Research

Back to Homepage
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
No items found.
Research
Threat Intelligence Report: The Pro-Iran Hacktivist Ecosystem 2026

Moving beyond traditional state-centric APT structures, the pro-Iran coalition of jihadist-aligned collectives, nationalist actors, and opportunistic groups coordinates via Telegram to turn low-cost cyber operations into high-impact psychological warfare. While individual actors primarily rely on technically unsophisticated tradecraft like DDoS-for-hire tools, website defacements, and recycled breach data, their strategic strength lies in speed, visibility, and rapid mobilization alongside real-world kinetic events.

Executive Summary

The cyber environment surrounding the U.S.-Iranian conflict and regional tensions has produced a decentralized wartime cyber ecosystem in service of Iran. It is not a single organized force, instead, it is a loose mix of jihadist-aligned cyber collectives, nationalist actors, and state-adjacent influence networks that converge around shared enemies and geopolitical narratives. This activity has intensified with tensions around the events in Iran and the attacks on regional infrastructure.

The ecosystem operates through Telegram channels and websites, shared target lists, DDoS-for-hire tools, recycled breach data and leak-amplification campaigns. Attack claims and propaganda often appear within hours of kinetic events. This gives actors a deniable auxiliary role while keeping them separate from formal state structures. 

Most activity remains technically unsophisticated. DDoS attacks, website defacements, and  hack & leak extortion-style messaging with exaggerated claims are more common than verified advanced intrusions. The strategic effect comes less from technical capability than from speed, visibility, and ideological framing that make it into news cycles. In practice these actors use cyber activity as scalable asymmetric information warfare. Even with limited high-end capability, loosely aligned ideological and state-adjacent networks can impose psychological, political, and economic pressure on adversaries during periods of regional crisis.

Iran Aligned Actor Groups


The current pro-Iran and “Axis of Resistance” cyber ecosystem is decentralized, blending hacktivist groups, ideological cyber militias, influence operators, and jihadist cyber propagandists. This ecosystem does not operate as a single command infrastructure, instead functioning as a loose knit cyber mobilization network. Coordination happens through online platforms like Telegram and websites created for dumps of data and propaganda release. All of these are then amplified by social media and news reporting picking up on splashy reports of hack-and-leak operations for the most part. 

The groups in this report show how modern cyber conflict is moving beyond traditional espionage toward more influence operations. Much of this activity is built for wartime influence by leveraging public visibility for asymmetric pressure against perceived enemies.

Their primary tradecraft centers on DDoS campaigns, hack-and-leak operations, propaganda amplification, and extortion-style messaging. Targeting is often symbolic, with activity directed against government, telecommunications, healthcare, finance, logistics, and open-source infrastructure that is aligned with, or within the borders of, the enemies of the state they are supporting.

The ecosystem matters less because of proven advanced capability and more because of scale, coordination, and visibility. It can turn low-cost disruption into wartime psychological pressure. Groups such as Handala, 313 Team, Cyber Islamic Resistance, Fatimiyoun/FAD Team, Dark Storm, CJM, Keymous+, DieNet, MONARCH, Killnet, and other coalition actors create the appearance of a broad transnational cyber front. They do this primarily through synchronized propaganda and hacking campaigns.

One notable example of this activity is the May 2026 DDoS campaign against Canonical and Ubuntu infrastructure. This campaign demonstrated how commercial stresser tools and coalition amplification could be used to create outsized disruption against globally important digital platforms.

As tensions rise around the Strait of Hormuz and the wider regional conflict these actors should be treated as deniable asymmetric auxiliaries (e.g. proxies). They may not always demonstrate high-end capability but they can still generate persistent disruption, economic and reputational damage, and psychological instability.

Islamic Cyber Resistance in Iraq / 313 Team

The Islamic Cyber Resistance in Iraq, also known as 313 Team, is one of the most visible Iraqi resistance-branded cyber personas in the pro-Iran ecosystem. Its “313” branding draws from Shia theology and militia culture, giving the group ideological weight inside Iran-aligned media and militia networks.

Operationally, 313 Team focuses on DDoS attacks and website disruption. It also uses Telegram propaganda, symbolic targeting and wartime messaging. The group gained visibility during the aforementioned May 2026 DDoS campaign against Canonical and Ubuntu infrastructure. The campaign affected ubuntu.com, Launchpad package repositories  and security APIs update systems as well as related services used by enterprise and cloud environments.

The group claimed use of the “Beamed” DDoS-for-hire platform. This reinforces the assessment that its model relies more on commercial stressers, shared infrastructure, and coalition tooling than it does on custom malware or advanced tradecraft.The Ubuntu campaign was significant because of asymmetric leverage rather than technical sophistication. By targeting open-source infrastructure used across enterprise cloud DevOps and security-update environments, the group created outsized visibility and operational friction with relatively simple methods, in this case DDoS. 

313 Team has also been linked to GitHub-hosted tooling. It has used public proof-of-impact services such as check-host[.]net to confirm events. Reporting also connects the group to SQL-injection tools, AI-generated propaganda, and defacement-style activity against government and institutional targets in Kuwait and the wider Gulf. 313 Team operates inside the broader coalition environment of similar groups. Reported aligned actors include RipperSec, Cyb3rDrag0nz, Cyber Fattah Team, Fatimiyoun/FAD Team, Conquerors Electronic Army, and other resistance-branded groups. These actors coordinate through Telegram, shared narratives, target lists, and synchronized public claims. This structure lets low-to-moderate capability actors create the appearance of a larger cyber front.

Threat Assessment:
Moderate-to-high for DDoS, disruption, propaganda amplification, and wartime information operations; low-to-moderate for opportunistic intrusion activity; currently low for verified advanced destructive or cyber-physical capability.

Handala Hack Team

Handala Hack Team is among the most consequential and psychologically sophisticated actors in the pro-Iran ecosystem. Unlike many disruption-focused hacktivist groups, Handala specializes in hack-and-leak operations, intimidation campaigns, identity exposure, and coercive information operations.

The group has repeatedly demonstrated a focus on:

Its activity aligns closely with Iranian information warfare objectives, even where formal command relationships remain unconfirmed. Handala’s operations frequently blend cyber intrusion claims with propaganda, coercive messaging, and public intimidation. Within the ecosystem, Handala functions as a high-credibility influence and leak node whose operations provide aspirational models for smaller hacktivist crews. It is also of note that recent attacks have leveraged hack and wiper activities that place Handala at a higher level of damage capabilities than the others profiled here.

Threat Assessment:
High for psychological operations, hack-and-leak activity, and reputational damage; moderate for broader disruptive capability.

Cyber Fattah Team

Cyber Fattah ( فاتح سايبر) is a pro-Iran hacktivist persona focused on wartime propaganda, DDoS activity, defacement operations, and symbolic disruption. The group operates within the broader Axis-aligned propaganda ecosystem and contributes to coalition attack volume during periods of regional escalation.

