.
The group claimed use of the “Beamed” DDoS-for-hire platform. This reinforces the assessment that its model relies more on commercial stressers, shared infrastructure, and coalition tooling than it does on custom malware or advanced tradecraft.The Ubuntu campaign was significant because of asymmetric leverage rather than technical sophistication. By targeting open-source infrastructure used across enterprise cloud DevOps and security-update environments, the group created outsized visibility and operational friction with relatively simple methods, in this case DDoS.
313 Team has also been linked to GitHub-hosted tooling. It has used public proof-of-impact services such as check-host[.]net to confirm events. Reporting also connects the group to SQL-injection tools, AI-generated propaganda, and defacement-style activity against government and institutional targets in Kuwait and the wider Gulf. 313 Team operates inside the broader coalition environment of similar groups. Reported aligned actors include RipperSec, Cyb3rDrag0nz, Cyber Fattah Team, Fatimiyoun/FAD Team, Conquerors Electronic Army, and other resistance-branded groups. These actors coordinate through Telegram, shared narratives, target lists, and synchronized public claims. This structure lets low-to-moderate capability actors create the appearance of a larger cyber front.
Threat Assessment: Moderate-to-high for DDoS, disruption, propaganda amplification, and wartime information operations; low-to-moderate for opportunistic intrusion activity; currently low for verified advanced destructive or cyber-physical capability.
Handala Hack Team
Handala Hack Team is among the most consequential and psychologically sophisticated actors in the pro-Iran ecosystem. Unlike many disruption-focused hacktivist groups, Handala specializes in hack-and-leak operations, intimidation campaigns, identity exposure, and coercive information operations.
Its activity aligns closely with Iranian information warfare objectives, even where formal command relationships remain unconfirmed. Handala’s operations frequently blend cyber intrusion claims with propaganda, coercive messaging, and public intimidation. Within the ecosystem, Handala functions as a high-credibility influence and leak node whose operations provide aspirational models for smaller hacktivist crews. It is also of note that recent attacks have leveraged hack and wiper activities that place Handala at a higher level of damage capabilities than the others profiled here.
Threat Assessment: High for psychological operations, hack-and-leak activity, and reputational damage; moderate for broader disruptive capability.
Cyber Fattah Team
Cyber Fattah ( فاتح سايبر) is a pro-Iran hacktivist persona focused on wartime propaganda, DDoS activity, defacement operations, and symbolic disruption. The group operates within the broader Axis-aligned propaganda ecosystem and contributes to coalition attack volume during periods of regional escalation.
Its operations are consistent with mid-tier wartime hacktivism:
public target selection
disruption claims
Telegram amplification
and symbolic attacks against state and infrastructure targets
The group’s strategic importance lies more in participation and coalition signaling than technical sophistication.
Threat Assessment: Moderate for DDoS, disruption, and propaganda amplification.
Fatimiyoun Cyber Team / FAD Team
Fatimiyoun Cyber Team, also referred to as FAD Team, combines militia-aligned ideological branding with rhetoric centered on cyber sabotage, destructive operations, and critical infrastructure intimidation. The group frequently references wiper malware, permanent destruction narratives, and infrastructure targeting themes.
The “Fatimiyoun” branding invokes the Afghan Shia militia ecosystem aligned with Iran’s regional proxy architecture, providing ideological legitimacy and escalation signaling.
Although public evidence of mature destructive capability remains limited, the group’s strategic value lies in psychological escalation. By repeatedly framing itself around cyber sabotage and infrastructure destruction, it injects uncertainty into the wartime information environment.
Threat Assessment: Moderate-to-high for intimidation and escalation signaling; unverified for sophisticated destructive operations.
Cyber Isnaad Front
Cyber Isnaad Front ("الجبهة الإسناد السيبرانية) represents the evolution of pro-Iran cyber activity from infrastructure disruption toward individualized coercive targeting. The group has reportedly published target lists and conducted intimidation-oriented campaigns focused on individuals tied to critical sectors. Its operations demonstrate the increasing fusion of cyber operations with psychological warfare and harassment tactics. Rather than focusing solely on institutional compromise, the group attempts to generate fear and pressure through exposure, intimidation, and public targeting.
Threat Assessment: Moderate for intimidation, doxxing, and psychological pressure campaigns.
Dark Storm Team
Dark Storm Team occupies a hybrid space between ideological hacktivism and criminal-adjacent cyber operations. The group has been linked to DDoS campaigns, ransomware claims, and attacks targeting financial-sector organizations.
Unlike purely ideological DDoS crews, Dark Storm’s association with ransomware narratives increases its risk profile by blending coercive financial pressure with wartime propaganda.The group contributes to the ecosystem by providing both disruption capability and criminal-style intimidation mechanics.
Threat Assessment: High for DDoS; moderate-to-high if ransomware capability is operationally validated.
APT Iran
APT Iran (مرکز تحقیقاتی) is primarily a branding-oriented pro-Iran hacktivist persona rather than a formally identified state APT. The name itself is strategically useful because it implies sophistication and state linkage regardless of actual operational capability.
The group appears focused on:
symbolic targeting (retribution ops)
propaganda-oriented disruption
and coalition participation for propaganda
Its value within the ecosystem is narrative inflation rather than uniquely advanced capability.
Threat Assessment: Moderate for disruption claims and propaganda amplification.
Evil Markhors
Evil Markhors (ایول مارخور) occupies a more operationally useful niche within the ecosystem by focusing on credential harvesting, reconnaissance, and exposed-system discovery. While less visible publicly than DDoS-centric actors, credential and recon-focused groups are strategically important because they can enable downstream compromise by coalition participants.
The group’s activities likely include:
password spraying
reconnaissance scanning
exposure discovery
and credential aggregation
In a decentralized coalition environment, such access-enablement actors can disproportionately increase ecosystem effectiveness.
Threat Assessment: Moderate for credential compromise and reconnaissance; potentially higher if access-sharing occurs across coalition actors.
Conquerors Electronic Army (CEA)
Conquerors Electronic Army (جيش الفاتحين الإلكتروني,) functions as a coalition-aligned DDoS and propaganda actor participating in wartime disruption campaigns. The group contributes to coalition messaging, attack volume, and amplification operations targeting Israeli and Western infrastructure.
Its operational profile is consistent with high-visibility wartime hacktivism:
DDoS
defacement
and public disruption claims
Threat Assessment: Moderate for DDoS and defacement activity.
Nation of Saviors (NOS)
Nation of Saviors is a smaller coalition participant operating within pro-Palestinian and anti-Israel narratives. Its significance lies primarily in coalition breadth and amplification rather than technical specialization.
The group contributes:
DDoS participation
propaganda reinforcement
and wartime messaging
Threat Assessment: Moderate for coalition participation and DDoS activity.
Hider Nex / Tunisian Maskers Cyber Force
Hider Nex, also known as Tunisian Maskers Cyber Force, is a regional pro-Palestinian actor associated with telecom-focused DDoS campaigns and symbolic infrastructure targeting.
The group’s operations demonstrate the ecosystem’s ability to rapidly mobilize around visible civilian infrastructure targets where even limited disruption can generate substantial media attention and psychological impact.
Threat Assessment: Moderate for symbolic disruption and telecom-targeted DDoS operations.
RipperSec
RipperSec (新闻频道) is a coalition-aligned hacktivist group focused on DDoS, defacement, and propaganda amplification based in Malaysia. The group’s importance lies in demonstrating how the ecosystem absorbs or aligns with preexisting hacktivist brands in order to rapidly increase campaign scale.
Its activity is primarily tactical:
disruption
visibility
and social-media amplification
Threat Assessment: Moderate for DDoS and defacement operations.
Cyb3rDrag0nz
Cyb3rDrag0nz represents another coalition-density actor contributing to DDoS campaigns, Telegram amplification, and wartime disruption messaging. Like many smaller crews in the ecosystem, its primary value lies not in technical specialization but in attack-volume generation and coalition optics.
Threat Assessment: Moderate for DDoS and propaganda participation.
Cyber Jihad Movement (CJM)
Cyber Jihad Movement (CJM الجهاد السيبراني) represents one of the most strategically significant developments within the wartime cyber ecosystem because it bridges Sunni jihadist cyber mobilization with the broader Iranian Axis-aligned cyber environment.
The group’s public statements call for “global cyber jihad” against the United States, Israel, and allied governments. This messaging signals a tactical convergence between historically hostile ideological ecosystems united temporarily around shared anti-Western objectives.
CJM’s importance is therefore ideological and mobilizational rather than purely technical. It expands the ecosystem’s recruitment potential, propaganda reach, and cross-platform amplification capacity.
Threat Assessment: Moderate for ideological mobilization, propaganda amplification, and public-sector disruption.
Keymous+
Keymous+ emerged as one of the highest-volume DDoS actors during the early 2026 wartime surge. Its strategic importance lies in attack tempo and operational persistence rather than advanced intrusion capability.
The group demonstrates how commodity stresser infrastructure and coordinated attack waves can create disproportionate operational burden and media attention.
Threat Assessment: High for DDoS volume and sustained disruption.
DieNet
DieNet functions similarly to Keymous+, contributing persistent high-volume DDoS activity against government and public-sector targets.
Its role within the coalition is to sustain operational noise, repeated disruption, and public claim generation during escalation cycles.
Threat Assessment: High for DDoS and operational disruption.
NoName057(16)
NoName057(16) aka DDoSiaProject is primarily a pro-Russian hacktivist actor that entered the broader anti-Western and pro-Iran wartime ecosystem opportunistically. Its participation demonstrates increasing convergence between Russian-aligned cyber activism and Middle East wartime cyber narratives.
The group is already well known for high-volume DDoS operations, making it a natural participant in coalition-style wartime disruption campaigns.
Threat Assessment: High for DDoS and coalition amplification.
Killnet
Killnet represents a pro-Russian hacktivist brand whose wartime participation appears primarily opportunistic and ideologically adjacent rather than directly subordinated to Iranian coordination structures. The group contributes symbolic support, amplification, and anti-Western targeting consistent with broader wartime narratives.
Threat Assessment: Moderate-to-high for DDoS and propaganda amplification.
Russian Legion aka CARDINAL aka MONARCH
The Russian Legion now increasingly uses the name MONARCH. It appears to function as an opportunistic anti-Western amplification actor within the wider Iran, Israel, and U.S. wartime cyber ecosystem.
The shift from Russian Legion to MONARCH fits a broader pattern of hacktivist identity cycling. It also fits the use of refreshed propaganda rebranding to maintain visibility and complicate attribution. The actor’s messaging remains focused on anti-Western, anti-Israel, and militarized geopolitical narratives. Its activity emphasizes symbolic targeting, wartime propaganda, and high-visibility disruption claims.
Operationally MONARCH appears to fill the same role previously associated with the Russian Legion. That role includes coalition participation, DDoS-focused disruption, influence amplification, and synchronized wartime messaging. However, there is limited public evidence of independently verified advanced intrusion capability.
Telegram and social media appear central to its model. These platforms allow the group to spread claims, announce targets, and amplify coalition building propaganda across loosely connected pro-Russian and pro-Iran information networks.
Analytically, MONARCH should be understood less as a standalone sophisticated threat actor and more as a coalition-force multiplier operating within a decentralized proxy cyber environment. Its strategic value derives from visibility, repetition, ideological alignment and the ability to reinforce a wider perception of coordinated cyber pressure.
Threat Assessment: Moderate for DDoS, coalition amplification, and wartime propaganda operations; low-to-moderate for independently verified advanced intrusion capability; currently low for demonstrated destructive or cyber-physical operations.
Server Killers
Server Killers illustrates the opportunistic nature of wartime cyber ecosystems. The group appears motivated by visibility and coalition participation rather than deep strategic coordination. Its presence demonstrates how wartime cyber conflicts attract loosely affiliated actors seeking relevance or opportunistic influence within larger geopolitical narratives.
Threat Assessment: Moderate for nuisance disruption and opportunistic DDoS activity.
Strategic Assessment
The pro-Iran cyber ecosystem increasingly resembles a form of decentralized digital proxy warfare rather than traditional state-centric cyber operations.
Its defining characteristics are:
coalition behavior
Telegram-native coordination
rapid mobilization
ideological amplification
and psychological disruption
The ecosystem’s center of gravity is not advanced malware, covert espionage, or long-term persistence. Instead, it is rapid disruption turned into strategic psychological effect through coalition activity, synchronized propaganda, and wartime information operations.
As regional conflict continues to intensify, these actors are likely to remain focused on:
DDoS campaigns
symbolic infrastructure targeting
leak operations
coercive messaging
and psychological pressure operations
Defensive Implications
Organizations should treat this cluster as a disruption and reputational-risk threat during periods of geopolitical escalation. Priority controls should focus on
DDoS readiness
WAF and CDN hardening
credential-stuffing detection
MFA enforcement
leaked-credential monitoring
abuse-desk escalation
executive doxxing monitoring
rapid response and communications procedures for false or exaggerated breach claims
The key analytic discipline is separating access from amplification. A Telegram claim does not prove intrusion. A DDoS screenshot does not prove compromise. A leaked sample does not prove current access.
Still, repeated low-end activity across many brands can create real operational pressure, reputational damage, and psychological cost.
Conclusions
The pro-Iran and “Axis of Resistance” cyber ecosystem is best understood as a decentralized wartime disruption network, not a traditional APT structure. Its strength is not advanced technical capability, but speed, visibility, coalition activity, and the ability to turn low-cost cyber actions into psychological and political pressure. Many of these groups function as proxies or cutouts for Iranian-aligned interests, with varying degrees of likely support, direction, encouragement, or operational tolerance from Iran. These groups and related actors help create the appearance of a broad transnational cyber front. That perception is itself part of the operation.
Most of these actors rely on basic tradecraft, including DDoS attacks, defacements, credential reuse, recycled breach data, public claims, and propaganda amplification to effect. These methods are often low-end, but they can still create real impact when many groups act at once during geopolitical escalation. The main defensive challenge is not only intrusion prevention, but also managing disruption, reputational risk, and alert fatigue across public-facing systems.
During future Gulf-region escalation, this ecosystem is likely to surge quickly, with claims appearing within hours of kinetic events.The core assessment is that this ecosystem is less a high-end cyber weapon than a scalable asymmetric pressure system, with value derived from mobilization, amplification, and psychological effect.
Threat Intelligence Report: Nation-State Targeting of Water Systems 2024–2026
DTI reveals how Russia, China, and Iran are exploiting weak OT security and internet-facing PLCs to target critical water and wastewater infrastructure. From Volt Typhoon's strategic pre-positioning to Sandworm-adjacent sabotage, discover the primary TTPs, vulnerabilities, and MITRE ATT&CK mappings reshaping modern hybrid warfare.
Executive Summary
Water and wastewater systems have become favored gray-zone targets because they are highly vulnerable and hold disproportionate strategic value. The combination of chronic underinvestment and weak baseline operational technology (OT) security make many of these critical systems easy to compromise. Such intrusions can have both physical and psychological impact, and disruptions often affect civilian life, public health, and trust in government.
Recent nation-state cyber activity targeting water systems includes Iranian IRGC-linked targeting of exposed programmable logic controllers (PLCs), Russian and pro-Russian access to municipal water-control environments, and PRC-linked pre-positioning in U.S. critical infrastructure, including water and wastewater systems. U.S. federal agencies, including CISA, FBI, NSA, and EPA, have warned that many utilities remain exposed through internet-facing human-machine interfaces (HMIs) and PLCs, weak credentials, shared accounts, legacy devices, limited monitoring, and poor IT/OT segmentation.
Operations targeting water systems fit a modern hybrid warfare doctrine that has become increasingly dominant in recent years. Russia, China, and Iran all use cyber access primarily as a shaping tool, not a destructive weapon. Water-system access specifically can create fear, test response thresholds, consume emergency resources, and provide leverage during crises. Each nation puts their unique twist on their operations. Russia tends to pair infrastructure access with pressure and destabilization. Iran often blends symbolic retaliation, psychological signaling, and opportunistic disruption. In contrast, China places more emphasis on long-term pre-positioning and strategic persistence.
All three models converge on the same underlying thesis: targeting civilian utilities provides strategic options.
Water Systems as Pre-War Terrain
From 2024 to 2026, water-sector targeting moved from opportunistic nuisance activity to a feature of state competition. Water systems are now pressure points used to create fear, test resilience, and prepare options before wider conflict. Specifically, threat actors have exploited internet-exposed PLCs and weak credentials to deface HMIs and make public spectacles out of their compromises.
Iran uses successful compromise of water systems for visible signaling, retaliation narratives, and propaganda, while Russia uses it for disruption, intimidation, and hybrid pressure against NATO-aligned states. Meanwhile, China focuses on quiet persistence, reconnaissance, and contingency access inside U.S. critical infrastructure. However, all of these operations are meant to serve the same purpose: setting the stage for war without crossing the threshold into open conflict.
Iran: CyberAv3ngers / IRGC-Linked PLC Targeting
Iran-linked activity has been the most direct in targeting water and wastewater systems.In April 2020, Iranian state-sponsored hackers launched a cyberattack targeting Israeli water and wastewater control systems. While this attack attempted to manipulate the SCADA systems, automated systems kicked in and thwarted the attempt. Had it succeeded, during a heat wave, it could have harmed many people.
In December 2024, CISA reported that the IRGC-affiliated CyberAv3ngers targeted and compromised Israeli-made Unitronics Vision Series PLCs used across multiple sectors, including U.S. water and wastewater systems. The activity exploited poor authentication and exposed PLC/HMI interfaces rather than sophisticated malware delivery. Clearly this shows that the Iranian government is accustomed to the idea of attacking public infrastructure, something usually outside the bounds of conventional warfare.
In April 2026, CISA, FBI, NSA, EPA, and partner agencies issued a new advisory warning that Iranian-affiliated cyber actors were exploiting internet-facing PLCs across critical infrastructure, including water, wastewater, energy, and government facilities. The EPA separately framed the advisory as a water-sector resilience warning, stressing that national security depends on water systems reporting incidents and hardening exposed OT assets.
Assessment: While Iran has demonstrated the ability to access exposed control devices, deface HMIs, and create public fear, the public evidence of their activity still points more toward opportunistic OT access than reliable cyber-physical sabotage at scale.
Primary TTPs
Threat level: High for exposed small and mid-sized utilities; moderate for mature utilities with segmented OT.
Russia: Pro-Russian Hacktivist and Sandworm-Adjacent Water Disruption
Russia-aligned actors have shown a willingness to use their access to manipulate water-control systems directly. In Mulshoe, Texas in January 2024, attackers accessed a remote industrial interface and caused a municipal water tank to overflow for roughly 30–45 minutes. The Cyber Army of Russia Reborn claimed responsibility, and Mandiant linked the group to Sandworm, Russia’s GRU-associated destructive cyber unit.
A little over a year later, in April 2025, attackers seized control of a dam in Bremanger, Norway. They opened a floodgate, releasing roughly 500 liters of water per second for four hours before the incident was stopped. Norway’s counterintelligence chief publicly blamed Russia-linked actors for the intrusion.
Assessment: Russian-linked activity is more sabotage-oriented than Iranian activity. The pattern fits Moscow’s broader hybrid campaign: low-cost disruptive access, public fear generation, and probing of Western infrastructure resilience.
Primary TTPs
Threat level: High in Europe and NATO-adjacent states; moderate-to-high in exposed U.S. municipal water systems.
China: Volt Typhoon Pre-Positioning in Water and Wastewater Networks
In February 2024, CISA, NSA, FBI, and allied agencies confirmed that Volt Typhoon had compromised IT environments across multiple U.S. critical infrastructure sectors, including water and wastewater, communications, energy, and transportation. The advisory assessed that the activity was intended to enable disruptive or destructive effects during a future crisis or kinetic conflict.
The same year, the EPA distributed an alert to more than 60,000 water and wastewater systems regarding Volt Typhoon and coordinated cybersecurity assistance for water infrastructure supporting U.S. defense-critical facilities.
Assessment: PRC water-sector targeting is strategically different from Iran and Russia. Rather than demonstrate immediate effects, Volt Typhoon’s objective is durable access, reconnaissance, and strategic pre-positioning.
Primary TTPs
Threat level: Severe strategic threat; lower risk of short-term disruption.
Poland and European Water-System Exposure
A May 2026 report released by the Polish Intelligence Service stated that hackers breached five Polish water treatment plants in 2025. The threat actors leveraged weak/default passwords and internet-exposed control systems. Once inside ICS controlling pumps and filters, they had the ability to alter chemical-dosing parameters. The attacks were never attributed to a specific nation-state or threat actor; however, the same intelligence report alluded to prior Russian and Belarusian hybrid operations against Polish infrastructure.
Assessment: Poland is a high-priority target because of its role as a NATO logistics hub for Ukraine. Even unattributed water-system intrusions in Poland should be assessed against Russian hybrid-warfare objectives: intimidation, disruption, reconnaissance, and resilience testing.
Threat level: High for this region downrange from Russia.
Major Non-Attributed Water-Sector Incidents Relevant to State Threat Modeling
American Water disclosed a cyber incident in October 2024 that affected customer-facing and billing systems, but not water or wastewater operations. Veolia North America reported a January 2024 ransomware incident that disrupted back-end systems and online bill payment, while treatment operations remained unaffected. Southern Water in the United Kingdom was also claimed by Black Basta, with customer and employee data at risk but no reported operational impact.
Other cases moved closer to operational risk. Arkansas City, Kansas shifted its water treatment facility to manual operations after a September 2024 cyber incident. Minot, North Dakota did the same in March 2026 after ransomware affected a server tied to the water treatment environment. In both cases, water remained safe, but operators had to rely on fallback procedures.
These incidents matter because they show that state actors do not need custom ICS malware to create risk. Billing systems, customer portals, GIS repositories, vendor access, remote administration, identity systems, backups, and SCADA-adjacent servers can all provide useful access or intelligence. Criminal and unattributed incidents should therefore be treated as live demonstrations of the same weaknesses a state actor could exploit with more patience, planning, and operational intent.
Common Vulnerabilities Exploited Across Cases
Water-sector targeting repeatedly converges on the same weaknesses:
Internet-facing HMIs and PLCs,
Weak or default credentials,
Exposed remote-access tools,
Shared operator accounts,
Unsupported legacy systems,
Limited monitoring,
Poor segmentation between IT and OT networks.
These gaps give actors simple access paths into systems that control pumps, valves, filters, chemical dosing, and alarms.
Reporting from the EPA and Government Accountability Office (GAO) shows that this is a systemic risk, not a one-off failure. The U.S. water sector includes roughly 170,000 water and wastewater systems, many of which operate with limited resources, voluntary security adoption, and uneven cyber maturity. This structure makes the sector easy to probe, difficult to standardize, and attractive to state and state-aligned actors seeking leverage, visibility, and disruption opportunities.
Strategic Assessment
The last two years show clear segmentation among state-sponsored and state-aligned actors. Iran uses water system intrusions to maximize ideological and psychological impact. Russia treats water and dam systems as part of sabotage-oriented hybrid warfare. China targets water infrastructure for strategic pre-positioning.
The near-term risk is not a Stuxnet-class attack. It is a low-complexity compromise of exposed OT that causes local disruption, unsafe operations, or panic. The larger strategic risk is quiet PRC-style persistence inside water-sector IT and OT-adjacent networks that could be used during a geopolitical crisis, such as kinetic conflict between the U.S. and China over Taiwan.
Conclusion
State and state-aligned actors treat water and wastewater infrastructure as strategic pressure points. The value is primarily psychological and political rather than kinetic. Even limited access or brief disruptions can trigger disproportionate reactions because water is tied directly to public health, trust, and government competence.
The most likely future is not a catastrophic “cyber Pearl Harbor.” It is persistent low-level access, intermittent disruption, coercive signaling, information operations, and pre-positioning for broader confrontations.
Appendix A: Indicators of Compromise and Detection Artifacts
Used by Iranian-affiliated APT actors to communicate with Rockwell Automation / Allen-Bradley PLCs
185.82.73[.]162
IP address
Jan 2025–Mar 2026
Same
185.82.73[.]164
IP address
Jan 2025–Mar 2026
Same
185.82.73[.]165
IP address
Jan 2025–Mar 2026
Same
185.82.73[.]167
IP address
Jan 2025–Mar 2026
Same
185.82.73[.]168
IP address
Jan 2025–Mar 2026
Same
185.82.73[.]170
IP address
Jan 2025–Mar 2026
Same
185.82.73[.]171
IP address
Jan 2025–Mar 2026
Same
CISA, FBI, NSA, EPA, DOE, and U.S. Cyber Command reported that Iranian-affiliated actors used overseas infrastructure to access internet-facing Rockwell Automation / Allen-Bradley PLCs, including CompactLogix and Micro850 devices, and that activity resulted in project-file extraction, HMI / SCADA data manipulation, operational disruption, and financial loss. (Internet Crime Complaint Center)
Iran: Ports, Devices, and Tools
Indicator / Artifact
Type
Relevance
TCP/44818
OT protocol port
EtherNet/IP / Rockwell Automation communications
TCP/2222
OT protocol port
EtherNet/IP implicit messaging
TCP/102
OT protocol port
Siemens S7 communications
TCP/502
OT protocol port
Modbus/TCP
TCP/22
Remote access port
SSH access; Dropbear SSH observed on victim endpoints
Dropbear SSH
Tool
Used for remote access persistence through port 22
Studio 5000 Logix Designer
Legitimate engineering software
Used to connect to and interact with exposed Rockwell PLCs
.ACD project files
Rockwell project artifact
Targeted / extracted project files containing ladder logic and configuration
The April 2026 joint advisory specifically called out malicious traffic to ports 44818, 2222, 102, 22, and 502, and noted Dropbear SSH deployment for remote access. (Internet Crime Complaint Center)
Iran: 2023 Unitronics / CyberAv3ngers Artifacts
Indicator / Artifact
Type
Relevance
Unitronics Vision Series PLCs
Targeted product family
Israeli-made PLC/HMI platform used in water, wastewater, energy, food, beverage, manufacturing, and healthcare
Default credentials
Access condition
Core compromise vector
"You have been hacked, down with Israel. Every equipment 'made in Israel' is CyberAv3ngers legal target."
Defacement text
HMI/PLC defacement message reported in 2023 activity
The earlier joint advisory reported IRGC-affiliated CyberAv3ngers targeting Unitronics Vision Series PLCs, commonly used in U.S. water and wastewater systems, and compromising devices using default credentials.
Russia: Cyber Army of Russia Reborn / Sandworm-Adjacent Activity
Indicator / Artifact
Type
Relevance
Cyber Army of Russia Reborn / CARR
Actor persona
Claimed water-system manipulation activity in Texas and Europe
Telegram claim videos
Influence artifact
Public proof-of-access / propaganda amplification
HMI screen recordings
Operational artifact
Demonstrated interaction with water-control interfaces
Water-level / stop-level manipulation
Process-control behavior
Associated with Muleshoe / Abernathy water tank incidents
SCADA / HMI access to small municipal utilities
Targeting pattern
Low-resource water utilities used as disruption targets
Mandiant linked CARR to Sandworm-associated infrastructure and personas, while Treasury reported that CARR claimed responsibility for overflowing water storage tanks in Abernathy and Muleshoe, Texas, and posted video of HMI manipulation. (CyberScoop)
Norway and Poland Exposure Artifacts
Indicator / Artifact
Type
Relevance
Bremanger / Risevatnet dam floodgate manipulation
Process-control behavior
Floodgate opened, releasing roughly 500 liters per second for four hours
Weak/default passwords
Access condition
Reported as common vector in European water incidents
Internet-exposed control systems
Exposure condition
Reported vector in Polish water treatment plant breaches
Pump, filter, and chemical-dosing control access
Process-control exposure
Relevant to Polish water treatment plant incident reporting
Reuters reported that Norway’s counterintelligence chief blamed Russian hackers for the April 2025 Bremanger dam incident. TNW and SecurityWeek reported that Polish water treatment plant breaches involved weak passwords and internet-exposed control systems; attribution remains unconfirmed for those Polish incidents. (Reuters)
China: Volt Typhoon Behavioral IOCs
Indicator / Artifact
Type
Relevance
wmic / WMIC
Native Windows tool
Process creation, discovery, credential-access workflows
ntdsutil.exe
Native Windows tool
Active Directory database extraction
ntds.dit
Credential artifact
Domain credential database targeted for exfiltration
SYSTEM registry hive
Credential artifact
Used with ntds.dit for password hash extraction
SECURITY registry hive
Credential artifact
Credential and policy data
netsh interface portproxy
Native Windows tool
Port forwarding / proxying for persistence and C2
PowerShell
Native Windows tool
Execution, discovery, and administration abuse
Compromised SOHO routers
Infrastructure
Proxying and operational obfuscation
C:\Windows\Temp\
Host artifact path
Staging location observed in advisory examples
C:\Users\Public\
Host artifact path
Staging location observed in advisory examples
ADMIN$ share output redirection
Windows admin artifact
Used in command execution / remote activity
NSA and partner agencies reported Volt Typhoon’s living-off-the-land model using built-in tools including wmic, ntdsutil, netsh, and PowerShell; the same advisory included examples of ntds.dit extraction, registry hive collection, and portproxy abuse.
Appendix B: MITRE ATT&CK Mapping
Actor / Stream
Tactic
Technique
ID
Observed / Assessed Use
Iran / CyberAv3ngers
Initial Access
Internet Accessible Device
T0883
Accessed publicly exposed PLCs without sufficient network hardening
Iran / CyberAv3ngers
Command and Control
Commonly Used Port
T0885
Used OT ports including 44818, 2222, 102, 502, and SSH on 22
Iran / CyberAv3ngers
C&C
Remote Access Software
T1219
Deployed Dropbear SSH for remote access
Iran / CyberAv3ngers
Impact
Stored Data Manipulation
T1565
Interacted with project files and altered HMI / SCADA display data
Iran / CyberAv3ngers
Initial Access
Valid Accounts
T1078
Inferred from default / weak credential abuse against PLCs
Iran / CyberAv3ngers
Impact
Defacement
T1491
HMI/PLC defacement messaging in Unitronics activity
Russia / CARR / Sandworm-adjacent
Initial Access
External Remote Services
T1133
Likely access through remote industrial interfaces / exposed remote control paths
Russia / CARR / Sandworm-adjacent
Initial Access
Valid Accounts
T1078
Likely weak credential or exposed HMI access model
Russia / CARR / Sandworm-adjacent
Discovery
Network Service Discovery
T1046
Assessed scanning / discovery of exposed water-control interfaces
Russia / CARR / Sandworm-adjacent
Impact
Service Stop / Process Disruption
T1489 / ICS-aligned impact
Manipulation of water-system process controls resulting in overflow / floodgate events
Russia / CARR / Sandworm-adjacent
Impact
Data Manipulation
T1565
Manipulation of set points, values, and control-system displays
Russia / CARR / Sandworm-adjacent
Collection / Influence
Screen Capture / Public Claims
T1113 / influence artifact
Claim videos showed screen recordings of HMI manipulation
China / Volt Typhoon
Initial Access
Exploit Public-Facing Application
T1190
Compromise of exposed edge devices and public-facing infrastructure
China / Volt Typhoon
Defense Evasion
Living-off-the-Land
Multiple
Use of native tools to blend with administration activity
China / Volt Typhoon
Execution
Windows Management Instrumentation
T1047
WMIC execution for process creation and credential-access workflows
China / Volt Typhoon
Credential Access
OS Credential Dumping: NTDS
T1003.003
Attempted extraction of ntds.dit and registry hives
China / Volt Typhoon
Command and Control
Proxy
T1090
netsh portproxy used for forwarding / covert access
China / Volt Typhoon
Execution
PowerShell
T1059.001
Native PowerShell use in LOTL activity
China / Volt Typhoon
Discovery
Account Discovery
T1087
Account and environment enumeration
China / Volt Typhoon
Discovery
Remote System Discovery
T1018
Network and host reconnaissance
China / Volt Typhoon
Lateral Movement
Remote Services
T1021
Movement through compromised internal environments
China / Volt Typhoon
Collection
Archive Collected Data
T1560
Staging and compression of collected data, including 7z examples
China / Volt Typhoon
Defense Evasion
Impair Defenses
T1562
Avoidance of EDR visibility through native tooling and low-noise operations
Poland / Unattributed
Initial Access
Internet Accessible Device
T0883
Internet-exposed ICS used as access path
Poland / Unattributed
Initial Access
Valid Accounts
T1078
Weak/default passwords
Poland / Unattributed
Impact
Data Manipulation
T1565
Potential manipulation of pump, filter, and dosing parameters
American Water / Unattributed
Initial Access
Unknown
N/A
Public reporting does not disclose technical access vector
American Water / Unattributed
Impact
Service Disruption
T1489, if confirmed
Customer-facing and billing systems were affected; company stated water/wastewater operations were not impacted
The Iran rows are directly mapped from AA26-097A’s ATT&CK tables; the Volt Typhoon rows are mapped from NSA/CISA/FBI partner reporting on living-off-the-land activity; the Russia and Poland rows are analytic mappings based on public incident descriptions and should be treated as lower-confidence than the official advisory mappings. (Internet Crime Complaint Center)
Threat Intelligence Report: Russia, Router, DNS, and Messaging-Layer Collection Operations
New research exposes Russian GRU (APT28) cyber operations using router compromise, DNS hijacking, and Signal/WhatsApp phishing for long-term espionage.
Executive Summary
Russian intelligence-linked cyber operations continue to emphasize communications-layer collection over disruptive or destructive activity. Recent reporting from U.S. agencies, allied partners, and private researchers highlights two lines of effort. One is the compromise of vulnerable SOHO routers for DNS hijacking and adversary-in-the-middle collection. The other is phishing against secure and commercial messaging platforms. Together, these operations support long-term intelligence collection against government, defense, critical infrastructure, diplomatic, media, NGO, and Ukraine-related targets.
The goal is access. Quiet and lasting. By taking routers and bending DNS, Russian operators can watch traffic, steer chosen victims, and steal credentials without putting malware on the machine. Their work against Signal, WhatsApp, Telegram, and Microsoft 365 gives them the other half: messages, contacts, trusted names, and private conversations. Together, it lets them collect, map people, and stay close to the networks that matter.
Key Assessments
Russia is increasingly treating edge infrastructure and messaging platforms as persistent intelligence-collection terrain. Router compromise provides GRU-linked operators with a passive upstream vantage point over victim traffic, while messaging-account compromise provides visibility into human networks, operational discussions, authentication workflows, and trusted social relationships. Together, these operations support long-duration intelligence collection, access persistence, credential interception, social-graph mapping, and pre-positioning for future contingency operations.
The most significant router activity is attributed to the Russian GRU's Unit 26165, tracked as APT28/Fancy Bear. U.S. and allied agencies report ongoing exploitation of vulnerable routers and edge devices to manipulate DNS and DHCP settings, enabling adversary-in-the-middle collection and credential interception without requiring endpoint malware. The objective is persistent intelligence collection and access rather than immediate disruption.
Evolution of GRU Tradecraft: From Intrusion and Disruption to Communications-Layer Collection
Russian messaging targeting now reaches beyond Signal. It includes WhatsApp, Telegram, and Microsoft 365 OAuth flows. The goal is not just the account. It is the conversation, the contact list, the trusted name, and the path into the next victim.
GRU tradecraft has changed, but the aim has not. The old operations broke in, stole, leaked, and sometimes destroyed. The new operation is quieter. It compromises routers, bends DNS, abuses QR codes, linked devices, cloud logins, and OAuth prompts. It sits close to the traffic and the trust. It maps who talks to whom and keeps access to the communications layer itself.
Victimology
The victim set falls into two groups. The first set is broad; router and DNS campaigns reach across home routers, small offices, and edge devices in many regions. However, Russian actors do not exploit every victim the same way. They look for value in targets with the highest likelihood of a significant intelligence yield such as military, government, critical infrastructure, foreign ministry, law enforcement, telecom, and email providers.
The second group is more personal. The messaging campaigns go after people whose conversations matter for Russian intelligence collection, including Ukrainian military personnel, government officials, politicians, journalists and researchers, activists, NGO staff and human-rights workers. Communications platforms like Signal, WhatsApp, Telegram, and Microsoft 365 then function as doors into contact lists, private conversations, trusted names, and the next victim.
Russian-linked targeting in 2026 focused on people and institutions with intelligence value. FBI/CISA reporting identified current and former government officials, military personnel, political figures, and journalists as high-value targets, while Volexity documented related activity against Ukraine-linked and human-rights organizations through Signal, WhatsApp, and Microsoft 365 OAuth compromise. Google reporting on defense-sector threats and Reuters coverage of Signal phishing against politicians, diplomats, military officers, and journalists reinforce the same pattern. The target set was strategic, not random.
Secondary exposure came through the tools those targets used every day. Microsoft reported Russian-linked compromise of home and small-office routers, DNS hijacking, and Outlook on the web targeting, while Lumen described broad router exploitation across more than 18,000 IPs in at least 120 countries. That scale gave operators a wide collection base. From there, they could sort victims by intelligence value and pursue the accounts, organizations, and communications channels that mattered most.
Router and DNS Hijacking Operations
In April 2026, the IC3 warned that Russian GRU actors were exploiting routers worldwide to steal military, government, and critical infrastructure data. The activity was tied to Unit 26165, also known as APT28, Fancy Bear, and Forest Blizzard. The actors changed DNS and DHCP settings, pushed victims through Russian-controlled resolvers, and used the access for quiet collection.
DOJ said the network relied on compromised SOHO routers, including thousands of TP-Link devices. The actors stole credentials, filtered DNS requests, and used false DNS records to stage adversary-in-the-middle attacks against services such as Outlook Web Access.
Microsoft assessed the campaign had run since at least August 2025, affecting more than 200 organizations and 5,000 consumer devices. The goal was not noise. It was persistent visibility.
Technical Tradecraft
The attack chain is simple and effective. The actors compromise routers, change DNS and DHCP settings, and push connected devices to use Russian-controlled resolvers. Most traffic can be watched quietly. Selected targets can be redirected.
The sharper risk is TLS interception. Forest Blizzard spoofed DNS responses for targeted domains, including Microsoft webmail. It then served bad certificates. If users clicked through the warning, the actor could read email and cloud traffic in plaintext.
The value is in the gap. Home routers, small-office routers, and remote-worker paths often sit outside enterprise EDR. The cloud account may be secure. The network edge may not be.
Messaging Application Targeting
Russian services are also targeting messaging accounts. FBI and CISA warned in March 2026 that Russian-linked actors had compromised thousands of commercial messaging accounts. Once inside, they could read messages, steal contacts, impersonate victims, and phish from trusted identities.
Google reported the same pressure against Signal. Actors abused the linked-device feature with malicious QR codes dressed as group invites, security alerts, pairing prompts, or Ukraine-themed apps. Once linked, the attacker could read future Signal messages in real time.
Microsoft saw Star Blizzard move into WhatsApp lures. Volexity saw suspected Russian actors use Signal and WhatsApp to push Microsoft 365 OAuth phishing. The pattern is clear. Russia is not only chasing accounts. It is chasing conversations, contacts, and trust.
Threat Level Assessment
The threat is highest for government, defense, critical infrastructure, telecom, energy, Ukraine-support organizations, journalists, NGOs, policy researchers, and other targets of likely intelligence value. These sectors align with Russian collection priorities and are most likely to face targeted exploitation after initial access.
Risk is also elevated for enterprises with remote or hybrid staff accessing Microsoft 365, webmail, VPN portals, cloud platforms, or sensitive collaboration tools from unmanaged home networks. For the broader private sector, the threat is moderate: router compromise may be broad, but follow-on exploitation appears selective and focused on victims with intelligence value.
Defensive Recommendations
Organizations should treat SOHO routers and remote-worker network paths as part of the attack surface. Replace end-of-life routers, patch firmware, disable remote administration, rotate router admin credentials, verify DNS settings, and monitor for unexpected resolvers. Remote-access policies should assume that home networks may be hostile.
For messaging applications, it is most important to prioritize linked-device hygiene. Users should regularly review linked devices in Signal, WhatsApp, and Telegram; remove unknown sessions; enable registration locks or PINs where available; and treat QR codes, group invites, “security alerts,” and video-call setup links as high-risk when received from sensitive contacts.
For enterprise identity, organizations should harden Microsoft 365 against OAuth and device-code phishing. Enforce phishing-resistant MFA, restrict risky OAuth consent flows, monitor anomalous device joins, review possible travel and token abuse, and train high-risk personnel not to return authentication codes to anyone.
Conclusion
Russian intelligence-linked cyber operations are moving closer to the communications layer. The objective is not immediate disruption. It is quiet access, persistent visibility, and control over the paths people use to communicate, authenticate, and coordinate.
The router and DNS hijacking activity shows the value of edge infrastructure. Compromised SOHO routers gave Russian operators a place to watch traffic, redirect selected victims, and intercept credentials without touching the endpoint. Messaging-platform targeting gave them the human layer: contacts, conversations, trusted names, and social relationships.
Together, these operations formed a durable intelligence-collection model. Broad compromise created scale. Selective follow-on targeting created value. Government, defense, critical infrastructure, Ukraine-support networks, journalists, NGOs, researchers, and political figures remained the highest-risk targets, while remote and hybrid workers widened the exposure path.
Now that this activity has been exposed, Russian operators will likely pivot again. They may shift infrastructure, rotate DNS and proxy methods, alter messaging lures, move to new linked-device abuse workflows, or lean harder into cloud identity and trusted-platform compromise. The collection requirement will remain. The access path will change.
The defensive lesson is direct. Organizations can no longer treat home routers, personal messaging apps, OAuth workflows, or linked-device features as outside the enterprise threat model. For Russian operators, these are not secondary surfaces. They are collection terrain. Once detected, that terrain will be reshaped, not abandoned.
Appendix A: MITRE ATT&CK Mapping
Initial Access/Persistence
Evasion and Credential Collection
Tactic
Technique
ID
Observed Use
Initial Access
Exploit Public-Facing Application
T1190
Exploitation of vulnerable SOHO and TP-Link routers
Initial Access
Phishing
T1566
Messaging-app phishing and OAuth lure delivery
Initial Access
Spearphishing Link
T1566.002
Delivery of malicious OAuth/device-code URLs
Initial Access
Valid Accounts
T1078
Abuse of compromised messaging and cloud accounts
Execution
User Execution
T1204
Victim interaction with QR codes and phishing links
Persistence
Account Manipulation
T1098
Addition of linked devices to Signal accounts
Persistence
External Remote Services
T1133
Continued access through compromised cloud identities
Persistence
Modify Authentication Process
T1556
OAuth workflow abuse and session persistence
Privilege Escalation
Abuse Elevation Control Mechanism
T1548
Router administrative compromise and configuration manipulation
Defense Evasion
Proxy
T1090
DNS and AiTM proxy routing
Defense Evasion
Impair Defenses
T1562
Operating outside enterprise EDR visibility
Credential Access
Adversary-in-the-Middle
T1557
TLS interception and DNS redirection
Credential Access
Steal or Forge Authentication Certificates
T1649
Use of fraudulent/invalid TLS certificates
Credential Access
Input Capture
T1056
Credential interception via redirected authentication flows
Credential Access
Credentials from Password Stores
T1555
Interception of stored or synced credentials
Discovery
Network Service Discovery
T1046
Reconnaissance through DNS visibility
Discovery
System Network Configuration Discovery
T1016
Observation of network and resolver configurations
Discovery
Gather Victim Identity Information
T1589
Collection of contact lists and identity relationships
Discovery
Gather Victim Network Information
T1590
DNS and routing visibility collection
Collection
Email Collection
T1114
Interception of Outlook Web Access traffic
Collection
Audio Capture
T1123
Potential collection through compromised communication workflows
Collection
Data from Information Repositories
T1213
Access to cloud-hosted communications
Collection
Screen Capture
T1113
Potential follow-on account monitoring activities
Collection
Data from Cloud Storage
T1530
Microsoft 365 and cloud-message access
Command and Control
Application Layer Protocol
T1071
DNS- and HTTPS-based communications
Command and Control
Encrypted Channel
T1573
Use of TLS/HTTPS transport
Command and Control
Dynamic Resolution
T1568
Actor-controlled DNS infrastructure
Exfiltration
Exfiltration Over Web Service
T1567
Cloud-account data access and exfiltration
Impact
Network Denial of Service
T1498
Potential latent capability through router control
Threat Intelligence Report: ZionSiphon OT Malware First Attempts? Psyops? Both?
Analysis of ZionSiphon (SCADA_SecurityPatch_v8.4.exe), a .NET OT malware targeting Israeli water utilities. Discover its IOCs, targets, and flawed activation code.