Its operations are consistent with mid-tier wartime hacktivism:

  • public target selection
  • disruption claims
  • Telegram amplification
  • and symbolic attacks against state and infrastructure targets

The group’s strategic importance lies more in participation and coalition signaling than technical sophistication.

Threat Assessment:
Moderate for DDoS, disruption, and propaganda amplification.

Fatimiyoun Cyber Team / FAD Team

Fatimiyoun Cyber Team, also referred to as FAD Team, combines militia-aligned ideological branding with rhetoric centered on cyber sabotage, destructive operations, and critical infrastructure intimidation. The group frequently references wiper malware, permanent destruction narratives, and infrastructure targeting themes.

The “Fatimiyoun” branding invokes the Afghan Shia militia ecosystem aligned with Iran’s regional proxy architecture, providing ideological legitimacy and escalation signaling.

Although public evidence of mature destructive capability remains limited, the group’s strategic value lies in psychological escalation. By repeatedly framing itself around cyber sabotage and infrastructure destruction, it injects uncertainty into the wartime information environment.

Threat Assessment:
Moderate-to-high for intimidation and escalation signaling; unverified for sophisticated destructive operations.

Cyber Isnaad Front

Cyber Isnaad Front ("الجبهة الإسناد السيبرانية) represents the evolution of pro-Iran cyber activity from infrastructure disruption toward individualized coercive targeting. The group has reportedly published target lists and conducted intimidation-oriented campaigns focused on individuals tied to critical sectors. Its operations demonstrate the increasing fusion of cyber operations with psychological warfare and harassment tactics. Rather than focusing solely on institutional compromise, the group attempts to generate fear and pressure through exposure, intimidation, and public targeting.

Threat Assessment:
Moderate for intimidation, doxxing, and psychological pressure campaigns.

Dark Storm Team

Dark Storm Team occupies a hybrid space between ideological hacktivism and criminal-adjacent cyber operations. The group has been linked to DDoS campaigns, ransomware claims, and attacks targeting financial-sector organizations.

Unlike purely ideological DDoS crews, Dark Storm’s association with ransomware narratives increases its risk profile by blending coercive financial pressure with wartime propaganda.The group contributes to the ecosystem by providing both disruption capability and criminal-style intimidation mechanics.

Threat Assessment:
High for DDoS; moderate-to-high if ransomware capability is operationally validated.

APT Iran

APT Iran (مرکز تحقیقاتی) is primarily a branding-oriented pro-Iran hacktivist persona rather than a formally identified state APT. The name itself is strategically useful because it implies sophistication and state linkage regardless of actual operational capability.

The group appears focused on:

  • symbolic targeting (retribution ops)
  • propaganda-oriented disruption
  • and coalition participation for propaganda

Its value within the ecosystem is narrative inflation rather than uniquely advanced capability.

Threat Assessment:
Moderate for disruption claims and propaganda amplification.

Evil Markhors

Evil Markhors (ایول مارخور) occupies a more operationally useful niche within the ecosystem by focusing on credential harvesting, reconnaissance, and exposed-system discovery. While less visible publicly than DDoS-centric actors, credential and recon-focused groups are strategically important because they can enable downstream compromise by coalition participants.

The group’s activities likely include:

  • password spraying
  • reconnaissance scanning
  • exposure discovery
  • and credential aggregation

In a decentralized coalition environment, such access-enablement actors can disproportionately increase ecosystem effectiveness.

Threat Assessment:
Moderate for credential compromise and reconnaissance; potentially higher if access-sharing occurs across coalition actors.

Conquerors Electronic Army (CEA)

Conquerors Electronic Army (جيش الفاتحين الإلكتروني,) functions as a coalition-aligned DDoS and propaganda actor participating in wartime disruption campaigns. The group contributes to coalition messaging, attack volume, and amplification operations targeting Israeli and Western infrastructure.

Its operational profile is consistent with high-visibility wartime hacktivism:

  • DDoS
  • defacement
  • and public disruption claims

Threat Assessment:
Moderate for DDoS and defacement activity.

Nation of Saviors (NOS)

Nation of Saviors is a smaller coalition participant operating within pro-Palestinian and anti-Israel narratives. Its significance lies primarily in coalition breadth and amplification rather than technical specialization.

The group contributes:

  • DDoS participation
  • propaganda reinforcement
  • and wartime messaging

Threat Assessment:
Moderate for coalition participation and DDoS activity.

Hider Nex / Tunisian Maskers Cyber Force

Hider Nex, also known as Tunisian Maskers Cyber Force, is a regional pro-Palestinian actor associated with telecom-focused DDoS campaigns and symbolic infrastructure targeting.

The group’s operations demonstrate the ecosystem’s ability to rapidly mobilize around visible civilian infrastructure targets where even limited disruption can generate substantial media attention and psychological impact.

Threat Assessment:
Moderate for symbolic disruption and telecom-targeted DDoS operations.

RipperSec

RipperSec (新闻频道) is a coalition-aligned hacktivist group focused on DDoS, defacement, and propaganda amplification based in Malaysia. The group’s importance lies in demonstrating how the ecosystem absorbs or aligns with preexisting hacktivist brands in order to rapidly increase campaign scale.

Its activity is primarily tactical:

  • disruption
  • visibility
  • and social-media amplification

Threat Assessment:
Moderate for DDoS and defacement operations.

Cyb3rDrag0nz

Cyb3rDrag0nz represents another coalition-density actor contributing to DDoS campaigns, Telegram amplification, and wartime disruption messaging. Like many smaller crews in the ecosystem, its primary value lies not in technical specialization but in attack-volume generation and coalition optics.

Threat Assessment:
Moderate for DDoS and propaganda participation.

Cyber Jihad Movement (CJM)

Cyber Jihad Movement (CJM الجهاد السيبراني) represents one of the most strategically significant developments within the wartime cyber ecosystem because it bridges Sunni jihadist cyber mobilization with the broader Iranian Axis-aligned cyber environment.

The group’s public statements call for “global cyber jihad” against the United States, Israel, and allied governments. This messaging signals a tactical convergence between historically hostile ideological ecosystems united temporarily around shared anti-Western objectives.

CJM’s importance is therefore ideological and mobilizational rather than purely technical. It expands the ecosystem’s recruitment potential, propaganda reach, and cross-platform amplification capacity.

Threat Assessment:
Moderate for ideological mobilization, propaganda amplification, and public-sector disruption.

Keymous+

Keymous+ emerged as one of the highest-volume DDoS actors during the early 2026 wartime surge. Its strategic importance lies in attack tempo and operational persistence rather than advanced intrusion capability.

The group demonstrates how commodity stresser infrastructure and coordinated attack waves can create disproportionate operational burden and media attention.

Threat Assessment:
High for DDoS volume and sustained disruption.

DieNet

DieNet functions similarly to Keymous+, contributing persistent high-volume DDoS activity against government and public-sector targets.

Its role within the coalition is to sustain operational noise, repeated disruption, and public claim generation during escalation cycles.

Threat Assessment:
High for DDoS and operational disruption.

NoName057(16)

NoName057(16) aka DDoSiaProject is primarily a pro-Russian hacktivist actor that entered the broader anti-Western and pro-Iran wartime ecosystem opportunistically. Its participation demonstrates increasing convergence between Russian-aligned cyber activism and Middle East wartime cyber narratives.

The group is already well known for high-volume DDoS operations, making it a natural participant in coalition-style wartime disruption campaigns.

Threat Assessment:
High for DDoS and coalition amplification.

Killnet

Killnet represents a pro-Russian hacktivist brand whose wartime participation appears primarily opportunistic and ideologically adjacent rather than directly subordinated to Iranian coordination structures. The group contributes symbolic support, amplification, and anti-Western targeting consistent with broader wartime narratives.

Threat Assessment:
Moderate-to-high for DDoS and propaganda amplification.

Russian Legion aka CARDINAL aka MONARCH

The Russian Legion now increasingly uses the name MONARCH. It appears to function as an opportunistic anti-Western amplification actor within the wider Iran, Israel, and U.S. wartime cyber ecosystem.

The shift from Russian Legion to MONARCH fits a broader pattern of hacktivist identity cycling. It also fits the use of refreshed propaganda rebranding to maintain visibility and complicate attribution. The actor’s messaging remains focused on anti-Western, anti-Israel, and militarized geopolitical narratives. Its activity emphasizes symbolic targeting, wartime propaganda, and high-visibility disruption claims.

Operationally MONARCH appears to fill the same role previously associated with the Russian Legion. That role includes coalition participation, DDoS-focused disruption, influence amplification, and synchronized wartime messaging. However, there is limited public evidence of independently verified advanced intrusion capability.

Telegram and social media appear central to its model. These platforms allow the group to spread claims, announce targets, and amplify coalition building propaganda across loosely connected pro-Russian and pro-Iran information networks.

Analytically, MONARCH should be understood less as a standalone sophisticated threat actor and more as a coalition-force multiplier operating within a decentralized proxy cyber environment. Its strategic value derives from visibility, repetition, ideological alignment and the ability to reinforce a wider perception of coordinated cyber pressure.

Threat Assessment:
Moderate for DDoS, coalition amplification, and wartime propaganda operations; low-to-moderate for independently verified advanced intrusion capability; currently low for demonstrated destructive or cyber-physical operations.

Server Killers

Server Killers illustrates the opportunistic nature of wartime cyber ecosystems. The group appears motivated by visibility and coalition participation rather than deep strategic coordination. Its presence demonstrates how wartime cyber conflicts attract loosely affiliated actors seeking relevance or opportunistic influence within larger geopolitical narratives.

Threat Assessment:
Moderate for nuisance disruption and opportunistic DDoS activity.

Strategic Assessment

The pro-Iran cyber ecosystem increasingly resembles a form of decentralized digital proxy warfare rather than traditional state-centric cyber operations. 

Its defining characteristics are:

  • coalition behavior
  • Telegram-native coordination
  • rapid mobilization
  • ideological amplification
  • and psychological disruption

The ecosystem’s center of gravity is not advanced malware, covert espionage, or long-term persistence. Instead, it is rapid disruption turned into strategic psychological effect through coalition activity, synchronized propaganda, and wartime information operations.

As regional conflict continues to intensify, these actors are likely to remain focused on:

  • DDoS campaigns
  • symbolic infrastructure targeting
  • leak operations
  • coercive messaging
  • and psychological pressure operations

Defensive Implications

Organizations should treat this cluster as a disruption and reputational-risk threat during periods of geopolitical escalation. Priority controls should focus on 

  • DDoS readiness 
  • WAF and CDN hardening 
  • credential-stuffing detection 
  • MFA enforcement
  • leaked-credential monitoring 
  • abuse-desk escalation 
  • executive doxxing monitoring
  • rapid response and communications procedures for false or exaggerated breach claims

The key analytic discipline is separating access from amplification. A Telegram claim does not prove intrusion. A DDoS screenshot does not prove compromise. A leaked sample does not prove current access.

Still, repeated low-end activity across many brands can create real operational pressure, reputational damage, and psychological cost.

Conclusions

The pro-Iran and “Axis of Resistance” cyber ecosystem is best understood as a decentralized wartime disruption network, not a traditional APT structure. Its strength is not advanced technical capability, but speed, visibility, coalition activity, and the ability to turn low-cost cyber actions into psychological and political pressure. Many of these groups function as proxies or cutouts for Iranian-aligned interests, with varying degrees of likely support, direction, encouragement, or operational tolerance from Iran. These groups and related actors help create the appearance of a broad transnational cyber front. That perception is itself part of the operation.

Most of these actors rely on basic tradecraft, including DDoS attacks, defacements, credential reuse, recycled breach data, public claims, and propaganda amplification to effect. These methods are often low-end, but they can still create real impact when many groups act at once during geopolitical escalation. The main defensive challenge is not only intrusion prevention, but also managing disruption, reputational risk, and alert fatigue across public-facing systems. 

During future Gulf-region escalation, this ecosystem is likely to surge quickly, with claims appearing within hours of kinetic events.The core assessment is that this ecosystem is less a high-end cyber weapon than a scalable asymmetric pressure system, with value derived from mobilization, amplification, and psychological effect.

Learn More
Research
Threat Intelligence Report: Nation-State Targeting of Water Systems 2024–2026

DTI reveals how Russia, China, and Iran are exploiting weak OT security and internet-facing PLCs to target critical water and wastewater infrastructure. From Volt Typhoon's strategic pre-positioning to Sandworm-adjacent sabotage, discover the primary TTPs, vulnerabilities, and MITRE ATT&CK mappings reshaping modern hybrid warfare.

Executive Summary

Water and wastewater systems have become favored gray-zone targets because they are highly vulnerable and hold disproportionate strategic value. The combination of chronic underinvestment and weak baseline operational technology (OT) security make many of these critical systems easy to compromise. Such intrusions can have both physical and psychological impact, and disruptions often affect civilian life, public health, and trust in government. 

Recent nation-state cyber activity targeting water systems includes Iranian IRGC-linked targeting of exposed programmable logic controllers (PLCs), Russian and pro-Russian access to municipal water-control environments, and PRC-linked pre-positioning in U.S. critical infrastructure, including water and wastewater systems. U.S. federal agencies, including CISA, FBI, NSA, and EPA, have warned that many utilities remain exposed through internet-facing human-machine interfaces (HMIs) and PLCs, weak credentials, shared accounts, legacy devices, limited monitoring, and poor IT/OT segmentation.