Executive Summary
ZionSiphon is a malware sample (“SCADA_SecurityPatch_v8.4.exe”) that has been circulating in public sandboxes since 2025. It is best understood as a Windows-based implant with explicit industrial control system (ICS) targeting intent but with a critical limitation in its verification of geographic data that fundamentally constrains its operational viability. While earlier analysis established the malware as functionally capable at the host level, subsequent findings confirm the presence of a critical XOR bug in its geographic validation logic, preventing the payload from activating in its intended environment. Additionally, there is no evidence of vendor-specific protocol handling, no confirmed register mapping, and no interaction with PLC firmware or engineering toolchains. The malware appears to rely on file-based or high-level configuration manipulation, which may not translate into actual process changes in most industrial environments.
The malware’s architecture remains coherent and deliberate. It combines geographic scoping, environment-aware execution, and embedded process manipulation logic, demonstrating a structured conceptual model of water treatment and desalination systems. Its internal string corpus provides high-confidence evidence of targeting, including references to Mekorot and major desalination facilities such as Sorek, Hadera, Ashdod, Palmachim, Shafdan, and Eilat water plants in Israel, alongside a dense vocabulary covering reverse osmosis, chlorine dosing, and salinity control. Filesystem-based validation and vendor-associated paths further reinforce that the malware is engineered to identify and operate within specific industrial environments.
However, the XOR validation flaw introduces a decisive constraint. The malware is designed to restrict execution to Israeli (“IL”) network ranges and to self-destruct if those conditions are not met. Due to the encoding error, this validation check never evaluates as true, meaning the malware fails to recognize its target environment even when present. As a result, the payload does not progress to its process manipulation stage and instead frequently triggers its own cleanup routines. This explains previously observed inconsistent or absent execution behavior: rather than reflecting conditional activation alone, it represents a systemic failure in the activation pathway.
The intended sabotage model remains conceptually clear despite this failure. ZionSiphon includes embedded parameters designed to manipulate critical control points, such as increasing chlorine dosing and altering reverse osmosis pressure, and contains references to industrial protocols including Modbus, DNP3, and S7comm. These elements demonstrate an understanding of how disruption could be achieved within water treatment systems. However, these attempts are just that. The malware does not contain actual ICS code that would attempt to effect those changes. What it does do, is attempt to do so through the manipulation of the OT layer (e.g. the Windows machines that the malware is detonated on to change those levels in the front end) However, because the activation condition cannot be satisfied, this logic remains dormant and unexecuted, reinforcing that the malware is not currently capable of delivering physical-world impact.
This reframes the malware’s maturity. ZionSiphon operates entirely at the Windows host layer, using registry persistence, PowerShell-based execution, and USB-oriented propagation logic. It is a real, functioning implant in terms of execution mechanics, but the XOR bug prevents it from transitioning into an active sabotage phase, rendering it effectively non-operational as an ICS attack tool.
Compounding this limitation is the absence of any meaningful communication stack or command-and-control (C2) channel. The malware assessed (SCADA_SecurityPatch_v8.4.exe)
does not maintain operator connectivity, does not receive tasking, and cannot adapt its behavior dynamically once deployed. This removes the possibility of controlled, iterative interaction with target systems, an essential component of any serious ICS attack capability.
As a result, even in a hypothetical scenario where the activation flaw did not exist, the operational model would still be extremely constrained. The malware behaves more like a single-shot, pre-scripted payload than a coordinated intrusion tool. In practical terms, this resembles a “drive-by” action with no ability to correct aim, adjust targeting, or respond to environmental feedback and in this case, executed with insufficient precision to achieve its intended effect.
In its present form, ZionSiphon is therefore more accurately categorized as a prototype, misconfigured payload, or intentionally constrained artifact, rather than a deployable cyber-physical weapon. Its structure demonstrates intent and conceptual targeting, but lacks the control, reliability, and feedback mechanisms required for sustained or meaningful impact on water infrastructure systems.
An additional dimension now strengthens this interpretation: the nature of the code itself. The malware exhibits a pattern of semantically rich but technically shallow ICS logic, where process terminology and targeting concepts are convincing, but underlying implementation depth is limited. This includes incomplete protocol handling, an absence of PLC-resident execution, and a lack of deterministic control paths. Combined with the presence of a critical logic error in a core validation function, this suggests a development process that may have incorporated partial automation or assisted code generation, rather than rigorous engineering validation. While not determinative, the structure is consistent with a scenario in which elements of the code, particularly naming conventions, scaffolding, or ICS-related logic may have been augmented through LLM-style assistance, while overall assembly and operational framing remain human-directed.
The presence of explicit ideological messaging embedded within the binary further complicates interpretation. Decoded content referencing attacks on Israeli population centers introduces a clear narrative and psychological layer that is independent of technical execution. When combined with a payload that cannot activate and a second stage that cannot execute past the Windows host, this raises the possibility that the malware functions, at least in part, as a PSYOP-adjacent artifact, where the objective is to project capability, signal intent, and shape perception rather than achieve immediate operational effect.
From a capability perspective, ZionSiphon still reflects an early-stage attempt to approximate a Stuxnet-like attack model, leveraging a Windows foothold to influence industrial processes. However, the combination of incomplete ICS integration, execution fragility, and the XOR validation failure indicates that it falls well short of a reliable implementation. Whether this reflects immature development, operator error, or deliberate constraint remains unresolved, but it clearly places the malware within a mid-tier or experimental development context.
The most accurate interpretation is therefore layered:
Technical Layer: A real Windows-based malware implant with coherent targeting logic
Capability Layer: Non-functional as an ICS weapon due to a critical validation flaw
Development Layer: Likely a prototype or partially validated build, with possible assisted code generation elements
Psychological Layer: Potential signaling artifact, where perceived capability exceeds actual execution
ZionSiphon should therefore be understood as a conceptually mature but functionally broken ICS-targeting malware, whose significance lies less in its current operational capability and more in what it reveals about the evolving accessibility, modularity, and perception-driven use of cyber-physical attack tooling.
Malware Analysis: SCADA_SecurityPatch_v8.4.exe
ZionSiphon (SCADA_SecurityPatch_v8.4.exe), as understood by the malware sample from 2025, is best understood as a Windows-hosted operational malware implant built around explicit OT and water-sector targeting intent rather than a purely conceptual or symbolic artifact. The cumulative evidence gathered through static reverse engineering, sandbox telemetry, recovered string analysis, and vendor reporting materially reduces earlier uncertainty about the malware’s purpose and operational model. The sample is a PE32 Mono/.NET executable that relies on the Common Language Runtime (mscoree.dll) for execution, placing its logic entirely within the Windows host layer rather than within PLC firmware or native controller environments. Architecturally, this positions ZionSiphon as host-based OT intrusion tooling designed to compromise operator or engineering workstations as the pathway toward potential process disruption.
The malware’s execution workflow is internally coherent and operationally plausible. Embedded identifiers and execution strings including RunAsAdmin, SystemHealthCheck, Start-Process -Verb RunAs, target_verify.log, and delete.bat map to a structured lifecycle involving privilege escalation, persistence, environment validation, and cleanup. Hybrid Analysis telemetry confirmed that the sample stages itself into %LOCALAPPDATA%\svchost.exe, establishes persistence through the current-user Run registry key under SYSTEMHEALTHCHECK, and invokes cleanup routines through batch execution if execution conditions are not met. The masquerading of the payload as svchost.exe reflects recognizable adversary tradecraft intended to blend into legitimate Windows process naming conventions rather than functioning as a placeholder or incomplete concept.
The strongest evidence of deliberate targeting lies within the malware’s environment modeling and industrial process references. The binary contains extensive water-sector-specific configuration names and file paths including C:\ChlorineControl.dat, C:\DesalConfig.ini, C:\RO_PumpSettings.ini, C:\SalinityControl.ini, and C:\WaterTreatment.ini, alongside references to industrial and desalination-associated entities such as Schneider Electric, IDE Technologies, and WaterGenix. These are not generic enterprise strings or superficial theming elements. Instead, they reflect a logically structured representation of desalination and water-treatment operational environments. Additional managed-code identifiers including IncreaseChlorineLevel, IsDamDesalinationPlant, GetProcesses, and CreateUSBShortcut further demonstrate that the malware was designed to enumerate processes, validate target environments, and interact with removable media in ways consistent with industrial intrusion workflows.
The sabotage-oriented process logic embedded in the sample reinforces this assessment. Strings such as Chlorine_Dose=10, Chlorine_Flow=MAX, Chlorine_Pump=ON, Chlorine_Valve=OPEN, and RO_Pressure=80 define a conceptual model for manipulating chemical dosing and reverse-osmosis pressure systems. These parameters correspond to operationally sensitive functions within water-treatment infrastructure and imply an intent to push process variables into potentially disruptive or unsafe states. While there is no evidence that the malware contains mature PLC-specific payload delivery or ladder-logic manipulation capability, the embedded logic clearly moves beyond espionage-oriented collection tooling and into the domain of intended process interference.
At the same time, the malware remains technically constrained and immature when compared to fully operational ICS-native malware families such as Stuxnet, TRITON, Industroyer, or IOCONTROL. Although the sample references industrial protocols including Modbus and DNP3, there is still no evidence of complete protocol implementation, vendor engineering software integration, PLC firmware interaction, or safety-system manipulation. Hybrid Analysis telemetry also confirmed the absence of meaningful DNS resolution, outbound HTTP traffic, or operational command-and-control communications during execution. Despite containing networking functionality through .NET TcpClient, socket APIs, and connection-handling routines, the malware did not demonstrate active beaconing or remote tasking behavior. This strongly suggests an autonomous or pre-scripted execution model in which actions are triggered locally through environment validation rather than controlled dynamically through external infrastructure.
The detonated filename itself further reinforces this operational model. The use of naming the file SCADA_SecurityPatch_v8.4.exe strongly suggests deliberate masquerading as a legitimate industrial software update or maintenance utility. Combined with the extensive OT-themed naming conventions and water-sector references embedded throughout the sample, this creates a highly plausible watering-hole or trusted-update delivery scenario. Under such a model, attackers could establish a malicious website or compromised vendor portal advertising a supposed SCADA or water-treatment software patch and direct operators or engineers toward it through spear-phishing or industry-themed communications. Once executed, the malware could establish persistence, validate the target environment, and opportunistically seed removable media for downstream propagation into more sensitive operational enclaves.
Execution gating and cleanup behavior further support the conclusion that the malware was designed for selective deployment rather than indiscriminate execution. The presence of target_verify.log, environment-validation logic, Israeli IP-range geofencing, and cleanup mechanisms such as delete.bat indicate that the malware evaluates its environment before activating fully and removes artifacts if conditions are not satisfied. This reflects a controlled operational philosophy intended to minimize exposure and reduce forensic visibility outside intended targets.
Overall, ZionSiphon occupies an unusual position within the spectrum of OT malware. It is substantially more operationally coherent than simple propaganda or proof-of-concept malware and demonstrates a complete host-level intrusion lifecycle including privilege escalation, persistence, environment validation, removable-media interaction, and cleanup. At the same time, it lacks the mature ICS-native functionality associated with the most sophisticated cyber-physical malware families. The result is a malware framework that appears operationally credible at the Windows host layer and explicitly aligned toward water-sector disruption, while still remaining developmental, partially constrained, and dependent on contextual execution and human-assisted propagation to achieve meaningful operational impact.
Actor Assessment and Strategic Framing
Attribution remains unconfirmed. The available evidence supports a plausible Iranian nexus, but it does not prove that ZionSiphon was created or deployed by an Iranian state actor, an Iranian proxy, or any specific Iranian APT cluster. The malware’s target selection, embedded references to Israeli water infrastructure, and decoded anti-Israel messaging align with operational themes long associated with Iranian cyber activity directed at Israeli civilian infrastructure. Public reporting also places the malware in the context of Israeli water-treatment and desalination targeting.
Within that frame, the best technical fit is still a mid-tier, MOIS-aligned ecosystem such as MuddyWater or a related contractor/proxy environment, rather than a top-tier bespoke ICS weapons program. The sample’s architecture is a managed PE32 Mono/.NET executable that runs through mscoree.dll, stages itself as %LOCALAPPDATA%\svchost.exe, persists via the SystemHealthCheck Run key, elevates through PowerShell using Start-Process -FilePath ... -Verb RunAs, and cleans up through delete.bat and target_verify.log. That pattern is closer to commodity or lightly customized Iranian tradecraft than to a highly specialized controller-native platform. The Falcon Sandbox report also confirms a malicious score, registry persistence, self-deletion behavior, guarded-memory anti-analysis features, Base64 decoding capability, and the absence of relevant DNS, HTTP, or contacted-host infrastructure.
At the same time, the malware does not exhibit the hallmarks of a mature ICS weapon. It contains water-sector process logic, industrial vocabulary, and protocol references, but no demonstrated PLC-resident code, no ladder-logic manipulation, no vendor-specific engineering-stack abuse, no validated register maps, and no deterministic command path into real control systems. Public reporting similarly describes it as a targeted OT/ICS malware strain aimed at Israeli water systems, but not as a proven Stuxnet- or TRITON-class capability. The most defensible technical reading is that this is a Windows-hosted OT sabotage implant whose ICS layer is still incomplete, experimental, or intentionally simplified. (Darktrace)
The strongest evidence for an Iran-aligned framing comes from the decoded strings. The sample contains extensive water/OT targeting strings tied to Israeli infrastructure and desalination operations, including facility and environment markers such as Mekorot, Sorek, Hadera, Ashdod, Palmachim, Shafdan, and Eilat Desal, alongside control-oriented terms such as DesalPLC, OsmosisPLC, WaterPLC, ChlorineCtrl, ChlorineDose, RO_Pump, and BrineControl. More importantly, the decoded ideological content includes the explicit line “Poisoning the population of Tel Aviv and Haifa”, and the malware also contains an execution-guardrail message reading “Target not matched. Operation restricted to IL ranges. Self-destruct initiated.” These strings materially strengthen the assessment that the malware is framed as anti-Israel and specifically oriented toward Israeli water infrastructure.
However, those same strings are also the clearest reason not to overstate attribution. Ideological text that points toward Iran and against Israel can support an Iran-aligned hypothesis, but it can also function as attribution theater. An actor seeking to implicate Iran, exaggerate Iranian capability, or exploit existing expectations about Iranian cyber behavior could deliberately embed precisely these kinds of messages. The sample’s combination of overt anti-Israel language, Israeli geofencing, Mekorot branding, and incomplete ICS execution depth is consistent not only with a genuine Iranian capability in development, but also with a scenario in which another actor is muddying the water by constructing a malware artifact that looks Iranian on first inspection. In that sense, the ideological layer is evidentiary, but not dispositive.
That ambiguity is especially important because ZionSiphon also reads as an early attempt at a Stuxnet-like attack path against Israel, but without Stuxnet-like engineering maturity. The malware clearly models cyber-physical effects: it hunts for desalination and treatment artifacts, references Modbus and DNP3, and embeds static sabotage values such as Chlorine_Dose=10, Chlorine_Flow=MAX, Chlorine_Pump=ON, Chlorine_Valve=OPEN, and RO_Pressure=80. It is trying to move from a Windows foothold on operator or engineering systems into process disruption. That is strategically significant. But the implementation still falls well short of a real, deterministic industrial attack platform, which makes it plausible both as a prototype capability and as a signaling artifact meant to invoke the idea of an Iranian Stuxnet-for-Israel scenario.
The Falcon Sandbox findings reinforce the dual-use interpretation. The sample is operationally real at the host level: it persists, stages, executes, validates the environment, and self-cleans. But it shows no relevant DNS requests, no relevant HTTP traffic, and no relevant contacted hosts, which means there is no public evidence of a live C2-backed campaign around this sample. That absence supports the view that ZionSiphon is either a self-contained, pre-scripted sabotage implant or a demonstration artifact whose strategic value derives partly from being discovered and analyzed.
The most accurate conclusion is therefore deliberately layered. ZionSiphon may well be consistent with MOIS-linked Iranian operational patterns, and MuddyWater remains the closest tradecraft fit among known Iranian clusters. But there is still no real proof that an Iranian actor built it, and the available data also supports the possibility that another actor intentionally embedded Iran-supporting and anti-Israel text to create exactly that impression. In practical terms, ZionSiphon should be understood as a hybrid artifact: a real host-based malware implant with clear OT sabotage intent, a likely experimental or early-stage attempt to approximate a Stuxnet-like attack path against Israeli infrastructure, and a possible PSYOP or attribution-shaping tool whose ambiguity may itself be part of its operational effect.
Detection Profile and Operational Maturity Assessment
Integration of multi-source analysis including static reverse engineering of the uploaded samples, sandbox telemetry from ANY.RUN and Hybrid Analysis, and detection data from VirusTotal provides a consolidated view of ZionSiphon’s true position within the threat landscape. The resulting picture is not ambiguous: the malware is operationally real at the host-implant layer, but its ICS disruption capability remains unproven and likely immature in its current form.
From a detection standpoint, VirusTotal confirms that the sample is broadly recognized as malicious across multiple engines. However, the classification is inconsistent and generic, with most vendors labeling the file as a .NET or MSIL-based trojan, loader, or agent. There is no consensus naming, and critically, no engine identifies the sample as ICS malware or associates it with industrial protocol abuse. This absence is not incidental. It indicates that the malware’s OT-specific logic is not driving its detection profile. Instead, detection is triggered by conventional behaviors, such as PowerShell-based execution, registry persistence, process masquerading, and general suspicious activity, placing ZionSiphon firmly within the detection envelope of commodity Windows malware.
This observation aligns directly with the static and dynamic analysis of the binary. Reverse engineering confirms that the sample is a Mono/.NET executable with a minimal import table and all functional logic embedded internally. The malware establishes persistence through a Run key (SystemHealthCheck) pointing to a disguised payload (svchost.exe), relaunches itself with elevated privileges via PowerShell, and implements cleanup routines using delete.bat and target_verify.log. These behaviors are not theoretical; they are consistent across sandbox environments and embedded directly in the binary. The implant layer is therefore fully functional and operationally credible, with no indication of being a placeholder or decoy.
Where the assessment becomes more complex is at the ICS interaction layer. The binary contains extensive water-sector targeting artifacts, including configuration paths, process identifiers, and explicit manipulation strings such as Chlorine_Dose=10, Chlorine_Flow=MAX, and RO_Pressure=80. These elements demonstrate clear intent to interfere with water treatment processes, particularly chemical dosing and pressure regulation. However, the implementation lacks the depth required for reliable real-world execution.
Dynamic analysis reinforces this limitation. Execution behavior varies significantly between sandbox runs, with some environments exhibiting full persistence and artifact creation, while others produce minimal activity or even a “no threat detected” verdict. This inconsistency suggests that the malware is highly dependent on environmental conditions, potentially due to validation gating, incomplete code paths, or anti-analysis mechanisms. While this behavior could be interpreted as evasive design, it also introduces uncertainty regarding execution reliability, particularly in non-laboratory conditions.
The broader implication is that ZionSiphon occupies a hybrid position between commodity malware and specialized OT tooling. Its underlying framework is indistinguishable from generic .NET malware, as confirmed by both imphash clustering and VirusTotal classification. Its distinguishing features, the ICS targeting logic and sabotage intent, are layered on top of this framework but are not yet expressed in a technically mature or reliably executable form. This architectural choice provides flexibility and ease of development but limits the malware’s ability to achieve consistent physical impact.
From an operational perspective, the malware is highly likely to succeed in compromising Windows-based systems, particularly those associated with engineering or supervisory functions in water-sector environments. It can persist, execute, and perform environment validation with high confidence. It may also disrupt local applications or introduce configuration inconsistencies that affect operator workflows. However, the probability that it can directly and reliably manipulate physical processes such as chlorine dosing or system pressure—remains low without further development or environment-specific customization.
This duality is central to understanding ZionSiphon. It is not a non-functional artifact, nor is it a mature ICS weapon. It is a functional host-based implant with embedded, but not yet fully realized, OT disruption logic. Its current form suggests either an early-stage capability under development or a modular framework intended for future enhancement. In either case, the gap between intent and execution is evident.
The most defensible conclusion is that ZionSiphon represents a transitional class of malware, bridging traditional IT compromise and potential OT impact. Its significance lies less in its immediate effectiveness and more in what it signals: that targeted, domain-aware cyber-physical tooling can be constructed using relatively accessible components. While it does not yet demonstrate the precision or reliability of established ICS malware families, it provides a clear indication of direction toward more modular, adaptable, and potentially proliferating OT-focused threats.
Strategic Assessment and Forward Outlook
ZionSiphon is best understood as a targeted ICS sabotage capability in development, combining deliberate, domain-aware targeting logic with a modular and reusable technical foundation. The accumulated evidence of static analysis, sandbox telemetry, and decoded string corpus confirms that the malware encodes a coherent conceptual model of water treatment operations, particularly chlorine dosing and reverse osmosis control. At the same time, it relies on a commodity Windows/.NET implant layer for execution, persistence, privilege escalation, and delivery. This hybrid construction places the malware in a transitional category: operationally real and credible at the host level, but not yet reliably effective at the control-system level.
The broader strategic context reinforces this interpretation, while also introducing a critical layer of ambiguity. Since 2025, Israeli water infrastructure, especially systems associated with Mekorot, has remained a recurring target in cyber operations and reporting. ZionSiphon fits squarely within that targeting pattern, including its geographic scoping to Israeli networks and its explicit references to desalination facilities and water-treatment processes. However, there is still no publicly confirmed instance of successful cyber-induced physical disruption to these systems in the current reporting cycle. This persistent gap between targeting intensity and observable impact is analytically significant. It highlights both the priority placed on this sector and the continued limitations of adversary capabilities.
ZionSiphon embodies that gap directly. Its embedded parameter manipulation strings, process-specific vocabulary, and environment validation logic clearly demonstrate intent to influence physical processes. Yet its reliance on static configuration assumptions, incomplete industrial protocol handling, absence of validated PLC interaction, and environment-dependent execution behavior indicate that it is not yet a mature or deterministic ICS weapon. In its current form, the malware is more likely to produce host-level compromise, configuration disruption, and operational friction than sustained or precise control over industrial processes.
At the same time, the sample introduces an additional dimension that materially affects its strategic interpretation: the presence of explicit ideological messaging and narrative cues embedded within the binary. These elements are not required for execution and instead serve a signaling function, shaping how the malware is interpreted once discovered. Combined with its Israeli targeting, they create an artifact that is not purely technical. This opens the possibility that ZionSiphon is functioning in part as a PSYOP-adjacent tool, where perception of capability and intent is itself an operational objective. Importantly, while the messaging aligns with Iran-aligned narratives, there is no definitive proof that the malware originates from an Iranian actor. The same elements that support an Iranian attribution hypothesis could also be deliberately constructed by another actor to mimic, exaggerate, or redirect attribution, effectively muddying the waters.
From a capability perspective, ZionSiphon also reads as an early-stage attempt to approximate a Stuxnet-like attack model, but within a far less mature development ecosystem. It follows the same broad conceptual pathway leveraging a Windows foothold to reach and influence physical processes but lacks the deep engineering integration, protocol precision, and reliability that defined earlier state-developed ICS weapons. It is therefore best characterized as a process-aware prototype, reflecting ambition and direction rather than fully realized capability.
Despite its current limitations, the malware’s architecture carries significant forward-looking implications. By decoupling ICS-specific logic from the underlying implant, ZionSiphon reflects a modular design philosophy that enables rapid iteration and reuse. The Windows-based execution layer provides a stable foundation onto which increasingly sophisticated OT-specific components can be layered. Future variants could therefore evolve quickly, incorporating:
More complete protocol implementations (e.g., Modbus, DNP3, or vendor-specific interfaces)
Improved environment detection and targeting precision
Greater execution reliability and error handling
Limited feedback mechanisms or controlled tasking capabilities
Such evolution would move the capability from conceptual disruption toward repeatable and controllable operational effects, narrowing the current gap between intent and execution.
The most significant implication is structural rather than purely technical. ZionSiphon signals that cyber-physical attack development is becoming more accessible. Unlike earlier ICS malware such as Stuxnet, which required extensive resources, specialized engineering knowledge, and tightly integrated development pipelines, this model leverages widely available tooling and incremental domain understanding. The barrier to entry is therefore lower, enabling a broader range of actors including contractors, proxy groups, or semi-professional operators to experiment with OT-oriented malware development.
This shift also increases the likelihood of proliferation and adaptation. The same architectural model could be repurposed across sectors by substituting environment-specific logic, extending beyond water infrastructure into energy, manufacturing, or transportation systems. Even if ZionSiphon itself remains limited, it represents a template for iterative development, where successive improvements progressively close the gap between conceptual capability and operational effectiveness.
Finally, the dual-use nature of the malware remains strategically important. In an environment where no confirmed physical attacks have occurred despite persistent targeting, artifacts like ZionSiphon may serve not only as technical tools but also as instruments of signaling and perception management. Their discovery, analysis, and public reporting contribute to an evolving perception of cyber-physical threat capability, influencing defensive postures, policy responses, and strategic calculations.
ZionSiphon should therefore be understood not as a fully realized ICS weapon, but as a directional indicator: a hybrid artifact that combines real host-level capability, emerging cyber-physical intent, and potential psychological or attribution-shaping effects.
Appendix A – Indicators of Compromise: ZionSiphon / SCADA_SecurityPatch_v8.4.exe
Hybrid mapped the sample to execution guardrails, sandbox/VM checks, host discovery, process enumeration, and language/locale discovery.
A.5 Water / OT Targeting Indicators
Process name checks
DesalPLC
OsmosisPLC
ROController
DesalMonitor
SchneiderRO
RO_Filter
DamRO
ChlorineDose
ReverseOsmosis
RO_Membrane
WaterGenix
DesalFlow
RO_Pump
WaterTreat
ChlorineCtrl
SalinityCtrl
WaterPLC
SeaWaterRO
BrineControl
Directory checks
C:\Program Files\Desalination
C:\Program Files\RO Systems
C:\Program Files\Schneider Electric\Desal
C:\Program Files\DesalTech
C:\Program Files\IDE Technologies
C:\Program Files\Aqua Solutions
C:\Program Files\Water Treatment
C:\Program Files\Hydro Systems
Configuration file checks
C:\DesalConfig.ini
C:\WaterTreatment.ini
C:\ROConfig.ini
C:\ChlorineControl.dat
C:\DesalSettings.conf
C:\RO_PumpSettings.ini
C:\Program Files\Desalination\system.cfg
C:\SalinityControl.ini
Facility / sector strings
Mekorot
Shafdan
Sorek
Schneider Electric
Hadera
IDE Technologies
Ashdod
WaterGenix
Palmachim
Hybrid file metadata also lists ProductName and FileDescription as Mekorot, reinforcing the Israeli water-sector masquerade.
A.6 Configuration Manipulation Indicators
Chlorine_Dose
10
Chlorine_Pump
ON
Chlorine_Flow
MAX
Chlorine_Valve
OPEN
RO_Pressure
80
These remain high-confidence impact-oriented strings tied to chlorine handling and reverse-osmosis pressure manipulation.
A.7 Network and Protocol Indicators
Network APIs and socket capability
Hybrid confirms socket capability but also reports:
Network APIs
System.Net
NetworkStream.Read
System.Net.Sockets
NetworkStream.Write
TcpClient
TcpClient.Close
TcpClient.Connect
WSAStartup
TcpClient.BeginConnect
setsockopt
TcpClient.GetStream
gethostbyname
GetAddrInfoW
Network activity
No relevant DNS requests
No relevant contacted hosts
No relevant HTTP requests
This supports the assessment that no operational C2 was observed during detonation.
Industrial protocol references
Protocol / pattern
Bytes
Modbus
DNP3
S7comm
Modbus request pattern
01 03 00 00 00 0A
DNP3 partial pattern
05 64 0A 0C 01 02
S7comm partial pattern
03 00 00 13 0E 00
S7comm partial pattern
05 00 1C 22 1E
A.8 Targeting and Geofencing Indicators
IPv4 ranges observed in binary/memory
2.52.0.0 – 2.55.255.255
5.28.0.0 – 5.29.255.255
79.176.0.0 – 79.191.255.255
212.150.0.0 – 212.150.255.255
Hybrid directly reported the 2.52.0.0-2.55.255.255 and 5.28.0.0-5.29.255.255 ranges as potential IP ranges in binary/memory.
A.9 USB / Removable-Media Propagation Indicators
Recovered strings and behavioral primitives
CreateUSBShortcut
SetAttributes
DriveInfo
.lnk
GetLogicalDrives
shell32.dll
GetFiles
svchost.exe
CopyFileW
CopyFileExW
Assessed removable-media artifacts
\svchost.exe
*.lnk files in root of removable media
Shortcut TargetPath pointing to hidden executable
Icon spoofing via shell32.dll,4
Hybrid confirms GetLogicalDrives, file-copy behavior, and file-attribute capability, but did not capture a complete successful USB infection event during detonation. Therefore, USB propagation should be treated as strongly supported by strings and vendor reverse engineering, not as a fully observed sandbox behavior.
A.10 Self-Deletion and Cleanup Indicators
Cleanup artifacts
%TEMP%\delete.bat
cmd.exe /c "%TEMP%\delete.bat"
Observed deletion targets
C:\SCADA_SecurityPatch_v8.4.exe
%TEMP%\delete.bat
Hybrid observed cmd.exe executing %TEMP%\delete.bat and marking both the original sample and cleanup script for deletion.
No confirmed fully executed USB infection event in sandboxThese negative indicators suggest a constrained or pre-operational deployment model, likely centered on local execution, environmental validation, and workflow-assisted movement rather than remotely tasked command-and-control.
APPENDIX B Static Reverse Engineering of the Uploaded Sample
The uploaded file, identified by SHA-256 07c3bbe60d47240df7152f72beb98ea373d9600946860bad12f7bc617a5d6f5f, is a PE32 Mono/.NET executable, indicating that all operational logic is implemented in managed code rather than native binaries. The import table is minimal and limited to the CLR bootstrap (mscoree.dll via _CorExeMain), which is characteristic of .NET malware that delegates functionality to internal assemblies. This structural choice confirms that the sample is a Windows-hosted implant, not a controller-resident ICS payload, and that its operational model depends on execution within userland environments such as engineering workstations or operator systems.
The binary exhibits a coherent and internally consistent execution model. Embedded strings and method identifiers indicate that the malware initiates execution by attempting to relaunch itself with elevated privileges through PowerShell, using a command pattern consistent with Start-Process -FilePath ... -Verb RunAs. This is followed by persistence establishment via the Windows registry. Specifically, the malware is designed to write a Run key under Software\Microsoft\Windows\CurrentVersion\Run using the value name SystemHealthCheck, pointing to a staged payload masquerading as svchost.exe within the user’s local application directory. This persistence mechanism is operationally credible and aligns with common masquerade techniques intended to blend malicious binaries with legitimate system processes.
The sample’s most distinctive feature is its environment validation logic, which is explicitly tailored to water treatment and desalination systems. The binary contains numerous hardcoded file paths and configuration filenames associated with industrial processes, including chlorine control, reverse osmosis, salinity regulation, and water treatment operations. These include paths such as C:\ChlorineControl.dat, C:\DesalConfig.ini, C:\RO_PumpSettings.ini, and C:\WaterTreatment.ini, as well as vendor- or application-associated directories such as C:\Program Files\Schneider Electric\Desal\config.ini and C:\Program Files\WaterGenix\system.conf. The presence of these strings indicates that the malware performs host-based reconnaissance to determine whether it is executing within a relevant operational environment before proceeding.
This validation stage is further reinforced by recovered method names such as IsDamDesalinationPlant, GetProcesses, and DriveInfo, which suggest a structured approach to system classification. The malware likely enumerates running processes, inspects filesystem artifacts, and evaluates system characteristics to determine whether the host is associated with desalination or water treatment infrastructure. Only upon successful validation does the malware proceed to its impact phase, indicating a gated execution model designed to minimize noise and avoid unintended activation.
The impact logic itself is revealed through a set of explicit configuration strings embedded in the binary. These include Chlorine_Dose=10, Chlorine_Flow=MAX, Chlorine_Pump=ON, Chlorine_Valve=OPEN, and RO_Pressure=80. These values correspond directly to operational parameters within water treatment systems and suggest that the malware is designed to modify or inject configuration data affecting chemical dosing and pressure control. While static analysis cannot confirm whether these values map precisely to real-world control systems, their specificity and coherence indicate a clear intent to disrupt physical processes, particularly those related to water quality and system stability.
In addition to its primary payload, the malware includes functionality for removable media interaction, as evidenced by strings such as CreateUSBShortcut, .lnk, and shell32.dll, 4. This suggests the ability to create deceptive shortcut files on USB drives, potentially enabling lateral movement or execution in segmented environments where direct network propagation is not feasible. This feature is consistent with operational environments in ICS networks, where air gaps or limited connectivity often necessitate physical transfer mechanisms.
The sample also implements a cleanup and self-deletion routine, using artifacts such as target_verify.log and delete.bat. These components indicate that the malware logs the outcome of its environment validation and, if conditions are not met or execution fails, initiates a self-removal process via a batch script. This behavior aligns with a low-footprint operational model, where the malware seeks to avoid detection by minimizing residual artifacts on non-target systems.
From a tradecraft perspective, the binary demonstrates a functional and intentional design. It includes persistence, privilege escalation, environment validation, removable media handling, and process-specific manipulation logic. These elements collectively support the assessment that the sample is a real and operational Windows-based implant, not merely a decoy or string-based artifact. However, the malware does not exhibit the characteristics of a mature ICS platform. There is no evidence of PLC firmware interaction, vendor-specific engineering tool manipulation, or deep integration with industrial control protocols at the controller level.
The most accurate classification is that this sample represents a host-side OT sabotage implant, designed to operate within Windows environments that interface with water treatment systems. Its strength lies in its targeting logic and process awareness, rather than in advanced ICS exploitation techniques. This places it in a transitional category of malware that bridges traditional IT compromise and OT disruption, relying on access to engineering or supervisory systems to influence physical processes.
Threat Intelligence Report: The SDA / Structura / Doppelgänger, Influence Operations, Infrastructure, Reach, and Potential
How does the Doppelgänger influence campaign reach 5M+ users? Read DTI’s latest report on the SDA/Structura ecosystem, featuring a deep dive into narrative propagation, domain rotation tactics, and a 72-hour crisis influence timeline.
Executive Summary
The Doppelgänger (aka Social Design Agency (SDA)) campaigns are a coordinated series of online influence operations attributed to Russian-linked actors and associated with the technical operator, Structura. The campaign leverages a distributed ecosystem of spoofed media websites, Telegram amplification networks, and coordinated X/Twitter bot account clusters to disseminate political narratives targeting Western audiences.
The operational architecture is designed around a feeder-and-amplifier model. Controlled websites host narrative artifacts such as articles, memes, and commentary. These artifacts are distributed through Telegram channels with large subscriber bases and are subsequently injected into active discussions on X through coordinated reply swarms.
This architecture enables the campaign to scale rapidly while maintaining resilience against disruption. Domain infrastructure can be regenerated quickly, social accounts are disposable, and narratives can be redistributed through independent amplification channels.
Analysis of subscriber counts and documented campaign activity suggests that a typical Doppelgänger narrative wave exposes approximately 1.5 to 2.7 million users, with larger event-driven campaigns potentially reaching 3 to 5 million users.
The campaign’s objective is not necessarily direct persuasion but narrative saturation, in which repeated exposure across multiple platforms introduces and normalizes targeted narratives within the information ecosystem.
Actor and Organizational Structure
The operational structure of the Doppelgänger influence campaign reflects a coordinated system that combines strategic messaging organizations, technical infrastructure providers, and elements associated with Russia’s broader state-directed political communication environment. At the center of this ecosystem are two entities that appear to play complementary roles: the Social Design Agency (SDA) and Structura. Together, these organizations form the operational core of the campaign’s architecture, linking narrative development with the technical systems required to publish, distribute, and amplify influence content across multiple digital platforms.
The Social Design Agency (SDA) appears to function as the primary strategic and operational planning body behind the campaign. Open-source investigations and public reporting have associated the organization with a number of large-scale information operations targeting audiences in Europe and North America. Within the Doppelgänger ecosystem, SDA’s role is assessed to focus on the design and coordination of narrative components that underpin the campaign’s messaging. This includes the development of thematic narratives, the planning and timing of coordinated influence activities, and the orchestration of distribution through social
media channels and affiliated amplification networks. SDA also appears to maintain relationships with technical service providers responsible for maintaining the infrastructure used to host and disseminate campaign content. In this capacity, the organization functions as the central coordinating entity that aligns narrative development, operational timing, and distribution strategies across the broader influence network.
Complementing this strategic function, Structura appears to provide the technical infrastructure that allows the campaign to operate at scale. Structura acts as the backbone of the Doppelgänger ecosystem by managing the digital assets used to publish, distribute, and track campaign narratives. Its responsibilities include the registration and administration of domains used for pseudo-media websites, the deployment and maintenance of the web infrastructure hosting campaign articles, and the operation of redirect systems that guide audiences from social media platforms to campaign-controlled sites. Structura is also believed to operate analytics and tracking capabilities that enable operators to measure engagement levels, monitor traffic patterns, and evaluate the performance of individual narratives. These capabilities support both operational resilience and adaptive campaign management, allowing infrastructure to be regenerated or replaced quickly when domains are seized, blocked, or otherwise disrupted.
Evidence from multiple public investigations further suggests that the Doppelgänger campaign operates within a broader ecosystem of Russian state-aligned information activities. Reporting has connected elements of the network to organizations and political communication structures associated with the Russian Presidential Administration, including the government-linked organization ANO Dialog and senior political figures such as Sergei Kiriyenko, who has been identified in public reporting as playing a significant role in coordinating domestic and international messaging initiatives. While the precise command relationships within this ecosystem are not fully transparent, these connections indicate that the operation likely functions within a wider strategic communications environment linked to Russian state interests.
Taken together, the interaction between SDA’s narrative planning and campaign coordination functions, Structura’s management of technical infrastructure, and the broader involvement of state-linked political communication structures suggests a coordinated operational model. Within this model, influence operations are integrated into a larger system of information confrontation. Inside the system, messaging strategy, technical infrastructure, and distribution networks are aligned to introduce and amplify narratives within the international information environment in ways that support broader geopolitical objectives.
Synthetic Media Personnel Structure (RRN Employee Layer)
Analysis of the ingested employee directory from Reliable Recent News provides direct insight into the constructed human layer underpinning the Doppelgänger ecosystem. In contrast to infrastructure or domain-based analysis, this dataset reveals how the operation systematically simulates a functioning media organization through a curated set of personnel, roles, and hierarchical relationships. This structure does not reflect a genuine workforce; rather, it constitutes a deliberately engineered organizational façade designed to support narrative attribution and reinforce perceived credibility.
The employee listing presents a fully developed newsroom hierarchy that closely mirrors legitimate Western media institutions, with an Editor-in-Chief at the apex, followed by senior and section editors, subject-matter analysts, and a base layer of journalists, correspondents, and contributors. The consistency and repeatability of this structure indicate a templated design rather than organic organizational growth, replicating the visual and procedural signals of editorial rigor, review, and domain expertise associated with credible outlets. In practice, these roles function primarily as perception management mechanisms: senior editors act as legitimacy anchors, analysts serve as authority proxies for geopolitical narratives, and journalists provide bylines that convert anonymous content into ostensibly reported material. Collectively, this framework simulates the full lifecycle of journalism analysis, reporting, editing, and publication without any underlying authentic process.
The identities themselves exhibit hallmarks of synthetic construction, including generic Western naming conventions, absence of external validation, and minimal or templated biographical detail, supporting their assessment as fabricated and designed for reuse. The uniform role structure enables rapid replication across domains, reinforcing consistent credibility signals while allowing personas to be reassigned or recycled without disrupting the façade of institutional integrity. Functionally, this layer operates as an intermediary between content and audience perception, transforming unattributed messaging into authored analysis extended across websites, Telegram channels, and social platforms to create a persistent identity presence. This demonstrates that the Doppelgänger operation incorporates identity fabrication as a core architectural component that is structured, reusable, and integral to delivery. It also means that effective disruption must address not only infrastructure but this portable persona layer, which can be rapidly redeployed to reconstitute credible media fronts.
Infrastructure Architecture
Feeder Website Network
The operational foundation of the Doppelgänger campaign is a distributed network of websites designed to host narrative content while closely mimicking legitimate news organizations. These sites function as the primary publishing layer of the campaign, providing the initial point of origin for narratives that are subsequently distributed across social media platforms.
Rather than relying exclusively on social media posts, the campaign infrastructure directs audiences to these external domains, which are designed to resemble independent media outlets. This approach provides several operational advantages. First, it allows operators to publish long-form narrative content that appears to originate from a news-style source rather than from social media accounts. Second, it creates a stable destination for links shared across Telegram channels and X/Twitter accounts, enabling narratives to persist even when individual social media posts are removed or accounts are suspended.
The feeder sites also serve an important operational security function. By hosting narrative content on controlled domains, operators create a layer of separation between the messaging infrastructure and the social media accounts used to distribute the content. This separation complicates attribution and allows narratives to circulate through secondary citation chains in which the original campaign infrastructure is no longer visible.
In addition to narrative hosting and attribution shielding, the feeder websites allow operators to collect traffic metrics and engagement data. By directing audiences to controlled domains, campaign operators can measure which narratives attract the greatest engagement and adjust future messaging accordingly.
Investigations into the Doppelgänger infrastructure have identified several representative domains associated with the campaign’s publishing network, including rrn[.]world *now an investigative site into SDA not an SDA controlled domain*, memhouse[.]online, truemaps[.]info, tribunalukraine[.]info, and avisindependent[.]eu. Alongside these domains, the ecosystem includes numerous cybersquatted sites designed to resemble well-known Western news organizations. These domains typically replicate visual branding, layout, and naming conventions of legitimate media outlets in order to increase the perceived credibility of the hosted content.
Redirect and Tracking Infrastructure
Supporting the feeder website network is a layered redirect and traffic-management system that enables the campaign to control how audiences reach narrative content. This infrastructure provides several operational capabilities, including audience geo-targeting, detailed traffic analytics, link obfuscation, and rapid substitution of infrastructure when individual domains are disrupted.
Redirect chains allow campaign operators to route users through multiple intermediary links before they arrive at the final destination site. This technique serves both operational security and campaign optimization purposes. From an operational perspective, it obscures the relationship between the original distribution platform and the hosting domain, making attribution more difficult. From an analytics perspective, it allows operators to monitor user engagement and measure the performance of individual links and narratives.
Public investigations have identified the use of traffic-management platforms such as Keitaro, a software system widely used in affiliate marketing ecosystems to manage link routing and analyze traffic patterns. When applied within influence operations, tools of this type can provide operators with detailed information about audience behavior, including geographic distribution, referral sources, and click-through rates. These capabilities enable campaign managers to refine messaging and distribution strategies based on real-time engagement metrics.
Domain Rotation and Regeneration
A defining characteristic of the Doppelgänger infrastructure is its ability to regenerate quickly when individual domains are blocked or seized. The campaign employs a strategy of continuous domain rotation in which new websites are deployed to replace disrupted infrastructure with minimal delay.
Evidence from multiple investigations indicates that replacement domains can appear with rapidity after a disruption event. This rapid regeneration capability suggests the presence of an organized infrastructure management process capable of registering domains, deploying website templates, and integrating new sites into the existing redirect and distribution systems on short notice.
The ability to rapidly replace infrastructure significantly increases the resilience of the campaign. Even when individual domains are removed by platform enforcement actions or law enforcement interventions, the broader narrative distribution network can continue operating with minimal interruption. As a result, the campaign’s influence activities persist through a cycle of disruption and regeneration that allows operators to maintain a continuous presence within the information ecosystem.
Operational Distribution Model
The Doppelgänger campaign distributes narratives through a structured, multi-stage pipeline designed to move content from controlled publishing infrastructure into large-scale public exposure across social media platforms. Rather than relying on a single channel for dissemination, the campaign employs a layered distribution architecture in which each stage performs a distinct operational role. This structure allows operators to maintain separation between narrative creation, infrastructure hosting, and public amplification, increasing both the resilience and scalability of the campaign.
The process begins with content creation, where narratives are developed and formatted for publication. At this stage, messaging themes are crafted to align with broader campaign objectives and current geopolitical developments. The narratives are typically designed to resemble journalistic reporting or analysis in order to increase their credibility and shareability once introduced into public discourse.
Once created, the content is published on feeder websites controlled by the campaign infrastructure. These sites serve as the primary hosting layer for narrative material and provide a stable destination for links that will later be shared across social media platforms. By placing the content on standalone domains that mimic legitimate news outlets, operators create a degree of separation between the narrative source and the social accounts used for distribution.