Operations targeting water systems fit a modern hybrid warfare doctrine that has become increasingly dominant in recent years. Russia, China, and Iran all use cyber access primarily as a shaping tool, not a destructive weapon. Water-system access specifically can create fear, test response thresholds, consume emergency resources, and provide leverage during crises. Each nation puts their unique twist on their operations. Russia tends to pair infrastructure access with pressure and destabilization. Iran often blends symbolic retaliation, psychological signaling, and opportunistic disruption. In contrast, China places more emphasis on long-term pre-positioning and strategic persistence. 

All three models converge on the same underlying thesis: targeting civilian utilities provides strategic options.

Water Systems as Pre-War Terrain

From 2024 to 2026, water-sector targeting moved from opportunistic nuisance activity to a feature of state competition. Water systems are now pressure points used to create fear, test resilience, and prepare options before wider conflict. Specifically, threat actors have exploited internet-exposed PLCs and weak credentials to deface HMIs and make public spectacles out of their compromises.

Iran uses successful compromise of water systems for visible signaling, retaliation narratives, and propaganda, while Russia uses it for disruption, intimidation, and hybrid pressure against NATO-aligned states. Meanwhile, China focuses on quiet persistence, reconnaissance, and contingency access inside U.S. critical infrastructure. However, all of these operations are meant to serve the same purpose: setting the stage for war without crossing the threshold into open conflict.

Iran: CyberAv3ngers / IRGC-Linked PLC Targeting

Iran-linked activity has been the most direct in targeting water and wastewater systems.In April 2020, Iranian state-sponsored hackers launched a cyberattack targeting Israeli water and wastewater control systems. While this attack attempted to manipulate the SCADA systems, automated systems kicked in and thwarted the attempt. Had it succeeded, during a heat wave, it could have harmed many people. 

In December 2024, CISA reported that the IRGC-affiliated CyberAv3ngers targeted and compromised Israeli-made Unitronics Vision Series PLCs used across multiple sectors, including U.S. water and wastewater systems. The activity exploited poor authentication and exposed PLC/HMI interfaces rather than sophisticated malware delivery. Clearly this shows that the Iranian government is accustomed to the idea of attacking public infrastructure, something usually outside the bounds of conventional warfare.

In April 2026, CISA, FBI, NSA, EPA, and partner agencies issued a new advisory warning that Iranian-affiliated cyber actors were exploiting internet-facing PLCs across critical infrastructure, including water, wastewater, energy, and government facilities. The EPA separately framed the advisory as a water-sector resilience warning, stressing that national security depends on water systems reporting incidents and hardening exposed OT assets.

Assessment: While Iran has demonstrated the ability to access exposed control devices, deface HMIs, and create public fear, the public evidence of their activity still points more toward opportunistic OT access than reliable cyber-physical sabotage at scale.

Primary TTPs

Threat level: High for exposed small and mid-sized utilities; moderate for mature utilities with segmented OT.

Russia: Pro-Russian Hacktivist and Sandworm-Adjacent Water Disruption

Russia-aligned actors have shown a willingness to use their access to manipulate water-control systems directly. In Mulshoe, Texas in January 2024, attackers accessed a remote industrial interface and caused a municipal water tank to overflow for roughly 30–45 minutes. The Cyber Army of Russia Reborn claimed responsibility, and Mandiant linked the group to Sandworm, Russia’s GRU-associated destructive cyber unit.


A little over a year later, in April 2025, attackers seized control of a dam in Bremanger, Norway. They opened a floodgate, releasing roughly 500 liters of water per second for four hours before the incident was stopped. Norway’s counterintelligence chief publicly blamed Russia-linked actors for the intrusion.

Assessment: Russian-linked activity is more sabotage-oriented than Iranian activity. The pattern fits Moscow’s broader hybrid campaign: low-cost disruptive access, public fear generation, and probing of Western infrastructure resilience. 

Primary TTPs

Threat level: High in Europe and NATO-adjacent states; moderate-to-high in exposed U.S. municipal water systems.

China: Volt Typhoon Pre-Positioning in Water and Wastewater Networks

In February 2024, CISA, NSA, FBI, and allied agencies confirmed that Volt Typhoon had compromised IT environments across multiple U.S. critical infrastructure sectors, including water and wastewater, communications, energy, and transportation. The advisory assessed that the activity was intended to enable disruptive or destructive effects during a future crisis or kinetic conflict.

The same year, the EPA distributed an alert to more than 60,000 water and wastewater systems regarding Volt Typhoon and coordinated cybersecurity assistance for water infrastructure supporting U.S. defense-critical facilities.

Assessment: PRC water-sector targeting is strategically different from Iran and Russia. Rather than demonstrate immediate effects, Volt Typhoon’s  objective is durable access, reconnaissance, and strategic pre-positioning. 

Primary TTPs

Threat level: Severe strategic threat; lower risk of short-term disruption.

Poland and European Water-System Exposure

A May 2026 report released by the Polish Intelligence Service stated that hackers breached five Polish water treatment plants in 2025. The threat actors leveraged weak/default passwords and internet-exposed control systems. Once inside  ICS controlling pumps and filters, they had the ability to alter chemical-dosing parameters. The attacks were never attributed to a specific nation-state or threat actor; however, the same intelligence report alluded to prior Russian and Belarusian hybrid operations against Polish infrastructure.

Assessment: Poland is a high-priority target because of its role as a NATO logistics hub for Ukraine. Even unattributed water-system intrusions in Poland should be assessed against Russian hybrid-warfare objectives: intimidation, disruption, reconnaissance, and resilience testing.

Threat level: High for this region downrange from Russia.

Major Non-Attributed Water-Sector Incidents Relevant to State Threat Modeling

American Water disclosed a cyber incident in October 2024 that affected customer-facing and billing systems, but not water or wastewater operations. Veolia North America reported a January 2024 ransomware incident that disrupted back-end systems and online bill payment, while treatment operations remained unaffected. Southern Water in the United Kingdom was also claimed by Black Basta, with customer and employee data at risk but no reported operational impact.

Other cases moved closer to operational risk. Arkansas City, Kansas shifted its water treatment facility to manual operations after a September 2024 cyber incident. Minot, North Dakota did the same in March 2026 after ransomware affected a server tied to the water treatment environment. In both cases, water remained safe, but operators had to rely on fallback procedures.

These incidents matter because they show that state actors do not need custom ICS malware to create risk. Billing systems, customer portals, GIS repositories, vendor access, remote administration, identity systems, backups, and SCADA-adjacent servers can all provide useful access or intelligence. Criminal and unattributed incidents should therefore be treated as live demonstrations of the same weaknesses a state actor could exploit with more patience, planning, and operational intent.

Common Vulnerabilities Exploited Across Cases

Water-sector targeting repeatedly converges on the same weaknesses: 

  • Internet-facing HMIs and PLCs, 
  • Weak or default credentials, 
  • Exposed remote-access tools, 
  • Shared operator accounts, 
  • Unsupported legacy systems, 
  • Limited monitoring,
  • Poor segmentation between IT and OT networks. 