Following publication, the narrative enters the Telegram amplification stage. Telegram channels with established audiences serve as the primary distribution engine for the campaign. These channels repost links to the feeder websites, exposing the narratives to large subscriber bases and creating the initial wave of engagement. Because many of these channels already maintain audiences interested in geopolitical or ideological content, Telegram functions as an efficient mechanism for rapidly spreading narratives to receptive communities.
After gaining traction within Telegram networks, the campaign proceeds to X/Twitter injection. At this stage, coordinated social media accounts begin posting links to the feeder sites or discussing the narratives within existing conversations on the platform. These posts often appear within replies to trending topics, political discussions, or posts from influential accounts. The goal of this stage is to introduce the narrative into broader public discourse, reaching users who are not directly connected to the Telegram amplification network.
The final stage of the pipeline is audience exposure, where the narrative reaches individuals across the wider information ecosystem. At this point, the content may be encountered through social media threads reposted by other users, or referenced in discussions across forums, blogs, and other digital platforms. Once a narrative reaches this stage, it may continue circulating independently of the original campaign infrastructure.
This multi-stage distribution model allows the Doppelgänger campaign to move narratives from controlled infrastructure into mainstream online discourse while maintaining operational flexibility. By separating narrative creation, hosting, and amplification across distinct layers, the campaign achieves both scalability and resilience, enabling it to sustain influence activities even when individual domains or accounts are disrupted.
Telegram Amplification Layer
Within the Doppelgänger campaign architecture, Telegram functions as the primary distribution engine and reach multiplier. While feeder websites host the narrative content and X/Twitter accounts inject the narratives into public conversation, Telegram channels provide the high-capacity amplification required to expose those narratives to large audiences quickly.
The platform’s structure makes it particularly well suited to this role. Telegram channels can accumulate very large subscriber bases and distribute content instantly to those audiences without the algorithmic filtering mechanisms present on many Western social media platforms. As a result, a single post in a high-subscriber channel can expose campaign narratives to hundreds of thousands of users within minutes.
The Doppelgänger campaign leverages this dynamic by utilizing established channels within the broader pro-Kremlin Telegram ecosystem. These channels function as distribution hubs, reposting links to feeder websites and circulating campaign narratives across interconnected networks of subscribers. Once a narrative appears in one of these large channels, it is frequently reposted by smaller affiliated channels, creating an amplification cascade that expands the narrative’s reach across the platform.
Several prominent Telegram channels have been identified as major amplifiers within this ecosystem. These include Readovka, SolovievLive, IntelSlava, Ukraina[.]ru, and OstashkoNews, each of which maintains a substantial subscriber base and regularly circulates geopolitical and war-related content aligned with pro-Kremlin messaging. Collectively, these channels represent a significant distribution network capable of reaching millions of users.
Combined subscriber counts across these channels exceed five million accounts. However, subscriber overlap between channels means that the total audience exposed to a given narrative is smaller than the raw subscriber numbers might suggest. Many users subscribe to multiple channels within the same information ecosystem, which reduces the number of unique individuals reached by each amplification wave.
Taking this overlap into account, the estimated unique exposure per narrative wave distributed through these major channels historically has approximately been up to 1.2 to 2.4 million viewers. This range reflects the realistic audience size likely to encounter a narrative during a typical amplification cycle.
Because of this reach, Telegram serves as the central amplification layer within the Doppelgänger campaign. The platform enables rapid dissemination of narratives from the feeder website network and provides the initial audience engagement that supports subsequent injection of those narratives into broader social media conversations on platforms such as X/Twitter.
X / Twitter Injection Layer
Within the Doppelgänger campaign architecture, X (formerly Twitter) serves a different operational function from Telegram. Whereas Telegram channels provide large-scale distribution to existing subscriber audiences, X is primarily used as a mechanism for narrative insertion into active public conversations. The platform’s role in the campaign is therefore less about direct reach through large follower bases and more about leveraging algorithmic visibility within ongoing discussions.
Unlike traditional influence campaigns that rely on prominent influencers or high-follower accounts, Doppelgänger operators typically deploy clusters of disposable social media profiles. These accounts are designed to be rapidly created, used for short operational periods, and replaced when suspended or detected. As a result, the accounts associated with these operations often exhibit several common characteristics.
Most have minimal follower counts, indicating that they are not intended to build long-term audiences. Many profiles are recently created, sometimes within days or weeks of their participation in coordinated posting activity. Usernames frequently consist of generic or randomly generated combinations of characters, and profile images are commonly drawn from stock photography or produced using AI-generated portrait tools. These traits collectively suggest that the accounts are designed primarily for operational utility rather than credibility or sustained engagement.
Instead of broadcasting content to followers, these accounts engage in coordinated reply behavior. Operators target posts that are already receiving significant engagement—such as political discussions, breaking news events, or posts from high-profile accounts—and insert replies containing links to feeder websites or narrative fragments aligned with campaign messaging. By appearing within existing conversation threads, the campaign attempts to expose the narrative to users who are already participating in or observing those discussions.
Investigations into the Doppelgänger campaign have documented several examples of this tactic. One operation targeting U.S. audiences involved approximately thirty-nine coordinated accounts posting replies within political discussions. Other investigations have identified larger botnet-style clusters consisting of more than one thousand coordinated accounts, indicating that the scale of these operations can vary significantly depending on the campaign objectives.
Within the overall influence architecture, the X layer therefore contributes algorithmic amplification rather than follower-based distribution. By inserting narratives into high-visibility discussion threads, the campaign can exploit platform algorithms that prioritize active conversations, allowing content posted by otherwise low-follower accounts to appear in front of large audiences. In this way, the X component of the campaign acts as a bridge between the controlled distribution channels of Telegram and the broader public information environment.
Narrative Propagation Mechanics
The spread of narratives within the Doppelgänger ecosystem follows a cascade-style propagation model in which content moves through a sequence of amplification stages. Each stage expands the potential audience and increases the likelihood that the narrative will enter broader online discourse. This cascading structure allows relatively small origin accounts or channels to generate large-scale exposure once the narrative reaches high-capacity distribution nodes.
The process typically begins with an origin post, which may appear either on a feeder website or within a smaller Telegram channel associated with the campaign ecosystem. At this stage, the narrative exists within a relatively limited audience environment and functions primarily as the initial seed for the distribution pipeline.
From there, the narrative is introduced into a Telegram origin channel, where it begins to circulate within networks of subscribers that regularly consume geopolitical or ideological content aligned with pro-Kremlin messaging. These origin channels often serve as staging points where narratives are prepared for broader amplification.
The critical expansion phase occurs when the narrative is reposted by a large Telegram amplifier channel with a substantial subscriber base. Channels operating at this level of the ecosystem can expose content to hundreds of thousands of users simultaneously. Once a narrative reaches this stage, it becomes highly visible across the Telegram information environment.
Following publication in a major amplifier channel, the narrative enters a secondary repost cascade. Smaller affiliated channels frequently repost content originating from large channels, either automatically or through loosely coordinated editorial behavior. This reposting activity produces a cascading effect in which the narrative spreads across interconnected Telegram communities, further expanding its reach.
After the narrative gains traction within Telegram, the campaign introduces the content into the X/Twitter layer through coordinated account activity. Clusters of disposable accounts begin posting links, excerpts, or commentary related to the narrative within active discussions on the platform. This step serves to insert the narrative into broader public conversations, particularly those involving political or geopolitical topics.
The final stage of the cascade occurs when the narrative achieves secondary discourse uptake. At this point, users outside the original campaign infrastructure begin referencing or discussing the narrative independently. The content may appear in comment threads, forums, blog posts, or other social media discussions, often without direct reference to the original source.
Through this cascade model, a narrative originating from a relatively small node within the campaign network can rapidly expand to reach a much larger audience. The combination of Telegram amplification and social media insertion enables the Doppelgänger ecosystem to convert limited initial publication into widespread exposure across multiple digital platforms.
Campaign Reach and Effects
Subscriber metrics from major Telegram amplification channels, combined with observed activity patterns, enable bounded estimates of reach for a typical Doppelgänger narrative wave. The distribution model using Telegram as the primary amplifier, followed by coordinated activity on X/Twitter means total exposure is driven by the number of participating channels and the intensity of downstream social amplification.
Operationally, narrative waves fall into three intensity tiers:
Baseline Campaign The most common configuration. Narratives are pushed through multiple large Telegram channels, then reinforced by coordinated X/Twitter reply clusters. This layered amplification produces an estimated reach of 1.5–2.7 million users, with 100,000–300,000 interactions. Secondary uptake expands to 10,000–40,000 mentions, indicating spillover beyond controlled infrastructure into broader discourse.
Low-Intensity Campaign A single major Telegram channel with limited X/Twitter support. The distribution cascade is constrained, yielding 800,000–1.3 million users reached, 40,000–120,000 interactions, and 2,000–5,000 secondary mentions. Despite lower scale, narratives still penetrate sizable audiences, particularly within high-interest topics.
High-Intensity Campaign Aligned with major geopolitical events, leveraging elevated attention and search activity. Multiple high-capacity Telegram channels and dense X/Twitter coordination drive accelerated spread. Estimated reach increases to 3–5 million users, with 250,000–700,000 interactions and 40,000–100,000 secondary mentions. At this stage, narratives routinely escape campaign control and persist in wider information ecosystems.
Across all tiers, the architecture demonstrates consistent scaling behavior: small origin points are amplified through Telegram, reinforced via coordinated social activity, and ultimately propagated into broader public discourse.
Strategic Impact Assessment
The Doppelgänger campaign is engineered for visibility, not direct persuasion. Its architecture–feeder websites, Telegram amplification, and coordinated X/Twitter activity–prioritizes rapid distribution and repeated exposure across platforms to maximize encounter frequency.
The objective is to seed narratives into the information environment and sustain their circulation, rather than secure immediate belief. Repetition across multiple sources increases perceived relevance and can shape interpretation of events, even when claims remain contested.
A central mechanism is manufactured ubiquity. By injecting narratives into active discussions and amplifying them across channels, the campaign creates the appearance of widespread, organic debate. This perceived consensus elevates legitimacy, particularly when content surfaces simultaneously across domains and platforms.
Effectiveness does not require broad persuasion. Limited engagement is sufficient to generate secondary propagation mentions, reposts, and commentary that extend reach beyond controlled infrastructure. As these references accumulate, narratives diffuse into general discourse, producing a form of information contamination in which repeated exposure normalizes their presence.
Over time, this process increases perceived credibility and embeds narratives within the broader information ecosystem. The strategic outcome is not conversion, but contextual influence shaping how events are framed and understood.
Doctrinal Context: Doppelgänger Within Russian Information Confrontation Strategy
The operational architecture of the SDA / Doppelgänger campaign aligns closely with established Russian concepts of information confrontation (informatsionnoye protivoborstvo/информационное противоборство), a strategic doctrine that integrates information operations into broader geopolitical competition.
Rather than focusing solely on direct persuasion or propaganda in the traditional sense, Russian information confrontation doctrine emphasizes shaping the information environment itself. The objective is to influence how events are interpreted, weaken adversary cohesion, and introduce persistent uncertainty into public discourse.
The layered architecture observed in the Doppelgänger campaign, such as combined web infrastructure, social amplification networks, and rapid regeneration capabilities reflects this doctrinal emphasis on environmental influence rather than individual audience conversion.
Continuity With Soviet Active Measures
The operational structure of the Doppelgänger campaign demonstrates clear continuity with Soviet-era Active Measures, a category of covert influence operations historically conducted by the KGB and other Soviet intelligence services. Active Measures were designed to shape political perceptions abroad through the controlled dissemination of misleading or manipulated information. Rather than relying solely on overt propaganda channels, these operations frequently used covert or semi-covert mechanisms intended to obscure the origin of the messaging and create the appearance of independent sources.
Historically, Active Measures campaigns relied on a combination of forged publications, front organizations, and intermediary actors to introduce narratives into foreign information environments. Articles containing false or misleading claims were often placed in controlled outlets or sympathetic publications, where they could be cited by other media organizations without clear attribution to Soviet state actors. This layered dissemination model enabled narratives to circulate widely while masking their true origin in the same manner as the SDA/Doppelgänger campaigns do in the 21st century.
Several core techniques were characteristic of these operations. Soviet intelligence services frequently published fabricated or manipulated articles in outlets under their influence, ensuring that narratives appeared to originate from credible media sources. They also relied on intermediaries, sometimes sympathetic individuals or organizations, and sometimes unwitting participants to amplify and redistribute these narratives. Additionally, front organizations and proxy institutions were used to conceal the involvement of state actors, creating plausible deniability and complicating attribution.
The modern Doppelgänger ecosystem replicates many of these operational concepts but implements them through digital infrastructure rather than traditional print or broadcast channels. In place of forged newspapers or pamphlets, the campaign operates cloned media websites designed to resemble legitimate news organizations. Instead of proxy publications in foreign countries, the campaign relies on pseudo-journalistic domains that host narrative content while maintaining the appearance of independent media outlets.
Likewise, where Soviet Active Measures depended on diplomatic contacts, activist groups, or aligned publications to redistribute narratives, the Doppelgänger campaign utilizes Telegram amplification channels to perform a similar role. These channels function as distribution hubs that rapidly disseminate narratives to large subscriber bases. Finally, the rumor propagation networks historically used to circulate political claims have been replaced by coordinated X/Twitter reply swarms, which insert narratives into active discussions across social media platforms.
Although the underlying techniques remain conceptually similar, the digital environment dramatically increases the speed, scale, and reach of these operations. Where Cold War Active Measures might have taken weeks or months to propagate through traditional media channels, digital infrastructure allows narratives to circulate globally within hours. This acceleration enables modern influence campaigns such as Doppelgänger to achieve levels of audience exposure and message repetition that were difficult to achieve through earlier forms of covert propaganda.
Alignment With Contemporary Russian Hybrid Warfare Doctrine
The operational design of the Doppelgänger campaign also reflects principles associated with Russia’s contemporary hybrid warfare doctrine, which integrates informational influence with broader geopolitical strategy. Discussions of this doctrine frequently reference writings and strategic concepts attributed to Russian military leadership that emphasize the growing importance of non-military tools in modern conflict.
Hybrid warfare is characterized by the coordinated use of military, political, economic, and informational instruments to influence adversaries while avoiding direct conventional confrontation. Within this framework, influence operations play a central role in shaping public perception, undermining adversary cohesion, and influencing decision-making environments before or during geopolitical crises.
Information operations such as the Doppelgänger campaign function as one component of this broader strategic toolkit. By introducing and amplifying narratives across digital information environments, the campaign can affect political discourse and public perception in ways that complement diplomatic, economic, or military pressure. The architecture of the campaign–combining narrative development, infrastructure hosting, and multi-platform distribution–demonstrates how modern influence capabilities can operate continuously alongside other forms of geopolitical competition.
Within the context of hybrid warfare strategy, campaigns like Doppelgänger serve several strategic purposes. They can weaken public support for adversary policies, particularly in democratic societies where political legitimacy depends on public opinion. By amplifying internal political disagreements or contentious social issues, such operations may also intensify existing divisions within target societies, complicating unified responses to international crises.
Influence campaigns can also contribute to strategic ambiguity surrounding geopolitical events. By introducing multiple competing explanations or allegations into public discourse, the information environment becomes more difficult to interpret, increasing uncertainty about the causes or implications of major developments. In addition, these campaigns can help shape international narratives around conflicts, promoting interpretations that align with Russian strategic messaging while challenging competing perspectives.
The Doppelgänger campaign’s operational emphasis on narrative saturation rather than direct persuasion aligns closely with this doctrinal approach. Rather than focusing on convincing audiences of a single specific claim, the campaign introduces a large volume of narratives designed to circulate simultaneously across the information ecosystem. This proliferation of competing narratives can complicate consensus formation, increase confusion about the reliability of information sources, and ultimately influence how audiences interpret geopolitical events.
Information Environment Manipulation
Russian information confrontation doctrine prioritizes control of the interpretive context through which audiences understand events. Perception is shaped less by facts than by narrative frameworks that assign meaning, causality, and emotional weight. By manipulating these frameworks, influence operations can alter how events are interpreted without changing the underlying facts.
Accordingly, campaigns focus on reshaping context rather than advancing isolated claims. This is achieved by promoting alternative explanations, introducing conspiratorial interpretations, and amplifying emotionally charged narratives to influence perception and legitimacy.
The Doppelgänger campaign operationalizes this model through a repeatable distribution pipeline. Narratives are developed in alignment with strategic objectives, published on feeder websites designed to mimic legitimate media, amplified via Telegram channels, and then inserted into active discussions on X/Twitter. This sequence enables rapid, multi-platform injection of interpretive frames into public discourse.
The architecture is modular and resilient, allowing narratives to be redeployed across domains, channels, and account clusters even after disruption. This persistence sustains exposure over time, reinforcing narrative frames and embedding them within the broader information environment.
Strategic Persistence
A defining characteristic of Russian information confrontation strategy is operational persistence. Rather than relying on isolated or short-lived influence campaigns, Russian information operations are typically conducted as continuous activities designed to exert sustained pressure on the information environments of targeted societies. This approach recognizes that influence within complex media ecosystems is cumulative; narratives may gain traction gradually through repeated exposure rather than through a single high-impact campaign.
Within this framework, influence operations are structured to remain active over extended periods, allowing operators to continually introduce, reinforce, and adapt narratives in response to changing geopolitical conditions. The objective is not simply to deliver a single message but to maintain a persistent presence within public discourse, ensuring that strategically aligned narratives remain visible and repeatedly encountered by audiences.
The Doppelgänger ecosystem reflects this emphasis on persistence through several operational mechanisms embedded within its infrastructure and distribution architecture. One such mechanism is rapid domain regeneration, which allows operators to replace disrupted or seized feeder websites quickly. When a domain is taken offline, replacement sites can be deployed within a short time frame, allowing the narrative distribution pipeline to continue functioning with minimal interruption.
The campaign also relies heavily on disposable social media accounts, particularly on platforms such as X/Twitter. These accounts are typically created with minimal investment in long-term identity or follower growth, allowing them to be used for short operational cycles and replaced easily if they are suspended or detected. This disposable-account model reduces the impact of platform enforcement actions and enables the campaign to maintain continuous activity despite account removals.
Another key element of this persistence is the campaign’s integration with existing Telegram channels that already possess large subscriber bases. Because these channels operate as stable distribution hubs within the broader pro-Kremlin information ecosystem, they provide a consistent amplification platform that does not need to be rebuilt for each campaign wave. This existing infrastructure allows narratives to be circulated repeatedly through established audiences.
Finally, the campaign reinforces persistence through the repeated reintroduction of narratives across multiple operational cycles. Even after a particular narrative has circulated through the distribution pipeline, the same or slightly modified messaging may be reintroduced in later campaign waves, often in response to new geopolitical developments. This repetition increases the likelihood that the narrative will become embedded within broader online discourse.
Taken together, these mechanisms allow the Doppelgänger campaign to maintain long-term influence activity even when individual components of the infrastructure are disrupted. The persistence of the system ensures that the broader narrative themes promoted by the campaign remain present within the information environment, enabling influence operations to continue shaping discourse over time.
Strategic Implications
The Doppelgänger campaign represents a mature influence capability that fuses traditional propaganda methods with modern digital infrastructure. It operates as a coordinated ecosystem, producing, distributing, and reinforcing narratives across platforms, rather than as isolated disinformation activity.
This model aligns with state-level information confrontation, where influence operations are integrated into broader geopolitical strategy. Its architecture functions as a persistent mechanism for shaping external information environments.
These components form a scalable, resilient distribution system. Modular design enables rapid adaptation, infrastructure regeneration, and repeated campaign cycles despite disruption.
Effectiveness is not defined by direct persuasion, but by cumulative environmental impact. Through sustained narrative injection and amplification of controversy, the campaign degrades informational coherence, proliferates competing interpretations, and complicates consensus formation.
Detection Framework Development
The operational characteristics of the Doppelgänger campaign produce a number of recurring technical and behavioral indicators that can assist analysts in identifying active influence operations. Although individual domains, social media accounts, and distribution channels may change over time, the underlying structure of the campaign’s infrastructure and propagation mechanisms generates patterns that are observable across multiple campaign waves.
These indicators generally fall into three broad categories: infrastructure indicators, behavioral indicators, and cross-platform propagation indicators. Together, they provide a framework for identifying and tracking influence activity associated with the Doppelgänger ecosystem.
Infrastructure Indicators
Infrastructure indicators are the most consistent signals of the campaign. The feeder network relies on recently registered domains that mimic legitimate news or commentary sites, using media-style naming to project credibility.
A key pattern is rapid domain rotation: sites are replaced quickly after disruption, often reusing similar naming conventions, branding, and technical configurations. Redirect infrastructure is also common, routing users through intermediary links to obscure source relationships while enabling traffic tracking.
Repeated website templates further indicate standardization. Shared layouts, visual elements, and backend configurations suggest the use of prebuilt deployment packages that support rapid infrastructure regeneration.
Behavioral Indicators
Beyond infrastructure, the campaign exhibits clear behavioral indicators of coordination. Telegram repost cascades are the most visible signal, where identical narratives propagate rapidly across multiple channels from a small set of origin posts.
Synchronized posting is also common, with near-identical content appearing across channels and accounts within minutes, indicating centralized dissemination. Clusters of newly created social media accounts characterized by low followers, generic identities, and stock or AI-generated images support short, disposable operational cycles.
On X/Twitter, activity often takes the form of reply swarms, where coordinated accounts inject narrative fragments and links into active discussions to amplify visibility and reach.
Cross-Platform Indicators
A third category of indicators involves the cross-platform propagation patterns that characterize the campaign’s distribution pipeline. Narratives often follow a consistent sequence of appearance across platforms, beginning with publication on a feeder website and subsequently spreading through Telegram amplification channels.
Shortly after appearing on Telegram, the same narratives may be introduced into X/Twitter discussions through coordinated account activity. This sequence—feeder site publication followed by Telegram amplification and social media insertion—represents a recurring propagation pattern that can signal the presence of a coordinated influence operation.
By monitoring these infrastructure, behavioral, and cross-platform indicators together, analysts can identify emerging campaign waves and better understand the mechanisms through which the Doppelgänger ecosystem distributes narratives across the digital information environment.
Disruption Strategy
Disrupting the Doppelgänger ecosystem requires a multi-layered approach targeting both infrastructure and distribution channels. Its design of rapidly replaceable domains, disposable accounts, and persistent amplification hubs means mitigation must be continuous and coordinated, not episodic.
Domain seizures and infrastructure takedowns can interrupt the publishing pipeline, but must be repeated due to rapid regeneration. Collaboration with registrars and hosting providers, using identifiable patterns in domain naming and deployment, can slow replacement cycles.
Account removal is equally critical. Suspending coordinated clusters on platforms like X/Twitter reduces narrative insertion into high-visibility discussions, while botnet detection helps identify and disrupt amplification networks exhibiting synchronized behavior.
Monitoring Telegram channels provides early warning and visibility into narrative propagation, even when direct removal is constrained.
Because campaign assets are disposable by design, effective disruption depends on sustained, cross-platform pressure. This raises operational costs, degrades distribution efficiency, and incrementally reduces overall campaign impact.
Potential Operational Pivots During Major Geopolitical Crisis
The Doppelgänger architecture is highly adaptable and can be rapidly repurposed for influence operations during major geopolitical crises, including the U.S.–Iran conflict. By integrating narrative development, controlled web infrastructure, and multi-platform distribution, it provides a ready mechanism for injecting crisis narratives into Western information environments.
In such scenarios, the system would likely be used to frame events in real time. Feeder sites could publish alternative interpretations of incidents emphasizing escalation, civilian harm, or legal violations while Telegram and X/Twitter amplification insert these narratives into early-stage public discourse.
It can also be used to exacerbate domestic divisions, promoting skepticism about intervention, highlighting economic costs, or questioning strategic legitimacy. Concurrently, the system can introduce multiple, conflicting explanations for key events, generating uncertainty and complicating verification.
The infrastructure supports targeted messaging, enabling narratives tailored to specific audiences, such as economic risk for European audiences, and political or military costs for U.S. audiences across languages and regions. It also facilitates information laundering, where content from pseudo-journalistic sites is recirculated and cited beyond the originating network.
Overall, Doppelgänger functions as a rapid-deployment influence platform. In crisis conditions, it can shape initial interpretations, amplify divisions, and establish persistent narrative frames that influence how conflicts are understood.
Example Crisis Influence Timeline: Narrative Propagation During the First 72 Hours
In a major geopolitical crisis such as the recent military confrontation between the United States and Iran the Doppelgänger influence infrastructure could be rapidly activated to shape early interpretations of events. Because the campaign’s architecture integrates narrative development, feeder website infrastructure, Telegram amplification networks, and coordinated social media activity, it is capable of introducing narratives into the information environment within hours of a triggering event.
The following model outlines how a typical influence operation using the Doppelgänger ecosystem could unfold during the first seventy-two hours following a major geopolitical incident. While the precise timing and scale of each phase may vary depending on operational objectives, documented campaign behavior suggests that the propagation pipeline follows a predictable sequence.
Initial Event Window (0–6 Hours)
The first phase begins immediately after a major geopolitical event becomes public knowledge. During this period, information environments are highly volatile and public understanding of the event is still forming. This stage provides an opportunity for influence operations to introduce interpretive narratives before authoritative reporting stabilizes the factual narrative.
During this window, campaign operators can rapidly produce narrative content aligned with strategic messaging objectives. These narratives may frame the event as evidence of escalation, highlight alleged civilian impacts, question the legitimacy of military actions, or introduce competing explanations regarding responsibility for the event.
Once developed, the narrative is published on one or more feeder websites within the Doppelgänger infrastructure. These articles typically mimic the appearance of legitimate news reporting, enabling them to be shared in social media discussions without immediately revealing their origin within a coordinated campaign.
Amplification Phase (6–24 Hours)
Following initial publication, the narrative enters the Telegram amplification layer, where links to the feeder websites are reposted across established pro-Kremlin Telegram channels. Because many of these channels maintain large subscriber bases and distribute content without algorithmic filtering, this stage can expose the narrative to hundreds of thousands of users within a short period of time.
Large Telegram channels function as distribution hubs that initiate the amplification cascade. Once the narrative appears in one or more of these channels, smaller affiliated channels frequently repost the content, expanding its reach across interconnected communities. This cascade effect can rapidly increase the narrative’s visibility across the Telegram information ecosystem.
At this stage, the narrative begins generating engagement in the form of reposts, comments, and reactions, creating the appearance of active discussion around the topic.
Cross-Platform Injection Phase (24–48 Hours)
Once the narrative has gained traction within Telegram networks, the campaign typically proceeds to cross-platform injection, introducing the content into broader public discussions on platforms such as X/Twitter. Clusters of disposable accounts begin posting links, excerpts, or commentary related to the narrative within active political conversations.
Rather than broadcasting content to followers, these accounts frequently target high-visibility discussion threads, including posts by journalists, politicians, or commentators addressing the crisis. By inserting replies into these conversations, the campaign attempts to expose the narrative to audiences that are not directly connected to the Telegram ecosystem.
This stage significantly expands the potential audience and increases the likelihood that the narrative will be encountered by individuals participating in broader geopolitical discussions.
Secondary Uptake Phase (48–72 Hours)
During the final stage of the initial propagation cycle, the narrative may begin to achieve secondary uptake outside the campaign’s direct infrastructure. Users who encounter the narrative through social media discussions may reference or repeat the claims in additional posts, blogs, forums, or commentary threads.
At this point, the narrative can circulate independently of the original campaign infrastructure. Because the narrative now appears across multiple platforms and sources, it may begin to influence how audiences interpret the underlying geopolitical event.
Even when the narrative itself remains contested, the presence of repeated references and discussions can contribute to information contamination, where the narrative becomes embedded within the broader discourse surrounding the event.
Strategic Implication
This seventy-two-hour propagation model illustrates how the Doppelgänger infrastructure can function as a rapid-deployment influence platform during geopolitical crises. By introducing narratives early in the information cycle and amplifying them across multiple platforms, the campaign can shape initial interpretations of events and inject competing narratives into public discourse before authoritative accounts become widely established.
Because the campaign’s infrastructure is modular and persistent, the same narratives can also be reintroduced in subsequent cycles as new developments occur, allowing influence operations to remain active throughout the duration of a geopolitical crisis.
Analytical Judgment
The Doppelgänger campaign is a resilient, scalable influence system built for sustained, multi-platform operations. It integrates narrative development, controlled web infrastructure, and coordinated social amplification to repeatedly inject and reinforce strategic messaging.
Its durability derives from a modular design that separates creation, hosting, and distribution, enabling rapid replacement of disrupted domains and accounts with minimal impact on operations. Cross-platform amplification extends reach: feeder sites provide controlled publication, Telegram delivers high-volume exposure, and coordinated X/Twitter activity inserts narratives into broader discourse.
Rapid regeneration further reinforces persistence, allowing infrastructure and accounts to be reconstituted quickly after takedowns. Within this model, Telegram functions as the primary reach engine, while X/Twitter enables penetration into high-visibility Western discussions.
Overall, Doppelgänger exemplifies a modern influence architecture that combines traditional propaganda logic with flexible digital infrastructure, sustaining narrative presence despite continuous disruption.
Technical Appendix A: Full Infrastructure Map of the SDA / Structura Ecosystem
MOIS Linked MOIST GRASSHOPPER / Homeland Justice / KarmaBelow80 / Handala Hackers / Campaigns and Evolution
Explore the evolution of MOIS-linked actors Homeland Justice, Karma, and Handala. Analysis of destructive malware, surveillance integration, and the 2026 Stryker incident.
Executive Overview
The evidence examined across this analysis spanning U.S. government reporting, private-sector threat intelligence research, passive DNS and infrastructure enrichment, and longitudinal review of archived web and Telegram content supports a high-confidence assessment that the personas Homeland Justice, Karma, and Handala do not represent discrete or ideologically independent hacktivist groups. Rather, they constitute a coordinated, MOIS-aligned cyber influence ecosystem operating under multiple branded identities that serve distinct but complementary operational roles.
This assessment is supported by multiple converging lines of evidence, including clear temporal continuity, operational consistency, infrastructure linkage, and behavioral alignment. Activity transitions seamlessly from Homeland Justice operations targeting Albania in 2022 to Karma campaigns against Israeli entities in late 2023, and subsequently to Handala-branded operations from 2024 onward. Across these phases, the actors consistently employ a repeatable pattern of intrusion, data exfiltration, disruptive or destructive action, and rapid public disclosure through controlled infrastructure. This is reinforced by shared or cross-referenced domains, persistent use of Telegram for amplification and coordination, and common hosting and obfuscation strategies. The personas also exhibit consistent rhetorical framing, target selection logic, and methods of psychological coercion. Taken together, these indicators support the conclusion that these identities function as operational layers applied to a single underlying capability, enabling segmentation of audiences and messaging while maintaining continuity of tradecraft. This modular branding approach aligns with broader state-aligned cyber operations that leverage multiple personas to project decentralization while masking centralized control.
Since its emergence in 2022, the campaign has evolved from a destructive intrusion operation into a multi-functional cyber influence framework. The initial Albania operation combined long-term compromise with ransomware-style encryption, disk wiping, and public attribution, already indicating that technical disruption was paired with narrative objectives. Over time, the campaign expanded to incorporate espionage, persistent access, structured data exfiltration, and coordinated hack-and-leak activity designed to shape perception and behavior. The addition of surveillance capabilities, particularly those leveraging Telegram-based command-and-control, marks a further shift toward continuous monitoring and transnational repression targeting both institutions and individuals. In its current form, the campaign represents a cohesive and adaptive system in which intrusion, disruption, surveillance, and information operations are integrated into a unified strategy aligned with MOIS objectives, capable of applying sustained pressure across both cyber and cognitive domains.
Ministry of Intelligence and Security (MOIS) Connection
The operational ecosystem encompassing Handala, Homeland Justice, and the persona cluster associated with Karma and KarmaBelow80 is most coherently understood not as a loose federation of ideologically aligned actors, but as a structured, state-directed campaign operating under the authority of Iran’s Ministry of Intelligence and Security (MOIS). When viewed through the lens of command-and-control, tradecraft consistency, and synchronized effects, the activity attributed to these brands reflects the hallmarks of an intelligence service executing coordinated cyber operations in support of national objectives rather than independent or purely proxy-driven behavior.
At the center of this structure is the reported involvement of Seyed Yahya Hosseini Panjaki, an individual assessed to be affiliated with MOIS and linked to its internal security and counter-terrorism apparatus. The significance of this attribution lies less in the identity of the individual operator and more in what it implies structurally. His role represents a command-level function within an institutional hierarchy, indicating that these cyber operations are subject to formal tasking, oversight, and strategic alignment. This shifts the analytical framing away from contractor-driven or semi-deniable activity and toward a model in which operations are integrated into the broader intelligence mandate of the Iranian state.
Within this framework, the distinct public-facing identities of Handala, Homeland Justice, and KarmaBelow80 function as operational veneers rather than discrete entities. Each brand aligns with a specific subset of MOIS objectives while drawing from a shared pool of capabilities, infrastructure, and tradecraft. Handala’s activity is most closely aligned with psychological and information operations, characterized by curated leaks, narrative shaping, and the deliberate amplification of politically resonant material. The timing and framing of these disclosures indicate coordination with broader messaging goals, suggesting that the technical intrusion component is only one phase of a larger influence cycle.
Homeland Justice, by contrast, represents the disruptive and punitive arm of this ecosystem. Its operations, particularly those conducted against Albanian government infrastructure, demonstrate a full-spectrum intrusion lifecycle in which long-term access is leveraged to enable data exfiltration, destructive deployment, and overt attribution. The combination of wiper activity, ransomware-style encryption, and coordinated public messaging reflects a model of calibrated escalation designed to impose both operational and reputational costs on the target. This is consistent with MOIS mandates involving internal security and retaliatory action against perceived adversaries.
The Karma and KarmaBelow80 personas introduce an additional layer of flexibility into the ecosystem. Rather than being tied to a single operational profile, these identities appear to function as adaptive interfaces that can be deployed across different phases of an operation. They enable the same underlying capability set to be presented under different contextual narratives, enhancing deniability while maintaining continuity of effect. This is particularly relevant in environments where attribution pressure is high, as it allows operators to fragment their public footprint without fragmenting their operational infrastructure.
The coherence across these actor clusters is most evident in the structure of their operations. Intrusions frequently follow a repeatable progression: initial access is established through credential compromise or exploitation of exposed services, followed by the deployment of webshells or other persistence mechanisms. Once footholds are secured, actors conduct internal reconnaissance and lateral movement using enterprise-scale tooling, enabling them to map the target environment and identify high-value data stores. Exfiltration is then carried out in a controlled manner, often staged to support subsequent public release. The final phase varies depending on strategic intent, ranging from silent intelligence collection to destructive action or coordinated leak publication.
What distinguishes this ecosystem is the degree to which these phases are integrated and interchangeable. The same intrusion can evolve from a covert surveillance operation into a disruptive attack or an influence campaign without requiring a fundamental shift in tooling or access. This reflects the modular architecture described earlier, but at an organizational level it also implies centralized capability management. MOIS oversight provides the mechanism through which these modules can be allocated, combined, and sequenced in accordance with mission objectives.
The involvement of a command-level figure such as Panjaki provides a unifying explanation for this consistency. It accounts for the alignment between technical operations and information effects, the disciplined escalation observed in target engagements, and the reuse of infrastructure and tooling across ostensibly separate actor brands. It also explains the resilience of the ecosystem. Disrupting one public-facing identity or infrastructure cluster does not degrade the underlying capability, because those assets are components of a larger, centrally managed system.
From an analytical standpoint, this structure necessitates treating Handala, Homeland Justice, and KarmaBelow80 as manifestations of a single operational apparatus rather than independent threat actors. Their differences are functional rather than organizational, reflecting the segmentation of roles within a coordinated campaign. The strategic value of this model lies in its flexibility: MOIS can conduct espionage, disruption, and influence operations in parallel, or transition between them as conditions dictate, all while maintaining a coherent operational footprint.
This convergence of command authority, modular capability, and multi-domain execution underscores the maturation of MOIS cyber operations into a fully integrated instrument of state power. It is not simply the presence of advanced tooling or destructive capability that defines this ecosystem, but the way in which those capabilities are orchestrated under centralized direction to produce layered, cumulative effects across technical and informational domains.
Campaign Expansion and Evolution
Initial Emergence in Albania (2022)
Homeland Justice[.]org website
The campaign first became publicly visible during the 2022 attacks against the Government of Albania, which established both its technical baseline and its enduring operational model. Iranian state actors operating under the Homeland Justice persona achieved initial access approximately fourteen months prior to public disclosure by exploiting an internet-facing Microsoft SharePoint vulnerability. This early foothold indicates a deliberate pre-positioning phase, consistent with long-dwell intrusion strategies observed across MOIS-aligned operations.
Following initial compromise, the actors transitioned into a structured post-exploitation workflow designed to ensure persistence, expand access, and map the target environment. Webshells were deployed on compromised servers, providing durable and low-friction access while enabling command execution without reliance on large malware payloads. From this foothold, operators conducted systematic internal reconnaissance, enumerating network topology, identifying key systems, and mapping trust relationships across the enterprise.
Credential harvesting was a central component of this phase. Through a combination of mailbox access, credential dumping, and account manipulation, the actors obtained privileged credentials that enabled lateral movement and escalation. Movement across the environment was conducted using standard administrative protocols, including Remote Desktop Protocol (RDP), Server Message Block (SMB), and File Transfer Protocol (FTP), allowing activity to blend with legitimate administrative traffic and reducing the likelihood of early detection.
The compromise of Microsoft Exchange infrastructure further expanded access. By leveraging Exchange, the actors were able to access and manipulate mailboxes, create or modify accounts, and extract large volumes of sensitive communications. This email corpus provided both intelligence value and material for later disclosure, aligning with the campaign’s hack-and-leak model.
Data exfiltration occurred in parallel with lateral expansion, with operators systematically staging and extracting large datasets from across the environment. Only after sufficient access, intelligence collection, and data acquisition had been achieved did the actors transition to the destructive phase. This sequencing – extended pre-positioning, comprehensive collection, and delayed disruption – demonstrates a disciplined operational approach in which technical compromise is leveraged to maximize both intelligence yield and downstream psychological impact.
Establishment of the Operational Model
The impact phase of the Albania operation combined ransomware-style encryption with destructive wiping, employing tools such as GoXML.exe and cl.exe, supported by propagation utilities and raw disk access drivers that enabled direct manipulation of underlying storage. These capabilities were deployed in a coordinated manner to maximize operational disruption, impair system recovery, and degrade institutional functionality. The sequencing of encryption followed by wiping reflects a deliberate approach designed not only to deny access to systems and data, but to ensure lasting damage and complicate remediation efforts.
More significant than the tooling itself, however, was the deliberate integration of public-facing infrastructure into the attack lifecycle. The Homeland Justice persona was used to claim responsibility, disseminate messaging, and frame the operation within a broader political and ideological narrative. Websites and Telegram channels functioned as controlled dissemination platforms through which the actors published statements, amplified claims, and selectively exposed information. This layer transformed what would otherwise have been a destructive cyber incident into a visible and ongoing influence operation.
This approach established a foundational operational model in which technical compromise and information operations were inseparably linked. Cyber intrusion and destruction served as enabling mechanisms for narrative exploitation, with the ultimate objective extending beyond disruption to include coercion, reputational damage, and behavioral influence. In this model, the value of the operation was realized not solely through the technical impact, but through the controlled release of information and the shaping of perception in the aftermath of the attack.
Continued Activity and Tooling Refinement (2023)
In late 2023, the Homeland Justice campaign re-emerged with renewed activity targeting Albanian entities, demonstrating clear continuity in both target selection and operational methodology. This phase reinforced that the earlier Albania operations were not isolated incidents, but part of a sustained and adaptive campaign. The actors maintained their focus on politically relevant targets while reapplying the same core model of intrusion followed by destructive impact, indicating both persistence of intent and retention of operational access or capability.
During this period, the introduction of the No-Justice Wiper marked a refinement in destructive tooling. Designed for rapid and irreversible disruption, the malware emphasized system incapacitation, including preventing successful operating system boot. The use of signed binaries suggests an increased emphasis on evasion and trust abuse, while PowerShell-based propagation reflects a growing reliance on native system capabilities to enable flexible and low-friction deployment. Together, these developments indicate an evolution toward more efficient, harder-to-detect operations while preserving the campaign’s core objective of high-impact disruption.
Geographic Expansion and Rebranding: Karma Phase (2023-2024)
Following the Israel-Hamas conflict in October 2023, the campaign expanded geographically and adopted the Karma persona.
Despite this rebranding, the underlying tradecraft remained consistent. Operations targeted Israeli organizations and employed a hybrid approach combining custom tooling with publicly available utilities, including bespoke webshells, credential validation tools, reverse SSH tunneling, and destructive mechanisms such as BiBi Wiper.
Actors increasingly relied on hands-on-keyboard techniques, including manual file deletion and disk formatting, prioritizing speed and operational impact. Evidence from this phase suggests a division of labor between intrusion and destructive operators, indicating a modular and coordinated ecosystem.
Maturation and Specialization: Handala Phase (2024 Present)
Handala-hack.tw 2026
The expansion of the Handala infrastructure set with the inclusion of handala-hack[.]ps and, more importantly, handala-hack[.]tw, provides a clearer view into how the actor operationalizes its domain layer over time. These domains are not isolated artifacts. They are part of a repeatable system in which naming conventions, narrative timing, and platform coordination matter more than persistence of any single asset. The repeated appearance of the handala-hack string across multiple TLDs indicates that the domain itself is not intended to endure. It is intended to be recognized, replaced, and reactivated, carrying forward an identity that survives takedown actions and jurisdictional pressure.
The .tw variant is particularly instructive when placed in historical context. Earlier iterations of the ecosystem relied heavily on .to infrastructure, which has long been associated with abuse-tolerant hosting and low-friction registration. The shift into .ps and .tw reflects both symbolic and operational adaptation. The .ps domain carries clear political signaling aligned with the actor’s ideological framing, reinforcing the Palestinian narrative embedded throughout the campaign. By contrast, handala-hack[.]tw appears to serve a different function: jurisdictional dispersion and operational redundancy. Taiwan’s namespace does not inherently carry the same ideological weight, which suggests its use is pragmatic rather than symbolic. In effect, the actor is separating message-layer signaling (.ps) from resilience-layer infrastructure (.tw).
When mapped against the historical leak cadence observed across the full archive, these domains align with distinct phases of campaign activity. Early in the lifecycle, Handala has relied on single-domain publication points tied to specific claim sets. These initial leaks focused on individual targets, often framed as penetrations of named Israeli intelligence or defense figures. The content emphasized access mailboxes, communications, and internal correspondence without attempting to demonstrate systemic reach. Domains in this phase acted as announcement boards, each tied to a discrete narrative event.
As the campaign matured, the scale of claims expanded. The archive shows repeated assertions of large-volume email exfiltration, often in the range of tens of thousands to over one hundred thousand messages. These claims were accompanied by broader institutional framing, suggesting not just individual compromise but organizational penetration. It is in this phase that domain rotation becomes more pronounced. Rather than maintaining a single persistent site, the actor begins to distribute content across multiple similarly branded domains, each capable of hosting or referencing new disclosures. The emergence of domains like handala-hack[.]to and handala-redwanted[.]to reflect this shift toward functionally differentiated nodes, one for breach claims, another for intimidation or doxxing.
The introduction of handala-hack[.]tw appears to correspond with the later stages of this evolution, where the campaign moves beyond exposure into strategic signaling and maximalist claims. Posts associated with this period increasingly reference infrastructure targeting, large-scale destructive capability, and systemic access. Claims such as multi-petabyte data wipes or pre-mapped critical infrastructure targets emerge alongside continued email leak narratives. The domain layer, in this context, becomes less about hosting data and more about anchoring the claim itself. The presence of a new domain signals a new phase of activity, regardless of whether the underlying data is verifiable.
Historically, each wave of leaks follows a recognizable pattern. A new or resurfaced domain appears, often with the familiar handala-hack naming structure. Within a short time window, posts are published asserting compromise of a high-value target. These posts are then amplified through Telegram channels now including identifiers such as @HANDALA_INTEL and further propagated via X accounts. The domain serves as the canonical reference point, but the operational impact is generated through distribution. Even when domains are seized or taken offline, the narrative persists because it has already been exported to other channels.
The content associated with these domains consistently emphasizes three categories of disclosure. The first is email data, which remains the dominant theme across the archive. Whether targeting individuals like Eran Ortal or broader institutional mailboxes, the actor repeatedly frames access to communications as evidence of deep penetration. The second category is identity and contact data, including phone numbers and membership lists, often used in campaigns against dissidents or civilian networks. The third is strategic or infrastructural intelligence, where the actor claims to possess detailed knowledge of critical systems such as water and electricity networks. Each category serves a distinct psychological function: exposure, intimidation, and deterrence.
The inclusion of corporate targets, such as Stryker Corporation, marks another important shift visible in the historical record. Earlier phases of the campaign were tightly focused on Israeli state and intelligence entities. Later phases expand outward, incorporating Western corporate actors to demonstrate global reach. The claims associated with these targets are often the most extreme, including assertions of large-scale data destruction. Whether or not these claims are technically accurate is secondary to their narrative role. They signal that the actor’s reach is not confined to a single geography or sector.
Across all these phases, the domain layer including handala-hack[.]tw remains structurally consistent. The sites themselves are simple, often WordPress-based, with minimal technical sophistication. They do not host malware, nor do they expose command-and-control infrastructure. Instead, they function as narrative anchors, providing a stable URL that can be cited, shared, and referenced across platforms. The real operational activity occurs elsewhere, in the intrusion layer (which remains opaque) and the amplification layer (Telegram and X). The domain is simply the point where those layers intersect publicly.
What emerges from the full dataset, now augmented by the newly observed domains, is a clear pattern: Handala’s infrastructure is designed to be expendable, but its identity is designed to persist. Domains are created, used, and abandoned. Telegram channels are taken down and reconstituted. Yet the naming conventions handala-hack, HANDALA_ and the narrative structure remain constant. This allows the actor to survive disruption without losing coherence. Each new domain, including handala-hack[.]tw, is not a fresh start but a continuation of an ongoing campaign.
In historical context, the leaks themselves should be understood not as isolated incidents but as components of a sustained psychological operation. Early disclosures establish credibility, mid-phase leaks expand perceived capability, and later claims introduce strategic and deterrent messaging. The domain infrastructure evolves in parallel, moving from single-use publication points to a distributed, rotating set of narrative nodes. The result is a system in which the appearance of a new domain is itself a signal, an indication that the next cycle of claims, amplification, and psychological effect is underway.
Ultimately, the addition of handala-hack[.]tw does not represent a new capability. It represents the continued refinement of an existing model. The actor does not depend on any specific domain to achieve its objectives. Instead, it relies on the predictable regeneration of infrastructure combined with consistent narrative execution. In that sense, the domain is not the asset. The campaign is.
Adverse Effects and Real-World Impact of Handala Leak Operations
Analysis of the Handala archive, corroborated with external reporting, demonstrates a consistent divergence between claimed impact and verified operational consequences. While the group presents its activities as large-scale, destructive cyber intrusions, the observable real-world effects fall into a narrower set of categories: operational disruption (rare), exposure and reputational damage (common), and psychological or coercive effects (systematic).
The most clearly substantiated case of material operational impact is the attack against Stryker Corporation. Reporting indicates that the intrusion disrupted core business functions, including order processing, manufacturing, and shipment operations, with recovery extending over multiple days. The incident also reportedly resulted in the remote wiping of tens of thousands of devices, affecting employees across multiple regions and, in some cases, impacting personally owned devices enrolled in enterprise systems. This represents a genuine destructive and operational cyber event, distinguishing it from the majority of Handala’s activity. The scale and severity of this incident further triggered a law enforcement response, including domain seizures targeting Handala infrastructure, indicating that the event crossed the threshold from influence activity into infrastructure-level concern.
A second category of confirmed impact involves high-profile personal data exposure, exemplified by the breach of Kash Patel. In this case, the publication of personal emails, images, and documents created reputational harm and potential counterintelligence risk, even though the exposed material was not assessed as containing sensitive government information. The significance of this event lies less in technical compromise and more in its function as a public humiliation and signaling operation, consistent with Handala’s broader objectives of intimidation and reputational pressure against Western officials.
Other reported incidents fall into a more ambiguous category. The claimed attack against Hebrew University of Jerusalem, involving tens of terabytes of wiped and exfiltrated data, represents a credible, but not fully independently verified, destructive event. While multiple secondary sources describe the incident, there is limited primary confirmation of the full scale of impact. This pattern — where claims are partially supported but not conclusively validated — is characteristic of the Handala ecosystem and complicates direct attribution of operational consequences.
In contrast, some claims appear to have produced primarily reputational or narrative effects without technical confirmation. The alleged compromise of Verifone, for example, was publicly denied by the company, with no evidence of disruption or data loss. In such cases, the adverse effect is not system compromise but forced defensive communication, in which the targeted organization must respond to public allegations, thereby amplifying the narrative regardless of its validity.
A substantial portion of the archive consists of operations targeting individuals within the Israeli intelligence and security ecosystem, including Sima Shine, Ilan Steiner, Deborah Oppenheimer, and Eran Ortal. In these cases, the adverse effects are consistently limited to exposure of alleged communications, reputational damage, and intelligence-related pressure. Although large-scale email leaks are claimed, there is no strong independent evidence of downstream operational disruption, institutional failure, or policy impact. These incidents function primarily as hack-and-leak influence operations, designed to erode trust and project vulnerability rather than to degrade capability.
The campaign also includes a distinct category of identity exposure and intimidation, illustrated by the targeting of VahidOnline. The leak of tens of thousands of user identities and phone numbers associated with dissident networks constitutes a form of digital repression, exposing individuals to harassment, surveillance, or potential physical risk. Unlike corporate or institutional targets, the impact here is distributed across a population, amplifying fear and discouraging participation in opposition or media activities.
Beyond digital exposure, the archive and supporting reporting indicate a pattern of coercive escalation into the physical domain. Handala has been linked to doxxing campaigns against individuals such as defense-sector employees, including alleged exposure of personal details of engineers associated with defense contractors. These actions are often accompanied by explicit threats, transforming cyber activity into psychological coercion with potential real-world implications. Even when the accuracy of the leaked data is uncertain, the act of publication itself generates fear and imposes a defensive burden on victims.
Taken together, these cases demonstrate that Handala’s operational impact is best understood across three tiers. At the highest tier are rare but significant operational disruptions, such as the Stryker incident, which produce measurable effects on systems and services. At the intermediate tier are verified exposures of personal or organizational data, which create reputational and intelligence risks but do not necessarily disrupt operations. At the lowest tier are narrative-driven claims and unverified leaks, which nonetheless generate psychological and informational effects by forcing responses and sustaining uncertainty.
The overall pattern supports a clear analytical conclusion: Handala’s effectiveness does not depend on consistent technical success. Instead, it derives from the ability to convert a limited number of real or plausibly real intrusions into a sustained campaign of perception management, intimidation, and coercive signaling. The majority of adverse events observed are therefore not technical in nature, but psychological and reputational, aligning closely with the broader doctrine of cyber-enabled influence operations.
Parallel Surveillance and Influence Operations
Expansion into Surveillance (2023-2026)
In parallel with its destructive and hack-and-leak operations, the campaign expanded significantly into surveillance and transnational repression beginning in late 2023 and continuing through 2026. This shift represents a broadening of operational scope from institutional disruption to targeted monitoring of individuals, particularly dissidents, journalists, activists, and members of opposition networks. Rather than relying solely on network exploitation, the actors adopted a more tailored approach centered on social engineering and user-level compromise, indicating both improved targeting intelligence and a strategic intent to exert pressure beyond traditional cyber domains.
Access in this surveillance branch is typically achieved through trojanized applications masquerading as legitimate software, including messaging tools, password managers, and media utilities. These lures are often aligned with the expected behavior and digital environment of the target, suggesting prior reconnaissance and profiling. Upon execution, these files deploy staged malware chains that establish persistence and initiate communication with operator-controlled infrastructure. The second-stage implants are modular and designed for continuous data collection, including screen capture, audio interception (with specific capability to monitor conferencing platforms), file harvesting, and credential access. Data is often staged locally, compressed, and prepared for exfiltration in a manner that minimizes detection while maximizing collection efficiency.
A defining characteristic of this surveillance capability is its use of Telegram as a command-and-control channel, leveraging the legitimate Telegram API to transmit instructions and exfiltrated data. This approach allows malicious traffic to blend with normal user activity, complicating network-based detection while simultaneously enabling rapid, distributed control of infected hosts. In some cases, the same platform is used for both covert communication and overt messaging, reinforcing the campaign’s broader integration of technical and informational operations. Taken together, this surveillance expansion demonstrates a transition toward a persistent, person-centric operational model, in which intrusion, monitoring, and psychological pressure are applied in tandem to influence both institutional behavior and individual decision-making.
Telegram as Dual-Use Infrastructure
Telegram occupies a central and multifaceted role within this ecosystem, functioning simultaneously as a covert command-and-control (C2) channel and an overt platform for messaging, amplification, and audience engagement. This dual-use design is not incidental; it reflects a deliberate operational choice to consolidate multiple functions, control, communication, and influence within a single, widely trusted platform. By embedding operational activity within a legitimate and globally used service, the actors reduce their reliance on dedicated infrastructure while increasing resilience against disruption. At the same time, the platform’s scale and accessibility allow it to serve as a high-capacity distribution mechanism for narrative content, enabling rapid dissemination of messaging to both targeted and broad audiences.
From a technical perspective, the use of Telegram as C2 is enabled through abuse of the Telegram Bot API, which allows malware to communicate with operator-controlled bots over encrypted channels that are indistinguishable from normal application traffic. This design significantly complicates detection, as network telemetry alone is often insufficient to differentiate benign from malicious use. Implants can issue commands, upload exfiltrated data, and receive tasking through standard API calls, effectively turning Telegram into a low-cost, low-visibility control infrastructure. Because Telegram traffic is commonly permitted in enterprise and personal environments, this approach provides a reliable communication channel that blends seamlessly into expected user behavior, reducing the likelihood of interception or blocking.
Concurrently, Telegram channels associated with the campaign function as public-facing dissemination nodes, distributing propaganda, operational claims, and references to leaked data. Channels such as those linked to the Homeland Justice persona serve as hubs where messaging is curated, amplified, and framed within ideological or political narratives. The presence of archive files, named data releases, and coordinated messaging indicates that these channels are not passive outlets, but active components of the operational workflow. This convergence of covert C2 and overt communication within the same platform effectively bridges the technical and informational domains, allowing the actors to move seamlessly from intrusion and data collection to public exposure and psychological influence, all within a unified infrastructure.
Malware and Operational Evolution
Evolutionary Overview
The campaign demonstrates a progression from discrete, high-impact destructive events into a modular and adaptive operational toolkit capable of supporting a wide range of objectives across multiple target sets. Early activity, particularly during the Albania operations, was centered on singular, coordinated events in which long-term access culminated in ransomware-style encryption, wiping, and public attribution. Over time, however, these capabilities were not abandoned; instead, they were retained and integrated into a broader operational framework that supports espionage, surveillance, disruption, and influence operations in parallel.
This evolution is distinctly additive rather than substitutive. Earlier destructive tools and techniques such as disk wiping, scripted propagation, and webshell-based persistence remain in active use, while newer capabilities have been layered on top. These include modular malware implants for surveillance, Telegram-based command-and-control, enterprise-scale tooling for network enumeration and control, and structured leak infrastructure for public disclosure. The result is a toolkit that can be dynamically assembled based on operational requirements, allowing actors to shift between stealthy collection, overt disruption, and psychological operations without fundamentally altering their underlying tradecraft.
The modular nature of this toolkit also enables operational flexibility and resilience. Components can be deployed independently or in combination, depending on the target environment and desired outcome. For example, an intrusion may begin as a surveillance operation, transition into data exfiltration, and culminate in either destructive action or controlled leak publication, all using elements of the same toolkit. This layered approach reduces dependency on any single capability and allows the campaign to adapt to defensive pressures, infrastructure disruption, or shifting strategic priorities while maintaining continuity of effect.
Phase I: Destructive Intrusion Model
The Albania campaign established a repeatable model centered on prolonged, covert access followed by synchronized destructive impact and overt attribution. Operators achieved initial entry well in advance of the impact phase, maintained persistence through webshells and credential reuse, and conducted systematic reconnaissance and lateral movement across the environment. During this period, they harvested credentials, mapped network topology, and accessed email systems, enabling large-scale data exfiltration and the prepositioning of tools required for coordinated execution. This extended preparation phase indicates a deliberate emphasis on operational depth and positioning, rather than opportunistic disruption.
The transition to the impact phase was tightly orchestrated. Encryption and wiping components were deployed in sequence to maximize disruption, degrade recovery options, and ensure sustained operational impact across affected systems. The use of propagation mechanisms and administrative access allowed the actors to execute these actions broadly and nearly simultaneously, amplifying the scale of disruption. This was not a simple ransomware event; it was a destructive operation designed to disable systems, disrupt services, and create immediate strategic effect, particularly within government infrastructure.
Equally important was the deliberate and immediate move to public attribution and narrative control. Under the Homeland Justice persona, the actors claimed responsibility, released messaging, and framed the attack within a political and ideological context. This transformed the operation from a purely technical incident into a hybrid cyber–influence event, where the technical damage served as the foundation for broader psychological and reputational impact. The Albania campaign thus established a durable operational model: gain long-term access, prepare the environment, execute coordinated destruction, and rapidly exploit the event through controlled public disclosure to achieve strategic influence.
Phase II: Iterative Destructive Refinement
The introduction of the No-Justice Wiper reflects a clear refinement in the actor’s destructive capability, emphasizing speed, reliability, and operational efficiency. Compared to earlier tooling that combined encryption and wiping in a more sequential and resource-intensive manner, the No-Justice variant appears optimized for rapid execution and immediate impact. Its design prioritizes system incapacitation, including corruption of critical structures required for operating system startup, thereby preventing recovery through conventional means. This shift indicates a move toward direct, irreversible disruption, reducing the time between execution and effect while minimizing the opportunity for defensive response.
At the same time, the use of signed binaries demonstrates an increased focus on evasion through trust abuse. By leveraging code-signing mechanisms, the actors are able to bypass or reduce scrutiny from endpoint protection systems that rely on signature-based trust models. This reflects a more sophisticated understanding of defensive controls and suggests that the tooling has been adapted based on prior detection and mitigation efforts. The combination of trusted execution and destructive functionality allows the malware to operate with a lower likelihood of immediate detection, increasing the probability of successful deployment across multiple systems.
The reliance on PowerShell-based propagation and execution further underscores a transition toward living-off-the-land techniques. By utilizing native system capabilities, the actors reduce their dependency on large or complex malware payloads, enabling more flexible and stealthy deployment within compromised environments. PowerShell scripts can be rapidly modified, obfuscated, and distributed using existing administrative channels, allowing for efficient lateral spread and coordinated execution. Together, these elements – streamlined destructive logic, trust-based evasion, and native execution – illustrate a broader evolution toward leaner, more adaptable tooling that enhances both effectiveness and survivability within contested network environments.
Phase III: Hybrid Operational Model
The Karma phase introduced a distinctly hybrid operational approach that combined bespoke tooling with hands-on-keyboard techniques and widely available utilities, enabling flexible execution across heterogeneous environments. Rather than relying exclusively on custom malware, operators blended lightweight webshells and purpose-built components with native administrative tools and publicly available software. This reduced development overhead, shortened deployment time, and allowed rapid adaptation to differences in target infrastructure whether on-premises Windows domains, Linux servers, or mixed environments while preserving the ability to execute high-impact actions.
A defining feature of this phase was the increased emphasis on manual tradecraft and living-off-the-land techniques. Operators leveraged standard system utilities and administrative protocols such as RDP for lateral movement, built-in command-line tools, and common utilities like SDelete or disk formatting to perform destructive actions without introducing large, easily detectable binaries. Custom elements, including webshells (e.g., Karma Shell) and credential validation tools (e.g., do.exe), were used selectively to maintain access and verify privileges, while publicly available tools such as reGeorg enabled post-compromise control. This blend allowed operators to pivot quickly within compromised networks, execute tasks with minimal friction, and evade signature-based defenses by masking activity as legitimate administration.
The result was a modular, operator-driven execution model that prioritized flexibility, speed, and reliability over stealth alone. By combining custom implants with manual techniques and off-the-shelf tools, the actors could tailor operations to the specific constraints of each target, escalate privileges, propagate across systems, and initiate disruption with minimal dependency on a single capability. This hybridization also improved resilience: if one tool or method was detected or blocked, operators could readily substitute alternatives without disrupting the overall operation. In effect, the Karma phase marked a transition toward a more adaptable and scalable approach, capable of sustaining coordinated campaigns across diverse technical environments while maintaining alignment with the campaign’s broader objectives of disruption and influence.
Phase IV: Multi-Vector Destruction and Enterprise Tooling
Under the Handala persona, operations expanded into a coordinated, multi-method destruction model that reflects a clear increase in operational maturity and planning discipline. Rather than relying on a single payload or technique, actors began employing parallel destructive mechanisms, including custom wipers, PowerShell-based recursive deletion, and encryption via legitimate tools such as VeraCrypt. These methods were often executed in tandem across multiple systems, ensuring redundancy in effect and significantly reducing the likelihood of recovery. This approach demonstrates a shift from opportunistic disruption to deliberate, layered impact engineering, where multiple techniques reinforce one another to guarantee system failure and data loss.
At the same time, the incorporation of enterprise-scale tooling enabled the actors to operate more effectively within complex network environments. Tools such as NetBird facilitated persistent internal connectivity and remote control across segmented networks, while ADRecon provided comprehensive visibility into Active Directory structures, users, and permissions. This combination allowed operators to map target environments in detail, identify high-value systems, and coordinate execution across domains with greater precision. The use of Group Policy and administrative scripting further enabled centralized deployment of destructive actions, amplifying scale and synchronizing impact across large portions of the network.
These developments collectively indicate a transition toward a structured, scalable operational model capable of sustaining complex campaigns within enterprise environments. The reliance on both custom and legitimate tools, combined with coordinated execution and network-wide visibility, reflects an evolution beyond isolated incidents into systematic, organization-level disruption capability. Under Handala, the campaign demonstrates not only technical sophistication, but also an increased ability to integrate access, control, and destruction into a cohesive and repeatable operational framework aligned with broader strategic objectives.
Phase V: Surveillance Integration
Telegram-based malware campaigns introduced a persistent monitoring layer that materially expanded the campaign’s scope beyond episodic disruption into continuous intelligence collection. Initial access is commonly achieved through trojanized applications tailored to the target’s context, such as messaging clients, password managers, or media tools suggesting prior reconnaissance and profiling. Once executed, staged loaders deploy modular implants that establish persistence and enable ongoing telemetry collection, including screen capture, keystroke or clipboard capture, file harvesting, and, in some cases, audio interception of conferencing applications. Data is typically staged locally, compressed, and queued for exfiltration, allowing operators to control the cadence of collection and minimize anomalies that might trigger detection.
A defining feature of this capability is the use of Telegram’s Bot API as command-and-control, which allows implants to communicate over encrypted channels indistinguishable from normal Telegram traffic. This design provides a resilient, low-cost infrastructure that blends into expected network behavior and is difficult to block without disrupting legitimate use. Operators can issue tasking, retrieve data, and manage multiple hosts via bot commands, effectively turning Telegram into a distributed control plane. Because Telegram is widely permitted across enterprise and personal environments, this approach increases reliability while reducing dependence on bespoke infrastructure that is more easily identified and taken down.
Operationally, this surveillance layer supports transnational repression by enabling targeted, person-centric campaigns against dissidents, journalists, and opposition figures. Continuous monitoring yields sensitive personal and organizational insights that can be selectively disclosed, used to intimidate, or leveraged to shape narratives in subsequent leak operations. This tight coupling between covert collection and overt exposure allows actors to move seamlessly from surveillance to psychological pressure, aligning technical activity with influence objectives. The result is a persistent, adaptive capability that extends the campaign’s reach from network disruption to sustained coercion of individuals and communities across borders.
Phase VI: Convergence (Stryker-Era Operations)
Recent activity, particularly the Stryker incident (March 2026), demonstrates a clear convergence of destructive, surveillance, and influence capabilities into a unified operational model, while also marking a significant evolution in how these effects are delivered. Unlike earlier phases that relied heavily on malware deployment within compromised networks, emerging reporting indicates that Handala-linked actors achieved administrative access to enterprise management infrastructure, specifically Microsoft Intune, and used it as a force-multiplier for both disruption and scale. (Cyber Magazine)
In the Stryker case, investigators and multiple reports suggest that attackers compromised an Intune administrative account or management console, allowing them to issue remote commands directly to enrolled endpoints. Intune, as a cloud-based endpoint management platform, is designed to enforce policies, deploy software, and remotely wipe devices. By gaining privileged access to this system, the actors were able to bypass traditional malware deployment entirely and instead execute a centralized wipe command across tens of thousands of devices simultaneously. Reports indicate that as many as 80,000–200,000 devices, including laptops and mobile endpoints, were wiped, while approximately 50 terabytes of data were exfiltrated prior to the destructive action. (TechRadar)
This technique represents a fundamental shift in operational tradecraft. Rather than relying on endpoint-level persistence and execution, the actors targeted the control plane of the enterprise itself. With access to Intune, they effectively inherited the organization’s own administrative authority, allowing them to push destructive actions at scale with minimal friction and high reliability. As one analysis noted, once inside such a system, “an adversary… just need[s] to press a button,” highlighting how legitimate enterprise tooling can be weaponized for immediate, large-scale impact.
The implications of this approach are significant. First, it dramatically reduces the need for detectable malware artifacts, complicating traditional detection strategies that rely on endpoint indicators. Second, it enables near-instantaneous, synchronized disruption across globally distributed infrastructure, as seen in the simultaneous impact across dozens of countries in the Stryker event. Third, it allows actors to combine data exfiltration, destructive wiping, and public attribution within a tightly compressed timeline, reinforcing the campaign’s hack-and-leak model while increasing operational tempo. (Tenable)
Critically, this evolution does not replace earlier capabilities but integrates with them. The same ecosystem that previously relied on wipers, PowerShell scripts, and Telegram-based command-and-control now demonstrates the ability to pivot into identity and access compromise at the enterprise management layer, effectively collapsing the distinction between intrusion, execution, and impact. In this model, surveillance capabilities provide intelligence and targeting, administrative compromise enables execution at scale, and influence infrastructure websites and Telegram amplify the effects through public messaging and data release.
Taken together, the Stryker incident illustrates the campaign’s progression into a fully converged operational framework, where destructive, surveillance, and influence capabilities are no longer sequential phases but simultaneous, interdependent components. The abuse of Intune marks a notable escalation in both technical sophistication and strategic impact, demonstrating that the actors are not only adapting their tooling, but are increasingly targeting the centralized control mechanisms of modern enterprise environments to achieve rapid, large-scale disruption aligned with broader geopolitical objectives.
Operational Model: Hack-and-Leak as Psychological Operations
The Homeland Justice and Handala campaigns are best understood as state-directed hack-and-leak operations engineered for psychological impact, in which technical intrusion serves as a means to produce exploitable narratives rather than an end in itself. From their earliest manifestation, these operations have been structured to convert access into influence: compromise enables collection, collection enables disclosure, and disclosure is shaped to achieve coercive or reputational effects. This framing distinguishes the activity from financially motivated ransomware or purely clandestine espionage, positioning it instead within a model of cyber-enabled information warfare aligned with state objectives.
From the Albania campaign onward, data theft has been systematically paired with controlled, curated public disclosure through actor-operated infrastructure, including websites and Telegram channels such as @Homeland Justice1. These platforms function as dissemination nodes where messaging is crafted, amplified, and aligned with political narratives. The release of stolen material, often selective, staged, or thematically framed, is designed to maximize audience impact, reinforce claims of legitimacy, and sustain attention over time. In this sense, the infrastructure is not merely a repository for leaked data, but an active component of the operational workflow, bridging the gap between technical compromise and public perception.
@Homeland Justice1 Telegram Channel
Within this model, destructive actions serve primarily to amplify visibility and urgency, creating conditions that heighten the impact of subsequent disclosures. Wiping, encryption, and service disruption draw attention to the incident and signal capability, but the strategic value is realized through narrative amplification of how the event is presented, interpreted, and circulated. The transition to the Handala persona reflects a further refinement of this approach, with increased segmentation of infrastructure to support distinct functions such as leak publication, propaganda, and targeted exposure of individuals. This specialization indicates a maturing operational framework in which success is measured less by persistence or financial return, and more by the ability to shape perception, apply pressure, and influence behavior across both institutional and individual targets.
Infrastructure and Domain Ecosystem
The infrastructure supporting the Homeland Justice and Handala campaigns reflects a deliberate, layered architecture designed to separate public-facing operations from backend control while enabling specialized functions across the ecosystem. Core domains such as Homeland Justice[.]org, handala-hack[.]to, handala-redwanted[.]to, and karmabelow80[.]org operate as visible nodes for messaging, leak publication, and intimidation, serving as the primary interface through which the actors communicate with both targets and broader audiences. These platforms are used to disseminate propaganda, frame narratives, and release or reference stolen data, transforming technical intrusions into publicly consumable events aligned with the campaign’s psychological objectives.
Behind this visible layer, additional domains such as homelandjustice[.]cx and Homeland Justice[.]ru likely function as alternate or backend infrastructure, supporting operational continuity and resilience. This separation suggests an architecture in which public-facing assets can be replaced or rotated without disrupting underlying capabilities, thereby reducing exposure while maintaining persistence. Within this system, each domain appears to serve a distinct and purpose-driven role, contributing to a modular framework that supports narrative framing, data publication, and targeted exposure. This functional segmentation reinforces the broader operational model, enabling the actors to coordinate technical compromise with controlled disclosure and messaging in a cohesive and scalable manner.
Tactics, Techniques, and Procedures (TTPs)
The campaign demonstrates a high degree of consistency in its tactics, techniques, and procedures (TTPs) across all observed phases, reflecting a mature and repeatable operational playbook. Initial access is typically achieved through a combination of exploitation of internet-facing services and targeted social engineering depending on the operational context. In earlier phases, actors leveraged vulnerabilities in externally exposed systems such as Microsoft SharePoint or Exchange to gain footholds within enterprise environments. In parallel, particularly in later surveillance-oriented activity, access has been obtained through user-centric compromise, including phishing and the delivery of trojanized applications tailored to specific targets. This dual approach allows the actors to flexibly pursue either broad network intrusion or highly targeted individual access depending on mission requirements.
Once access is established, persistence is maintained through a mix of webshell deployment and registry-based mechanisms, enabling continued control over compromised systems even in the face of remediation efforts. Webshells, often deployed on IIS or similar web servers, provide durable remote access and are frequently reused or redeployed as needed. Registry modifications and scheduled tasks are used to ensure execution at startup or at defined intervals, supporting long-term presence within the environment. Lateral movement is conducted using standard administrative protocols such as RDP, SMB, and Windows Management Instrumentation (WMI), often leveraging harvested credentials to blend activity with legitimate administrative behavior. This reliance on native protocols reduces the need for specialized tooling and helps evade detection by appearing consistent with normal network operations.
Credential access is a critical component of the campaign and is achieved through both credential harvesting and memory dumping techniques. Actors extract credentials from configuration files, email systems, and browser stores, while also leveraging native Windows components such as rundll32 and comsvcs.dll to dump LSASS memory and obtain plaintext credentials or hashes. These credentials are then used to escalate privileges and expand access across the network. Execution throughout the campaign frequently relies on PowerShell and command-line utilities, reflecting a strong preference for living-off-the-land techniques. PowerShell scripts are used for payload delivery, lateral movement, and destructive actions, and can be easily obfuscated or modified to evade detection while maintaining operational flexibility.
Data exfiltration is conducted using a combination of traditional methods and platform abuse, depending on the target environment and desired level of stealth. Files are typically staged locally, compressed, and transferred using standard protocols such as HTTP(S), FTP, or cloud storage services. In more advanced phases, particularly those involving surveillance, the actors leverage Telegram-based exfiltration, using the platform’s API to transmit data through encrypted channels that blend with legitimate traffic. This approach provides both resilience and deniability, as it reduces dependence on dedicated command-and-control infrastructure and leverages widely permitted network activity.
The impact phase integrates multiple destructive techniques, including disk wiping, file encryption, and manual system destruction, often executed in a coordinated manner across numerous endpoints. Custom wipers, PowerShell-based deletion scripts, and legitimate tools such as disk formatting utilities or encryption software are used in combination to maximize damage and complicate recovery. In some cases, actors manually execute commands to delete critical files or disable services, reinforcing the overall impact. This phase is frequently followed by immediate public disclosure, with the actors claiming responsibility and releasing messaging or data through controlled infrastructure. This rapid transition from technical action to public exposure is a defining characteristic of the campaign, linking operational execution directly to its broader objective of psychological influence and coercion.
Evolution of Personas
The progression from Homeland Justice to Karma and ultimately Handala reflects deliberate rebranding rather than a change in the underlying actor set. Core tradecraft, targeting logic, infrastructure patterns, and operational sequencing remain consistent, indicating continuity of capability and control. Homeland Justice was tightly aligned with the Albania campaign, emphasizing retaliation and coercive political messaging. As operations expanded, particularly after the Israel-Hamas conflict, the Karma persona enabled repositioning within a broader ideological frame while preserving the same methods. Handala represents a further evolution toward a durable, scalable identity suited for sustained, multi-theater activity.
These personas function as operational “skins” layered over a stable technical and organizational foundation. Each is tailored to specific audiences and narratives: Homeland Justice to Albanian political dynamics and the MEK (Mojahedin-e-Khalq), Karma to anti-Israeli messaging, and Handala to broader symbolic framing applicable across conflicts. This segmentation optimizes psychological resonance while complicating attribution by creating the appearance of distinct groups.
Multiple personas also manage exposure and risk. Branding shifts allow actors to distance current activity from prior campaigns, reset perception, and adapt to changing conditions without abandoning infrastructure or tradecraft. Parallel operations can run under different identities, reinforcing perceived decentralization. Despite this, consistent use of hack-and-leak workflows, Telegram and leak sites, and similar tooling confirms these are not separate entities but components of a unified, centrally directed ecosystem.
Strategic Assessment
These campaigns represent a state-directed, cyber-enabled influence capability that aligns closely with the operational doctrine of Iran’s Ministry of Intelligence and Security (MOIS), in which cyber operations are employed not solely for intelligence collection or disruption, but as instruments of coercion, signaling, and psychological pressure. The integration of intrusion, disruption, and narrative manipulation into a single operational system reflects a deliberate strategy in which technical access is leveraged to produce effects in the information domain. In this model, network compromise enables data acquisition and operational positioning; disruption amplifies visibility and urgency; and controlled disclosure shapes perception, imposes reputational cost, and pressures decision-making. These elements are not sequential but interdependent, forming a cohesive framework designed to influence both institutional behavior and individual actors across geopolitical contexts.
Recent infrastructure activity over the last several weeks provides direct, empirical support for this assessment and demonstrates that this capability remains active, adaptive, and operationally synchronized. Between 19 March and 23 March 2026, the actor cluster executed a compressed domain registration burst, provisioning at least eight new domains across all three personas: Handala, Karma/KarmaBelow80, and Homeland Justice. The majority of these domains are Handala-branded, including handala-hack[.]pro, handala-hack[.]shop, handala-hack[.]tw, handala-redwanted[.]cc, and handala-redwant[.]to, indicating that Handala remains the primary outward-facing operational identity. In parallel, the registration of karmabelow80[.]biz, karmabelow80[.]st, and notably Homeland Justice[.]info demonstrates that legacy personas are being actively reconstituted rather than retired.
This pattern is analytically significant. It indicates that personae evolution within this ecosystem is not linear but additive and concurrent. The actors are not transitioning from one identity to another; instead, they are maintaining multiple branded layers simultaneously, enabling them to pivot narratives, distribute operational risk, and complicate attribution. The near-simultaneous reactivation of Homeland Justice alongside active Handala expansion suggests deliberate attribution shaping and historical continuity signaling, reinforcing the perception of a persistent, ideologically driven campaign lineage.
The temporal characteristics of this activity further reinforce its operational intent. The tight clustering of registrations within a five-day window is consistent with pre-operational staging or infrastructure regeneration following disruption rather than routine domain churn. The inclusion of both “hack”-labeled domains and “redwanted”-style domains within this burst indicates parallel preparation for both intrusion-linked branding and leak-and-shame operations, which are central to this ecosystem’s influence model. This aligns with prior observed behavior in which compromised data is rapidly operationalized for public dissemination and psychological effect.
Comparable operational patterns can be observed in other state-aligned ecosystems, including Russian influence campaigns such as those associated with the Doppelgänger campaigns and hack-and-leak operations attributed to GRU-linked actors, and DPRK multi-cluster activity, where distinct operational units specialize in intrusion, financial operations, or disruption. However, the Homeland Justice / Handala ecosystem is distinguished by its consistent and tightly coupled integration of hack-and-leak operations with overt psychological messaging. Whereas Russian operations often separate intrusion from amplification, and DPRK activity frequently prioritizes financial or espionage outcomes, this campaign persistently merges technical compromise with immediate public attribution, curated disclosure, and ideological framing. The latest domain registrations reinforce this distinction by showing that infrastructure supporting both compromise and narrative dissemination is provisioned in parallel, not sequentially.
Accordingly, this activity should not be interpreted as a series of isolated incidents or campaigns, but as a persistent, evolving capability embedded within a broader state strategy. The newly observed domain registrations demonstrate that this capability can be rapidly reconstituted, expanded, and rebranded on demand, even in the face of prior takedowns or disruptions. The reuse of naming conventions, the continuity of tradecraft, the simultaneous operation of multiple personas, and the structured expansion of domain infrastructure all indicate an enduring operational framework rather than ad hoc activity. This capability can be activated, scaled, or redirected in response to changing geopolitical conditions, allowing it to remain relevant across multiple theaters and target sets. As such, it represents a sustained mechanism through which the state can project influence, apply pressure, and shape narratives in the cyber and information domains over time.
Persistent integration with information operations
Appendix B – MITRE ATT&CK Matrix by Campaign Phase
his appendix presents a matrix-style mapping of the Homeland Justice / Karma / Handala ecosystem across the MITRE ATT&CK Enterprise framework, broken down by campaign phase. It highlights how capabilities evolved while maintaining continuity across tactics.
B.1 Albania Campaign (2022) – Homeland Justice
Tactic
Techniques
Initial Access
T1190 Exploit Public-Facing Application
Execution
T1059 Command Interpreter, T1059.001 PowerShell
Persistence
T1505.003 Web Shell
Privilege Escalation
T1078 Valid Accounts
Defense Evasion
T1070 Indicator Removal
Credential Access
T1003.001 LSASS Memory
Discovery
T1087 Account Discovery
Lateral Movement
T1021.001 RDP, T1021.002 SMB
Collection
T1114.002 Remote Email Collection
Command & Control
T1105 Ingress Tool Transfer
Exfiltration
T1041 Exfiltration Over C2
Impact
T1486 Data Encryption, T1561.001 Disk Wipe, T1485 Data Destruction
B.2 No-Justice Wiper Phase (Late 2023)
Tactic
Techniques
Execution
T1059.001 PowerShell
Persistence
T1078 Valid Accounts
Defense Evasion
T1218 System Binary Proxy Execution, T1036 Masquerading
Lateral Movement
T1021 Remote Services
Command & Control
T1105 Ingress Tool Transfer
Impact
T1561.001 Disk Wipe, T1485 Data Destruction, T1490 Inhibit Recovery
B.3 Karma Phase (Israel Operations 2023–2024)
Tactic
Techniques
Initial Access
T1190 Exploit Public-Facing Application
Execution
T1059, T1059.001 PowerShell
Persistence
T1505.003 Web Shell
Privilege Escalation
T1078 Valid Accounts
Defense Evasion
T1070 File Deletion, T1562 Impair Defenses
Credential Access
T1003.001 LSASS Memory
Discovery
T1018 Remote System Discovery
Lateral Movement
T1021.001 RDP, T1021.002 SMB
Collection
T1005 Data from Local System
Command & Control
T1105 Ingress Tool Transfer
Exfiltration
T1041 Exfiltration Over C2
Impact
T1485 Data Destruction, T1561 Disk Wipe
B.4 Handala Phase (2024–Present)
Tactic
Techniques
Initial Access
T1190, T1566 Phishing
Execution
T1059.001 PowerShell, T1218.011 Rundll32
Persistence
T1547 Boot/Logon Autostart
Privilege Escalation
T1078 Valid Accounts
Defense Evasion
T1036 Masquerading, T1562 Impair Defenses
Credential Access
T1003.001 LSASS, T1555 Credential Stores
Discovery
T1087 Account Discovery, T1069 Permission Groups
Lateral Movement
T1021 RDP/SMB
Collection
T1005 Local Data
Command & Control
T1105 Tool Transfer
Exfiltration
T1041 Exfiltration
Impact
T1485 Data Destruction, T1486 Encryption, T1490 Inhibit Recovery
B.5 Telegram Surveillance Campaign (2023–2026)
Tactic
Techniques
Initial Access
T1566 Phishing, T1204 User Execution
Execution
T1059.001 PowerShell
Persistence
T1547 Registry Run Keys
Defense Evasion
T1036 Masquerading
Credential Access
T1555 Credential Stores
Discovery
T1087 Account Discovery
Collection
T1113 Screen Capture, T1123 Audio Capture, T1005 Data Collection
Command & Control
T1071.001 Web Protocols (Telegram API)
Exfiltration
T1041 Exfiltration via C2
Impact
(Indirect – psychological/repression rather than system destruction)
B.6 Persona / Influence Infrastructure Layer
Tactic
Techniques
Resource Development
T1583.001 Domains, T1583.003 VPS
Establish Accounts
T1585.001 Social Media Accounts
Stage Capabilities
T1608 Upload/Stage Data
Command & Control
T1102 Web Service (Telegram as platform)
B.7 Cross-Phase ATT&CK Heat Map (Summary)
Tactic
Consistency Level
Initial Access
High
Execution (PowerShell / CLI)
Very High
Persistence
High
Credential Access
Very High
Lateral Movement
Very High
Collection
High
Command & Control
High
Exfiltration
High
Impact
Very High
Influence / Persona Ops
Unique / Defining
APPPENDIX C Leaks Impact
Victim
Leak (Relative Timeline)
Claimed Data
Confirmed Adverse Event
Impact Type
Confidence
Stryker Corporation
Late (T10)
Large-scale data + "wipe"
Operational disruption to manufacturing, ordering, and shipments; systems restoration required; ~80,000 devices reportedly wiped
Operational + destructive
HIGH
Kash Patel
External (not in TW mirror but linked campaign)
Emails, personal data
Public exposure of personal emails and documents; reputational and counterintelligence risk
Exposure / reputational
HIGH
Hebrew University of Jerusalem
Late (parallel campaign)
40–48 TB wiped, 23 TB exfil (claimed)
Claimed destructive attack; partial reporting, no strong independent confirmation of full scale
Operational (claimed)
MEDIUM
Verifone
Mid–late (external claim)
Payment system compromise (claimed)
Company denied breach; no confirmed disruption
Reputational only
LOW
VahidOnline
Mid (T5)
~180,000 users + phone numbers
Doxxing and exposure of identities; intimidation risk to dissident network
Identity exposure / intimidation
MEDIUM-HIGH
Sima Shine
Mid (T4)
~100,000 emails (claimed)
Public leak claims; reputational and intelligence exposure; no confirmed operational disruption
Exposure / reputational
MEDIUM
Ilan Steiner
Early–Mid (T3)
~50,000 emails (claimed)
Public leak claims; financial/internal exposure narrative; no confirmed secondary impact
Exposure / reputational
MEDIUM
Deborah Oppenheimer
Early (T2)
Private communications (claimed)
Public exposure claims; limited external corroboration of downstream effects
Exposure / reputational
LOW-MEDIUM
Eran Ortal
Early (T1)
Strategic documents (claimed)
Narrative exposure of military planning; no confirmed operational consequence
Exposure / narrative
LOW-MEDIUM
Israeli Security Institutions (aggregate)
Mid–Late (T7)
~50,000+ emails (claimed)
Systemic compromise narrative; no confirmed service disruption or institutional failure
Exposure / perception
MEDIUM
Mossad-linked "Treasury"
Mid–Late (T6)
Financial/internal documents (claimed)
Corruption/financial exposure narrative; no confirmed operational impact
Narrative / reputational
LOW-MEDIUM
Israeli Water Infrastructure
Late (T8)
Target database (claimed)
No confirmed breach; deterrence signaling only
Strategic signaling
LOW
Israeli Energy Grid
Late (T9)
Target database (claimed)
No confirmed breach; deterrence messaging
Strategic signaling
LOW
Lockheed Martin engineers (Israel)
External campaign
Personal data (dox)
Doxxing + threats; intimidation campaign; limited validation of dataset accuracy
Handala: MOIS Linked Cyber Influence Ecosystem Threat Intelligence Assessment
Discover how Handala, Homeland Justice, and Karma function as a unified MOIS-linked cyber influence ecosystem. This threat intelligence assessment reveals how Iran uses "hack-and-leak" operations to weaponize perception over technical complexity.
Operational Structure and Attribution
The activity attributed to Homeland Justice, Karma/KarmaBelow80, and Handala is most accurately assessed as a single, coordinated cyber influence ecosystem aligned with Iran’s Ministry of Intelligence and Security (MOIS; وزارت اطلاعات جمهوری اسلامی ایران), rather than a collection of independent hacktivist groups. These personas function as interchangeable operational veneers applied to a consistent underlying capability. Their purpose is not to reflect organizational separation, but to enable segmentation of messaging, targeting, and attribution while preserving continuity of infrastructure and tradecraft.
The use of the name “Handala” itself reinforces the ideological framing of the campaign. Handala (حنظلة) is a well-known Palestinian symbol created by cartoonist Naji al-Ali, depicting a barefoot child who has turned his back on the world in protest of injustice and dispossession. Within the context of this cyber campaign, the adoption of the Handala identity serves to anchor operations within a broader “resistance” narrative, signaling alignment with anti-Israeli and anti-Western themes while providing a culturally resonant and emotionally charged brand for influence operations.
Across all observed phases, the actors exhibit clear temporal continuity, shared infrastructure patterns, and a repeatable operational workflow. The persistence of these elements, despite rebranding, indicates centralized direction and capability management. The use of multiple identities is therefore best understood as a mechanism for narrative flexibility and operational deniability, rather than evidence of distinct actor groups.
Evolution of the Operational Model
The campaign first became visible under the Homeland Justice brand during the 2022 Albania operations, which established its foundational model: long-term access, structured data exfiltration, destructive or disruptive action, and immediate public disclosure. From the outset, technical operations were tightly coupled with messaging, indicating that disruption alone was not the objective. Instead, cyber activity was used to enable narrative exploitation and psychological impact.
Subsequent phases reflect an additive evolution rather than a replacement of capabilities. The Karma phase introduced a hybrid execution model combining custom tooling, publicly available utilities, and hands-on-keyboard tradecraft. This increased operational flexibility and reduced reliance on bespoke malware. The Handala phase further expanded this model into a multi-vector framework integrating destruction, surveillance, and influence operations. The addition of Telegram-based command-and-control and surveillance tooling marked a shift toward persistent, person-centric targeting, extending the campaign’s reach beyond institutions to individuals.
Convergence of Capabilities
Recent activity demonstrates a convergence of previously distinct operational components into a unified framework. Intrusion, surveillance, disruption, and influence are no longer sequential phases, but simultaneous and interdependent functions. The Stryker incident illustrates this evolution, where large-scale data exfiltration, enterprise-level disruption through administrative control systems, and immediate narrative amplification were executed in a tightly integrated manner.
This shift reflects a broader transition away from malware-centric operations toward identity and access compromise at the control-plane level, enabling rapid, scalable impact with minimal reliance on detectable artifacts. It also demonstrates an increased ability to align technical execution with strategic messaging in near real time.
Infrastructure and Amplification Model
The ecosystem is supported by a layered infrastructure designed to separate operational functions while maintaining resilience. Public-facing domains and Telegram channels act as dissemination and amplification nodes, where messaging is curated, claims are published, and stolen data is selectively exposed. These platforms are integral to the operational workflow, bridging the gap between technical compromise and public perception.
Twitter April 2026 Amplification acct
Telegram Amplification Accounts Over Time
Infrastructure is intentionally ephemeral. Domains are frequently rotated, and personas are rebranded or reactivated as needed. However, naming conventions, messaging patterns, and distribution channels remain consistent, allowing the campaign to maintain coherence despite disruption. This results in a system where infrastructure is disposable, but identity and narrative persist.
Operational Effects and Impact
The observable impact of this ecosystem reveals a consistent divergence between claimed and verified outcomes. While the actors present their operations as large-scale destructive intrusions, confirmed system-level disruption is relatively rare. Instead, the majority of activity produces data exposure, reputational damage, and psychological pressure, often targeting both institutions and individuals.