These gaps give actors simple access paths into systems that control pumps, valves, filters, chemical dosing, and alarms.

Reporting from the EPA and Government Accountability Office (GAO) shows that this is a systemic risk, not a one-off failure. The U.S. water sector includes roughly 170,000 water and wastewater systems, many of which operate with limited resources, voluntary security adoption, and uneven cyber maturity. This structure makes the sector easy to probe, difficult to standardize, and attractive to state and state-aligned actors seeking leverage, visibility, and disruption opportunities.


Strategic Assessment

The last two years show clear segmentation among state-sponsored and state-aligned actors. Iran uses water system intrusions to maximize ideological and psychological impact. Russia treats water and dam systems as part of sabotage-oriented hybrid warfare. China targets water infrastructure for strategic pre-positioning.

The near-term risk is not a Stuxnet-class attack. It is a low-complexity compromise of exposed OT that causes local disruption, unsafe operations, or panic. The larger strategic risk is quiet PRC-style persistence inside water-sector IT and OT-adjacent networks that could be used during a geopolitical crisis, such as kinetic conflict between the U.S. and China over Taiwan.

Conclusion

State and state-aligned actors treat water and wastewater infrastructure as strategic pressure points. The value is primarily psychological and political rather than kinetic. Even limited access or brief disruptions can trigger disproportionate reactions because water is tied directly to public health, trust, and government competence.

The most likely future is not a catastrophic “cyber Pearl Harbor.” It is persistent low-level access, intermittent disruption, coercive signaling, information operations, and pre-positioning for broader confrontations. 

Appendix A: Indicators of Compromise and Detection Artifacts

Iran: CyberAv3ngers / Iranian-Affiliated PLC Targeting

Indicator Type Year Relevance
135.136.1[.]133 IP addressMarch 2026 Used by Iranian-affiliated APT actors to communicate with Rockwell Automation / Allen-Bradley PLCs
185.82.73[.]162 IP addressJan 2025–Mar 2026Same
185.82.73[.]164 IP addressJan 2025–Mar 2026Same
185.82.73[.]165 IP addressJan 2025–Mar 2026Same
185.82.73[.]167 IP addressJan 2025–Mar 2026Same
185.82.73[.]168 IP addressJan 2025–Mar 2026Same
185.82.73[.]170 IP addressJan 2025–Mar 2026Same
185.82.73[.]171 IP addressJan 2025–Mar 2026Same

CISA, FBI, NSA, EPA, DOE, and U.S. Cyber Command reported that Iranian-affiliated actors used overseas infrastructure to access internet-facing Rockwell Automation / Allen-Bradley PLCs, including CompactLogix and Micro850 devices, and that activity resulted in project-file extraction, HMI / SCADA data manipulation, operational disruption, and financial loss. (Internet Crime Complaint Center)

Iran: Ports, Devices, and Tools

Indicator / Artifact Type Relevance
TCP/44818 OT protocol port EtherNet/IP / Rockwell Automation communications
TCP/2222 OT protocol port EtherNet/IP implicit messaging
TCP/102 OT protocol port Siemens S7 communications
TCP/502 OT protocol port Modbus/TCP
TCP/22 Remote access port SSH access; Dropbear SSH observed on victim endpoints
Dropbear SSH Tool Used for remote access persistence through port 22
Studio 5000 Logix Designer Legitimate engineering software Used to connect to and interact with exposed Rockwell PLCs
.ACD project files Rockwell project artifact Targeted / extracted project files containing ladder logic and configuration

The April 2026 joint advisory specifically called out malicious traffic to ports 44818, 2222, 102, 22, and 502, and noted Dropbear SSH deployment for remote access. (Internet Crime Complaint Center)

Iran: 2023 Unitronics / CyberAv3ngers Artifacts

Indicator / Artifact Type Relevance
Unitronics Vision Series PLCsTargeted product familyIsraeli-made PLC/HMI platform used in water, wastewater, energy, food, beverage, manufacturing, and healthcare
Default credentialsAccess conditionCore compromise vector
"You have been hacked, down with Israel. Every equipment 'made in Israel' is CyberAv3ngers legal target."Defacement textHMI/PLC defacement message reported in 2023 activity

The earlier joint advisory reported IRGC-affiliated CyberAv3ngers targeting Unitronics Vision Series PLCs, commonly used in U.S. water and wastewater systems, and compromising devices using default credentials.

Russia: Cyber Army of Russia Reborn / Sandworm-Adjacent Activity

Indicator / Artifact Type Relevance
Cyber Army of Russia Reborn / CARR Actor persona Claimed water-system manipulation activity in Texas and Europe
Telegram claim videos Influence artifact Public proof-of-access / propaganda amplification
HMI screen recordings Operational artifact Demonstrated interaction with water-control interfaces
Water-level / stop-level manipulation Process-control behavior Associated with Muleshoe / Abernathy water tank incidents
SCADA / HMI access to small municipal utilitiesTargeting pattern Low-resource water utilities used as disruption targets

Mandiant linked CARR to Sandworm-associated infrastructure and personas, while Treasury reported that CARR claimed responsibility for overflowing water storage tanks in Abernathy and Muleshoe, Texas, and posted video of HMI manipulation. (CyberScoop)

Norway and Poland Exposure Artifacts

Indicator / Artifact Type Relevance
Bremanger / Risevatnet dam floodgate manipulationProcess-control behavior Floodgate opened, releasing roughly 500 liters per second for four hours
Weak/default passwords Access condition Reported as common vector in European water incidents
Internet-exposed control systems Exposure condition Reported vector in Polish water treatment plant breaches
Pump, filter, and chemical-dosing control accessProcess-control exposure Relevant to Polish water treatment plant incident reporting

Reuters reported that Norway’s counterintelligence chief blamed Russian hackers for the April 2025 Bremanger dam incident. TNW and SecurityWeek reported that Polish water treatment plant breaches involved weak passwords and internet-exposed control systems; attribution remains unconfirmed for those Polish incidents. (Reuters)

China: Volt Typhoon Behavioral IOCs

Indicator / Artifact Type Relevance
wmic / WMIC Native Windows tool Process creation, discovery, credential-access workflows
ntdsutil.exe Native Windows tool Active Directory database extraction
ntds.dit Credential artifact Domain credential database targeted for exfiltration
SYSTEM registry hive Credential artifact Used with ntds.dit for password hash extraction
SECURITY registry hive Credential artifact Credential and policy data
netsh interface portproxy Native Windows tool Port forwarding / proxying for persistence and C2
PowerShell Native Windows tool Execution, discovery, and administration abuse
Compromised SOHO routers Infrastructure Proxying and operational obfuscation
C:\Windows\Temp\ Host artifact path Staging location observed in advisory examples
C:\Users\Public\ Host artifact path Staging location observed in advisory examples
ADMIN$ share output redirection Windows admin artifact Used in command execution / remote activity

NSA and partner agencies reported Volt Typhoon’s living-off-the-land model using built-in tools including wmic, ntdsutil, netsh, and PowerShell; the same advisory included examples of ntds.dit extraction, registry hive collection, and portproxy abuse.

Appendix B: MITRE ATT&CK Mapping

Actor / Stream Tactic Technique ID Observed / Assessed Use
Iran / CyberAv3ngers Initial Access Internet Accessible Device T0883 Accessed publicly exposed PLCs without sufficient network hardening
Iran / CyberAv3ngers Command and Control Commonly Used Port T0885 Used OT ports including 44818, 2222, 102, 502, and SSH on 22
Iran / CyberAv3ngers C&C Remote Access Software T1219 Deployed Dropbear SSH for remote access
Iran / CyberAv3ngers Impact Stored Data Manipulation T1565 Interacted with project files and altered HMI / SCADA display data
Iran / CyberAv3ngers Initial Access Valid Accounts T1078 Inferred from default / weak credential abuse against PLCs
Iran / CyberAv3ngers Impact Defacement T1491 HMI/PLC defacement messaging in Unitronics activity
Russia / CARR / Sandworm-adjacent Initial Access External Remote Services T1133 Likely access through remote industrial interfaces / exposed remote control paths
Russia / CARR / Sandworm-adjacent Initial Access Valid Accounts T1078 Likely weak credential or exposed HMI access model
Russia / CARR / Sandworm-adjacent Discovery Network Service Discovery T1046 Assessed scanning / discovery of exposed water-control interfaces
Russia / CARR / Sandworm-adjacent Impact Service Stop / Process Disruption T1489 / ICS-aligned impact Manipulation of water-system process controls resulting in overflow / floodgate events
Russia / CARR / Sandworm-adjacent Impact Data Manipulation T1565 Manipulation of set points, values, and control-system displays
Russia / CARR / Sandworm-adjacent Collection / Influence Screen Capture / Public Claims T1113 / influence artifact Claim videos showed screen recordings of HMI manipulation
China / Volt Typhoon Initial Access Exploit Public-Facing Application T1190 Compromise of exposed edge devices and public-facing infrastructure
China / Volt Typhoon Defense Evasion Living-off-the-Land Multiple Use of native tools to blend with administration activity
China / Volt Typhoon Execution Windows Management Instrumentation T1047 WMIC execution for process creation and credential-access workflows
China / Volt Typhoon Credential Access OS Credential Dumping: NTDS T1003.003 Attempted extraction of ntds.dit and registry hives
China / Volt Typhoon Command and Control Proxy T1090 netsh portproxy used for forwarding / covert access
China / Volt Typhoon Execution PowerShell T1059.001 Native PowerShell use in LOTL activity
China / Volt Typhoon Discovery Account Discovery T1087 Account and environment enumeration
China / Volt Typhoon Discovery Remote System Discovery T1018 Network and host reconnaissance
China / Volt Typhoon Lateral Movement Remote Services T1021 Movement through compromised internal environments
China / Volt Typhoon Collection Archive Collected Data T1560 Staging and compression of collected data, including 7z examples
China / Volt Typhoon Defense Evasion Impair Defenses T1562 Avoidance of EDR visibility through native tooling and low-noise operations
Poland / Unattributed Initial Access Internet Accessible Device T0883 Internet-exposed ICS used as access path
Poland / Unattributed Initial Access Valid Accounts T1078 Weak/default passwords
Poland / Unattributed Impact Data Manipulation T1565 Potential manipulation of pump, filter, and dosing parameters
American Water / Unattributed Initial Access Unknown N/A Public reporting does not disclose technical access vector
American Water / Unattributed Impact Service Disruption T1489, if confirmed Customer-facing and billing systems were affected; company stated water/wastewater operations were not impacted

The Iran rows are directly mapped from AA26-097A’s ATT&CK tables; the Volt Typhoon rows are mapped from NSA/CISA/FBI partner reporting on living-off-the-land activity; the Russia and Poland rows are analytic mappings based on public incident descriptions and should be treated as lower-confidence than the official advisory mappings. (Internet Crime Complaint Center)

Learn More
Research
Threat Intelligence Report: Russia, Router, DNS, and Messaging-Layer Collection Operations

New research exposes Russian GRU (APT28) cyber operations using router compromise, DNS hijacking, and Signal/WhatsApp phishing for long-term espionage.

Executive Summary

Russian intelligence-linked cyber operations continue to emphasize communications-layer collection over disruptive or destructive activity. Recent reporting from U.S. agencies, allied partners, and private researchers highlights two lines of effort. One is the compromise of vulnerable SOHO routers for DNS hijacking and adversary-in-the-middle collection. The other is phishing against secure and commercial messaging platforms. Together, these operations support long-term intelligence collection against government, defense, critical infrastructure, diplomatic, media, NGO, and Ukraine-related targets.

The goal is access. Quiet and lasting. By taking routers and bending DNS, Russian operators can watch traffic, steer chosen victims, and steal credentials without putting malware on the machine. Their work against Signal, WhatsApp, Telegram, and Microsoft 365 gives them the other half: messages, contacts, trusted names, and private conversations. Together, it lets them collect, map people, and stay close to the networks that matter.

Key Assessments

Russia is increasingly treating edge infrastructure and messaging platforms as persistent intelligence-collection terrain. Router compromise provides GRU-linked operators with a passive upstream vantage point over victim traffic, while messaging-account compromise provides visibility into human networks, operational discussions, authentication workflows, and trusted social relationships. Together, these operations support long-duration intelligence collection, access persistence, credential interception, social-graph mapping, and pre-positioning for future contingency operations.

The most significant router activity is attributed to the Russian GRU's Unit 26165, tracked as APT28/Fancy Bear. U.S. and allied agencies report ongoing exploitation of vulnerable routers and edge devices to manipulate DNS and DHCP settings, enabling adversary-in-the-middle collection and credential interception without requiring endpoint malware. The objective is persistent intelligence collection and access rather than immediate disruption.

Evolution of GRU Tradecraft: From Intrusion and Disruption to Communications-Layer Collection

Russian messaging targeting now reaches beyond Signal. It includes WhatsApp, Telegram, and Microsoft 365 OAuth flows. The goal is not just the account. It is the conversation, the contact list, the trusted name, and the path into the next victim.

GRU tradecraft has changed, but the aim has not. The old operations broke in, stole, leaked, and sometimes destroyed. The new operation is quieter. It compromises routers, bends DNS, abuses QR codes, linked devices, cloud logins, and OAuth prompts. It sits close to the traffic and the trust. It maps who talks to whom and keeps access to the communications layer itself.