Media hype cycle of low hanging fruit hack of FBI director’s 2009 email account
Sensationalized Reward Offer for Trump or Netanyahu 2026
Many claims remain partially verified or unverified, yet still generate significant downstream effects. Organizations are compelled to investigate and respond, media coverage amplifies the narrative, and uncertainty is sustained. In practice, the perception of compromise often produces effects equivalent to confirmed compromise, enabling the actors to achieve disproportionate impact relative to their demonstrated technical capability.
Role of Telegram and Surveillance Integration
Telegram plays a central role within this ecosystem as both a command-and-control channel and a public dissemination platform. By leveraging a widely trusted service, the actors reduce infrastructure overhead and increase operational resilience. Malware can communicate with operator-controlled bots using encrypted channels indistinguishable from legitimate traffic, while Telegram channels simultaneously serve as hubs for messaging and amplification.
The integration of surveillance capabilities further expands the campaign’s scope. Trojanized applications and user-targeted lures enable persistent monitoring of individuals, particularly dissidents and opposition networks. This allows the actors to move seamlessly from covert collection to overt exposure, reinforcing the link between technical activity and psychological pressure.
Strategic Assessment
This ecosystem represents a state-directed instrument of cyber-enabled influence, in which technical operations are tightly integrated with narrative manipulation and media amplification dynamics to achieve coercive and strategic effects. Intrusion enables access, access enables collection, and collection enables controlled disclosure. However, the decisive phase is the conversion of that disclosure into a high-visibility narrative event. Incidents such as the compromise of Kash Patel demonstrate how relatively limited technical access can be operationalized through the modern news cycle, where rapid reporting, social media propagation, and secondary analysis amplify the perceived scale and significance of the breach. In this model, the hype cycle is not incidental; it is a core component of the operation, transforming modest compromises into strategic effects.
The maintenance of multiple concurrent personas, the rapid regeneration of infrastructure, and the consistent integration of cyber and information operations indicate a mature and adaptive capability optimized for this environment. These personas allow the actors to continuously seed new events into the information ecosystem, while disposable domains and Telegram channels ensure persistence of messaging even as infrastructure is disrupted. Each operation is effectively designed as a trigger for a predictable amplification loop: initial claim, media pickup, public discourse, and institutional response. This loop imposes reputational and operational costs on targets regardless of the underlying technical depth.
As a result, the system can be activated, scaled, or redirected in response to geopolitical conditions with minimal reliance on sustained intrusion capability. Its effectiveness lies in the ability to synchronize cyber activity with the tempo of the information environment, using the hype cycle to magnify impact across multiple theaters and target sets. In practical terms, this means that perception, attention, and narrative momentum are treated as operational objectives on par with access and disruption, allowing the actors to remain effective even when technical outcomes are limited.
Conclusion
Homeland Justice, Karma, and Handala should be treated as components of a unified operational apparatus, not discrete threat actors. Their effectiveness does not derive from sustained technical superiority or advanced intrusion tradecraft, but from their ability to fuse low-to-moderate cyber capability with disciplined psychological and informational operations to create a cohesive and scalable system.
Across observed incidents, the underlying modus operandi is consistent with opportunistic, identity-layer compromise rather than sophisticated exploitation. Initial access is frequently achieved through relatively low-complexity methods such as password guessing, credential stuffing, phishing, exploitation of weak or reused credentials, and poor security hygiene in externally exposed services. Even in higher-impact cases such as Stryker Corporation, the available indicators suggest that compromise likely originated from weak identity and access controls or misconfigured management infrastructure, rather than novel vulnerabilities or advanced malware deployment. This aligns with a broader pattern in which targets are selected not for hardened defenses, but for accessible attack surfaces and exploitable operational gaps.
In this sense, these actors operate closer to low-tier intrusion crews or access brokers in their technical execution. However, what differentiates them is not how they gain access, but what they do with it. Limited footholds – often no more than a compromised account, exposed dataset, or peripheral system – are systematically transformed into hack-and-leak operations designed for maximum psychological and media impact. Small or ambiguous datasets are framed as large-scale breaches; partial access is presented as systemic compromise; and unverified claims are released in ways that ensure rapid amplification.
This is where the integration with influence operations becomes decisive. The ecosystem relies heavily on timing, narrative construction, and media exploitation to convert low-level technical events into high-visibility incidents. The breach and leak involving Kash Patel is illustrative: a compromise of a personal account technically limited in scope was rapidly elevated into a widely covered event, generating disproportionate attention relative to its technical impact. This reflects a deliberate strategy in which the news cycle functions as an extension of the operation, amplifying reach and reinforcing perceived capability.
Targets are therefore often targets of opportunity, selected for their symbolic value, media relevance, or potential to generate secondary effects. The objective is not persistent access or long-term control, but event generation creating moments that can be exploited for narrative gain. Each operation is structured to trigger a predictable response cycle: disclosure, media coverage, public reaction, and institutional response. This cycle imposes real costs on victims and defenders, regardless of the underlying technical depth of the compromise.
The result is a model in which technical simplicity coexists with strategic effectiveness. Low-level intrusions, when paired with coordinated amplification and ambiguity, produce outcomes typically associated with more advanced actors. The distinction between hacking and influence is therefore not incidental but intentional. Cyber activity provides the entry point, but the primary objective is the shaping of perception, the erosion of confidence, and the projection of capability.
This approach reflects a broader evolution in state-aligned cyber operations. Rather than investing exclusively in high-end capabilities, actors can achieve comparable strategic effects by combining accessible intrusion techniques with sophisticated information operations. In this framework, success is measured not by the depth of compromise, but by the ability to control the narrative surrounding that compromise.
Accordingly, Homeland Justice, Karma, and Handala should be understood not as elite intrusion actors, but as hybrid operators leveraging low-cost cyber access to generate high-impact psychological effects. Their significance lies in demonstrating that, in the current information environment, perception can be weaponized as effectively as technical capability. Furthermore, it demonstrates that even modest breaches can be scaled into strategic events when amplified through media and narrative control.
DPRK Malware Modularity: Diversity and Functional Specialization
Explore the DPRK’s modular malware architecture. Analyze how North Korea uses compartmentalized toolchains for espionage, crypto theft, and strategic signaling.
Executive Summary
North Korea’s cyber program has evolved into a deliberately fragmented malware ecosystem, optimized for mission specialization, operational resilience, and attribution resistance. Analysis of multiple vendor, government, academic, and secondary reporting confirms that what appears externally as a “fracture” is, in practice, a mature portfolio model: parallel malware development pipelines aligned to discrete strategic objectives.
This structure enables the DPRK to conduct simultaneous espionage, revenue generation, and disruptive operations without cross-contaminating tooling, infrastructure, or exposure. Compartmentalization and diversity is therefore assessed as a feature of program maturity, not decentralization or degradation.
Strategic Drivers
The current compartmentalization and diversity of North Korea’s malware ecosystem is not an accidental byproduct of growth or internal disorder; it is a rational response to sustained and cumulative strategic pressure. Over more than a decade, international sanctions have progressively constricted the regime’s access to hard currency, elevating cyber operations from an auxiliary intelligence function to a core mechanism of economic survival. At the same time, increasingly coordinated law-enforcement actions and intelligence disclosures have reduced the lifespan of individual campaigns, forcing DPRK operators to assume that any exposed tool, infrastructure cluster, or technique will eventually be neutralized.
This pressure has been compounded by the repeated public exposure of specific malware families and campaign narratives. Once-effective tools are now rapidly fingerprinted, attributed, and disseminated across defensive communities, collapsing their operational utility. Parallel to this, target environments particularly in finance, technology, and government have become more defensively mature, with improved telemetry, faster incident response cycles, and greater cross-sector information sharing. In aggregate, these factors have raised the cost of persistence and reduced the viability of monolithic, long-lived malware platforms.
In response, the DPRK has adapted by restructuring its cyber program around principles of resilience rather than longevity. Malware development and operations are increasingly compartmentalized, both technically and organizationally, ensuring that exposure in one mission area does not cascade across the entire program. Toolchains are treated as consumable assets: designed to be burned, replaced, and reconstituted with minimal strategic loss. This loss-tolerant posture enables multiple teams to operate in parallel, pursuing espionage, revenue generation, and disruptive objectives simultaneously without competing for the same infrastructure or codebase.
Crucially, this model also maximizes ambiguity. By separating tooling, infrastructure, and operational patterns along mission lines, the DPRK complicates attribution and slows defender decision-making. What emerges is not compartmentalization and diversity as weakness, but compartmentalization and diversity as control: a cyber apparatus engineered to absorb pressure, survive exposure, and continue functioning even as individual components are repeatedly stripped away.
Compartmentalized Malware Architecture
Espionage Oriented Malware Track
The espionage-oriented malware track represents the most traditional and strategically conservative pillar of the DPRK cyber program. Its purpose is not disruption or immediate financial return, but the quiet, sustained extraction of intelligence from institutions that shape policy, security planning, and strategic decision-making. Targets are selected for their informational value rather than their economic utility, encompassing government ministries, defense contractors, academic research centers, think tanks, and organizations operating at the margins of policy formation.
Operations within this track are characterized by restraint and patience. Activity is deliberately low-noise, with operators prioritizing extended dwell time over rapid exploitation. Initial access is leveraged to establish durable footholds that enable credential harvesting, mailbox surveillance, and systematic document collection. Once embedded, the objective is to observe, monitor, and siphon information continuously, often for months or years, with minimal operational disruption to the victim environment. Destructive actions and monetization are intentionally avoided, as they increase detection risk and prematurely terminate access.
Technically, this restraint is reflected in the tooling. Malware associated with espionage missions favors script-heavy loaders, most commonly PowerShell or VBS that blend into normal administrative activity and reduce the need for large, easily detected binaries. Backdoors are frequently memory-resident, minimizing on-disk artifacts and complicating forensic recovery. Initial access commonly relies on weaponized documents or carefully crafted lures tailored to the professional context of the target, reinforcing the emphasis on social engineering over exploit development.
Once access is established, trusted cloud services are routinely abused for command-and-control and staging. By operating through platforms already embedded in enterprise workflows, operators obscure malicious traffic within legitimate usage patterns and benefit from the implicit trust afforded to major service providers. This approach further reduces operational noise while extending persistence in environments with increasingly mature perimeter defenses.
This espionage track is most commonly associated with Kimsuky, which has long been assessed as a primary intelligence-collection component within the DPRK cyber ecosystem. Its campaigns exemplify the regime’s preference for slow, methodical access to high-value information streams, reinforcing the view that espionage remains a foundational mission even as financial and disruptive cyber operations expand alongside it.
Financial Operations Malware Track
The financially oriented malware track reflects the most adaptive and economically consequential arm of the DPRK cyber program. Its overriding purpose is revenue generation: converting access into currency in order to blunt the effects of international sanctions and directly fund regime priorities, including strategic weapons development. Unlike espionage operations, success in this track is measured not in persistence or insight, but in speed, scale, and yield.
Operations in this category are characterized by a markedly faster tempo. Campaigns are designed to move quickly from initial access to monetization, accepting shorter dwell times and higher exposure risk in exchange for financial return. Targeting is broad and opportunistic, with a pronounced focus on cryptocurrency exchanges, blockchain developers, decentralized finance platforms, and the software supply chains that underpin them. Rather than selecting victims for their strategic influence, operators select ecosystems where a single compromise can yield outsized financial gain or cascade into downstream access.
This operational urgency is mirrored in infrastructure management. Hosting, domains, and delivery mechanisms are treated as disposable, with rapid churn used to stay ahead of takedowns and blacklist propagation. Infrastructure longevity is not a priority; instead, it is optimized for brief windows of effectiveness before inevitable exposure. This burn-and-replace mindset distinguishes financial campaigns from the more conservative espionage track and underscores their role as an economic instrument rather than a long-term intelligence platform.
Technically, tooling within this track is purpose-built for theft. Wallet stealers and browser injectors are used to intercept credentials, private keys, and transaction workflows directly at the user layer. Clipboard hijacking exploits habitual behaviors to silently redirect cryptocurrency transfers. Increasingly, operators have demonstrated sophistication in compromising trust boundaries within the developer ecosystem itself, embedding malicious code into open-source packages or trojanizing software updates relied upon by exchanges and development teams. By inserting malware upstream, they convert trusted tooling into a scalable access vector.
Compromise of exchange infrastructure and developer environments further amplifies impact, allowing attackers to move laterally across platforms, users, and assets with minimal additional effort. These techniques reflect a deep understanding of how modern financial and crypto ecosystems are built and where their implicit trust assumptions can be subverted.
This revenue-focused track is most commonly associated with Lazarus Group, which has evolved from a primarily espionage-linked actor into a central pillar of the DPRK’s sanctions-evasion strategy. Its operations illustrate how malware has been weaponized not just as a tool of intrusion, but as a mechanism of state finance, tightly coupled to the regime’s broader strategic objectives.
Disruptive / Coercive Malware Track
The disruptive and coercive malware track represents the most overt and politically expressive component of the DPRK cyber program. Unlike espionage or financially motivated operations, its primary purpose is not persistence or profit, but strategic signaling. These operations are designed to demonstrate capability, impose costs, or deliver retaliation during periods of heightened geopolitical tension, serving as a cyber analogue to more traditional forms of state messaging and coercion.
Operationally, this track prioritizes impact over longevity. Dwell times are intentionally short, as operators expect rapid detection once payloads are deployed. Rather than avoiding attention, these campaigns are constructed to generate it, producing effects that are immediately visible to victims, governments, and, in some cases, the broader public. Tooling and infrastructure are treated as expendable, with a clear willingness to burn assets in exchange for a decisive, time-bound outcome.
The technical execution of these operations reflects this mindset. Payloads frequently take the form of wipers or ransomware-like tools capable of inflicting widespread disruption across enterprise environments. Once initial access is achieved, operators emphasize rapid lateral movement to maximize reach before containment measures can be enacted. Domain-wide execution is a common objective, enabling simultaneous impact across large portions of a target organization and amplifying both operational and psychological effect.
Timing is a critical element. Deployments are often aligned with external political, military, or diplomatic events, reinforcing the interpretive link between the cyber operation and broader state intent. This temporal coordination strengthens the signaling function of the attack, ensuring that the disruption is read not as isolated cybercrime, but as an intentional act within a wider strategic context.
This disruptive track is most commonly associated with Andariel, which has been linked to campaigns emphasizing sabotage, rapid execution, and overt impact. Within the fragmented DPRK malware ecosystem, this track functions as the regime’s blunt instrument: less subtle than espionage, less financially focused than theft, but uniquely suited to delivering unmistakable signals when strategic conditions demand it.
Cross-Track Technical Invariants
Despite the visible compartmentalization and diversity of tooling and operations, analysis across the full body of known malware reporting reveals a set of persistent unifying elements that cut across mission lines. These commonalities indicate that divergence at the payload and campaign level does not equate to independence at the development or strategic level. Instead, they point to shared standards, reuse patterns, and centralized oversight shaping how disparate malware tracks are built and deployed.
At the technical layer, recurring cryptographic routines and packing styles appear across otherwise distinct malware families. While implementations are often modified to frustrate signature-based detection, the underlying design choices remain recognizable, suggesting common developer playbooks or shared internal libraries. Similarly, loader architectures show strong familial resemblance: lightweight initial components designed to stage or decrypt secondary payloads, reused across campaigns with incremental variation rather than wholesale redesign.
Infrastructure analysis reinforces this picture. Even as domains and servers are rapidly rotated at the campaign level, overlap persists at lower layers of the stack, including registrars, hosting providers, and preferred geographic regions. This reuse reflects both operational convenience and institutional familiarity, revealing constraints and preferences that are difficult to fully obfuscate even in a fragmented model.
Perhaps most importantly, all tracks continue to rely heavily on social engineering as the primary initial access vector. Whether the objective is espionage, financial theft, or disruption, operators consistently exploit human trust rather than novel technical exploits. This dependence underscores a strategic assessment that human-mediated access remains more reliable, scalable, and adaptable than vulnerability-driven intrusion, particularly against increasingly hardened technical defenses.
Once access is achieved, there is a consistent preference for operating within trusted ecosystems. Cloud platforms, developer tooling, and collaboration services are repeatedly abused for command-and-control, staging, or lateral movement. By embedding malicious activity within environments already sanctioned and trusted by enterprises, operators reduce detection risk and leverage the implicit legitimacy of widely used services.
Taken together, these patterns demonstrate that compartmentalization and diversity exists primarily at the operational and payload level, not at the level of governance or development philosophy. The DPRK malware ecosystem is best understood as a collection of specialized instruments built from a common toolkit, governed by shared standards and strategic direction, even as execution diverges to meet distinct mission objectives.
Why Compartmentalization and Diversity Matters
Operationally, compartmentalization and diversity confers a high degree of resilience on the DPRK cyber program. Because malware families, infrastructure, and delivery mechanisms are compartmentalized by mission, the exposure or neutralization of one toolchain has limited impact beyond its immediate operational context. When a specific malware family is detected, attributed, and burned, the loss is contained; parallel mission tracks continue to function largely unaffected. This loss tolerance allows operators to assume compromise as a routine condition rather than an exceptional failure, encouraging aggressive use of tooling without risking systemic degradation of the broader program.
This resilience is reinforced by deliberate attribution friction. Divergent malware families, distinct infrastructure clusters, and varying tradecraft across campaigns complicate efforts to collapse activity into a single coherent actor model. Defenders and analysts are forced to disentangle overlapping indicators, slowing attribution and increasing uncertainty about scope and intent. Campaign clustering becomes more difficult as shared characteristics are diluted by intentional variation, while residual commonalities remain subtle enough to require sustained analytic effort to identify.
At the policy level, this ambiguity has concrete effects. Unclear attribution complicates decision-making around response options, escalation thresholds, and public messaging. When activity cannot be cleanly assigned to a single actor or mission set, responses tend to be slower, more cautious, and less coordinated. In this way, compartmentalization and diversity functions not only as a technical or operational safeguard, but as a strategic instrument shaping how adversary actions are interpreted while also constraining the speed and confidence with which states and organizations can respond.
Parallel Execution
Compartmentalization and diversity enables the DPRK cyber program to operate on multiple fronts simultaneously without the internal friction that would otherwise arise from shared tooling, infrastructure, or operational dependencies. By separating malware families and operational workflows along mission lines, distinct teams can pursue diplomatic, financial, and technological targets in parallel, each optimized for its own objectives and risk profile. This structure avoids the bottlenecks and trade-offs inherent in monolithic campaigns, where a single exposure can force a pause or redesign across all activity.
Against diplomatic and policy-oriented targets, espionage-focused operations can proceed patiently, maintaining long-term access and information flow without being disrupted by the higher-noise activities of financial theft or disruptive attacks. At the same time, financially motivated campaigns can move aggressively against cryptocurrency exchanges, developer communities, and related infrastructure, burning tooling and infrastructure as needed without jeopardizing sensitive intelligence footholds elsewhere. Disruptive operations, when activated, can deliver rapid and visible impact without revealing or contaminating the quieter channels of access maintained in parallel.
This separation of concerns allows the DPRK to treat its cyber operations as a portfolio of independent but strategically coordinated efforts. Each mission track operates according to its own tempo, tolerance for exposure, and technical requirements, yet all contribute to overarching state objectives. The result is a cyber apparatus capable of sustained, multi-domain engagement across diplomatic, economic, and technological domains without mutual interference or cascading operational risk.
Defender Implications
The fragmented structure of the DPRK malware ecosystem fundamentally alters the detection problem for defenders. Static malware signatures degrade rapidly as tooling is routinely modified, re-packed, or replaced altogether. Even when individual samples are successfully identified, their utility is short-lived, offering only fleeting defensive value before variants emerge. Similarly, campaign-level indicators of compromise once effective for clustering activity no longer generalize across operations, as distinct mission tracks deliberately minimize shared surface indicators.
As a result, malware-focused detection in isolation is increasingly insufficient. Focusing on payloads alone risks missing the broader operational context in which access is gained, maintained, and exploited. In a segmented model, the absence of a known malware signature does not imply the absence of DPRK activity; it may simply reflect a different mission track employing different tooling, infrastructure, or delivery mechanisms.
Effective defense therefore requires a shift in priorities. Behavioral analytics become critical for identifying anomalous patterns of access, execution, and data movement that persist regardless of specific malware families. Identity and access monitoring is particularly important, as many DPRK operations across espionage, financial, and disruptive tracks depend on credential abuse and trusted account usage rather than exploit-driven compromise. Strengthening security around supply chains and developer ecosystems is equally essential, given the regime’s demonstrated willingness to compromise upstream tooling to achieve scalable access. Cloud telemetry correlation, spanning authentication events, API usage, and cross-service activity, provides the visibility necessary to detect abuse within trusted platforms.
Organizations that frame DPRK activity too narrowly by treating it exclusively as espionage or, alternatively, as financial cybercrime risk creating analytical blind spots. The segmented nature of the threat means that focusing defenses on a single “type” of activity can leave other mission tracks undetected. Instead, a holistic approach, grounded in behavior, identity, and ecosystem trust relationships, is required to account for the full breadth of DPRK cyber operations.
Malware compartmentalization and diversity in the Broader APT Landscape
The deliberate burn-and-replace approach observed in DPRK malware campaigns is not without precedent among advanced state-aligned threat actors. However, comparative analysis shows that while similar tactics exist elsewhere, the degree of institutionalization and mission coupling seen in DPRK operations is unusually pronounced.
Several other APT actors have adopted rapid malware turnover, modular tooling, and payload rotation to evade detection and extend campaign viability under defensive pressure.
Russian intelligence–linked actors, such as APT29, have repeatedly evolved malware families over time, transitioning from early Duke variants to successive, distinct frameworks. These shifts demonstrate intentional tool refresh cycles designed to defeat signature-based detection, but they largely occur within a single strategic mission space of long-term espionage rather than across parallel, economically distinct objectives.
Similarly, APT28has historically rotated between multiple malware families across campaigns, adapting tooling to geopolitical context and operational exposure. While this reflects a willingness to abandon burned tools, the activity remains more campaign-reactive than structurally segmented.
Chinese-linked APT41 presents a closer analogue in that it has demonstrably conducted both state-aligned espionage and financially motivated operations, often with overlapping personnel and infrastructure. APT41’s use of supply-chain compromise, rapid tool replacement, and diverse malware frameworks mirrors aspects of the DPRK model. However, public reporting indicates less rigid separation between mission toolchains, with greater reuse across objectives.
Iranian actors such as Charming Kitten likewise exhibit frequent shifts in malware payloads and delivery mechanisms, particularly in response to exposure. These changes improve survivability but do not rise to the level of a fully articulated portfolio model; tool churn here appears tactically driven, rather than strategically compartmentalized.
Finally, disruptive-focused Russian activity attributed to Sandworm demonstrates an extreme willingness to burn tooling entirely, particularly in wiper and destructive campaigns. However, this behavior is episodic and event-driven, rather than embedded in a standing, multi-mission cyber architecture.
Below is a comparative table showing how DPRK actors stand relative to other major nation-state APT actors (Russia, China, and Iran) in terms of tool churn, mission separation, and burn tolerance. This is based on multiple public sources outlining state-aligned cyber capabilities, campaign evolution, and malware practices.
High — Frequent tool replacement across multiple distinct malware families; new tooling expected as exposed. Part of intentional program design (burn/rebuild).
Moderate — Malware families evolve (e.g., MiniDuke → OnionDuke → CosmicDuke), but changes are often adaptive rather than systematic churn.
Wikipedia
Moderate to High — Some modular platforms (ShadowPad) persist with evolving variants; APT41 leverages diverse malware and reuses components across operations.
SentinelOne
Low to Moderate — Generally stable toolsets with iterative updates; malware families deployed repeatedly across campaigns rather than replaced entirely.
Low–Moderate — Primarily espionage and disruption; mission roles are contextual but not structurally separated as distinct portfolios.
Wikipedia
Moderate — APT41 uniquely combines espionage + financial operations, but toolsets are often reused between missions.
TerraZone
Low — Focused primarily on espionage; mission separation is less pronounced.
Picus Security
Burn Tolerance (willingness to discard tools)
Very High — Tool loss anticipated and baked into design; "burn and replace" is normative.
Moderate — Tools are refreshed when detection risk becomes too high, but not as a planned operational norm.
Moderate — Tools evolve to evade detection; often reused rather than fully discarded; some long-lived frameworks.
Low–Moderate — Tools persist across campaigns; not typically discarded unless externally exposed.
Malware Modularity
High — Early-stage loaders, persistence, and mission payloads frequently have distinct and individual modules.
High — Uses modular backdoors and plugin architectures (e.g., Cozy Bear's Duke variants).
Wikipedia
High — Both modular backdoors (ShadowPad) and custom/third-party tools used.
SentinelOne
Moderate — Modular in some groups (e.g., OilRig's PowerShell modules) but less generalized than for large nation actors.
Picus Security
Cross-Campaign Reuse of Family
Low — Malware families are mission distinct and often unique to a given operational track.
Moderate — Reuse of older frameworks with evolution; variants often retain lineage.
Wikipedia
Moderate to High — Some core backdoors reused across different campaign objectives.
SentinelOne
High — Smaller toolsets reused across multiple campaigns with minor updates.
Picus Security
Integration with Financial Crime
Explicit — Financial malware track is part of the core strategy to generate revenue.
Rare — Russian state groups typically avoid financially focused malware as a strategy.
Present — APT41 engages in some financially motivated activity alongside state espionage.
TerraZone
Minimal — Iranian actors mostly focus on espionage or disruption, not economic theft or revenue generation.
Analytic Distinction: Why the DPRK Model Is Different
What distinguishes the DPRK cyber program is not the existence of malware rotation itself, but how completely burn-and-replace logic is integrated into program design.
Across other APT ecosystems, rapid malware turnover is typically:
A response to detection,
Confined to a single mission domain, or
Implemented unevenly across campaigns.
By contrast, DPRK operations demonstrate:
Standing parallel malware portfolios, not ad-hoc replacements,
Acceptance of tool loss as routine, not exceptional,
And centralized strategic coordination despite decentralized execution.
This places DPRK activity closer to an industrialized cyber production model, where malware is treated as a consumable input rather than a prized asset.
In contrast, espionage tooling is expected to retain its emphasis on low-noise persistence. Malware supporting intelligence collection will continue to prioritize stealth, credential abuse, and cloud-based living-off-the-land techniques that enable extended dwell times even in increasingly monitored environments.
Taken together, these trends indicate that compartmentalization and diversity is not a transitional phase but a durable feature of the DPRK cyber program. As defensive pressure increases, diversification by mission will deepen, further entrenching a model built to absorb exposure, frustrate attribution, and sustain operations across multiple strategic domains.
Summary Findings
The DPRK malware ecosystem is not simply more prolific or more chaotic than that of its peers; it is more deliberately structured at a fundamental, programmatic level. Where many advanced persistent threat actors treat malware as a semi-durable asset to be preserved and refined over time, the DPRK treats malware as an inherently expendable input. Tool exposure is not regarded as a failure state; it is an assumed outcome. As a result, operational planning begins from the premise that any given toolchain will eventually be detected, attributed, and neutralized.
This assumption fundamentally reshapes how the DPRK designs and deploys cyber capabilities. Malware is engineered for utility within a limited lifespan rather than for long-term survivability. Development pipelines emphasize speed, modularity, and replaceability over elegance or longevity. When a tool is burned, it is not mourned or patched indefinitely; it is discarded and superseded, often by a parallel or already-prepared alternative. In this sense, compartmentalization and diversity is not a defensive reaction to disruption, but the default state of the ecosystem.
By contrast, many other APT actors burn tools reluctantly and reactively. Russian, Chinese, and Iranian groups typically rotate malware families after exposure, but such decisions are often tied to specific campaigns or incidents. The underlying assumption remains that tools should persist as long as possible, evolving incrementally to preserve prior investment. The DPRK departs from this logic entirely. Its cyber operations reflect an acceptance that persistence at the tool level is illusory, and that strategic continuity must instead be achieved through organizational design and operational redundancy.
Seen in comparative context, DPRK cyber operations are therefore best understood not as an anomaly, but as a mature instantiation of a broader trend among advanced threat actors pushed to its logical extreme by unique economic and political constraints. Persistent sanctions, direct linkage between cyber activity and state revenue, and sustained international scrutiny have compressed the DPRK’s tolerance for operational pause or degradation. Under these conditions, a cyber program built around long-lived platforms would be brittle. A program built around compartmentalization and diversity, parallel execution, and consumable tooling is resilient.
Malware diversity, rapid churn, and concurrent mission execution are not symptoms of disorder or indiscipline. They are the visible mechanics of a system engineered to function under constant pressure, where exposure is continuous and inevitability assumed. In this model, coherence does not reside in individual tools, but in strategy: centralized intent, mission-aligned portfolios, and an operational architecture designed to endure even as its individual components are repeatedly destroyed.
APPENDIX A: Representative DPRK Malware IOCs
Government-Published Malware Variants & Names
These malware families have been documented in U.S. government malware reports and advisories associated with North Korean state actors (often referred to collectively as HIDDEN COBRA by U.S. agencies): (CISA)
BLINDINGCAN – Remote access tool used to maintain persistence and network exploitation. (CISA)
COPPERHEDGE – Manuscrypt family variant attributed to North Korean APT targeting exchanges/crypto ecosystems. (CISA)
TAINTEDSCRIBE – Full-featured beaconing implant used by DPRK actors. (CISA)
PEBBLEDASH – North Korean beaconing implant family. (CISA)
BISTROMATH – Remote access implant with multiple versions observed. (CISA)
SLICKSHOES – Dropper with beaconing capabilities. (CISA)
CROWDEDFLOUNDER – Beaconing payload with packing protections. (CISA)
ELECTRICFISH – Proxy malware for tunnelled traffic. (CISA)
BADCALL – Proxy server malware with Fake TLS methods. (CISA)
Joanap – RAT enabling botnet management and secondary payload execution. (Wikipedia)
Note: CISA malware analysis reports (MARs) frequently include sample hashes, file Thatnames, network indicators, and signatures for these variants. (CISA)
Appendix B: Malware Linked Activities and Attribution Context
Cryptocurrency-Facilitating Malware
AppleJeus – Malware family used to facilitate cryptocurrency theft, often distributed under the guise of fake trading platforms or wallets. (CISA)
Operational Artifacts & TTP Context
While specific IOCs vary by incident and campaign, the following patterns are relevant to detection and triage:
Botnet infrastructure IPs associated with DDoS and proxy relays used by DPRK actors. (CISA)
Credential harvesting and session token theft in spearphishing campaigns (e.g., mobile-delivered QR code phishing vectors). (Internet Crime Complaint Center)
Proxy and beaconing communication over Fake TLS or tunneled channels seen in BADCALL/ELECTRICFISH series. (CISA)
Appendix C: Known Malware Families by Associated Actor
FudModule cbd1634cf7c638f2faf5e3ec79137db6704ec9de8df798fc46aeeed38de3da9b (noted as shared with GOLDEN) (CrowdStrike)
Supplemental “legacy DPRK MAR-derived” hashes (bridging set; keep as non-exclusive DPRK nexus): Use these as heritage/overlap indicators for “DPRK malware ecosystem” rather than hard-binding them to LABYRINTH specifically.
BLINDINGCAN (multiple SHA256)
BISTROMATH (multiple SHA256)
SLICKSHOES, CROWDEDFLOUNDER, BUFFETLINE, BADCALL (SHA256) (These remain useful as “DPRK malware portfolio” IOCs, but they are not the cleanest proof of the three-unit split without additional clustering work.)
Exposure of TLS Private Key for Myclaw 360 in Qihoo 360 “Security Claw” AI Platform
DTI analysis of a leaked TLS private key from Qihoo 360's AI security platform, covering cryptographic validation, threat scenarios, and incident response.
Executive Summary
DTI analyzed the confirmed exposure of a Transport Layer Security (TLS) private key associated with the wildcard certificate *.myclaw[.]360[.]cn, which appears tied to the Security Claw (安全龙虾) artificial-intelligence assistant platform developed by Qihoo 360. Earlier public discussion of the issue relied primarily on screenshots and reposted commentary claiming that the certificate and private key were embedded in the platform’s installer package. The material provided for this investigation includes the full X.509 certificate and corresponding private key. Cryptographic validation confirms that the supplied private key matches the public key contained in the certificate, establishing that the exposed credential is authentic and operational rather than a placeholder or decoy.
The certificate is issued by WoTrus CA Limited under the issuing chain WoTrus RSA DV SSL CA 2. It is a wildcard certificate covering both *.myclaw[.]360[.]cn and myclaw[.]360[.]cn and was originally issued with a validity period spanning 12 March 2026 through 12 April 2027. Because wildcard certificates authenticate any host within the domain namespace, possession of the corresponding private key would allow an attacker to impersonate services across the entire Security Claw infrastructure if the certificate remained trusted and unrevoked.
Subsequent certificate-transparency analysis conducted during this investigation indicates that the certificate has since been rotated and replaced as part of an apparent incident-response action. CT log entries show that on 16 March 2026, a new wildcard certificate for *.myclaw[.]360[.]cn was issued with a new RSA key pair and shortened validity period, replacing the originally exposed certificate. The rapid issuance of the replacement certificate and the change in key material strongly suggest that Qihoo 360 detected the credential exposure and executed emergency key rotation to invalidate the compromised trust material.
Infrastructure analysis further confirms that the parent domain ecosystem (360[.]cn) is registered to Beijing Qihoo Technology Co., Ltd. (北京奇虎科技有限公司) and uses internally controlled DNS and mail infrastructure. This strongly supports attribution of the myclaw[.]360[.]cn namespace to Qihoo 360’s operational domain environment. The exposure therefore represents a confirmed cryptographic trust-material leak, with potential consequences including server impersonation, TLS interception, credential theft, and malicious update delivery within the Security Claw ecosystem. Although the certificate appears to have been rotated following discovery of the issue, the operational impact ultimately depends on whether the compromised key was actively deployed in production services and whether any adversary obtained the key prior to remediation.
Background: Qihoo 360 and the Security Claw Platform
Qihoo 360 is widely recognized as one of China’s largest cybersecurity and internet-technology companies, operating across both consumer and enterprise security markets. Since its founding in the early 2000s, the company has developed a broad portfolio of security and software products that include antivirus platforms, endpoint protection suites, web browsers, vulnerability-scanning tools, and large-scale threat-intelligence services. Through these products, Qihoo 360 has established an extensive user base spanning hundreds of millions of individual users as well as corporate and government customers. Much of the company’s security ecosystem is built around large telemetry pipelines that collect threat data from deployed endpoints and feed it into centralized analytics systems used to detect malware, exploit campaigns, and network intrusions.
In recent years the company has increasingly invested in artificial-intelligence technologies as part of its broader cybersecurity strategy. Like many large security vendors, Qihoo 360 has begun integrating machine-learning models and generative AI capabilities into its defensive tools, both to automate analysis tasks and to provide interactive interfaces for users and analysts. This effort has produced a range of AI-enabled assistants and intelligent agents designed to augment traditional security workflows. These systems typically allow users to query threat data, analyze malware samples, or receive automated recommendations through natural-language interfaces powered by backend AI models.
However, they have started pulling back on this, as they have begun learning about the pitfalls.
The Security Claw (安全龙虾) platform appears to be one of the products emerging from this initiative. Based on publicly available information and artifacts analyzed during this investigation, Security Claw functions as a locally installed client application that interacts with remote services operated by Qihoo 360. Rather than performing all processing locally, the client appears to act as a front-end interface that communicates with cloud-hosted AI infrastructure. These backend services operate within the myclaw.360.cn domain namespace, which appears to serve as the central network environment for the platform’s API endpoints and inference services.
Reports associated with the platform indicate that the client software connects to at least one backend endpoint located at https://myclaw[.]360[.]cn:19798, a service running on a non-standard port rather than the default HTTPS port 443. The use of such ports is common in internal service architectures where applications communicate directly with API gateways or service nodes without passing through standard web-server front ends. The presence of this endpoint suggests that the client communicates with a specialized service interface rather than a conventional public website.
Architecturally, this design reflects a hybrid deployment model commonly used by modern AI assistant platforms. In this model, a lightweight local application acts as a wrapper that manages user interactions, authentication, and system integration while delegating computationally intensive tasks such as natural-language processing, model inference, and large-scale data retrieval to cloud infrastructure. The client collects user prompts and contextual information from the local system and forwards these requests to backend services where AI models perform the actual analysis or generate responses.
Systems built on this architecture typically consist of multiple interconnected backend components. These may include authentication services responsible for validating client identities, API gateways that route requests to the appropriate services, telemetry collectors that gather usage and performance data from deployed clients, and inference endpoints hosting the machine-learning models used to generate responses. Additional components often include update services responsible for delivering model updates or configuration files to the client software. All of these elements operate together to create the user-facing experience of an AI assistant while relying on centralized cloud infrastructure to perform the majority of processing tasks.
Technical Findings
Certificate Structure
Analysis of the certificate associated with the Security Claw infrastructure indicates that it is a standard X.509 server authentication certificate issued for the wildcard domain namespace *.myclaw[.]360[.]cn. The certificate’s Common Name (CN) is configured as *.myclaw[.]360[.]cn, enabling it to authenticate any host operating under that subdomain space. In addition to the wildcard identifier, the certificate’s Subject Alternative Name (SAN) extension explicitly includes both *.myclaw.360[.]cn and the root host myclaw[.]360[.]cn. This configuration allows the certificate to be used by both the base domain and any subordinate services, a design pattern typically employed in microservice architectures where multiple backend services operate under a single domain namespace.
The certificate was issued by WoTrus RSA DV SSL CA 2, a certificate authority chain operated by WoTrus CA Limited, a Chinese certificate authority widely used within domestic cloud infrastructure and enterprise platforms. The certificate’s validity window begins on 12 March 2026 and extends through 12 April 2027, reflecting a relatively long operational lifespan typical of domain-validated certificates used in application backends. Cryptographically, the certificate employs an RSA 2048-bit public key, a widely adopted key size for TLS server authentication that provides an established balance between security strength and compatibility across client platforms.
The certificate is uniquely identified by the serial number 98dfeafdc4c32371f0ab490c8a3c7819, which serves as the certificate authority’s internal identifier for the issued credential. Its cryptographic fingerprint, calculated using the SHA-256 hashing algorithm, is 5a0a0df9695395223a1d342d2ccf82f449b342a281ed056dfa7880965bcbe3ca. This fingerprint provides a reliable mechanism for identifying the certificate across transparency logs, passive TLS telemetry, and network monitoring systems.
Functionally, the certificate is a domain-validated TLS certificate intended solely for server authentication. It does not contain certificate authority privileges and cannot be used to sign subordinate certificates or create additional trust anchors. Instead, its purpose is to enable servers operating under the myclaw[.]360[.]cn namespace to prove domain ownership during TLS handshakes, allowing clients to establish encrypted connections that they believe originate from legitimate Security Claw infrastructure.
The provided certificate is an X.509 server certificate with the following key attributes:
Common Name: *.myclaw.360.cn Subject Alternative Names: *.myclaw.360.cn myclaw.360.cn Issuer: WoTrus RSA DV SSL CA 2 Organization: WoTrus CA Limited Validity Period: Not Before: 2026-03-12 Not After : 2027-04-12 Public Key Algorithm: RSA 2048-bit Certificate Serial Number: 98dfeafdc4c32371f0ab490c8a3c7819 The certificate’s SHA-256 fingerprint is: 5a0a0df9695395223a1d342d2ccf82f449b342a281ed056dfa7880965bcbe3ca
Private Key Validation
Cryptographic analysis confirms that the private key provided in the dataset corresponds directly to the public key embedded within the associated TLS certificate. This relationship was verified by extracting and comparing the RSA modulus from both the certificate and the private key. The modulus values match exactly, demonstrating that the two artifacts form a valid cryptographic key pair.
This verification establishes that the exposed private key is the genuine operational key associated with the certificate rather than unrelated or fabricated data. In other words, the key is capable of performing the cryptographic operations required to authenticate servers presenting the certificate during Transport Layer Security (TLS) negotiations.
Within TLS architecture, the private key represents the confidential element of the certificate pair and functions as the mechanism by which a server proves its identity to connecting clients. During the TLS handshake process, the server must demonstrate possession of this secret key in order to validate that it legitimately controls the certificate presented to the client. If the server successfully performs this proof, the client accepts the certificate as authentic and proceeds to establish an encrypted communication channel.
Consequently, possession of the private key enables any system holding it to complete TLS handshakes that appear fully legitimate to clients relying on standard certificate validation. This capability effectively allows the holder of the key to impersonate servers operating under the certificate’s domain namespace and establish encrypted connections that clients would normally interpret as trusted communications with the genuine service.
Infrastructure Attribution
To assess ownership and operational control of the namespace, passive DNS intelligence and domain-registration data indicate that the namespace is part of the broader Qihoo 360 domain ecosystem. This determination provides strong evidence that the infrastructure supporting the Security Claw platform is operated directly within the company’s network environment.
The parent domain 360[.]cn is registered to 北京奇虎科技有限公司 (Beijing Qihoo Technology Co., Ltd.), a major Chinese cybersecurity and internet-technology firm. Domain registration records show that the domain was originally created on 17 March 2003 and is maintained through the registrar Xiamen eName Technology Co., Ltd. These details align with long-standing records identifying Qihoo 360 as the primary operator of the 360[.]cn domain space and its associated services.
The use of dedicated DNS and mail infrastructure under corporate-controlled domains strongly suggests that Qihoo 360 manages its core network services internally rather than outsourcing these functions to third-party providers. This pattern is typical of large security vendors that maintain tight operational control over their infrastructure for security, reliability, and compliance reasons.
Additional enrichment data indicates that the 360.cn domain environment routinely deploys wildcard TLS certificates issued by WoTrus, the same certificate authority responsible for the *.myclaw.360.cn certificate examined in this investigation. The reuse of this certificate authority and wildcard certificate deployment pattern across the broader Qihoo domain ecosystem reinforces the conclusion that the MyClaw certificate originates from the company’s established PKI practices rather than from an unrelated or externally managed infrastructure.
Taken together, the domain registration data, passive DNS records, and PKI deployment patterns provide strong attribution linking the myclaw.360.cn namespace to Qihoo 360’s operational infrastructure, supporting the assessment that the exposed TLS credentials were associated with a service environment under the company’s direct control.
Threat Analysis
The exposure of a Transport Layer Security (TLS) private key associated with a wildcard certificate introduces several potential attack scenarios that could compromise both the integrity and confidentiality of communications within the affected service environment. Because TLS certificates serve as the cryptographic mechanism through which clients authenticate remote servers and establish encrypted channels, possession of the corresponding private key effectively allows an attacker to masquerade as legitimate infrastructure. In this case, the affected certificate covers the wildcard namespace *.myclaw[.]360[.]cn, meaning that any service operating under that domain could theoretically be impersonated if the certificate remained trusted and unrevoked.
One of the most direct risks presented by such an exposure is server impersonation. An attacker in possession of the private key could deploy a malicious server configured to present the same certificate during TLS negotiation. Because the certificate chains to a publicly trusted certificate authority and matches the expected domain namespace, client applications connecting to the attacker’s infrastructure would likely complete the TLS handshake successfully and treat the connection as legitimate. The wildcard nature of the certificate significantly amplifies this risk, as it would allow the attacker to impersonate any host within the myclaw[.]360[.]cn namespace rather than a single specific service endpoint.
A related and potentially more damaging scenario involves man-in-the-middle (MITM) interception. If an attacker were able to manipulate DNS responses, compromise a local network, or otherwise redirect client traffic, they could route requests intended for legitimate MyClaw infrastructure to servers under their control. Because the attacker possesses the correct private key, the TLS handshake would succeed and encrypted sessions would be established without triggering certificate warnings. Under such circumstances, the attacker could decrypt and inspect traffic passing through the connection. Data potentially exposed through such interception could include authentication credentials, session cookies, API tokens used by the application, and the contents of AI prompts or conversation logs exchanged between the client and backend inference services.
Another risk concerns malicious update distribution. Many modern software platforms retrieve updates, configuration files, or model components from backend servers under their operational domain namespace. If the Security Claw client retrieves such resources from endpoints within myclaw[.]360[.]cn, an attacker capable of impersonating those endpoints could deliver modified update packages or configuration files. In the worst case, this could allow the distribution of malicious binaries to client systems, effectively transforming the incident into a supply-chain compromise affecting all users receiving the spoofed updates.
Finally, the exposure creates the possibility of AI response manipulation within the Security Claw platform itself. Because the platform functions as an AI assistant that communicates with backend inference services, impersonating those services could allow attackers to alter responses returned by the AI system. This could enable injection of malicious prompts, manipulation of analysis results, or the insertion of misleading security guidance into automated workflows. In environments where the AI system assists with security analysis or operational decision-making, such manipulation could have cascading effects on downstream processes.