Victimology

The victim set falls into two groups. The first set is broad; router and DNS campaigns reach across home routers, small offices, and edge devices in many regions. However, Russian actors do not exploit every victim the same way. They look for value in targets with the highest likelihood of a significant intelligence yield such as military, government, critical infrastructure, foreign ministry, law enforcement, telecom, and email providers.

The second group is more personal. The messaging campaigns go after people whose conversations matter for Russian intelligence collection, including Ukrainian military personnel, government officials, politicians, journalists and researchers, activists, NGO staff  and human-rights workers. Communications platforms like Signal, WhatsApp, Telegram, and Microsoft 365 then function as doors into contact lists, private conversations, trusted names, and the next victim.

Russian-linked targeting in 2026 focused on people and institutions with intelligence value. FBI/CISA reporting identified current and former government officials, military personnel, political figures, and journalists as high-value targets, while Volexity documented related activity against Ukraine-linked and human-rights organizations through Signal, WhatsApp, and Microsoft 365 OAuth compromise. Google reporting on defense-sector threats and Reuters coverage of Signal phishing against politicians, diplomats, military officers, and journalists reinforce the same pattern. The target set was strategic, not random.

Secondary exposure came through the tools those targets used every day. Microsoft reported Russian-linked compromise of home and small-office routers, DNS hijacking, and Outlook on the web targeting, while Lumen described broad router exploitation across more than 18,000 IPs in at least 120 countries. That scale gave operators a wide collection base. From there, they could sort victims by intelligence value and pursue the accounts, organizations, and communications channels that mattered most.

Router and DNS Hijacking Operations

In April 2026, the IC3 warned that Russian GRU actors were exploiting routers worldwide to steal military, government, and critical infrastructure data. The activity was tied to Unit 26165, also known as APT28, Fancy Bear, and Forest Blizzard. The actors changed DNS and DHCP settings, pushed victims through Russian-controlled resolvers, and used the access for quiet collection.

DOJ said the network relied on compromised SOHO routers, including thousands of TP-Link devices. The actors stole credentials, filtered DNS requests, and used false DNS records to stage adversary-in-the-middle attacks against services such as Outlook Web Access.

Microsoft assessed the campaign had run since at least August 2025, affecting more than 200 organizations and 5,000 consumer devices. The goal was not noise. It was persistent visibility.

Technical Tradecraft

The attack chain is simple and effective. The actors compromise routers, change DNS and DHCP settings, and push connected devices to use Russian-controlled resolvers. Most traffic can be watched quietly. Selected targets can be redirected.

The sharper risk is TLS interception. Forest Blizzard spoofed DNS responses for targeted domains, including Microsoft webmail. It then served bad certificates. If users clicked through the warning, the actor could read email and cloud traffic in plaintext.

The value is in the gap. Home routers, small-office routers, and remote-worker paths often sit outside enterprise EDR. The cloud account may be secure. The network edge may not be.

Messaging Application Targeting

Russian services are also targeting messaging accounts. FBI and CISA warned in March 2026 that Russian-linked actors had compromised thousands of commercial messaging accounts. Once inside, they could read messages, steal contacts, impersonate victims, and phish from trusted identities.

Google reported the same pressure against Signal. Actors abused the linked-device feature with malicious QR codes dressed as group invites, security alerts, pairing prompts, or Ukraine-themed apps. Once linked, the attacker could read future Signal messages in real time.

Microsoft saw Star Blizzard move into WhatsApp lures. Volexity saw suspected Russian actors use Signal and WhatsApp to push Microsoft 365 OAuth phishing. The pattern is clear. Russia is not only chasing accounts. It is chasing conversations, contacts, and trust.

Threat Level Assessment

The threat is highest for government, defense, critical infrastructure, telecom, energy, Ukraine-support organizations, journalists, NGOs, policy researchers, and other targets of likely intelligence value. These sectors align with Russian collection priorities and are most likely to face targeted exploitation after initial access.

Risk is also elevated for enterprises with remote or hybrid staff accessing Microsoft 365, webmail, VPN portals, cloud platforms, or sensitive collaboration tools from unmanaged home networks. For the broader private sector, the threat is moderate: router compromise may be broad, but follow-on exploitation appears selective and focused on victims with intelligence value.

Defensive Recommendations

Organizations should treat SOHO routers and remote-worker network paths as part of the attack surface. Replace end-of-life routers, patch firmware, disable remote administration, rotate router admin credentials, verify DNS settings, and monitor for unexpected resolvers. Remote-access policies should assume that home networks may be hostile.

For messaging applications, it is most important to prioritize linked-device hygiene. Users should regularly review linked devices in Signal, WhatsApp, and Telegram; remove unknown sessions; enable registration locks or PINs where available; and treat QR codes, group invites, “security alerts,” and video-call setup links as high-risk when received from sensitive contacts.

For enterprise identity, organizations should harden Microsoft 365 against OAuth and device-code phishing. Enforce phishing-resistant MFA, restrict risky OAuth consent flows, monitor anomalous device joins, review possible travel and token abuse, and train high-risk personnel not to return authentication codes to anyone.

Conclusion

Russian intelligence-linked cyber operations are moving closer to the communications layer. The objective is not immediate disruption. It is quiet access, persistent visibility, and control over the paths people use to communicate, authenticate, and coordinate.

The router and DNS hijacking activity shows the value of edge infrastructure. Compromised SOHO routers gave Russian operators a place to watch traffic, redirect selected victims, and intercept credentials without touching the endpoint. Messaging-platform targeting gave them the human layer: contacts, conversations, trusted names, and social relationships.

Together, these operations formed a durable intelligence-collection model. Broad compromise created scale. Selective follow-on targeting created value. Government, defense, critical infrastructure, Ukraine-support networks, journalists, NGOs, researchers, and political figures remained the highest-risk targets, while remote and hybrid workers widened the exposure path.

Now that this activity has been exposed, Russian operators will likely pivot again. They may shift infrastructure, rotate DNS and proxy methods, alter messaging lures, move to new linked-device abuse workflows, or lean harder into cloud identity and trusted-platform compromise. The collection requirement will remain. The access path will change.

The defensive lesson is direct. Organizations can no longer treat home routers, personal messaging apps, OAuth workflows, or linked-device features as outside the enterprise threat model. For Russian operators, these are not secondary surfaces. They are collection terrain. Once detected, that terrain will be reshaped, not abandoned.