Taken together, these scenarios illustrate how the compromise of TLS trust material, particularly a wildcard certificate, can extend beyond simple traffic interception and potentially affect software distribution mechanisms, AI service integrity, and user trust in the platform’s infrastructure.
The exposure of a private key associated with the wildcard TLS certificate for *.myclaw[.]360[.]cn introduces not only traditional network security risks such as impersonation and interception, but also a set of potential AI-enabled attack vectors that could exploit the architecture of the Security Claw platform itself. Because the platform appears to function as a locally installed AI assistant communicating with cloud-hosted inference services, control over the cryptographic trust boundary between client and backend services could enable adversaries to manipulate the AI system’s behavior in ways that extend beyond conventional software compromise. The integration of AI inference services into the operational workflow effectively creates a new attack surface in which model outputs, prompts, and analytic results become potential targets for adversarial manipulation.
One plausible attack scenario would involve AI response manipulation at the inference layer. If an attacker were able to impersonate backend inference services using the compromised certificate, they could intercept requests from the Security Claw client and return modified outputs generated by a malicious or modified AI model. In practice, this could allow the adversary to alter the results of automated security analyses performed by the platform. For example, malware samples submitted for analysis could be falsely classified as benign, while legitimate system components could be flagged as malicious. Such manipulations could degrade the reliability of the platform’s analytic output and undermine trust in automated security recommendations generated by the system.
Logic Diagram for Potential Attacks From Mistake
Another potential attack vector involves prompt-injection attacks targeting the AI interaction pipeline. Modern AI assistant architectures often rely on structured prompts sent from the client to backend models, where contextual instructions and system policies guide the model’s behavior. An adversary positioned within the communication channel could modify these prompts before they reach the inference service or inject additional instructions into the prompt stream. By manipulating these inputs, attackers could influence the behavior of the AI model, potentially causing it to disclose sensitive data, generate misleading analyses, or execute unintended actions within automated workflows. This type of attack is conceptually similar to adversarial prompt injection techniques observed in other large-language-model deployments.
A related scenario involves model poisoning or model-substitution attacks. If the Security Claw platform retrieves model components, configuration files, or inference instructions from backend servers under the myclaw[.]360[.]cn namespace, an adversary capable of impersonating those endpoints could distribute modified model weights or configuration artifacts to client systems. Such modifications could subtly alter the behavior of the AI system over time. For instance, the modified model might consistently downgrade the severity of certain classes of threats, ignore specific indicators of compromise, or generate outputs designed to mislead analysts reviewing the results. Because AI models often behave probabilistically rather than deterministically, detecting such manipulation could be significantly more difficult than identifying conventional malware.
The compromise could also enable data exfiltration through the AI interaction channel. Security Claw appears to operate as an assistant capable of processing user prompts, system telemetry, and potentially sensitive security data. If adversaries intercepted or controlled the backend inference endpoint, they could capture large volumes of input data sent from client systems. This data could include malware samples, internal network information, security logs, configuration data, or investigative notes submitted by analysts interacting with the AI assistant. Over time, such data collection could yield valuable intelligence about organizational networks, defensive tools, and investigative workflows.
Another possible attack vector would involve AI-driven social engineering and influence operations directed at analysts using the platform. If attackers controlled the AI responses returned to users, they could craft outputs designed to subtly influence human decision-making. For example, the AI might recommend specific remediation steps that inadvertently weaken security controls, suggest the dismissal of legitimate alerts, or provide misleading threat-intelligence summaries. Because users may perceive AI-generated recommendations as authoritative, particularly when the platform is marketed as a cybersecurity assistant, such manipulation could have cascading operational consequences within security operations centers or incident-response teams.
The exposure could further facilitate autonomous reconnaissance and exploitation capabilities embedded within the AI service architecture. If the adversary were able to modify backend AI services rather than merely impersonate them, they could theoretically integrate automated reconnaissance capabilities into the system itself. In this scenario, the AI service might analyze telemetry collected from client systems and automatically identify exploitable vulnerabilities or network configurations. Rather than simply returning analytic results to the user, the compromised system could covertly transmit reconnaissance data to attacker infrastructure or generate tailored exploit payloads targeting discovered weaknesses.
Finally, there is the possibility of supply-chain amplification through AI-driven automation. Security Claw’s architecture suggests that it may be integrated with broader Qihoo security services, potentially including threat-intelligence feeds, malware analysis pipelines, or automated defensive tooling. If attackers were able to manipulate the AI system at the backend level, they could leverage this integration to propagate malicious outputs across multiple connected services. For example, manipulated threat classifications could influence automated detection signatures distributed to endpoint security products, potentially degrading detection capability across a large installed base of users.
Taken together, these scenarios illustrate how the compromise of cryptographic trust material in an AI-enabled platform could enable attack techniques that extend beyond traditional network security threats. In conventional systems, the theft of a TLS private key primarily enables impersonation or interception attacks. In AI-integrated architectures, however, control over the communication channel between client and inference service also enables adversaries to manipulate the informational outputs of the system itself. Because users increasingly rely on AI-generated analysis to support operational decisions, such manipulation could have downstream effects that propagate through automated workflows, investigative processes, and defensive strategies.
Root Cause Assessment
The most plausible explanation for the exposure of the TLS private key is a failure within the software build and packaging pipeline used to produce the Security Claw client installer. Evidence associated with the incident indicates that the certificate and its corresponding private key were present within files bundled in the application’s installation package, suggesting that sensitive credential material was inadvertently included during the software build process.
In contemporary software development environments, application installers are frequently generated automatically through continuous integration and continuous delivery (CI/CD) pipelines. These pipelines often assemble installation packages directly from development repositories or build directories that may contain configuration files, test certificates, and other credentials used during internal development and debugging. If the build pipeline does not explicitly exclude such files through filtering rules or packaging controls, sensitive artifacts can unintentionally become part of the final distribution bundle.
This type of exposure is consistent with a broader class of supply-chain vulnerabilities in which development credentials are mistakenly distributed alongside production software. Similar incidents have been documented across the software industry, including cases where application installers or container images contained embedded API keys, code-signing certificates, or cloud service credentials. In each case, the root cause typically involved insufficient separation between development assets and production build artifacts, allowing confidential materials to propagate into publicly accessible software packages.
Analytical Assessment
The exposure of a private key associated with a wildcard TLS certificate constitutes a serious failure in the protection of cryptographic trust material. Within modern internet security architecture, TLS certificates serve as the foundation of authenticated encrypted communication between clients and servers. The corresponding private key is the critical secret that enables a server to prove its identity during the TLS handshake process. When this key is exposed outside of controlled infrastructure, the integrity of the entire trust relationship established by the certificate is compromised. In this case, the risk is amplified by the fact that the certificate is a wildcard credential for the domain namespace *.myclaw[.]360[.]cn, meaning that the key could theoretically authenticate any service operating under that domain hierarchy. As a result, possession of the private key could allow an attacker to impersonate multiple services across the platform rather than a single isolated endpoint.
Although the ultimate operational consequences depend on several factors including whether the certificate was actively deployed in production infrastructure and how quickly the credential was revoked or replaced, the discovery of the key in a publicly accessible software artifact strongly suggests that sensitive trust material was mishandled during the platform’s build or distribution process. Software installers and packaged binaries should never contain cryptographic secrets intended for server-side authentication. Their presence in distributed software indicates that development or deployment environments likely included credential files that were not properly excluded during packaging. Such mistakes are typically symptomatic of weaknesses in build pipeline controls, including insufficient separation between development assets and production artifacts, inadequate secret-scanning procedures, or a lack of automated checks designed to prevent sensitive files from being included in release builds.
The incident is particularly notable because it involves Qihoo 360, a company whose core business is cybersecurity. As a major provider of antivirus software, enterprise security tools, and threat-intelligence services, Qihoo 360 operates infrastructure that supports hundreds of millions of users. Organizations of this scale are expected to maintain mature security engineering practices, including strict credential management policies, secure build pipelines, and rigorous release validation procedures. The appearance of operational cryptographic material in distributed software raises questions about the robustness of those internal controls.
Even if the certificate was never deployed in production systems or if the exposure window was short due to rapid incident response and key rotation, the leak nonetheless highlights systemic risks associated with credential management within modern software development environments. Large-scale platforms frequently rely on numerous certificates, API keys, and other authentication secrets to operate complex distributed architectures. Without strong safeguards, these secrets can inadvertently propagate through development repositories, build directories, or installer packaging processes.
In this context, the exposure should be understood not only as a discrete technical vulnerability but also as an indicator of broader process weaknesses. Effective security engineering requires strict segregation of sensitive credentials, automated detection mechanisms for secrets in build artifacts, and clear procedures for revocation and rotation when exposure occurs. The presence of a valid TLS private key in publicly distributed software suggests that at least some of these controls were insufficiently implemented or failed during the platform’s release cycle. As AI-enabled platforms like Security Claw become more deeply integrated into security workflows and enterprise environments, ensuring the integrity of the cryptographic infrastructure underpinning these systems becomes increasingly critical.
Conclusion
Cryptographic validation confirms that the exposed material is a legitimate and operational TLS key pair for *.myclaw[.]360[.]cn. The RSA modulus in the certificate and private key match exactly, proving authenticity. The certificate chains to WoTrus RSA DV SSL CA 2, a publicly trusted authority, meaning any server using this key would be accepted as legitimate by clients.
The certificate’s structure aligns with Qihoo 360’s broader PKI practices, which rely on WoTrus-issued, domain-validated wildcard certificates to secure microservice-based architectures. As such, compromise of the private key represents a direct breach of the platform’s cryptographic trust boundary.
If deployed in production, the impact is substantial. An attacker with the key could impersonate any host within the myclaw.360.cn namespace, enabling seamless TLS-authenticated connections that appear legitimate. This extends beyond single-host compromise to full namespace-level impersonation. Under traffic redirection conditions (e.g., DNS or network manipulation), the same capability enables decryption and inspection of encrypted sessions, exposing credentials, tokens, and AI interaction data.
The risk also extends into platform integrity. Impersonated endpoints could deliver malicious updates or configuration data, while spoofed inference services could manipulate AI outputs or inject instructions into the interaction pipeline.
Impact ultimately hinges on deployment status and response timing. Evidence indicates the certificate was rapidly rotated, suggesting effective incident response and a potentially limited exposure window. However, if the key was obtained prior to rotation, exploitation during that interval remains plausible.
Further analysis should focus on certificate transparency logs, passive DNS telemetry, and any vendor disclosures to establish timeline, exposure scope, and whether the compromised certificate was ever actively used.
Analysis of the Doppelgänger / RRN disinformation ecosystem. Learn how this DevOps-style infrastructure uses automated media impersonation, TLD rotation, and cloud-native hosting to target global audiences and evade enforcement.
Executive Summary
The Doppelgänger / RRN ecosystem (RRN = Reliable Recent News) constitutes a new iteration of the Social Design Agency (SDA), a structurally mature, infrastructure-centric disinformation architecture that has been operating continuously from 2022 through 2026. Rather than functioning as a loose collection of spoofed websites or transient propaganda outlets, the network exhibits the hallmarks of a coordinated, professionally managed influence apparatus. Its design prioritizes infrastructure resilience, scalability, and operational continuity over short-term visibility.
At its core, the ecosystem relies on systematic media brand impersonation executed at scale. Recognizable Western news outlets are replicated through domain substitution, typo variants, and semantic extensions, producing a high-volume impersonation layer that mimics legitimate journalism. These impersonation domains are not isolated artifacts; they are anchored to a centralized narrative constellation built around the RRN brand family, which functions as a clearinghouse and coordination node for messaging.
rrn[.]com[.]tr current iteration of Researchers & Reporters Network (aka Doppelganger Disinfo Network)
Domain acquisition patterns indicate batch provisioning during defined campaign waves, most notably in mid-2022 and again in late-2024. These bursts reflect deliberate staging cycles rather than organic domain accumulation. Complementing this provisioning model is a deliberate top-level domain diversification strategy. The operation leverages low-cost and low-scrutiny TLDs, rotates extensions in response to enforcement actions, and preserves second-level domains across TLD swaps to maintain continuity. This enforcement-aware migration pattern demonstrates pre-positioned redundancy and lifecycle planning.
Hosting and delivery architecture further reinforce the operation’s sophistication. The ecosystem is cloud-native and heavily fronted by content delivery networks that obscure origin infrastructure. Backend services are distributed across hyperscaler platforms, including Google Cloud and to a lesser extent AWS, along with static asset reuse from legitimate domains, with micro-clustering patterns that distribute risk and reduce single points of failure. The absence of concentrated Russian hosting infrastructure suggests attribution resistance through geographic neutrality rather than lack of coordination.
Backend artifacts reveal structured CMS management. WordPress deployments exhibit role-based segmentation, coordinated account provisioning, and SEO-oriented publishing controls. These features indicate centralized backend governance and editorial workflow discipline. The infrastructure also reflects automated domain variant generation, employing scripted logic for brand tokens, typographical alterations, and semantic suffix combinations. This level of automation is consistent with a provisioning pipeline rather than manual spoofing. Assistance from Amazon Web Services Threat Intelligence enriched the presence of AWS IP addresses, identifying primarily legitimate assets being reused in off-AWS infrastructure.
The campaign demonstrates deliberate geographic micro-targeting across European Union member states and the United States. Infrastructure segmentation mirrors narrative segmentation, with country-specific impersonation clusters aligned to regional political contexts. This coupling of technical segmentation and messaging strategy underscores a hybridization of cyber infrastructure tradecraft and psychological operations.
Taken together, these characteristics indicate DevOps-style provisioning discipline and resilience engineering. Domains are stockpiled, rotated, and redeployed with minimal disruption. Infrastructure is compartmentalized, diversified, and rapidly replaceable. Such operational maturity is consistent with institutional backing and sustained management, rather than opportunistic or freelance activity.
Campaign Architecture Model
Across both structural reporting and dataset analysis, the campaign exhibits a deliberately layered and modular operational model. The architecture is not flat, nor is it improvisational. Instead, it reflects clear functional segmentation, with each tier responsible for a distinct operational objective.
At the apex sits an operator coordination layer. This tier likely manages provisioning workflows, narrative timing, infrastructure deployment, and enforcement response. It is the command-and-control plane of the information operation, though not in the malware sense; rather, it orchestrates domain registration cycles, publishing cadence, and geographic targeting priorities. This also shows the banality of disinformation being just a process driven means to a larger end in the global war on reality.
Beneath this layer resides the core narrative hub, anchored by the RRN domain family. This constellation functions as a central content repository and thematic synchronization point. It consolidates narratives, standardizes messaging frames, and acts as a reference anchor for downstream properties. When seizures occur, this hub migrates in controlled fashion, preserving continuity through second-level domain retention and TLD substitution.
Below the hub tier are country-specific narrative front domains. These properties localize messaging for particular audiences, adapting tone, framing, and political emphasis according to national context. They provide plausible deniability by presenting themselves as independent outlets, while remaining structurally tethered to the broader ecosystem.
The next layer consists of media impersonation domains. These are the most visible components of the campaign, designed to replicate established Western media brands with high visual fidelity. Their purpose is brand deception: to exploit audience trust in recognizable outlets and to embed narratives within seemingly legitimate editorial environments.
Supporting these front-facing elements is a redirect and tracking layer. This tier manages traffic flow, referral routing, and possibly engagement analytics. It enables flexible amplification pathways and allows operators to shift traffic patterns without modifying core content nodes.
Above distribution sits the SEO optimization layer. Search visibility is engineered through keyword structuring, backlink strategies, and metadata tuning. This layer ensures that impersonation domains surface within search ecosystems, increasing organic discovery and enhancing perceived legitimacy.
Finally, social media amplification functions as the outermost dissemination ring. Coordinated accounts, paid promotion, or content seeding strategies drive traffic toward the impersonation domains. Social platforms act as accelerants, extending reach into geographically segmented audiences.
At the terminus of this layered model are the audiences themselves, segmented by geography and political context. Messaging is not broadcast uniformly; it is calibrated. German audiences receive different narrative emphasis than U.S. or French audiences, even when core themes remain aligned.
This architecture separates content generation, brand deception, distribution mechanics, and resilience engineering into discrete but interconnected layers. The result is a modular influence system capable of rapid reconfiguration. When one layer is disrupted, such as through domain seizure, the remaining tiers persist to enable continuity. This structural separation is a defining feature of the campaign’s operational maturity.
Domain Corpus & Structural Clustering
The domain ecosystem resolves into three principal structural tiers: core hubs, narrative fronts, and media impersonation clusters. Each tier performs a distinct operational role within the broader influence architecture.
The core RRN hubs function as the gravitational center of the campaign. Observed anchors include rrn[.]world (2022-2025 * as of 2026 domain re-purposed by unknown entities exposing the doppelganger/SDA group), the previously seized rrn.media, its post-enforcement successor rrn[.]so, rrn[.]com[.]tr, and the earlier rrussianews[.]com. These domains operate as centralized narrative clearinghouses. They provide thematic consistency, content staging, and coordination continuity. When enforcement actions occur, the transition between domains preserves second-level naming conventions, indicating planned migration rather than reactive improvisation. The hub tier is not simply a publishing site; it is the synchronization layer for the ecosystem’s messaging and lifecycle management.
Beneath this central constellation sit the narrative front domains. Properties such as 50statesoflie., acrosstheline., avisindependent.eu, artichoc[.]cc, levinaigre[.]so, ukrlm[.]so, and shadowwatch[.]us are structured to appear as independent editorial outlets. Their purpose is reframing. Rather than overtly presenting RRN branding, they repackage aligned narratives under the veneer of autonomous journalism. This layer introduces plausible deniability and audience-specific tonality while remaining structurally tethered to the broader system. The naming conventions are less overtly imitative than the impersonation tier, but they are thematically suggestive, often invoking investigative or oppositional framing.
The largest and most visible component of the ecosystem is the media impersonation cluster, comprising approximately sixty percent of the observed domain corpus. This tier includes clones of prominent Western outlets such as Spiegel, Bild, Süddeutsche Zeitung, FAZ, Welt, T-Online, The Guardian, Daily Mail, ANSA, and variants referencing Fox News. These domains are engineered to replicate the visual and structural appearance of legitimate news brands, exploiting pre-existing public trust.
Impersonation within this cluster follows consistent technical patterns. Top-level domain substitution replaces primary brand extensions with lower-cost or less scrutinized alternatives. Typosquatting mechanisms include letter duplication, omission, and phonetic substitution, creating visually plausible but technically distinct domains. Additional variants employ brand-semantic suffixes or geographic modifiers to enhance credibility while maintaining differentiation from the authentic domain. The repetition and systematic variation across these brand families strongly suggest automated or scripted domain generation logic rather than manual, ad hoc spoofing.
Taken together, these three tiers illustrate a graduated deception model. The core hubs centralize narrative control. The narrative fronts contextualize and reframe messaging under independent branding. The impersonation clusters maximize credibility exploitation through high-fidelity replication. The structural coherence across all three layers reinforces the conclusion that this is a coordinated provisioning ecosystem rather than isolated instances of media spoofing.
Temporal analysis of the 48-domain dataset reveals that domain acquisition did not occur as a continuous or organic process. Instead, registrations cluster into two distinct provisioning bursts, each aligned with identifiable geopolitical inflection points.
The first wave occurred in mid-2022, coinciding with the escalation phase of the war in Ukraine. During this period, domain registrations expanded rapidly across multiple brand families and narrative fronts. The timing suggests synchronization with heightened geopolitical tension and intensified information competition. Rather than opportunistic spoofing, the burst reflects pre-coordinated deployment intended to support sustained narrative operations during a critical phase of the conflict.
The second wave emerged in September 2024. This provisioning cycle aligns with Western electoral timelines and follows public enforcement actions targeting earlier Doppelgänger infrastructure. The pattern indicates both narrative refresh and infrastructure regeneration. Domains registered during this period show evidence of replacement logic, TLD diversification, and continued brand-family clustering, consistent with an adaptive response to seizure activity.
Across both waves, several structural characteristics remain consistent. Registration timestamps fall within narrow windows, suggesting batch provisioning rather than independent acquisition. Multiple domains tied to the same media brand families appear within close temporal proximity, reinforcing the likelihood of centralized control. The recurrence of identical naming logic across separate waves further indicates a reusable deployment pipeline.
This temporal clustering model is incompatible with organic domain growth. Instead, it reflects planned campaign staging cycles in which infrastructure is provisioned in anticipation of narrative events or in response to enforcement disruption. The pattern is consistent with structured influence operations that operate in defined phases rather than continuous improvisation.
TLD Strategy & Enforcement Evasion
Analysis of top-level domain selection reveals a deliberate concentration in a specific family of extensions. Dominant TLDs across the ecosystem include .media, .agency, .ltd, .today, .life, .ws, .cc, .so, .beauty, .expert, .vip, .pics, and .top. The distribution is neither random nor purely aesthetic; it reflects operational utility.
These extensions share several characteristics. They are generally low in acquisition cost, widely available at scale, and subject to comparatively limited scrutiny relative to legacy TLDs. Many also carry news-semantic or quasi-professional connotations such as .media, .agency, .today, or .expert which enhance surface credibility when paired with recognizable media brand tokens. This semantic plausibility increases the likelihood that users will perceive the domains as legitimate news outlets rather than synthetic replicas.
The selection pattern also supports rapid provisioning and replacement. Because these TLDs are typically less saturated than primary brand equivalents, operators can register multiple variants quickly and in batch. This flexibility is critical to enforcement resilience.
Observed seizure-to-migration behavior reinforces this assessment. When rrn[.]media was disrupted, operations pivoted to rrn[.]so while preserving the second-level domain. Similarly, 50statesoflie[.]com reappeared under .cc and .so variants, and acrosstheline[.]press transitioned to a .cc counterpart. In each case, the second-level domain remained intact while only the top-level extension changed.
Preservation of the second-level domain across new TLDs constitutes a very high-confidence linkage signal. It demonstrates continuity of operator control and planning rather than independent replication. The pattern indicates that alternate TLDs were likely pre-positioned or rapidly provisioned using the same deployment pipeline. This TLD substitution model is therefore not merely a branding choice; it is a resilience mechanism embedded within the infrastructure strategy.
Registrar & Registration Patterns
Registrar-level analysis indicates deliberate diversification rather than consolidation. Domains within the ecosystem are distributed across multiple commercial registrars, including Cloudflare, GoDaddy (Jomax), Namecheap, Dynadot, and Porkbun. No single registrar dominates the corpus. This dispersion reduces the likelihood of centralized administrative exposure and complicates straightforward clustering based on registrar account identifiers alone.
Privacy shielding is applied almost universally. Registrant information is redacted or routed through privacy services, limiting direct attribution vectors. Registration durations are typically short, most commonly one- to two-year terms, reinforcing the disposable nature of the infrastructure. There is no evidence of long-term brand cultivation or multi-year strategic retention of primary domains. Instead, domains appear engineered for limited operational lifespan, with replacement assumed as part of the lifecycle model.
Taken together, these characteristics support a strategy of attribution resistance through registrar diversification. By spreading registrations across multiple providers, the operators reduce the impact of any single registrar-level disruption or investigative pivot. This also suggests compartmentalization: different domain clusters may be provisioned under separate registrar accounts to prevent a single compromise from exposing the full network.
The lifecycle management model is explicitly disposable. Domains are provisioned for campaign phases, used for narrative dissemination, and abandoned or replaced following enforcement pressure or strategic refresh cycles. This is consistent with burst registration waves and TLD substitution behavior observed elsewhere in the ecosystem.
Hosting & IP Space Analysis
Infrastructure analysis reveals a consistent architectural pattern built around layered hosting abstraction. At the outermost layer, domains are fronted by Cloudflare, which provides edge delivery, caching, and origin masking. This CDN fronting obscures backend IP exposure and complicates direct attribution through simple DNS resolution. Behind this edge layer, backend services are deployed across hyperscale cloud providers, principally Google Cloud, where individual sites resolve to distributed virtual instances. At the application layer, disposable WordPress nodes function as the publishing engine, allowing rapid content deployment and replacement without persistent infrastructure commitments.
The dataset supports this model. Across 48 domains, 34 unique IP addresses were observed, indicating distributed backend allocation rather than centralized hosting. A substantial portion of domains resolved through Cloudflare address space in the 104.x range, reinforcing the prevalence of CDN masking. Backend nodes and functions appeared in Google Cloud 34.x ranges as well as some lesser activity in AWS 15.x ranges, often in small micro-clusters of related domains sharing hyperscaler infrastructure or repurposing static assets or content from legitimate websites. A minor presence of European hosting providers exists, but without concentration sufficient to suggest geographic anchoring.
This configuration reflects a cloud-native deployment strategy optimized for flexibility and resilience. Hyperscaler infrastructure provides rapid provisioning, geographic neutrality, and scalable bandwidth, while CDN masking reduces visibility into origin servers. The distributed IP footprint and lack of single-ASN concentration further enhance survivability and reduce detection risk.
Notably, there is no observable concentration of infrastructure within Russian autonomous systems. This absence should not be interpreted as contradictory to Russian-aligned tradecraft. On the contrary, reliance on Western hyperscalers and CDN masking aligns with evolved attribution-resistant design principles. By operating within globally reputable cloud ecosystems, the campaign blends into high-volume commercial traffic, leveraging legitimate infrastructure to reduce investigative friction.
The resulting hosting posture is deliberately attribution-resistant. It prioritizes redundancy, geographic neutrality, and rapid redeployment capacity over static hosting stability. This design is consistent with a professionally managed influence operation engineered for persistence under enforcement pressure rather than a transient spoofing campaign.
DNS & Nameserver Linkage
DNS-layer analysis provides several high-probability linkage indicators that may offer stronger structural correlation than hosting data alone. While IP addresses can shift due to CDN fronting or cloud migration, nameserver configurations often persist across operational changes and therefore provide a more durable pivot.
One primary indicator would be the reuse of identical nameserver pairs across multiple brand families. If domains impersonating unrelated outlets such as Spiegel, Bild, and Süddeutsche share the same NS records, the likelihood of independent registration diminishes substantially. Shared nameserver infrastructure across distinct media brands would suggest centralized DNS provisioning rather than coincidental overlap.
A related signal would be reliance on the same DNS provider across otherwise unrelated impersonation domains. When domains targeting different national audiences or brands resolve through a common DNS control environment, it implies coordination at the administrative level. Similar time-to-live (TTL) values across domains can further reinforce this signal, as TTL configurations often reflect default settings applied at the account or template level rather than individually tuned parameters.
Consistency in Start of Authority (SOA) structure such as identical formatting conventions, refresh intervals, or authoritative contact placeholders would provide additional evidence of centralized DNS management. SOA artifacts are rarely manipulated for cosmetic purposes and often reveal provisioning templates used by operators.
If nameserver reuse were observed across the Spiegel, Bild, Süddeutsche, and RRN domain families, it would strongly indicate a unified DNS control plane underpinning both narrative hubs and impersonation properties. Such convergence would demonstrate that, despite registrar dispersion and TLD diversification, domain resolution remains orchestrated from a common administrative layer.
In comparative evidentiary strength, nameserver clustering is likely a more robust attribution signal than IP overlap. IP infrastructure can be transient, especially in cloud-native deployments. Nameserver configurations, by contrast, frequently reflect centralized provisioning logic and are less susceptible to routine backend rotation. As a result, DNS-layer commonality may provide the clearest structural linkage within a distributed, attribution-resistant hosting environment.
Backend CMS Artifact Analysis
Forensic review of recovered WordPress artifacts provides insight into backend governance and operational discipline. The earliest observable provisioning activity indicates bootstrap configuration using a Yandex-linked email account, suggesting centralized initial setup rather than distributed contributor onboarding. Following this bootstrap phase, multiple accounts associated with the @rrn[.]com[.]tr namespace were rapidly provisioned, reflecting coordinated account creation within a defined administrative domain.
User roles within the CMS exhibit structured segmentation. Accounts labeled with function-specific identifiers such as “seoadmin” and “RRN_Staff” indicate differentiated permissions and workflow responsibilities. This separation of duties is characteristic of managed editorial environments rather than informal publishing collectives. The presence of search-engine-optimization–focused accounts further demonstrates that visibility engineering was embedded into backend operations, not treated as an afterthought.
Artifacts dated to 2025 reveal application-password configurations, which are typically associated with API integrations, automated publishing pipelines, or credential compartmentalization for security control. The continued presence of such artifacts indicates ongoing maintenance and lifecycle management rather than abandonment of infrastructure following enforcement pressure.
Collectively, these backend signals imply centralized coordination of publishing workflows, structured SEO integration, and sustained operational oversight. The pattern reflects a professionalized content management hierarchy with defined roles, controlled credential distribution, and repeatable provisioning logic. Such characteristics are inconsistent with decentralized volunteer activism or loosely organized advocacy networks. Instead, they align with a managed, institutionally structured information operation.
Automated Domain Generation Model
Domain naming patterns across the ecosystem reveal consistent construction logic indicative of automation rather than manual registration. The observed formats follow repeatable templates. The most straightforward pattern replicates the core brand token directly as a second-level domain paired with an alternate top-level extension. A second pattern appends semantic qualifiers to the brand, often news-oriented or temporal terms before applying a conventional TLD. A third variation incorporates geographic modifiers, creating localized variants that maintain brand recognition while implying regional relevance. Additional structures involve typographical manipulation of the brand token itself or preservation of the second-level domain during TLD migration events.
Typographical techniques follow predictable methods. Letter duplication produces visually plausible variants such as “bildd.” Letter omission removes characters to create near-identical strings, for example “blld.” Phonetic substitution alters spelling while retaining recognizability, as in “build.” Semantic suffixes such as “-today,” “-live,” or “-life” introduce news-related framing, while geographic modifiers like “-eu” or “-asia” imply localized legitimacy. These manipulations are systematic and repeat across multiple brand families, reinforcing the likelihood of template-based domain generation.
The preservation of the second-level domain across new TLDs during enforcement events further supports the presence of structured provisioning logic. Rather than improvising new names, operators maintain core tokens and rotate extensions, suggesting preplanned substitution pathways embedded within the registration pipeline.
The consistency and recurrence of these patterns strongly suggest a scripted bulk provisioning mechanism. Domain creation appears to follow predefined logic trees, enabling rapid generation of multiple variants per target brand. This automation facilitates scalability, redundancy, and rapid replacement following seizure or suspension.
Based on the observed logic, predictive domain templates can be modeled. Likely future variants would include constructions such as brand paired with “.media,” “.agency,” or “.today.” Hyphenated semantic extensions appended to established brands such as brand-live or brand-life are also probable. Additionally, migration to lower-scrutiny country-code or generic TLDs such as “.cc” or “.so” remains consistent with prior behavior.
Monitoring Certificate Transparency logs against these structured templates is recommended as an early-warning mechanism. Because automated pipelines often generate certificates shortly after registration, template-based CT monitoring may identify new impersonation domains before large-scale amplification occurs.
Geographic Target Segmentation
Geographic segmentation within the ecosystem reflects deliberate alignment between infrastructure deployment and narrative emphasis. Targeting is not uniform across regions; instead, infrastructure tactics and messaging themes are calibrated to local political contexts and audience sensitivities.
Germany emerges as the most extensively targeted environment. The infrastructure footprint there is dominated by high-volume media impersonation, particularly of prominent national outlets. The corresponding narrative focus centers on anti-NATO themes, criticism of sanctions policy, and efforts to widen domestic political divisions. The scale and density of impersonation domains associated with German brands indicate prioritization beyond incidental inclusion.
In France, the operational model blends media clones with narrative front domains. Messaging frequently emphasizes the economic costs of sanctions and promotes themes of Ukraine-related fatigue. The infrastructure suggests a strategy aimed at reframing policy debates through domestically contextualized narratives rather than direct geopolitical confrontation.
The United States is approached through narrative front properties combined with election-cycle framing. Rather than relying exclusively on high-fidelity impersonation of national outlets, the ecosystem leverages independently branded sites to question institutional legitimacy and amplify distrust in democratic processes. Timing of domain provisioning aligns with electoral periods, reinforcing the assessment of politically sensitive targeting.
In the United Kingdom, media impersonation remains the dominant tactic. Messaging themes concentrate on skepticism toward NATO policy and criticism of foreign engagement. The structure parallels the German model but appears narrower in scope.
Italy is targeted primarily through impersonation of ANSA and related institutional brands. The emphasis shifts toward undermining institutional trust and reinforcing domestic dissatisfaction narratives. This indicates adaptation to national media ecosystems and audience trust structures.
Across the broader European Union, the campaign employs an amplification mesh model. Rather than focusing exclusively on single-country impersonation clusters, domains and social distribution mechanisms propagate narratives across borders, fostering cross-national polarization and reinforcing pan-European fissures.
The relative density of impersonation domains, narrative alignment, and provisioning volume suggests that Germany represents the highest-priority target within the ecosystem. Infrastructure investment and thematic emphasis converge most heavily in that information environment, indicating strategic weighting rather than incidental inclusion.
Germany appears highest-priority target.
What the Infrastructure Is Not
Infrastructure analysis reveals a consistent absence of indicators typically associated with financially motivated cybercrime or intrusion-focused operations. There is no evidence of malware command-and-control coordination embedded within the observed domains. The hosting architecture, DNS behavior, and certificate issuance patterns do not reflect infrastructure designed to manage implants, beacon traffic, or staged payload delivery.
Similarly, there are no artifacts suggesting phishing kit reuse or credential-harvesting frameworks. The domains do not exhibit structural similarities to common phishing templates, nor do they display the rapid redirect logic or form-handling mechanics associated with account compromise campaigns. The absence of credential collection endpoints or kit fingerprint overlap further distinguishes this ecosystem from conventional fraud operations.
There is also no observable affiliate monetization structure. The infrastructure does not show integration with traffic arbitrage networks, affiliate referral programs, or performance-based revenue systems. Domain lifecycles are short and aligned with narrative waves rather than revenue optimization windows. Likewise, there is no evidence of ad network integration, programmatic advertising infrastructure, or content-farming strategies designed to generate advertising impressions at scale.
Hosting patterns further differentiate the operation from typical criminal infrastructure. The ecosystem does not rely on bulletproof hosting providers or obscure offshore ASNs commonly associated with malware distribution or fraud. Instead, it leverages mainstream hyperscaler platforms and CDN fronting, prioritizing camouflage within legitimate cloud ecosystems rather than protection from law enforcement through hardened criminal service providers.
Collectively, these absences are analytically significant. The infrastructure is optimized for narrative dissemination, brand impersonation, and audience influence rather than financial extraction or technical exploitation. Its design reflects an information operation architecture engineered for credibility manipulation and distribution resilience. This is narrative delivery infrastructure, not cybercrime infrastructure.
Operational Maturity Assessment
The Doppelgänger ecosystem exhibits operational characteristics consistent with disciplined infrastructure engineering rather than ad hoc domain deployment. Provisioning behavior reflects DevOps-style methodology: domains are registered in coordinated bursts, deployed in structured waves, and integrated into a repeatable pipeline that supports rapid staging and replacement. Infrastructure is treated as code: scalable, replicable, and disposable.
Campaign activation appears synchronized with geopolitical or electoral inflection points, indicating burst staging rather than continuous organic growth. Domains are stockpiled in advance of use, enabling operators to activate replacement nodes with minimal latency following enforcement actions. This pre-positioned redundancy reduces operational downtime and demonstrates forward-planned lifecycle management.
Rapid pivoting in response to seizures further illustrates enforcement-aware design. When domains are disrupted, second-level identifiers are preserved and redeployed under alternate top-level domains. Hosting and DNS configurations are rotated without altering the broader narrative framework. The system absorbs disruption without collapsing, reflecting modular segmentation that isolates functional layers from single points of failure.
The architecture’s reliance on CDN masking, hyperscaler backend infrastructure, and distributed IP allocation demonstrates cloud-native proficiency. Deployment choices prioritize camouflage within legitimate commercial cloud environments, reducing attribution risk and complicating network-level blocking strategies. Infrastructure components are loosely coupled yet centrally coordinated, reinforcing resilience.
Attribution minimization is embedded throughout the lifecycle. Registrar dispersion, privacy shielding, and geographic hosting neutrality collectively reduce direct linkage signals. Operational design favors structural ambiguity while maintaining internal coherence.
The campaign’s evolution reflects increasing sophistication under pressure. During Phase I (2022–2023), the model centered on a relatively centralized RRN hub supported by impersonation spokes. Phase II (2024) introduced enforcement disruption through domain seizures, testing the resilience of the architecture. In Phase III (2024–2025), the ecosystem adapted into a more distributed modular mesh, reducing reliance on singular hubs and expanding TLD diversification.
Rather than diminishing under enforcement pressure, the infrastructure matured. Redundancy increased, segmentation deepened, and migration pathways became more seamless. The trajectory indicates learning and adaptation, reinforcing the assessment that the operation is professionally managed and strategically sustained rather than episodic or opportunistic.
Strategic Assessment
The Doppelgänger ecosystem exhibits characteristics consistent with industrialized influence infrastructure rather than episodic or improvised activity. Its provisioning discipline, redundancy planning, and lifecycle management imply sustained funding and coordinated oversight. The infrastructure is treated as a strategic asset, engineered for persistence under scrutiny and adaptable under enforcement pressure. This reflects a model in which infrastructure is not merely a vehicle for messaging but the foundation of the influence operation itself.
The operational posture aligns with an infrastructure-first influence warfare framework. Domains are provisioned in waves, diversified across TLDs, shielded behind CDN layers, and redeployed with minimal latency following disruption. Backend publishing environments are structured and role-segmented. DNS and hosting choices prioritize camouflage within legitimate hyperscaler ecosystems. These attributes collectively indicate that technical architecture is central to the campaign’s design, not secondary to narrative content.
Psychological operations are embedded within this technical foundation. Messaging is geographically segmented, timed to political cycles, and distributed through impersonation layers engineered to exploit audience trust. The technical and narrative components are integrated rather than siloed. DevOps-style provisioning supports narrative agility, enabling rapid amplification, replacement, or recalibration in response to geopolitical developments.
The campaign represents a hybridization of multiple strategic disciplines. Cyber infrastructure strategy provides resilience, obfuscation, and scalability. Narrative warfare supplies thematic direction and audience targeting. Search ecosystem manipulation ensures discoverability and legitimacy through SEO optimization. Election-cycle timing introduces temporal precision, aligning infrastructure activation with moments of heightened political sensitivity.
Taken together, these characteristics distinguish the operation from opportunistic spoofing or isolated propaganda efforts. The ecosystem reflects structured, enforcement-aware influence engineering. Its design anticipates disruption, incorporates redundancy by default, and integrates technical and psychological components into a cohesive operational model.
Editor’s Note: DomainTools Investigations engaged in pre-publication collaboration with both Google Threat Intelligence Group and Amazon Web Services Threat Intelligence on this material. Both teams were immediately responsive, engaging in analysis in their respective areas and providing helpful feedback. We appreciate their partnership.
Lotus Blossom (G0030) and the Notepad++ Supply-Chain Espionage Campaign
How Lotus Blossom (G0030) compromised the Notepad++ update pipeline in a precision supply-chain espionage campaign targeting high-value organizations.
Executive Summary
In late 2025 and early 2026, a series of independent disclosures by software maintainers, security researchers, and national cyber authorities converged on an unsettling conclusion: for months, the update mechanism of one of the world’s most widely used open-source text editors had been quietly subverted. What initially appeared to be an isolated infrastructure anomaly was ultimately revealed to be a sustained compromise of the Notepad++ update pipeline, stretching back roughly six months. As investigators reconstructed the timeline, tracking unauthorized access to hosting infrastructure, lingering credentials that outlived initial remediation, and selectively altered update responses, a far more deliberate operation came into focus. This report is the product of analysis and parallel reconstruction of all public reporting on Lotus Blossom with additional research by DTI, drawing together technical forensics, victimology, and strategic context to assess both the campaign and the actor behind it.
The evidence points to a quiet, methodical intrusion rather than a blunt supply-chain smash-and-grab. From their foothold inside the update infrastructure, the attackers did not indiscriminately push malicious code to the global Notepad++ user base. Instead, they exercised restraint, selectively diverting update traffic for a narrow set of targets, organizations and individuals whose positions, access, or technical roles made them strategically valuable. Taken together, the operational choices, tooling, and victim profile support attribution, with moderate to high confidence, to the China-aligned espionage actor commonly tracked as Lotus Blossom (G0030) in concurrence with other organizations assessment.
What most clearly distinguishes this campaign is its precision. The malicious updates were tailored, the delivery carefully gated, and the operational noise deliberately kept low. There is no evidence of ransomware, financial theft, destructive activity, or influence operations. That absence is itself a signal. Everything about the intrusion, from the limited number of victims to the patient dwell time, points to an intelligence-gathering mission oriented toward quietly acquiring insight rather than extracting immediate material gain. The inferred objectives align closely with state intelligence priorities, encompassing political decision-making, economic and financial visibility, and access to telecommunications and technical environments.
Viewed in a broader historical context, the Notepad++ compromise represents a clear evolution in Lotus Blossom’s tradecraft. Earlier campaigns relied heavily on spear-phishing and bespoke backdoors delivered directly to victims. Rather than compromising end-user systems through conventional infrastructure attacks, such as opportunistic abuse of widely trusted software updates, the actors shifted the locus of trust toward the developer ecosystem itself. By abusing a legitimate update mechanism relied upon specifically by developers and administrators, they transformed routine maintenance into a covert entry point for high-value access. Yet despite this technical evolution, the strategic logic remains consistent. The campaign reflects continuity in purpose, a sustained focus on regional strategic intelligence, executed with more sophisticated, more subtle, and harder-to-detect methods than in prior iterations.
Actor Overview: Lotus Blossom (G0030)
Lotus Blossom is best understood as one of the more durable and methodical Chinese cyber-espionage clusters, with activity traced by multiple vendors and government-linked research groups back to at least 2009–2010. Over more than a decade of operations, the group has appeared under a shifting set of aliases, reflecting differences in vendor telemetry and analytic frameworks, but those naming inconsistencies mask a striking continuity beneath the surface. Across campaigns separated by years, Lotus Blossom exhibits the same core patterns: recurring malware families, stable operational rhythms, and a highly consistent choice of targets. This continuity is one of the strongest indicators that analysts are observing a single, long-lived espionage program rather than a loose collection of short-term intrusion efforts.
At its core, Lotus Blossom is a mission-driven intelligence actor, not a financially motivated threat group. There is no credible reporting tying the cluster to ransomware, extortion, cryptomining, or large-scale fraud. Instead, its operations consistently prioritize access, visibility, and persistence. In multiple documented campaigns, compromised environments remained under observation for months or even years, with operators carefully enumerating systems, staging data locally, and maintaining footholds through understated persistence mechanisms. The absence of monetization artifacts, such as payment infrastructure, monetization tooling, or public-facing impact, strongly reinforces the assessment that Lotus Blossom’s mandate is intelligence collection rather than profit.
Geographically, the group’s center of gravity has long been Southeast Asia, a region that aligns closely with Chinese strategic, diplomatic, and security interests. Vietnam, the Philippines, Hong Kong, Taiwan, and neighboring states recur repeatedly in public reporting. Over time, however, there is clear evidence of measured expansion beyond this core theater. More recent campaigns, including the Notepad++ supply-chain operation, show activity extending into Central America and Oceania, suggesting either broadened tasking or an adaptive response to evolving intelligence priorities. Importantly, this expansion has not come with a change in tempo or style; the group applies the same low-noise tradecraft regardless of geography.
One of Lotus Blossom’s defining traits is its tolerance for long dwell times and multi-year campaigns. Unlike vulnerability-driven actors that move rapidly from exploitation to exit, Lotus Blossom appears comfortable maintaining access with minimal interaction, sometimes returning to environments long after initial compromise. This patience is reflected in how the group manages infrastructure and malware lifecycles. Tooling is not rapidly discarded after exposure; instead, families are iterated and refined over years, with new variants introduced only when necessary. This approach reduces operational risk and supports sustained intelligence collection.
Operationally, the group shows a strong preference for quiet persistence over disruption. Techniques documented across campaigns emphasize blending in rather than standing out: registry-based persistence, Windows services, DLL sideloading, and the use of legitimate administrative utilities. Command-and-control traffic is frequently disguised as normal web or API activity, and in some cases tunneled through legitimate platforms. This tradecraft minimizes alerts and allows the actor to remain embedded in sensitive networks without triggering incident response thresholds.
A key throughline across Lotus Blossom’s history is its reliance on custom backdoors that evolve but remain recognizably related. Early campaigns made use of backdoors such as Elise, followed by the long-running Sagerunex family, which has been observed in multiple variants since at least 2016 and is widely regarded as uniquely associated with the group. The emergence of Chrysalis in the Notepad++ supply-chain campaign represents the latest iteration of this lineage: a bespoke implant designed for stealth, flexibility, and long-term access. The persistence of these families across years underscores both development continuity and institutional knowledge within the operator set.
Within the broader Chinese APT ecosystem, Lotus Blossom occupies a regional strategic espionage tier. It is less globally expansive than groups such as APT10 or APT41, which have conducted large-scale, worldwide operations against managed service providers, supply chains, and intellectual property targets. At the same time, Lotus Blossom is markedly more disciplined and persistent than opportunistic or vulnerability-driven clusters that surge around new exploits and then fade. Its niche is sustained regional intelligence collection: quieter, narrower in scope, but exceptionally durable. That combination – longevity, patience, and restraint – has made Lotus Blossom one of the more consistently effective, and correspondingly harder to uproot, espionage actors operating in the Chinese cyber landscape.
Historical Operations and Tradecraft Evolution
Lotus Blossom’s operational history can be understood as a gradual but deliberate evolution, marked by clear phases in tooling, targeting, and delivery mechanisms, each building on lessons learned from the last.
In its early era, roughly spanning 2012 to 2015, Lotus Blossom was first brought into clear view through campaigns documented by multiple security vendors. During this period, the group focused heavily on government and military organizations across Southeast Asia, reflecting a tightly scoped intelligence mandate aligned with regional political and defense priorities. Access was typically achieved through spear-phishing, often using carefully crafted, weaponized documents designed to appear relevant to the recipient’s official duties. Once opened, these lures delivered a custom backdoor known as Elise, which gave the operators persistent access to compromised systems. The objectives in this phase were relatively unambiguous: the collection of political and defense intelligence, including insight into policy deliberations, military posture, and regional security relationships. The tradecraft was effective but conventional, relying on social engineering and direct victim interaction to establish initial footholds.
The middle era, from approximately 2016 through 2024, marks a period of consolidation and professionalization. During this time, Lotus Blossom transitioned away from Elise and adopted the Sagerunex backdoor family, which would become a defining element of its operations for nearly a decade. Sagerunex was not simply a replacement implant but a more flexible and durable platform, iterated across multiple variants and tailored for long-term persistence. Alongside this tooling shift, the group expanded its target set. While government entities remained important, campaigns increasingly encompassed telecommunications providers, media organizations, and manufacturing or industrial firms. This broader victimology suggests an intelligence remit that had widened to include information flows, public narratives, supply chains, and industrial capacity.
Technically, this era is notable for Lotus Blossom’s growing reliance on legitimate third-party services as covert command-and-control channels. By tunneling communications through cloud platforms, webmail, and other widely used services, the group was able to blend malicious traffic into normal enterprise activity, significantly reducing detection risk. At the same time, operators invested in improved operational security and persistence mechanisms, favoring low-visibility techniques such as Windows services, registry modifications, and careful privilege management. These choices enabled long dwell times and multi-year access to sensitive environments, reinforcing the group’s reputation for patience and discipline.
The modern era, beginning in 2025 and extending into 2026, represents the most pronounced shift in Lotus Blossom’s tradecraft. In this phase, the group adopted supply-chain compromise as a primary delivery vector, moving upstream to exploit trusted software distribution mechanisms rather than targeting victims directly. This approach dramatically reduced reliance on social engineering and increased the likelihood of execution in privileged, trusted contexts. Central to this period was the development and deployment of Chrysalis, a previously undocumented backdoor that fits within the group’s established lineage but reflects contemporary defensive realities, emphasizing stealth, flexibility, and survivability.
Operational focus in this era also shifted toward developer and administrator tooling, applications and environments used by individuals with elevated privileges and deep visibility into organizational systems. Even when positioned to affect a broad population, Lotus Blossom demonstrated highly selective victim delivery, carefully gating malicious updates to a narrow set of high-value targets. This restraint underscores the intelligence-driven nature of the activity and the group’s continued aversion to unnecessary exposure.
Viewed end to end, the Notepad++ supply-chain campaign stands as the clearest and most mature expression of this evolution. It combines the group’s longstanding strategic focus on regional intelligence with a modern delivery mechanism that exploits trust itself, integrating bespoke tooling, blended command-and-control, and disciplined selectivity into a single, tightly executed operation.
Targeting Patterns Across Lotus Blossom’s Operational History
Across more than a decade of observed activity, Lotus Blossom’s targeting patterns reveal a high degree of consistency in strategic intent, even as the specific sectors and access methods have evolved. Rather than pursuing breadth or opportunistic exploitation, the group has repeatedly demonstrated a preference for narrow, high-value target sets aligned with enduring state intelligence requirements.
Geographically, Lotus Blossom’s center of gravity has remained firmly anchored in Southeast Asia since its earliest documented campaigns. Countries such as Vietnam and the Philippines recur across multiple reporting periods, reflecting their geopolitical relevance, proximity to contested maritime regions, and the importance of regional security dynamics. Over time, the group’s targeting expanded outward in a measured fashion rather than a sudden global surge. East Asian entities, particularly in Hong Kong and Taiwan, appear during periods of heightened political sensitivity, while more recent operations show selective activity in Oceania and Central America. This pattern suggests deliberate tasking tied to evolving diplomatic, security, and economic priorities rather than indiscriminate global reach.
Sectorally, Lotus Blossom’s targeting history shows a clear progression from core state institutions toward broader strategic enablers. In its early years, the group focused heavily on government ministries and military or defense-adjacent organizations, consistent with a mandate centered on political and defense intelligence. As the group matured, it expanded into telecommunications providers, a shift that provided insight into information flows, network dependencies, and potential downstream access. Subsequent targeting of media organizations indicates an interest in narrative awareness and public messaging, while incursions into manufacturing and industrial sectors point to intelligence collection related to supply chains, industrial capacity, and economic resilience.
A notable and recurring theme is Lotus Blossom’s focus on access multipliers, entities or roles that provide visibility beyond their immediate organizational boundaries. Telecommunications operators, IT service providers, and managed service environments appear repeatedly because they offer the potential to observe or pivot into multiple downstream networks. This logic is further reinforced in the group’s most recent campaigns, which emphasize developer and administrator environments. By targeting the tools and systems used by highly privileged technical staff, Lotus Blossom maximizes intelligence yield while minimizing the number of compromises required.
Equally important is what the group does not target. There is little evidence of sustained activity against consumer sectors, retail organizations, or entities primarily associated with direct financial gain. Even when financial institutions appear in victimology, the surrounding indicators point toward financial intelligence and relationship mapping, not theft or fraud. This restraint reinforces the assessment that Lotus Blossom’s targeting is governed by intelligence value rather than monetization potential.
Finally, Lotus Blossom’s targeting is characterized by selectivity and patience. Campaigns routinely involve small numbers of victims, long dwell times, and repeated engagement with the same regions or sectors over many years. The Notepad++ supply-chain campaign exemplifies this approach: despite access to a potentially massive user base, the group limited malicious delivery to a tightly controlled subset of targets. This pattern is consistent with an actor that values sustained insight and low exposure over rapid or dramatic effects.
Taken together, Lotus Blossom’s targeting history reflects a disciplined, intelligence-driven model. Geography, sector, and individual victim selection all serve a coherent strategic purpose, supporting the conclusion that the group functions as a long-term regional intelligence collector rather than a broad-spectrum or opportunistic threat actor.
The Notepad++ campaign represents a deliberate and technically mature supply-chain operation built around the exploitation of trust, rather than the compromise of software code itself. Instead of tampering with the Notepad++ application or its publicly available source, the attackers targeted third-party hosting infrastructure responsible for distributing software updates. By positioning themselves within this upstream delivery path, they were able to influence what end users received without altering the integrity of the project’s codebase or repositories.
Central to the operation was the abuse of WinGUp (GUP.exe), the legitimate updater mechanism used by Notepad++. Under normal conditions, GUP.exe is responsible for periodically checking for updates and retrieving them from trusted servers. The attackers subverted this process by selectively redirecting update requests from chosen systems to attacker-controlled servers. To the end user, and to most security controls, the process appeared indistinguishable from a routine update transaction.
A critical distinguishing feature of this campaign is that the Notepad++ source code was never modified. This choice conferred several operational advantages. By avoiding source-level tampering, the attackers bypassed source-code reviews, integrity checks, and the scrutiny of the open-source community. The malicious payloads were delivered in the form of trojanized installers, injected only at the point of distribution, allowing the operation to remain invisible to developers and maintainers focused on the code itself.
This approach also enabled a high degree of plausible deniability. Because the compromise occurred within hosting and delivery infrastructure rather than the project’s repositories, attribution was obscured and initial investigations could plausibly attribute anomalies to misconfiguration or transient infrastructure issues. Most importantly, the attackers exercised tight control over victim selection. Update redirection was applied only to specific targets, ensuring that malicious installers were delivered to a narrow, high-value subset of users while the vast majority of the Notepad++ user base continued to receive legitimate updates without incident.
Taken together, these elements reflect a campaign characterized by advanced planning, privileged access, and operational restraint. The selective nature of delivery, the avoidance of unnecessary exposure, and the exploitation of infrastructure trust rather than code vulnerabilities are all hallmarks of Lotus Blossom’s established tradecraft. The Notepad++ supply-chain compromise stands as a clear example of how the group has adapted its methods to modern software ecosystems while remaining true to its long-standing emphasis on stealthy, intelligence-driven operations.
Infection Chains and Malware Deployment
Analysis of the Notepad++ supply-chain incident reveals that the operation was not built around a single, static infection pathway, but rather multiple distinct infection chains deployed over the course of several months. Each chain showed minor variations in tooling, payload composition, and supporting infrastructure, suggesting active management and iteration by the operators. This modularity allowed Lotus Blossom to adapt to changing conditions, rotate infrastructure, and selectively tailor implants to different victims, all while preserving a consistent operational framework.
Despite these variations, the infection chains shared a set of core behavioral elements that define the campaign’s execution. In every observed case, the process began with a legitimate Notepad++ update request, handled by the WinGUp (GUP.exe) updater. For selected targets, this trusted process was subverted to launch a malicious installer delivered from attacker-controlled infrastructure. From the perspective of the operating system and the user, the execution chain appeared routine, inheriting the trust and execution context of a normal software update.
Once execution was achieved, the malware performed initial reconnaissance to situate itself within the environment. Commands such as whoami and tasklist, along with broader system enumeration routines, were used to identify the current user context, running processes, and basic system characteristics. This early situational awareness informed subsequent decisions, including which payloads to deploy and how aggressively to establish persistence.
The next phase involved the staging of artifacts within user application data directories, a deliberate choice that balanced accessibility and stealth. By operating within per-user paths rather than system-wide locations, the malware reduced the likelihood of triggering security controls tied to protected directories, while still maintaining reliable execution and storage. These directories served as temporary holding areas for loaders, configuration files, and auxiliary components.
From this staging environment, the operation progressed to the deployment of a custom loader, responsible for orchestrating the remainder of the infection chain. The loader acted as a pivot point, handling decryption, unpacking, and execution of the final payloads. Depending on the target and the specific chain in use, this culminated in the installation of either Cobalt Strike–based implants or the Chrysalis backdoor. The presence of both options indicates a flexible approach: Cobalt Strike offered a mature, feature-rich post-exploitation framework, while Chrysalis provided a bespoke, lower-profile alternative aligned with Lotus Blossom’s preference for custom tooling.
In all observed chains, post-compromise communications were conducted using encrypted, low-frequency outbound connections over HTTPS. Beaconing intervals were deliberately sparse, and traffic was structured to resemble legitimate web or API interactions, minimizing anomalies in network telemetry. This communications model prioritized stealth and survivability over responsiveness, reinforcing the broader pattern of restraint and long-term access that characterizes Lotus Blossom’s operations.
Collectively, these infection chains demonstrate a disciplined, repeatable deployment model that balances adaptability with consistency. The variations across chains reflect active operational oversight, while the shared elements underscore a well-established playbook optimized for covert, intelligence-driven access rather than rapid exploitation or overt impact.
Tradecraft Observed in the Notepad++ Supply-Chain Operation
In analyzing the Notepad++ supply-chain compromise and correlating it with broader reporting on Lotus Blossom operations, a consistent theme emerges. The group relies on stealthy, evasive techniques that blend malicious activity into normal system behavior rather than overt exploitation that would draw defensive attention. This section explains the key tradecraft elements that enabled the campaign’s success and situates them within broader patterns observed in similar Chinese state-aligned espionage activity.
A foundational aspect of Lotus Blossom’s technique set is the frequent use of living-off-the-land (LOTL) utilities, trusted, legitimate system tools that are co-opted to execute malicious logic under the guise of normal administrative or maintenance tasks. In LOTL attacks, adversaries leverage binaries that are already present on the target system (such as command interpreters or native utilities) to perform reconnaissance, lateral movement, or privilege escalation. Because these tools are part of the standard operating environment, their invocation often escapes traditional signature-based defenses and is not flagged by endpoint security as anomalous behavior. This approach is deliberately evasive, allowing an attacker to achieve foothold and persistence while minimizing the generation of new, suspicious artifacts. (Kiteworks | Your Private Data Network)
Another sophisticated tactic documented in the Notepad++ intrusion was the abuse of DLL sideloading, an established evasion technique that enables malicious code to be loaded by a legitimate host process. In the Notepad++ case, researchers found that a renamed legitimate utility (the Bitdefender Submission Wizard) was used as the initial execution context. A malicious companion DLL, placed in the same directory with the same name expected by the host process, was then loaded in place of the legitimate library. This technique allows the adversary to inject custom payloads without directly executing an executable they control, further blending with normal system activity and reducing the footprint seen by defensive tools. (Security Affairs)
Once executed, many of the campaign’s implants communicated with remote infrastructure using API-style command-and-control (C2) endpoints designed to resemble benign web traffic. These endpoints often expose paths that mimic legitimate update, telemetry, or cloud service APIs rather than raw sockets or obvious HTTP beaconing. By shaping communications in this way and by hosting them behind domains or services that appear innocuous, operators improve the chances that their traffic will traverse restrictive egress filters and escape detection by network intrusion detection systems. This API-like pattern of C2 infrastructure has been observed not only in the Notepad++ campaign but also in prior Lotus Blossom activity where third-party services (e.g., Dropbox, Twitter, or webmail) were repurposed as covert tunnels for beaconing and data exfiltration. (Cisco Talos Blog)
Finally, Lotus Blossom’s infrastructure usage patterns demonstrate rotation and redundancy without abandoning operational grammar. Rather than hard-coding a static set of servers or domains, the group periodically shifts hosting providers, domain names, and IP space while maintaining consistent behavioral identifiers in their implants and C2 protocols. This approach complicates blunt IP-blocklist defenses while preserving the recognizable telemetry that seasoned defenders use to attribute activity over time. The result is an operational posture that is resilient to takedown and resistant to simple detection heuristics, yet still exhibits an identifiable signature across campaigns and years of activity.
Collectively, these tradecraft elements illustrate a highly disciplined adversary that prioritizes stealth, persistence, and low noise. By blending malicious activity into the fabric of normal system and network behavior, Lotus Blossom not only evaded detection during the Notepad++ campaign but also reaffirmed the group’s long-standing preference for covert intelligence collection over disruptive or noisy exploitation.
Victimology and Target Base
The victimology observed in the Notepad++ supply-chain campaign reinforces the assessment that this operation was tightly scoped and intelligence-driven, rather than opportunistic or indiscriminate. Public reporting and forensic analysis identify a small, carefully selected set of confirmed or strongly suspected victims, each of which aligns with Lotus Blossom’s historical targeting logic.
Among the confirmed or observed targets were a government organization in the Philippines, a financial institution in El Salvador, and an IT service provider in Vietnam. In addition, individual technical users were identified in Vietnam, Australia, and El Salvador. While the total number of victims was limited, the diversity of roles and sectors represented is significant. Each victim category provides a disproportionate intelligence return relative to the number of compromises required.
Geographic Pattern
The geographic distribution of victims is coherent and strategically consistent, rather than random. Southeast Asia remains the clear center of gravity, with Vietnam and the Philippines reflecting long-standing intelligence priorities for China. These countries sit at the intersection of contested maritime regions, regional security cooperation, and shifting diplomatic alignments, making them enduring targets for political, military, and economic intelligence collection.
Australia’s appearance in the victim set is also notable. As a Five Eyes intelligence partner, Australia represents a high-value target for insight into allied policy coordination, defense posture, and intelligence sharing frameworks. Even limited access to technical users in this environment can yield significant contextual intelligence.
The inclusion of El Salvador and, more broadly, Central America reflects a more recent but increasingly visible pattern. While not traditionally viewed as a primary cyber-espionage theater, the region functions as a financial and diplomatic intelligence gateway, offering visibility into international financial relationships, development financing, and external influence dynamics. The presence of both a financial institution and individual technical users in this geography suggests deliberate tasking rather than incidental spillover.
Sectoral Focus
Across all geographies, the sectoral composition of victims follows a consistent pattern. Targets cluster around government and policy-relevant institutions, financial systems and intermediaries, and IT and technical service providers. In the most recent phase of operations, particular emphasis is placed on developers and system administrators, individuals whose roles grant them privileged access and broad situational awareness within their organizations.
These targets function as access multipliers. A single compromised developer workstation or IT service provider can expose configuration data, credentials, network topologies, and downstream customer environments. Similarly, access to financial institutions or government agencies provides insight into policy deliberations, economic conditions, and institutional relationships that extend well beyond the compromised endpoint itself.
Taken together, the victimology of the Notepad++ campaign underscores Lotus Blossom’s disciplined targeting philosophy. The group consistently favors high-leverage roles and institutions that maximize intelligence value while minimizing operational exposure. The limited number of victims, combined with their strategic placement across regions and sectors, reinforces the conclusion that this campaign was designed to support sustained intelligence collection rather than broad access or immediate impact.
Why Notepad++?
Notepad++ occupies a uniquely advantageous position within technical environments, which helps explain its selection as a delivery vector in this campaign. The application is ubiquitous among technical users, including developers, system administrators, network engineers, and security analysts. In many organizations, it is installed by default on workstations used for infrastructure management, application development, and operational support. As a result, systems running Notepad++ often belong to users who possess elevated privileges, deep contextual knowledge of internal systems, and routine access to sensitive resources.
From an intelligence perspective, compromising such a tool offers an unusually high return on investment. Technical users commonly rely on Notepad++ to view, edit, and temporarily store credentials, configuration files, and infrastructure details in plaintext. Scripts and automation logic, used to manage servers, networks, cloud resources, and security controls, are frequently authored or reviewed within the editor. Access to these materials can reveal VPN endpoints, cloud service credentials, API keys, internal naming conventions, and operational workflows, providing insight far beyond the confines of a single endpoint. In many cases, these artifacts also reference institutional documentation, internal procedures, and architectural diagrams that are not otherwise externally visible.
Equally important is the trust relationship inherent in the software’s update mechanism. The Notepad++ updater is a routine, background process that users expect to run without intervention or scrutiny. By abusing this mechanism, the attackers were able to inherit the implicit trust that users and operating systems place in legitimate updates. This eliminated the need for phishing emails, malicious attachments, or other forms of overt social engineering that might raise suspicion or trigger defensive controls. The act of updating the software, normally a security-positive behavior, became the point of compromise.
In effect, the update process itself functioned as the lure. Rather than persuading users to take risky actions, the attackers embedded themselves in a workflow that users already regarded as safe and necessary. This inversion of trust reflects a sophisticated understanding of how technical users operate and underscores why Notepad++ was such an effective and strategically chosen access vector for an intelligence-focused campaign.
Political, Economic, Financial, and Espionage Motives
Intelligence Objectives and Strategic Rationale
The intelligence objectives underlying the Notepad++ supply-chain campaign align closely with long-standing state priorities, particularly in the political, economic, and strategic domains. The operation’s design and execution suggest a deliberate effort to build situational awareness rather than to achieve immediate operational effects.
Political Intelligence.
A central aim of the campaign appears to be sustained monitoring of government policy direction in Southeast Asia, a region where diplomatic alignment, security cooperation, and maritime disputes remain fluid. Access to technical users and institutions in this environment provides insight into policy deliberations, inter-agency coordination, and shifts in national posture that may not be visible through public channels. Closely related is the collection of intelligence on defense cooperation and maritime strategy, including how regional governments coordinate with one another and with external partners. The presence of targets linked to allied ecosystems further suggests an interest in alignment with U.S. and partner positions, offering indirect visibility into broader coalition dynamics and strategic intent.
Economic and Industrial Intelligence.
Beyond politics and defense, the campaign reflects a clear focus on economic and industrial intelligence. Access to financial institutions and technical service providers enables visibility into indicators of economic stability, capital flows, and institutional dependencies. Similarly, targeting entities involved in infrastructure and technology operations supports an understanding of modernization efforts, procurement cycles, and industrial capacity. Monitoring regulatory discussions and trade posture, often embedded in internal documentation, draft policies, and technical planning materials provides advanced awareness of economic decisions that can shape regional competitiveness and resilience.
Financial Intelligence (Non-Theft).
Notably, while financial institutions appear in the victim set, there is no evidence of fraud, theft, or fund diversion associated with this campaign. Instead, the activity is consistent with financial intelligence collection: mapping relationships between institutions, understanding transaction flows at a structural level, and identifying dependencies within national and regional financial systems. This distinction is important. The absence of monetization artifacts reinforces the assessment that the objective was insight, not profit, and places the activity firmly in the realm of state intelligence rather than cybercrime.
Strategic Espionage Doctrine.
Taken together, these objectives reflect a strategic espionage doctrine that prioritizes access over action, patience over disruption, and information dominance without escalation. The campaign was designed to quietly position the operator for long-term understanding, not to coerce, signal, or destabilize. By avoiding destructive activity and limiting exposure, the operation preserved freedom of action while minimizing diplomatic or political risk. In this sense, the Notepad++ supply-chain compromise represents intelligence preparation, laying the groundwork for informed decision-making rather than attempting to shape outcomes directly through cyber means.
Attribution Assessment
The totality of available evidence supports attribution of the Notepad++ supply-chain campaign, with moderate to high confidence, to Chinese actors, and specifically Lotus Blossom (G0030). This assessment is not based on any single indicator, but on the convergence of multiple independent factors that, taken together, form a coherent and internally consistent attribution picture.
First, the campaign aligns closely with Lotus Blossom’s longstanding geographic focus on Southeast Asia. Vietnam and the Philippines, both represented among confirmed or observed victims, have appeared repeatedly in the group’s historical operations over more than a decade. This persistent regional focus distinguishes Lotus Blossom from more globally oriented Chinese APT clusters and reinforces continuity with prior tasking rather than a one-off expansion by a different actor.
Second, the tooling lineage observed in this campaign is consistent with Lotus Blossom’s established development patterns. The deployment of Chrysalis, a previously undocumented backdoor, fits cleanly within the group’s historical reliance on bespoke implants such as Elise and Sagerunex. The design philosophy, custom code, low noise, and flexibility for long-term access, mirrors earlier Lotus Blossom tooling rather than the commodity frameworks or mixed criminal–espionage toolsets associated with other Chinese clusters.
Third, the selective nature of targeting and low infection counts strongly support this attribution. Despite access to an update mechanism capable of affecting a massive global user base, the attackers constrained delivery to a narrow set of high-value victims. This restraint is characteristic of Lotus Blossom’s operational model, which consistently favors precision and intelligence yield over scale. It contrasts sharply with campaigns conducted by other Chinese APTs that have demonstrated a willingness to pursue broad, high-volume access when aligned with their objectives.
Fourth, the campaign demonstrates mature operational security and infrastructure discipline. The use of infrastructure-level compromise, API-style command-and-control endpoints, low-frequency encrypted communications, and careful infrastructure rotation without abandoning recognizable campaign grammar reflects a level of planning and tradecraft that Lotus Blossom has exhibited repeatedly in past operations. These elements point to an actor experienced in sustaining access over long periods while minimizing detection and attribution risk.
Finally, the victimology aligns closely with historical Lotus Blossom target sets. Government entities, financial institutions used for intelligence rather than theft, IT service providers, and privileged technical users all fall squarely within the group’s established targeting preferences. This continuity in “who” is targeted is as significant as the technical “how,” reinforcing the conclusion that the campaign represents an evolution of an existing program rather than the work of a different group adopting similar techniques.
When weighed collectively, these factors form a strong attribution case. While other Chinese APT clusters share individual characteristics, such as supply-chain access, custom tooling, or regional interest, no other known group fits the full combination of geography, tradecraft, restraint, tooling lineage, and victimology as closely as Lotus Blossom.
Defensive and Strategic Implications
The Notepad++ supply-chain compromise carries implications that extend well beyond this single incident, both for network defenders and for policymakers concerned with national and economic security. The campaign highlights structural weaknesses in how trust is established, maintained, and defended in modern software ecosystems.
Implications for Defenders.
First, the operation underscores that open-source software is not inherently low risk. Transparency of code does not automatically translate into security when the distribution and update mechanisms sit outside the codebase itself. In this case, the source remained intact while the delivery path was subverted, demonstrating that trust can be undermined upstream of any code review or integrity check. Defenders should treat open-source tools with the same rigor applied to proprietary software, particularly where update mechanisms rely on third-party infrastructure.
Second, the campaign highlights updating infrastructure as a critical attack surface. Software updaters are privileged by design, frequently allowed through endpoint and network controls, and trusted to execute code without user scrutiny. When compromised, they provide an attacker with a reliable and stealthy execution path. Securing update pipelines through stronger integrity validation, monitoring of anomalous update behavior, and defense-in-depth around hosting and distribution, is therefore as important as securing the software itself.
Third, the targeting logic reinforces that developer and administrator workstations are among the highest-value espionage targets in modern environments. These systems often aggregate credentials, scripts, configuration files, and architectural knowledge that can expose entire networks or multiple downstream organizations. Traditional security models that focus primarily on servers or perimeter assets risk overlooking these high-leverage endpoints.
Finally, the campaign demonstrates the limits of indicator-driven defense. Behavioral detection and contextual analysis are more reliable than static IOCs against a patient, low-noise adversary. Infrastructure rotation, bespoke tooling, and selective targeting render simple blocklists and hash-based detection insufficient. Defenders are better served by focusing on anomalous process chains, unexpected updater behavior, unusual DLL loading patterns, and deviations in network communication profiles such as perimeter DNS or packet inspection, even when individual indicators appear benign in isolation.
Implications for Policy and National Security.
At a strategic level, the campaign illustrates that supply-chain compromise has become a primary vector for state-level espionage. As articulated in the work of Jian Tan on software supply-chain trust, capable actors increasingly avoid the cost of penetrating targets individually and instead position themselves inside trusted ecosystems that provide scalable, repeatable access to high-value users. This shift complicates deterrence and response, as such compromises can persist undetected for extended periods and propagate across multiple sectors simultaneously through a single poisoned trust relationship.
The victimology also highlights that smaller and mid-sized states are frequently targeted as intelligence gateways. Access to institutions in these countries can yield disproportionate insight into regional dynamics, allied relationships, and international financial or diplomatic flows. This reality challenges assumptions that only major powers or headline geopolitical rivals face sustained cyber-espionage pressure.
Finally, the incident reinforces that trust relationships within software ecosystems are now contested terrain. Developers, maintainers, hosting providers, and users all participate in chains of trust that adversaries actively seek to exploit. Protecting these ecosystems is both a technical and strategic challenge, requiring coordination between private industry, open-source communities, and governments to harden shared infrastructure without undermining the openness and collaboration that make these ecosystems valuable in the first place.
Taken together, these implications point to a future in which defending against espionage is less about patching individual vulnerabilities and more about protecting trust itself, in software, in infrastructure, and in the relationships that bind modern digital systems together.
Outlook and Forward Assessment
Looking ahead, the patterns observed in the Notepad++ campaign and in Lotus Blossom’s historical operations provide a useful basis for anticipating how this actor is likely to operate in the near to medium term. The group’s evolution has been incremental rather than abrupt, suggesting continuity of mission and tradecraft rather than experimentation for its own sake.
Likely Future Activity
Lotus Blossom is likely to continue targeting developer and administrator tooling, particularly applications and platforms that are widely deployed in technical environments and implicitly trusted by their users. These tools offer consistent access to privileged contexts and aggregate high-value information such as credentials, automation scripts, configuration data, and architectural documentation. As long as developers and administrators remain central to modern infrastructure operations, they will remain attractive espionage targets.
Geographically, future activity is expected to involve measured expansion into adjacent regions with strategic relevance, rather than a dramatic shift toward global saturation. Southeast Asia will almost certainly remain the core theater, but selective operations in regions that function as diplomatic, economic, or intelligence gateways, similar to the activity observed in Oceania and Central America, are likely to continue. Such expansion reflects evolving intelligence requirements rather than a change in operational philosophy.
From a delivery perspective, the group’s demonstrated success with the Notepad++ compromise strongly suggests an ongoing preference for supply-chain and trust-based access. Compromising distribution infrastructure, update mechanisms, or widely trusted platforms reduces reliance on social engineering and increases the likelihood of execution in high-trust environments. This model is efficient, stealthy, and well aligned with Lotus Blossom’s emphasis on low-noise, long-term access.
Warning Indicators
Defenders should be alert to a set of warning indicators that are subtle in isolation but meaningful in combination. Selective update anomalies, where only a small subset of systems receive unexpected update behavior, may indicate upstream manipulation rather than benign error. Similarly, low-volume, API-style beaconing that blends into normal HTTPS traffic can signal command-and-control activity designed to evade traditional network detection.
Another important indicator is the compromise of “boring but trusted” tools: utilities that are widely used, rarely scrutinized, and considered operationally mundane. These applications often sit outside the focus of security monitoring precisely because they are perceived as low risk, making them ideal vehicles for trust exploitation. Finally, defenders should treat long dwell times without overt impact as a potential red flag rather than a sign of benign activity. In Lotus Blossom’s operating model, the absence of disruption is often an intentional feature, not an accident.
Taken together, these indicators point to an adversary that values patience, precision, and invisibility. Future campaigns are likely to look unremarkable at first glance, blending into routine operational noise. Recognizing and responding to them will depend less on spotting dramatic events and more on detecting subtle deviations in how trusted systems behave over time.
Bottom-Line Judgment
The Notepad++ supply-chain campaign is a textbook example of modern Chinese state-aligned cyber-espionage, optimized for discretion, persistence, and strategic intelligence collection.
Lotus Blossom remains one of China’s most quietly effective APTs, less visible than headline actors, but deeply embedded in regional intelligence operations.
Analyst note: This appendix consolidates publicly reported and analytically derived IOCs associated with Lotus Blossom and the Notepad++ supply-chain campaign. The list is intended for threat hunting and contextual correlation, not as a stand-alone blocklist. The actor demonstrates frequent infrastructure rotation, selective delivery, and low-noise operations; therefore, behavioral correlation remains essential.
Command-and-Control Domains (observed in reporting):
cdncheck[.]it[.]com
wiresguard[.]com
Skycloudcenter[.]com
cdncheck.it.com
This domain has been observed as a command-and-control endpoint used by malicious payloads delivered in the Notepad++ supply-chain campaign; Cobalt Strike Beacons were configured to communicate with it, and attackers used paths like /api/update/v1 and /api/FileUpload/submit for C2 traffic.
It is deployed in multiple infection chains as a C2 domain, not a legitimate service; security analysts note its inclusion in IoCs tied to the Notepad++ compromise.
There is no public indication that cdncheck.it.com is associated with any legitimate “cdncheck” project such as the ProjectDiscovery tool named cdncheck (which is an open-source asset scanning tool). The similarity in names appears coincidental.
Summary: Used as attacker-controlled infrastructure; no publicly known legitimate service.
2. wiresguard.com (referred to in C2 contexts)
The domain api.wiresguard.com appears in Notepad++ campaign IoCs collected by security researchers—Beacons and API paths like /update/v1, /api/FileUpload/submit, and /api/getInfo/v1 were observed being used by Cobalt Strike implants and other payloads.
There is no evidence from public OSINT that the domain is linked to the WireGuard VPN project (the legitimate technology is spelled WireGuard). It is widely assessed to be an attacker-controlled domain imitating a plausible service name to blend into developer traffic.
Analysts treat this domain as part of malicious infrastructure rather than a trusted service provider.
Summary: Likely malicious C2 domain mimicking a benign service name; no legitimate affiliation found in open OSINT.
3. skycloudcenter.com
The subdomain api.skycloudcenter.com is identified in multiple IoC lists from incident analysis—it appears in URLs such as /a/chat/s/{GUID} used by the Chrysalis backdoor for encrypted communications.
Reporting notes that this domain is part of the API-style command-and-control infrastructure rather than a known cloud provider or mainstream SaaS platform.
There is no clear legitimate service tied to this domain in publicly indexed OSINT; its naming seems intended to resemble a cloud service but lacks authoritative footprint (no major product, published service, or corporate identity in searchable records).
Summary: Appears exclusively as attacker infrastructure used for backdoor C2; no confirmed legitimate service.
Associated IP Addresses (observed during campaign window):
45.77.31[.]210
59.110.7[.]32:8880
124.222.137[.]114:9999
45.77.31[.]210 (HTTPS)
Role in campaign: Hosted second-stage Cobalt Strike Beacon shellcode and exposed API-style C2 endpoints used by the Beacon (GET/POST patterns). (Securelist)
Vultr’s public ASN is AS20473 (The Constant Company). (IPinfo)
Analytic note: Securelist describes a later shift where the same “grammar” (paths, updater chain) persists while delivery/C2 pivots toward domains (e.g., cdncheck[.]it[.]com)—classic “rotate infra, keep protocol shape” tradecraft. (Securelist)
59.110.7[.]32:8880 (HTTP)
Role in campaign: Hosted a Cobalt Strike Beacon and implemented API-like endpoints for GET/POST comms (directly referenced as part of the Notepad++ supply-chain operation telemetry set). (Securelist)
Also appears in Abuse.ch ecosystem tracking as malicious-host infrastructure (additional corroboration signal, not attribution by itself). (urlhaus.abuse.ch)
124.222.137[.]114:9999 (HTTP)
Role in campaign: Hosted a Cobalt Strike Beacon with the same “API façade” pattern (update/status/info submission), and is listed by both Securelist (campaign IOC list) and Rapid7 (Chrysalis/related tooling context). (Securelist)
The 124.222.137.0/24 netblock is shown as AS45090 (Shenzhen Tencent Computer Systems Company Limited), i.e., Tencent Cloud–linked hosting. (IPinfo)
What these three IPs imply (campaign-level assessment)
All three are consistent with the campaign’s low-volume, high-control delivery model: they’re not mass-distribution nodes; they’re purpose-built staging/C2 with “benign enterprise API” URL shapes (/api/*/v1, /submit, etc.). (Securelist)
The hosting mix (Vultr + Alibaba Cloud + Tencent Cloud) is consistent with infrastructure agility and cost-effective rotation without changing the operational “grammar” (paths, beacon profile style). (Securelist)
Description: A previously undocumented custom backdoor deployed via malicious Notepad++ updates. It’s feature-rich, implements structured C2, and uses advanced loader obfuscation and API hashing techniques. It was delivered after DLL sideloading via renamed Bitdefender binaries and NSIS installer abuse.
Observed in: Multiple security reports on the Notepad++ supply-chain compromise confirm Chrysalis as the primary bespoke implant in the most recent execution chain. Chrysalis replaces or augments Cobalt Strike payloads in some infection conduits. (Rapid7)
Rapid7 cites the renamed Bitdefender utility abused for sideloading log.dll. (Help Net Security)
log.dll
Loader DLL
Decrypts/executes the backdoor
Rapid7 notes that log.dll loads and decrypts Chrysalis. (Help Net Security)
Sample Hash Indicators: (These are candidate hashes observed in threat-hunting discussions associated with Chrysalis–type activity; use with contextual correlation)
Notes: Chrysalis is associated with multi-stage loading and encrypted communications and is explicitly tied to the Notepad++ compromise in Rapid7 technical analysis. (Rapid7)
2. Sagerunex – Historical Lotus Blossom Backdoor Family
Description: A long-standing backdoor family consistently linked with Lotus Blossom operations in Southeast Asia prior to the Notepad++ incident. Sagerunex appears in multiple variants over years and is part of the group’s standard espionage toolkit. (Picus Security)
Behavior: Often installed as a Windows service or registry persistence component; connects to C2 via encrypted or tunneled channels; used for long-term access and data exfiltration. (Picus Security)
Sample Hash Indicators: (Historical Sagerunex variants are well documented in vendor telemetry but specific public hashes for this campaign have not been widely published. The below hashes are examples drawn from public threat intelligence discussions tied to earlier variants.)
Notes: Sagerunex’s variants may not be directly linked to the Notepad++ campaign but represent the broader Lotus Blossom backdoor lineage. (Picus Security)
3. Elise – Early Custom Backdoor (Historic, Pre-Campaign)
Description: An older custom backdoor associated with early Lotus Blossom campaigns (circa 2012–2015), widely referenced in historic vendor analysis. (Picus Security)
Behavior: Provided persistence and remote access, often delivered via spear-phishing lures targeting government and defense institutions.
Public Hashes: There are no widely published hashes specifically tied to Elise in the context of the Notepad++ campaign. Historical Elise variants appear in older vendor IOC sets but are not directly cited in current Notepad++ analyses.
Notes: Elise remains part of the Lotus Blossom malware ecosystem but is not directly observed in the Notepad++ supply-chain campaign in available public reporting. (Picus Security)
Renamed legitimate utilities (e.g., Bitdefender Submission Wizard / BluetoothService.exe) — used for DLL sideloading of malicious components. (Help Net Security)
Note on Hash Interpretation: Several hashes circulating in public hunting forums are included above for Chrysalis and Sagerunex, but these should be used only in conjunction with behavioral and contextual evidence (e.g., execution lineage, process ancestry, file paths, registry persistence) due to the non-global nature of the Notepad++ campaign.
Do not rely solely on blocklists. Many IOCs are short-lived.
Correlate with behavioral indicators:
Unexpected updater behavior
DLL sideloading chains
API-like HTTPS beaconing
Long-term low-noise persistence
Treat developer and admin endpoints as high-priority hunt targets.
Monitor update infrastructure and third-party hosting dependencies.
A.9 Confidence Statement
The IOCs listed above align with public vendor reporting and multi-source analysis of Lotus Blossom activity. While individual indicators may overlap with other actors or benign infrastructure, the combined presence of these IOCs with Lotus Blossom tradecraft patterns provides a strong basis for attribution and threat-hunting.
Appendix B: Sources and Citations
This appendix consolidates all primary reporting, technical analyses, and authoritative reference material used to support the assessments, attribution, and narrative in this report. Sources are grouped by function (technical analysis, media reporting, and reference frameworks) to allow readers to distinguish between direct forensic evidence, journalistic corroboration, and contextual intelligence baselines.
B.1 Primary Technical Analysis and Vendor Research
These sources form the core evidentiary basis for the campaign analysis, infection chains, victimology, and tradecraft assessment.
Security Affairs Coverage of DLL sideloading, infrastructure compromise, and China-linked APT analysis relevant to the Notepad++ campaign. https://securityaffairs.com/
No single source alone asserts attribution with certainty; confidence derives from convergent analysis across multiple independent sources.
B.5 Citation Handling Notes
No specific victim organizations are named in publicly available technical reporting; all victim references are sector- and country-level, consistent with source disclosures.
Indicators of Compromise (Appendix A) are drawn from public reporting and are time-bound and perishable.
This appendix reflects sources available as of February 2026; subsequent disclosures may refine or expand attribution and victimology.
THE KNOWNSEC LEAK: Yet Another Leak of China’s Contractor-Driven Cyber-Espionage Ecosystem
Leaked Knownsec documents reveal China’s cyberespionage ecosystem. Analyze TargetDB, GhostX, and 404 Lab’s role in global reconnaissance and critical infrastructure targeting.
EXECUTIVE SUMMARY
In November of 2025, an allegedly massive leak of data from Chinese company “KnownSec” was posted to a github account. The initial leak was covered by Wired Magazine, and a few other outlets. The leak has since been pulled off of Github and downloaded by very few, and of those few who gained access, only one uploaded 65 documents as a primer to the leak elsewhere for others to see. DTI was able to get the 65 document images and this report is derived from this slice of a much larger leak that is out there but not available.
On December 31 2025, platform and threat intelligence company Resecurity published an excellent analysis of the full leak. As we’ve been working through the 60+ available screenshots from the leak since early November, Resecurity’s post provides additional context in a few areas, especially targeting, that compliment the depth to which we analyzed Knownsec’s technical capabilities.
Ostensibly, KnownSec appeared to be just another security company, but this is only a half truth. In reality, like other reports we have written on Chinese firms, it has a shadow organization that works for the PLA, MSS, and the organs of the Chinese security state. This leak exposes a state-aligned cyber contractor that operates far beyond the role of a typical cybersecurity vendor. Its internal documents, product manuals, and data repositories show a company engineered to support Chinese national security, intelligence, and military objectives. Tools like ZoomEye and the Critical Infrastructure Target Library give China a global reconnaissance system that catalogs millions of foreign IPs, domains, and organizations mapped by sector, geography, and strategic value. Massive datasets containing real names, ID numbers, mobile phones, emails, and credentials allow Knownsec and its government clients to correlate infrastructure with people, enabling rapid deanonymization, targeting, and social engineering.
On top of this data foundation, Knownsec’s offensive products; GhostX, Un-Mail, and Passive Radar purport to provide a full intrusion and surveillance pipeline. GhostX delivers browser exploitation, routing manipulation, credential theft, and endpoint monitoring. Un-Mail enables covert takeover and continuous exfiltration of email accounts across major global providers. Passive Radar ingests PCAP data via local uploads, FTP, or SSH to reconstruct internal network topologies, user communication patterns, and service inventories. These tools work together to support long-term access, DNS hijack, admin takeover, and infrastructure control across foreign government, telecom, financial, and energy networks.
Organizational charts, customer lists, and internal briefings reveal Knownsec’s primary clients as Public Security Bureaus, defense research institutes, and likely the MSS, positioning it within China’s industrialized cyber-operations ecosystem. Its products are marketed directly to law enforcement and military customers, with teams explicitly labeled for “military industry,” “intelligence,” and “public-security support.” The leaked data shows a vertically integrated espionage stack for reconnaissance, exploitation, collection, and persistence, designed for both domestic surveillance and foreign intelligence operations, making Knownsec a central enabler of China’s modern cyber strategy.
Background
Knownsec (知道创宇), headquartered in Beijing, presents itself to the outside world as a familiar figure in the Chinese cybersecurity landscape, a company selling vulnerability assessments, penetration testing, and defensive solutions. It has long been framed as one of the country’s “white-hat” pillars, a firm dedicated to patching security gaps and strengthening networks. But the leaked internal documents, product manuals, work breakdown structure (WBS) project sheets, personnel directories, and vast infrastructure datasets tell a much more complex and far more consequential story. Beneath its public branding, Knownsec operates as an offensive intelligence contractor whose day-to-day work aligns directly with the operational needs of China’s security and military apparatus.
In practice, Knownsec functions within a tight constellation of state-aligned cyber contractors, a network that includes outfits like 404 Lab (internal to Knownsec) , Qi-An-Xin, Venustech, and i-SOON (安洵). These entities form a parallel ecosystem to China’s formal intelligence services, separate on paper, but woven into the broader machinery of state surveillance and cyberespionage. Together, they develop and maintain the tools, datasets, and capabilities required for large-scale identity tracking, offensive reconnaissance, infrastructure enumeration, and targeted intrusion. What sets Knownsec apart within this constellation is the degree of integration seen across its product lines: it does not merely produce one tool or one dataset, but rather an entire operational pipeline spanning discovery, exploitation, reconnaissance, persistence, and human-layer correlation.
The leaked materials reveal that Knownsec maintains some of the most extensive foreign targeting datasets yet seen in a contractor leak, covering Taiwan, Japan, South Korea, India, and multiple Western nations. Its clients include Public Security Bureaus at the provincial and national levels, defense research institutes, and intelligence-adjacent technical units. The company’s organizational charts and internal communications make clear that these relationships are not incidental; they are foundational to Knownsec’s business model and technical direction. In this light, Knownsec emerges not as a private security firm in the Western sense, but as a core node in China’s contractor-driven cyber state, a strategic architecture in which commercial entities serve as the research, development, and operational arms of state cyber power.
ACTOR TAXONOMY
Organizational Structure
Knownsec’s internal architecture per this dump, resembles less a commercial technology company and far more a defense integrator calibrated to state needs. The organizational hierarchy is sharply defined, layered, and optimized for the production of offensive cyber capabilities. Each division has a narrowly tailored mandate that fits into a larger operational machine, an arrangement that mirrors the compartmentalization and task specialization typical of state-sponsored research institutes and weapons contractors.
At the technical core is the 404 Security Lab (404 实验室), a unit responsible for offensive research, exploitation development, and deanonymization, including stewardship of the GhostX tooling family. This is the engine room where browser exploits, network manipulation modules, and deanonymization workflows are built. Surrounding it is the Product Technology R&D Center, which transforms raw offensive ideas into stable, deployable products (most notably Passive Radar), protocol-analysis frameworks, and related reconnaissance systems. Feeding these tools is the Data Business Division, which curates massive datasets, foreign breach archives, and credential repositories, effectively forming the human intelligence layer of Knownsec’s cyber operations. Where state-aligned priorities shift toward military readiness or battlefield cyber support, the Military Products Division (军工) adapts and reconfigures Knownsec’s core technologies – ZoomEye, Radar, GhostX – into militarized variants suitable for defense research institutes and specialized units. Meanwhile, the ZoomEye Team maintains the company’s most publicly recognizable asset: a continuous internet-wide scanning and exposure fingerprinting platform. Once all these tools are built, the Beijing Testing Group ensures they meet stability and operational-readiness requirements before deployment to customers.
This hierarchy fractures into distinct functional strata. At the strategic layer, executive leadership and cost-center directors coordinate funding, long-term planning, and alignment with state-customer requirements. The operational layer, project managers, planners, and supervisors – turns those directives into executable work, assigning tasks across teams and ensuring compliance with delivery timelines. The technical layer comprises exploit developers, reverse engineers, protocol analysts, “radar specialists” (aka those working with the platform dealing with internet scale sensing/detection), and data scientists, the hands-on specialists who build Knownsec’s offensive capabilities. Beneath them, the support layer handles content review, security inspection, documentation, and QA critical roles that ensure continuity and polish across the toolchain.
Viewed holistically, the internal structure mirrors the logic of a Chinese cyber-weapons manufacturer: program management offices overseeing multi-year development tracks; governance systems controlling scope, deliverables, and interdepartmental dependencies; and specialized teams that collaborate, integrate, and refine capabilities in parallel. The result is not a loose assemblage of researchers, but a multi-team, multi-layered production line, where offensive tools move from concept to deployment with the discipline and scale of an industrial operation aligned to national strategic priorities.
Org Structure per leak 2025
Role Characterization
Knownsec’s internal personnel structure forms a tiered hierarchy that resembles the command-and-control model of a state-linked defense contractor rather than a commercial cybersecurity vendor. At the top sits the strategic layer, composed of executive leadership, business-unit heads, and cost-center directors who set long-term priorities, allocate resources, and ensure alignment with the missions of Public Security Bureaus, military research institutes, and other government stakeholders. Their role is not merely administrative; they define the operational direction of Knownsec’s offensive tooling, selecting which capabilities to develop, which foreign networks to map, and which datasets to prioritize for correlation.
Beneath them churns the operational layer, populated by project managers, planners, and supervisors responsible for translating strategic objectives into actionable engineering programs. These individuals oversee WBS tasking, cross-team coordination, and delivery timelines. They determine how GhostX (“GhostX Framework” offensive cyber platform) modules integrate with Un-Mail (email interception tool), how Passive Radar ingests or parses PCAP data, and how TargetDB updates synchronize with ZoomEye (search engine) output. In effect, they are the connective tissue that binds Knownsec’s sprawling toolchain into a coherent, predictable development pipeline.
The technical layer of exploit developers, radar engineers, data analysts, infrastructure specialists is the skilled workforce that turns those plans into operational capabilities. These teams build the browser exploitation chains, protocol-analysis engines, deanonymization classifiers, and dataset-correlation tools that make Knownsec’s products function as integrated intrusion systems. Supporting them is a broad support layer of content reviewers, security inspectors, and test engineers who ensure data quality, operational safety, and readiness for customer deployment. This division of labor reinforces Knownsec’s resemblance to a Chinese cyber defense integrator, featuring programmatic control structures, specialized technical teams, and multi-layer orchestration designed to reliably produce offensive cyber capabilities at scale.
FULL CAPABILITY ANALYSIS
Global Reconnaissance Layer
Knownsec’s offensive operations begin with a global reconnaissance layer, a foundation built on visibility rather than exploitation. At the heart of this layer is ZoomEye, the company’s internet-wide scanning and fingerprinting platform. Externally marketed as a security research tool, ZoomEye in practice functions as a persistent intelligence sensor grid, one capable of mapping the exposed surfaces of entire nations. Unlike Shodan or FOFA, which rely on hybrid community indexing and slower crawl cycles, ZoomEye conducts full IPv4-space scanning, generating a continuously refreshed portrait of devices, services, and vulnerabilities across the global internet.
ZoomEye’s detection capabilities are unusually granular. Its internal documentation highlights a library of 40,000+ component fingerprints, allowing it to identify not just common servers but also specialized firewalls, industrial controllers, VPN concentrators, and software versions critical for exploitation targeting. The platform recrawls its indexed universe every 7–10 days, making its data nearly real-time, a crucial requirement for Chinese security organs that depend on freshness for both censorship enforcement and foreign operations. Every newly exposed port, misconfigured appliance, or unpatched system becomes visible to Knownsec’s analysts before many national CERTs are even aware of the shift.
The true power of ZoomEye emerges in its integration with Knownsec’s TargetDB (关基目标库: Key Target Library), a classified-style infrastructure database that cross-references ZoomEye results with sector, geographic, and organizational metadata. Raw IPs and banners from ZoomEye become tagged entries in a structured intelligence map identifying which systems belong to ministries, power companies, telecom operators, banks, or military units. In this way, ZoomEye doesn’t merely scan the internet; it prioritizes it, funneling raw exposure intelligence directly into China’s national-level targeting workflows.
ZoomEye
A global cyberspace search engine equivalent to Shodan/FOFA but with:
Full IPv4-space scanning
40,000+ component fingerprints
Rapid recrawl cycles (7–10 days)
Cross-integration with TargetDB
Zoom Eye aka “Eye of Zhong Kui” (Zhong Kui is a mythological demon-hunter; the name implies threat detection and purification.)
TargetDB (关基目标库)
Knownsec’s TargetDB (关基目标库) is the analytical backbone of its reconnaissance capability, an immense, curated intelligence repository that transforms raw internet data into a structured map of global critical infrastructure. Far more than a simple asset index, TargetDB resembles a state-run targeting platform: a system designed to catalog, classify, and prioritize foreign networks according to strategic value. The scale alone is staggering. Internal documentation lists 24,241 organizations, 378,942,040 IP addresses, and 3,482,468 domains, all tagged with metadata that places them within specific industries, national sectors, and operational categories. These entries span 26 geographic regions, covering not only China’s immediate neighbors but also major economies and political rivals across Asia, Europe, and the West.
What gives TargetDB its strategic potency is the precision of its annotations. Each organization and network block is mapped to sector designations such as military, military-industrial, government ministries, telecom operators, energy providers, financial institutions, transportation networks, media outlets, and educational institutions. This transforms an anonymous IP range into a clearly identified target: a ministry of foreign affairs server in Tokyo, a regional power-grid node in Kaohsiung, a financial-trading gateway in Mumbai, or a satellite uplink belonging to a Korean telecom. The database does not simply list assets; it assigns them meaning, aligning infrastructure with strategic objectives and intelligence requirements.
In practice, TargetDB functions as a foreign-target prioritization engine, allowing Chinese state clients to focus their operations on the most consequential systems. When paired with ZoomEye’s continuous scanning, TargetDB becomes a living intelligence reference that highlights newly exposed systems belonging to sensitive entities. This fusion of raw exposure data with organizational and geopolitical context gives Knownsec and its customers a ready-made blueprint for cyber campaigns identifying who matters, where they are located, and precisely which services are vulnerable at any given moment.
This database is a foreign-target prioritization engine.
The Critical Infrastructure Target Library contains:
24,241 organizations
378,942,040 classified IPs
3,482,468 domains
Sector mappings across 26 geographic regions
It annotates:
Military units
Government ministries
Telecom operators
Energy companies
Financial institutions
Media and education networks
Data Lake (o_data_*)
Knownsec’s o_data_ data lake* represents one of the most revealing and troubling components of the entire leak. Beneath the polished surface of its security products lies a sprawling, carefully indexed archive of global breach data, sourced from criminal markets, prior compromises, open leaks, and internal acquisitions. These datasets include LinkedIn collections from Brazil and South Africa, Taiwan Yahoo account dumps, Indian Facebook user sets, and extensive Chinese national datasets ranging from railway passenger manifests to banking records and ID-card tables. Layered atop this are telecom subscriber databases, often containing phone numbers, IMSI/IMEI identifiers, addresses, and account metadata. Each dataset is catalogued with schema details including username, password, id_card, mobile, email, real_name, address, investment_style, and more, making the data lake a high-resolution, global directory of human digital traces.
Within Knownsec’s operational ecosystem, this data lake is not a passive archive; it functions as an identity-correlation engine. When a TargetDB entry identifies an exposed service or a ZoomEye scan reveals a misconfigured endpoint, analysts can pivot into the o_data_* records to uncover the real-world individuals associated with that IP, email, or domain. A VPN endpoint in Osaka becomes a person with a name, mobile number, and password reuse history. A Taiwanese banking server becomes an enumerated list of employees with matching emails, credential pairs, and personal details. These correlations enable credential replay attacks, account takeover attempts, and highly tailored social-engineering operations long before any exploit payload is deployed.
But the most powerful function of the data lake is its role in deanonymization. Modern cyber operations often hinge on identifying the human behind the machine, and the o_data_* archives allow Knownsec and by extension its state customers to strip away anonymity across borders. By linking breached credentials, phone numbers, and identity documents to technical infrastructure, the data lake fuels a range of offensive workflows: spearphishing campaigns, targeted malware delivery, behavioral profiling, and covert influence operations. In effect, the o_data_* collection serves as the human-intelligence layer of Knownsec’s cyber apparatus, turning scattered breach records into a structured intelligence resource that drives foreign espionage, domestic tracking, and precision targeting at scale.
A massive archive of global breach data:
LinkedIn Brazil, South Africa
Taiwan Yahoo email/password datasets
Indian Facebook sets
Chinese national ID/railway/banking data
Telecom subscriber DBs
Purpose:
Correlate human identities
Enable credential replay
Enable deanonymization
Power targeted phishing and social engineering
Access Layer
Knownsec’s Access Layer is embodied most clearly in its flagship offensive toolkit, GhostX, a system designed not merely to breach endpoints but to reduce, reconstruct, and ultimately control digital identity. GhostX operates at the intersection of browser exploitation, network manipulation, and host persistence. It begins with browser fingerprinting, gathering granular details, plugins, fonts, extensions, power telemetry, and rendering quirks to create a durable identity signature that follows a user across VPNs, proxies, and devices. Once a target is profiled, GhostX can be set to escalate into active compromise: extracting browser-stored passwords, siphoning cookies and session tokens, and deploying keylogging modules that capture input in real time. These capabilities allow operators to pivot immediately into email accounts, internal dashboards, or social platforms without requiring traditional exploit chains.
But GhostX’s reach extends well beyond the endpoint. The suite includes tools for internal service identification, mapping what the compromised machine can see inside a network database, ports, admin interfaces, intranet portals, and shared resources. From there, GhostX can manipulate the network environment itself through routing attacks and DNS hijacking, redirecting traffic or impersonating internal systems. The ability to create new admin accounts on routers or internal services turns a momentary foothold into a durable position within the victim’s infrastructure, enabling stealthy lateral movement or long-term monitoring. Operators can also invoke remote command execution, screenshot capture, and webpage cloning, giving GhostX a Swiss-army-knife versatility normally found in high-end, nation-state-grade intrusion platforms.
Central to GhostX’s design is its suite of anti-forensic mechanisms and techniques such as code mixing, behavior shaping, and signatureless execution explicitly described in internal product briefs. These features aim to frustrate defenders, slow incident response, and complicate attribution. When combined, GhostX becomes a multi-vector exploitation and persistence framework, engineered to collapse anonymity, extract access, and maintain covert presence across both user endpoints and network infrastructure. It is a foundational component of Knownsec’s offensive cycle, bridging the gap between reconnaissance and deeper operational penetration.
GhostX Virtual Identity Reduction & Exploitation Suite
GhostX a multi-vector exploitation and persistence framework.
Capabilities include:
Browser fingerprinting
Password extraction
Cookie and credential theft
Keylogging
Website cloning
Screenshot monitoring
Internal service identification
Routing manipulation
DNS hijacking
Admin user creation
Command execution
Anti-forensics (code mixing, signature evasion)
Un-Mail Webmail Takeover & Persistent Collection
Knownsec’s Un-Mail platform is the company’s dedicated engine for webmail takeover and long-term communications exploitation, effectively turning inboxes into intelligence feeds. Unlike traditional phishing tools or standalone password stealers, Un-Mail is built to compromise webmail ecosystems at the application layer, beginning with XSS-based exploitation of major mail portals. These injection points allow attackers to intercept login sessions, capture live session tokens, or inject malicious scripts directly into a victim’s browser workflow. Once access is established, Un-Mail seamlessly transitions into session hijacking and cookie replay, bypassing MFA or password-change events and ensuring operators maintain continuous entry even as the victim continues to use their account.
The platform’s most powerful capability is its ability to perform IMAP/POP mailbox replication, silently downloading the entire mailbox including archived, deleted, or years-old communications into a local datastore under operator control. This “first sync” is typically followed by ongoing incremental collection, with Un-Mail monitoring for new messages and exfiltrating them in real time. Operators can configure keyword triggers for sensitive terms, automate alerts when certain contacts communicate, and selectively forward or clone messages without user visibility. Internal product slides emphasize full inbox exfiltration and customizable monitoring dashboards, indicating a mature COMINT-oriented architecture rather than a simple webmail attack script.
Un-Mail’s reach is expanded by its cross-provider compatibility, with explicit support for Gmail, Outlook/Hotmail, Yahoo, AOL, and major Chinese providers such as 163, 126, TOM, and Yeah.net. This broad compatibility allows Knownsec and its state clients to conduct communications intelligence collection across national borders, harvesting diplomatic correspondence, corporate strategy emails, and internal government mails for targeting purposes. The result is a tool purpose-built for persistent surveillance, supporting intelligence requirements ranging from domestic monitoring to foreign espionage, further evidence that Knownsec’s operational mission extends deep into offensive state-cyber tradecraft.
This enables communications intelligence collection (COMINT) across national borders.
Internal Network Discovery
Knownsec’s Passive Radar (无源雷达) is designed for the phase immediately following initial access, when the operational priority shifts from intrusion to comprehension. While tools such as GhostX focus on endpoints and Un-Mail captures communications, Passive Radar illuminates the internal network environment those systems inhabit. Its purpose is not exploitation in isolation, but the reconstruction of the operational terrain inside a compromised organization.
Unlike active scanners that generate detectable traffic, Passive Radar relies exclusively on the ingestion and analysis of packet capture (PCAP) data. This passive approach allows operators to observe a network as it actually behaves, without altering traffic patterns or triggering defensive controls. The system accepts PCAPs through three primary ingestion paths: direct offline uploads, remote retrieval via FTP, and secure acquisition over SSH. These mechanisms allow traffic to be sourced from compromised servers, misconfigured storage systems, network taps, or siphoned repositories without requiring live interaction with the target environment.
Once ingested, Passive Radar automatically extracts and classifies the network’s technical structure. It identifies IP addressing schemes, port usage, protocol signatures, service banners, device types, and traffic flows, assembling these elements into a coherent model of internal communications. By correlating flows over time, the platform reveals which systems communicate persistently, how authentication and directory services are organized, where data is aggregated or forwarded, and which services function as internal chokepoints.
This process exposes high-value internal assets that are often invisible from the perimeter: domain controllers, mail gateways, internal content-management systems, financial platforms, and management interfaces. Behavioral flow analysis highlights trust relationships, reused credentials, and open administrative paths that can be leveraged for lateral movement. Device classification further identifies unmanaged servers, weakly configured firewalls, and embedded or IoT systems that present escalation opportunities.
Through this transformation of raw packet data into structured internal intelligence, Passive Radar provides the situational awareness required to move beyond an initial foothold and toward sustained control of a target network.
Passive Radar (无源雷达)
The strategic significance of Passive Radar lies not merely in what it observes, but in how it collapses uncertainty for offensive operators. By deriving intelligence from real traffic rather than inferred exposure, the platform reveals how a network truly functions under normal conditions. This traffic-derived perspective exposes dependencies, trust boundaries, and operational habits that conventional vulnerability scanning cannot reliably detect.
Viewed through an offensive lens, Passive Radar functions as an internal reconnaissance and targeting system. Its outputs identify viable lateral-movement routes, uncover unencrypted administrative channels, and surface shared authentication paths that enable quiet expansion through a network. Instead of probing for weaknesses, it allows operators to exploit the structure that already exists, reducing noise while increasing precision.
This capability is particularly valuable in state-aligned operations, where persistence, attribution control, and long-term access outweigh speed. Passive Radar turns captured network traffic into operational intelligence that supports methodical expansion, selective exploitation, and planned data extraction. In effect, it converts the interior of a victim network from an opaque risk space into a charted environment suitable for controlled maneuver.
For Knownsec’s government and military customers, Passive Radar serves the same role in cyberspace that reconnaissance and terrain analysis serve in conventional operations. It enables planners to study internal infrastructure, anticipate defensive responses, and design lateral movement and persistence strategies with confidence. In this sense, Passive Radar is not simply a security product, but a foundational intelligence capability that bridges access and dominance within the digital battlespace.
A PCAP-based internal situational awareness tool:
3 ingestion modes:
Offline PCAP
FTP
SSH
Extracts:
IPs
Ports
Protocols
Behavioral flows
Services
Device types
Purpose:
Map internal networks
Identify critical hosts
Reveal lateral-movement opportunities
Build operational intelligence for deeper compromise
Persistence & Exfiltration Layer
Knownsec’s Persistence & Exfiltration Layer represents the phase of an operation where intrusion shifts from momentary access to steady, renewable intelligence collection. Once an endpoint or infrastructure node has been compromised through GhostX, Un-Mail, or Passive Radar–assisted lateral movement, Knownsec’s tooling activates a suite of mechanisms designed to keep the operator embedded indefinitely. At the user level, this includes keylogging and clipboard capture, which harvest credentials, sensitive text, and operational behavior with granular precision. These seemingly simple functions become powerful when combined with GhostX’s browser and routing manipulation: every password typed, every copied token, every pasted URL becomes part of the attacker’s internal map of the victim’s digital life.
Beyond user surveillance, Knownsec’s tools enforce persistence by manipulating the environment itself. Forced browsing modules can redirect users to attacker-controlled sites to refresh payloads or harvest updated cookies, while webshell interaction provides a remote backdoor for issuing commands and staging follow-up operations. The ability to perform DNS hijacking ensures long-term redirection and covert traffic interception, allowing Knownsec’s operators or their state clients to control access to internal or external resources without needing continuous endpoint presence. When this is combined with admin account creation on routers or internal network appliances, attackers gain durable infrastructure-level footholds that survive password changes, system updates, and even some forms of incident response.
Communication exfiltration remains a central pillar of Knownsec’s persistence strategy. Through Un-Mail, compromised inboxes can be synchronized via ongoing IMAP replication, creating a live copy of the user’s communications outside the victim network. New messages are silently collected, sensitive terms trigger alerts, and historical archives can be mined for strategic value. When all these elements operate together keystroke capture, environmental manipulation, infrastructure control, and communications replication they form a persistent intelligence foothold. This foothold is not just durable; it is regenerative, enabling long-term espionage, strategic monitoring, and operational leverage across months or even years, well after the initial compromise has been forgotten by the victim.
Includes:
Keylogging
Clipboard capture
Forced browsing
Webshell interaction
DNS hijack for long-term redirection
Admin account creation on routers
IMAP-based ongoing mailbox replication
This creates persistent intelligence footholds.
OPSEC & Anti-Forensics
Knownsec’s toolchain incorporates a mature OPSEC and anti-forensics layer, reflecting the needs of an organization that expects its operations to face scrutiny from both corporate defenders and national incident-response teams. Rather than treating stealth as an afterthought, Knownsec designs its offensive tools to actively manipulate the investigative environment, reshaping the forensic trail and degrading the defender’s ability to reconstruct what happened. This begins with proxy chain deployment, allowing operators to route traffic through multilayered, frequently shifting intermediaries that obscure the true origin of commands, payloads, or callback traffic. By automating these routing changes, Knownsec ensures that attribution efforts are diluted across ranges of unrelated IP space.
Beyond network obfuscation, Knownsec incorporates behavior-shaping and code-mixing techniques, which alter how malicious scripts behave on compromised systems. Instead of producing predictable logs or recognizable execution patterns, operations are blended into normal system activity or fragmented across modules that only reveal their true function when combined under specific conditions. These methods frustrate heuristic detection and force analysts to piece together sequences of behavior that appear benign in isolation.
Perhaps most challenging for defenders is the emphasis on signatureless execution and anti-tracing modules, which remove or modify indicators that typically reveal compromise. Malware components are often polymorphic or dynamically assembled, leaving no stable signatures for endpoint security tools to match. Meanwhile, anti-tracing features interfere with monitoring hooks, logging frameworks, and analyst tools, making post-incident reconstruction incomplete or misleading. Together, these OPSEC and anti-forensic capabilities signal that Knownsec’s offensive products are built not only to infiltrate networks but to survive inside them, resisting detection long enough to achieve intelligence objectives and complicating attribution even after an intrusion is discovered.
Capabilities:
Proxy chain deployment
Behavior obfuscation
Code mixing
No-signature execution
Anti-tracing modules
Designed to degrade defender and investigator visibility.
TRADECRAFT & TTPs
Knownsec’s operational workflow reflects a fully realized, contractor-engineered APT intrusion lifecycle, blending state objectives with commercial development discipline. What emerges from the leak is not a set of disconnected tools, but a coherent tactic-to-technology pipeline, where each stage of intrusion is supported by a purpose-built product or dataset. The tradecraft reads like a synthesis of China’s most capable threat actors APT31, APT41, Mustang Panda yet polished through a corporate engineering lens that emphasizes stability, modularity, and reuse across diverse missions.
The intrusion sequence begins with reconnaissance, powered by ZoomEye’s internet-wide scanning and the TargetDB attribution system, which labels millions of global IPs by organization, sector, and geopolitical relevance. Once a target is identified, Knownsec pivots into its human-layer intelligence using the o_data_* collections: massive breach datasets that reveal who operates which systems, how they authenticate, and which credentials or identities overlap across services. These datasets feed directly into resource development, where credential harvesting, identity correlation, and exploit development (largely through 404 Lab) prepare the ground for an intrusion tailored to the target’s technical and human profile.
Initial access is typically obtained through GhostX’s browser exploitation modules, social-engineering campaigns crafted through breach data, or Un-Mail’s XSS-based webmail compromise. Once inside, Knownsec’s operators transition smoothly into execution, deploying JavaScript payloads, browser implants, or DNS manipulation scripts to deepen footholds. The tooling then shifts into persistence mechanisms creating admin accounts on routers, setting up IMAP mailbox replication, and establishing proxy chains that ensure continued access even as environments shift.
From there, intrusions expand through privilege escalation and discovery, guided by routing manipulation and Passive Radar’s PCAP-derived intelligence to illuminate the structure of internal networks. Defense evasion occurs continuously through code mixing, signatureless execution, and behavioral obfuscation. Credential access is achieved via browser password extraction and keylogging, enabling lateral movement into systems that would otherwise require separate exploitation. As operators explore the victim environment, they perform service fingerprinting, internal command execution, and webshell interaction to propagate their influence.
Finally, intrusion objectives manifest through collection and exfiltration, with Knownsec tools capturing screenshots, siphoning mailboxes, and sending stolen data out via IMAP or DNS-hijacked channels. Command and control remains flexible and resilient, relying on web-based callbacks and multi-hop proxy chains that obscure operational origins. Taken together, this lifecycle reveals a level of integration rarely seen outside state intelligence services: a full-spectrum intrusion pipeline where reconnaissance, exploitation, persistence, and exfiltration are engineered as interoperable modules within a single contractor-driven ecosystem.
The Knownsec pipeline mirrors a modern APT intrusion lifecycle:
This aligns with APT31, APT41, Mustang Panda, but with a commercial-engineering polish.
SUPPLY-CHAIN INTELLIGENCE
Knownsec’s operational footprint is supported by a sophisticated and multilayered supply chain, one that mirrors the procurement logic of government-backed defense contractors rather than private-sector cybersecurity firms. Internal documents show that Knownsec does not restrict its infrastructure to domestic providers; instead, it strategically procures European hosting infrastructure, including services from companies such as EDIS and Impreza. These foreign VPS and storage nodes provide staging grounds for scanning operations, payload delivery, redirection infrastructure, and exfiltration endpoints. Their geographic dispersion reduces attribution risk and increases operational reach, aligning with the needs of state customers who require global coverage and plausible deniability.
Financial organization within Knownsec also reflects a formalized, state-integrated structure. Leaked WBS project sheets reveal clearly defined cost centers, funding lines, and project sponsors, which are exactly the type of internal accounting frameworks used in China’s defense-industrial enterprises. Dedicated budgets exist for offensive R&D, data acquisition, infrastructure hosting, and specialized tools like GhostX and Passive Radar as seen in the excel images from the dump. This financial governance ensures continuity across long-term development cycles and indicates that Knownsec’s offensive tooling is not an ad-hoc initiative but an institutionalized capability sustained by predictable funding streams.
A crucial component of the supply chain is the data acquisition ecosystem. Knownsec’s massive o_data_* archives encompassing foreign breach dumps, credential collections, telecom subscriber databases, and national-ID repositories come from a mix of purchases, criminal-market harvesting, and internal scraping operations. These datasets form the human-intelligence substrate upon which exploitation and social-engineering operations depend. Similarly, Knownsec’s PCAP supply chain relies on compromised machines, operator-controlled servers, or cooperation from state entities to provide raw network captures that feed Passive Radar’s analytical engine. The success of ZoomEye likewise depends on a distributed scanning infrastructure, sustained by supporting nodes, bandwidth, and hardware that Knownsec maintains across multiple jurisdictions.
Taken together, these elements show that Knownsec’s supply chain is not incidental; it is deliberately constructed to serve national offensive cyber objectives. Its infrastructure procurement resembles the logistical patterns of government-funded cyber units; its data ingestion relies on pipelines typical of intelligence services; and its budgeting and work breakdown structures parallel those of state research contractors. Whether through hosting arrangements abroad, civilian data lakes turned into intelligence assets, or long-term PCAP sourcing, Knownsec’s dependencies align closely with Chinese government procurement cycles and strategic priorities, underscoring its role as an embedded component of the PRC’s broader cyber operations ecosystem.
Evidence from internal documents shows:
They maintain internal cost centers for offensive tooling.
WBS projects show formal funding lines with project sponsors.
External datasets are purchased or harvested from criminal markets.
PCAP supply chain (victim or operator-controlled hosts)
ZoomEye sensor infrastructure
Data lake ingestion pipelines
Chinese-government procurement cycles
GLOBAL TARGETING
Knownsec’s leaked infrastructure data reveals a clear pattern of structured, high-value targeting focused on the critical infrastructure of strategically significant nations. Even in the limited-resolution tables available, the indicators of compromise (IOCs) point to a deliberate and methodical mapping of Taiwan’s financial, telecommunications, and energy sectors. The sample extracted entries illustrate this well: exposed Fortinet firewalls at Nan Shan Life Insurance and Hua Nan Commercial Bank, publicly reachable Sophos XG appliances at Chunghwa Telecom, and a vulnerable Check Point service tied to Taipower, Taiwan’s national energy provider. These enumerated services tagged by IP, port, device type, and application banner function as prevalidated targets, ready for exploitation by GhostX, network-fingerprinting modules, or customized military tooling. Although these samples represent only a fraction of the full dataset, they demonstrate the precision with which Knownsec cataloged foreign infrastructure exposure.
When these IOCs are contextualized within the broader leak, a picture of systematic targeting emerges. Taiwan is disproportionately represented across the leak, with evidence of interest not only in major telecom operators and financial institutions but also in power grid, nuclear-energy, and ISP-level assets. This coverage aligns closely with PRC strategic priorities and suggests an intent to build comprehensive operational knowledge of Taiwan’s connectivity fabric, resilience posture, and critical dependencies. Similar patterns appear in Knownsec’s datasets for Japan, where telecom providers, energy-sector nodes, and major industrial corporations are cataloged; and in South Korea, where financial institutions, telecom networks, and industrial infrastructure feature prominently.
Beyond East Asia, the targeting footprint widens. Knownsec’s o_data_* records include Indian telecom subscriber databases, Facebook identity datasets, and infrastructure ranges associated with Indian ministries. This mirrors Beijing’s intelligence interest in India’s digital ecosystem and supports operations requiring identity correlation or demographic profiling. Meanwhile, portions of the dataset referencing European or Western entities appear more fragmented, but they nonetheless indicate indirect exposure: customer lists and sector-tagged entries suggest an intelligence appetite for global critical infrastructure and multinational corporations, even if not yet operationalized at the same scale as East Asia.
Taken together, these patterns show that Knownsec’s targeting is strategic, multi-regional, and overtly political, aligning with the geopolitical interests of the PRC. The infrastructure data is not random reconnaissance; it is a curated map of cyber terrain that would enable espionage, influence, and potentially pre-positioning for disruptive operations. Each IOC and sector-tagged asset represents not just a point of exposure but a node in an intelligence-gathering architecture designed to give Chinese state clients deep visibility into the operational backbone of foreign nations.
This represents strategic, multi-region, politically aligned targeting.
Internal Data Exposure: Email Addresses, Employee Identities, and Functional Roles
The Knownsec leak provides an unusually clear view into the human architecture of a Chinese cyber-contractor supporting national security, public-security bureaus, telecom regulators, and critical-infrastructure stakeholders. Unlike previous contractor leaks such as i-SOON (Anxun) which focused primarily on tools and client lists, the KnownSec corpus reveals a segment of internal personnel structures, spanning project owners, planners, cost-center sponsors, WBS task leads, and supporting engineers.
This internal data forms a blueprint of how Knownsec organizes and distributes responsibility across its offensive research, cyberspace-mapping, radar-engineering, and data-fusion programs. It offers a rare look at the people behind these capabilities, and exposes the specific functional chains by which projects move from concept to FOC (full operational capability).
Employee Identity Data
The leak contains a complete cross-section of Knownsec personnel across multiple divisions:
Product Technology R&D Center (platform R&D, cyberspace mapping)
Product Technology Department (hardware radar, UI/UX, testing)
Product Technology Center 141 (high-level technical governance)
Public-Security Research Institute (entity fusion, PSB analytic systems)
A total of 22 named employees appear in the materials, each tied to specific organizational units and assigned responsibilities inside multi-stage research or engineering efforts. These employees represent a spectrum of roles from senior leadership with strategic authority to WBS task owners responsible for tactical implementation details.
This personnel visibility is valuable for understanding:
Which individuals enable offensive, defensive, or fusion-support tasks
How work is distributed across government-sponsored projects
Where relevant, email addresses and internal accounts allow correlation with procurement records, code repositories, or external infrastructure should those indicators surface elsewhere.
Internal Email Address Patterns
Every email address in the dump uses one of two company formats:
@knownsec.com → Headquarters operational accounts
@xm.knownsec.com → Xiamen-based R&D and engineering offices
No personal external addresses appear for employees; only official Knownsec accounts are used inside project governance systems.
The following email addresses were recovered from the leak so far:
zouxy2@knownsec.com
suig@knownsec.com
mas@knownsec.com
wangcp2@knownsec.com
chenc6@knownsec.com
hey5@knownsec.com
raosh@knownsec.com
anyh@knownsec.com
liuj13@knownsec.com
xuc2@knownsec.com
niexy2@knownsec.com
chenrl@xm.knownsec.com
chenjz@xm.knownsec.com
wangll@xm.knownsec.com
chenh4@xm.knownsec.com
liwc@xm.knownsec.com
wangl8@xm.knownsec.com
yangwh2@knownsec.com
zhanghj@knownsec.com
These addresses correspond directly to organizational positions inside Knownsec’s secure research and engineering divisions. There are no “throwaway” or operational aliases (e.g., Gmail/QQ/ProtonMail), which underscores that these individuals are internal employees, not contractors or external operators.
Functional Role Taxonomy
The personnel records reveal a clear hierarchy divided into strategic, operational, technical, and support layers.
Strategic Layer
These individuals control cost centers, approve research direction, and supervise multi-year programs. They connect Knownsec’s products to state-level requirements.
Key personnel:
李伟辰 (Li Weichen) – Head of Product Technology Center 141
These roles align with PRC state-integration patterns, where strategic decision-makers balance customer obligations with core R&D investment.
Operational Layer
Project managers, planners, and supervisors who translate strategic objectives into executable WBS chains.
Examples:
PM and supervisor for 404 Security Research 2023
PM/Planner for AW Detection (Project 391)
PM/Planner for Hardware Radar 2022 V3
PM of 404 Lab Pentest Research
Project planners for Cyberspace Mapping (Carrier Platform)
These individuals operationalize multi-team engineering efforts, reflecting the governance model observed in defense integrators.
Technical Layer
Engineers responsible for exploitation, radar algorithms, system optimization, and data fusion.
Representative technical staff:
WBS task owner for AW exploit and discovery chain
Owner of AW 3.5 system testing
Radar v3 implementation
Radar optimization and stability
Asset-identification system optimization
User and functional testing tasks
Data-fusion task execution for PSB
Lead engineer for network-entity fusion research
This tier performs the core offensive and analytic development that Knownsec markets to PRC state customers.
Support Layer
Personnel performing QA, compliance, test engineering, and administrative approvals.
Notable roles:
Beijing Testing Group (unnamed individuals except task owners)
Default approver across R&D workflows
These roles ensure Knownsec’s platforms (Radar, Carrier Platform, offensive tooling) meet regulator and PSB deployment conditions.
Organizational Insight Derived from Internal Personnel Records
The internal data paints a clear picture of Knownsec as a multi-division cyber contractor seamlessly embedded within the broader security and intelligence ecosystem of the People’s Republic of China. Its organizational structure, personnel assignments, and project governance models demonstrate a company that is not merely providing commercial cybersecurity services but is directly supporting national cybersecurity mandates, public-security operations, and critical-infrastructure oversight. Every major division within Knownsec aligns with a corresponding state need, creating an operational architecture that mirrors the functions of a state-affiliated defense integrator.
This alignment is particularly visible in how technical departments map to specific government tasking. The 404 Lab serves as the offensive research and exploit-development hub, producing capabilities that directly support public-security bureaus and the national CERT apparatus. Meanwhile, the Product Technology Centers operate as the engineering backbone for large-scale cyberspace-mapping platforms used by telecom regulators such as Ministry of Industry and Information Technology (MIIT) and Critical Infrastructure Intelligence Center (CNNIC). Parallel to these, the Public-Security Research Institute builds data-fusion and analytic systems tailored for police units, reflecting a tight coupling between Knownsec’s internal R&D efforts and the investigative workflows of law-enforcement agencies.
Even the company’s internal email domains reinforce these functional distinctions. Accounts using @xm.knownsec.com cluster around engineering-heavy roles located in Xiamen, supporting platform development, radar systems, and systems integration. In contrast, @knownsec.com addresses are associated with research, data-fusion, offensive tooling oversight, and leadership responsibilities in Beijing. These boundaries reveal an internal trust and specialization model consistent with sensitive state-oriented development work.
Knownsec’s work-breakdown-structure (WBS) governance further shows a degree of engineering discipline typically found in military-industrial contractors. Projects are organized under formal sponsorship, with named approvers, supervisory layers, and sequenced deliverables. Every task has a clearly identified owner, and responsibilities cascade through planners, supervisors, and technical implementers. This hierarchy captures operational accountability at each stage, ensuring that sensitive tooling and large-scale platforms move through development in a controlled, auditable way.
Personnel mapping highlights how deeply the company depends on specialized, interoperable technical units. Offensive engineers in the 404 Lab, radar architects in the Product Technology Department, large-scale mapping engineers in the R&D Center, and data-fusion specialists in the Public-Security Research Institute all operate in defined silos. However, these silos are not isolated; they form a layered production pipeline that transforms exploit research into operational platforms capable of national-scale reconnaissance, targeting, and surveillance. In this way, Knownsec operates not just as a security vendor but as a critical node in China’s state-aligned cyber ecosystem, where human expertise, organizational structure, and strategic intent converge into a cohesive operational capability.
Key observations:
Departments align to state tasking
404 Lab produces exploit and offensive research for PSB and national CERT.
Public-Security Research Institute builds fusion systems directly for police units.
Email domains reinforce internal trust boundaries
@xm.knownsec.com maps to engineering-heavy functions.
@knownsec.com maps to research, fusion, and leadership roles.
WBS governance reveals engineering maturity
Workflows mirror military-industrial contractors with formal sponsorship, deliverable tracking, and internal approvals.
Each task has a named owner, capturing chains of operational accountability.
Personnel mapping exposes internal specialization
Offensive engineering, radar systems, cyberspace mapping, and data fusion are isolated but interoperable teams.
These silos reflect a layered pipeline that moves from exploit research to national-scale targeting platforms.
Strategic Significance of the Internal Data Exposure
The personnel information exposed in the Knownsec leak provides an unusually rich foundation for adversarial intelligence analysis. Instead of viewing Knownsec through the limited lens of tools, platforms, or public-facing capabilities, analysts can now reconstruct the company’s true operational architecture by tracing projects, responsibilities, and decision-making authority back to named individuals. This transforms Knownsec from an abstract corporate entity into a map of people, teams, and functions revealing how its internal machinery supports the broader PRC cyber apparatus.
With individual identities tied directly to work-breakdown structures, cost centers, and project leadership roles, analysts can identify exactly who drives offensive research and development. Names connected to GhostX, Radar 2022V3, the Cyberspace Mapping “Carrier Platform,” and data-fusion systems allow a clear understanding of which personnel shape the direction of core offensive and reconnaissance tools. Decision-making chains also emerge: who authors budget proposals, who approves them, who signs off on deliverables, and who assumes technical ownership of the most sensitive tasks. These insights expose how Knownsec manages risk, allocates resources, and governs the development of capabilities that ultimately serve national-level customers.
The data also closes the loop between Knownsec’s internal operations and China’s public-sector clients. Analysts can now link specific individuals to the ministries, state-owned enterprises, and provincial public-security bureaus they support. Whether developing mapping infrastructure for MIIT, vulnerability research for PSB, or reconnaissance tooling for State Grid or the national telecom operators, the personnel lists clarify which engineers and managers are responsible for executing state-directed work. This creates a direct, traceable line from human operators to cyber capabilities used by the PRC government.
Granular operator-level visibility of this kind is almost never present in Chinese contractor leaks. Typical disclosures provide tools, artifacts, or billing records, but rarely full mappings of engineers, planners, cost-center owners, and project supervisors. The Knownsec leak stands apart in that it reveals not only what the company builds, but who builds it, who authorizes it, and who ensures its integration into the state security ecosystem. For analysts, this level of detail offers an unprecedented window into the human and organizational architecture of one of China’s most capable cyber contractors.
State Security and Intelligence Organizations Identified in the Knownsec Leak
The Knownsec leak provides direct insight into the company’s relationship with the national security, cyber-regulation, and public-security ecosystems of the People’s Republic of China. The documents show that Knownsec does not operate as a conventional cybersecurity vendor but instead as a tightly integrated contractor supporting multiple layers of the PRC’s intelligence and public-security infrastructure. The presence of specific ministries, bureaus, CERT bodies, and state-owned enterprises across internal worksheets and customer tables reveals a contractor ecosystem that mirrors the organizational structure of the Chinese cyber state.
The Ministry of Public Security (MPS) emerges as the most prominent stakeholder in Knownsec’s operations. Multiple internal project sheets reference public-security intelligence requirements, entity-fusion deliverables, and policing-oriented research, suggesting that Knownsec’s tools such as Network Entity Data C fusion systems and analytics platforms feed directly into law-enforcement intelligence workflows. The inclusion of the Beijing Municipal Public Security Bureau as a direct customer reinforces that Knownsec supports both national and regional PSB units, providing technical capabilities that underpin investigatory, surveillance, and cyber-intelligence missions. The company’s Public-Security Research Institute acts as an intermediary, developing analytic systems specifically designed for MPS use, including the “30 Institutes” project, which historically links to police intelligence research centers.
Beyond policing, the documents show that Knownsec’s platform technologies align with the needs of China’s cyber governance infrastructure. The MIIT and CNNIC, which oversee network resources, DNS infrastructure, and telecom regulation, appear in customer lists. These associations suggest that Knownsec’s large-scale cyberspace-mapping platforms and radar systems contribute to regulatory visibility across the national network space. Similarly, the presence of CNCERT/CC and CCERT indicates that Knownsec plays a role in the country’s coordinated incident response and vulnerability-management programs. These organizations sit at the intersection of defensive coordination and intelligence-informed cyber situational awareness, and Knownsec’s products appear to support both domains.
Several state-owned enterprises also appear in the dataset, including State Grid, China Mobile, and China Telecom. While not intelligence agencies in name, these entities represent critical-infrastructure and telecommunications networks of high strategic value to Chinese state security. Their appearance in Knownsec’s internal documentation implies that Knownsec provides reconnaissance, mapping, or defensive monitoring capabilities that directly support national requirements for energy grid protection, telecom oversight, and large-scale network exposure assessment. These relationships blur the line between commercial engagement and state-aligned intelligence support, reflecting the dual-use nature of Knownsec’s core platforms.
Taken together, the organizations referenced in the leak form a coherent picture of how Knownsec embeds itself in the state’s cyber and intelligence apparatus. The company’s divisions and product lines align closely with the functional needs of public-security bureaus, national regulators, telecom carriers, and critical infrastructure operators. The network of relationships visible across the documents illustrates a contractor deeply woven into China’s national security architecture. It confirms that Knownsec’s internal operations, research programs, and platform developments are not random or commercially opportunistic but are systematically shaped by the requirements of the PRC’s intelligence and regulatory ecosystem.
Summary: Intelligence / Security Org List
OrganizationTypeRole in DumpMPS – Ministry of Public SecurityNational Police / IntelligencePrimary stakeholder for offensive, data-fusion, and entity analytics systemsBeijing Public Security BureauMunicipal PSBDirect consumer of Knownsec platforms and analysisPublic-Security Research Institute (internal Knownsec)PSB-aligned R&DBuilds fusion tech for PSB intelligence unitsMIITTelecom & Cyber RegulatorOversight for mapping platforms, radar outputsCNNICNational DNS AuthorityDomain-level surveillance & infrastructure mappingCNCERT/CCNational CERTNational-level vulnerability, incident intelCCERTEducation & Research CERTSupporting CERT node“30 Institutes” (PSB Research Institutes)Public-Security Intelligence R&DEntity fusion, data pipelines, analytic systemsState GridStrategic CII targetIncluded for reconnaissance and mappingChina Mobile / China TelecomTelecom carriersInfrastructure mapping and metadata pipelines
APPENDICES
Appendix A Combined IOC List (Knownsec Leak Corpus)
Indicator of Compromise Summary Knownsec TargetDB, Radar, and Foreign CI Mapping
Below is the unified IOC dataset extracted from all Knownsec screenshots, TargetDB tables, Radar 2022V3 outputs, and CI-targeting images provided in this project.
The following organizations appear repeatedly in Knownsec’s internal customer lists, procurement docs, or radar/TargetDB slices. These constitute strategic targeting and cooperation indicators even when no IP/IaaS attributes were provided.
country,organization,type,notes
China,Ministry of Public Security,State Client,Internal security customer consuming Knownsec platforms
China,People’s Bank of China,Financial Regulator,Monitored via PKI-linked infrastructure
Radar 2022V3,Protocol-fingerprinting output,service banners/flows,Used to classify assets for later exploitation
Data-Fusion Projects,Identity correlation,IAM/credential merges,Used by Public-Security clients
These are behavioral indicators, not atomic IOCs, but they are directly tied to Knownsec’s operational tooling.
Appendix B MITRE ATT&CK Map
Appendix C Organizational Schema (Text)
State Ministries
↓
Knownsec Executive Leadership
↓
404 Lab | Product R&D | Military Division | Data Division
↓
Project Managers → Engineers → Operators
↓
Toolchain Deployment
Appendix D Master File List from Dump
Here is a consolidated file list of all Knownsec-related uploads in this project, reconstructed from the conversation history, OCR references, system logs, and tool notes.
This includes images, PDFs, spreadsheets, and indexes you uploaded for the Knownsec leak analysis.
MASTER FILE LIST OF UPLOADED FILES (Knownsec Project)