Appendix A: MITRE ATT&CK Mapping

Initial Access/Persistence

Evasion and Credential Collection

Tactic Technique ID Observed Use
Initial Access Exploit Public-Facing Application T1190 Exploitation of vulnerable SOHO and TP-Link routers
Initial Access Phishing T1566 Messaging-app phishing and OAuth lure delivery
Initial Access Spearphishing Link T1566.002 Delivery of malicious OAuth/device-code URLs
Initial Access Valid Accounts T1078 Abuse of compromised messaging and cloud accounts
Execution User Execution T1204 Victim interaction with QR codes and phishing links
Persistence Account Manipulation T1098 Addition of linked devices to Signal accounts
Persistence External Remote Services T1133 Continued access through compromised cloud identities
Persistence Modify Authentication Process T1556 OAuth workflow abuse and session persistence
Privilege Escalation Abuse Elevation Control Mechanism T1548 Router administrative compromise and configuration manipulation
Defense Evasion Proxy T1090 DNS and AiTM proxy routing
Defense Evasion Impair Defenses T1562 Operating outside enterprise EDR visibility
Credential Access Adversary-in-the-Middle T1557 TLS interception and DNS redirection
Credential Access Steal or Forge Authentication Certificates T1649 Use of fraudulent/invalid TLS certificates
Credential Access Input Capture T1056 Credential interception via redirected authentication flows
Credential Access Credentials from Password Stores T1555 Interception of stored or synced credentials
Discovery Network Service Discovery T1046 Reconnaissance through DNS visibility
Discovery System Network Configuration Discovery T1016 Observation of network and resolver configurations
Discovery Gather Victim Identity Information T1589 Collection of contact lists and identity relationships
Discovery Gather Victim Network Information T1590 DNS and routing visibility collection
Collection Email Collection T1114 Interception of Outlook Web Access traffic
Collection Audio Capture T1123 Potential collection through compromised communication workflows
Collection Data from Information Repositories T1213 Access to cloud-hosted communications
Collection Screen Capture T1113 Potential follow-on account monitoring activities
Collection Data from Cloud Storage T1530 Microsoft 365 and cloud-message access
Command and Control Application Layer Protocol T1071 DNS- and HTTPS-based communications
Command and Control Encrypted Channel T1573 Use of TLS/HTTPS transport
Command and Control Dynamic Resolution T1568 Actor-controlled DNS infrastructure
Exfiltration Exfiltration Over Web Service T1567 Cloud-account data access and exfiltration
Impact Network Denial of Service T1498 Potential latent capability through router control
Impact Hijack Execution Flow T1574 DNS response manipulation and traffic redirection
Learn More
Research
Threat Intelligence Report: ZionSiphon OT Malware First Attempts? Psyops? Both?

Analysis of ZionSiphon (SCADA_SecurityPatch_v8.4.exe), a .NET OT malware targeting Israeli water utilities. Discover its IOCs, targets, and flawed activation code.

Executive Summary

ZionSiphon is a malware sample (“SCADA_SecurityPatch_v8.4.exe”) that has been circulating in public sandboxes since 2025. It is best understood as a Windows-based implant with explicit industrial control system (ICS) targeting intent but with a critical limitation in its verification of geographic data that fundamentally constrains its operational viability. While earlier analysis established the malware as functionally capable at the host level, subsequent findings confirm the presence of a critical XOR bug in its geographic validation logic, preventing the payload from activating in its intended environment. Additionally, there is no evidence of vendor-specific protocol handling, no confirmed register mapping, and no interaction with PLC firmware or engineering toolchains. The malware appears to rely on file-based or high-level configuration manipulation, which may not translate into actual process changes in most industrial environments.

The malware’s architecture remains coherent and deliberate. It combines geographic scoping, environment-aware execution, and embedded process manipulation logic, demonstrating a structured conceptual model of water treatment and desalination systems. Its internal string corpus provides high-confidence evidence of targeting, including references to Mekorot and major desalination facilities such as Sorek, Hadera, Ashdod, Palmachim, Shafdan, and Eilat water plants in Israel, alongside a dense vocabulary covering reverse osmosis, chlorine dosing, and salinity control. Filesystem-based validation and vendor-associated paths further reinforce that the malware is engineered to identify and operate within specific industrial environments.

However, the XOR validation flaw introduces a decisive constraint. The malware is designed to restrict execution to Israeli (“IL”) network ranges and to self-destruct if those conditions are not met. Due to the encoding error, this validation check never evaluates as true, meaning the malware fails to recognize its target environment even when present. As a result, the payload does not progress to its process manipulation stage and instead frequently triggers its own cleanup routines. This explains previously observed inconsistent or absent execution behavior: rather than reflecting conditional activation alone, it represents a systemic failure in the activation pathway.

The intended sabotage model remains conceptually clear despite this failure. ZionSiphon includes embedded parameters designed to manipulate critical control points, such as increasing chlorine dosing and altering reverse osmosis pressure, and contains references to industrial protocols including Modbus, DNP3, and S7comm. These elements demonstrate an understanding of how disruption could be achieved within water treatment systems. However, these attempts are just that. The malware does not contain actual ICS code that would attempt to effect those changes. What it does do, is attempt to do so through the manipulation of the OT layer (e.g. the Windows machines that the malware is detonated on to change those levels in the front end)  However, because the activation condition cannot be satisfied, this logic remains dormant and unexecuted, reinforcing that the malware is not currently capable of delivering physical-world impact.

This reframes the malware’s maturity. ZionSiphon operates entirely at the Windows host layer, using registry persistence, PowerShell-based execution, and USB-oriented propagation logic. It is a real, functioning implant in terms of execution mechanics, but the XOR bug prevents it from transitioning into an active sabotage phase, rendering it effectively non-operational as an ICS attack tool.

Compounding this limitation is the absence of any meaningful communication stack or command-and-control (C2) channel. The malware assessed (SCADA_SecurityPatch_v8.4.exe)

does not maintain operator connectivity, does not receive tasking, and cannot adapt its behavior dynamically once deployed. This removes the possibility of controlled, iterative interaction with target systems, an essential component of any serious ICS attack capability.

As a result, even in a hypothetical scenario where the activation flaw did not exist, the operational model would still be extremely constrained. The malware behaves more like a single-shot, pre-scripted payload than a coordinated intrusion tool. In practical terms, this resembles a “drive-by” action with no ability to correct aim, adjust targeting, or respond to environmental feedback and in this case, executed with insufficient precision to achieve its intended effect.

In its present form, ZionSiphon is therefore more accurately categorized as a prototype, misconfigured payload, or intentionally constrained artifact, rather than a deployable cyber-physical weapon. Its structure demonstrates intent and conceptual targeting, but lacks the control, reliability, and feedback mechanisms required for sustained or meaningful impact on water infrastructure systems.

An additional dimension now strengthens this interpretation: the nature of the code itself. The malware exhibits a pattern of semantically rich but technically shallow ICS logic, where process terminology and targeting concepts are convincing, but underlying implementation depth is limited. This includes incomplete protocol handling, an absence of PLC-resident execution, and a lack of deterministic control paths. Combined with the presence of a critical logic error in a core validation function, this suggests a development process that may have incorporated partial automation or assisted code generation, rather than rigorous engineering validation. While not determinative, the structure is consistent with a scenario in which elements of the code, particularly naming conventions, scaffolding, or ICS-related logic may have been augmented through LLM-style assistance, while overall assembly and operational framing remain human-directed.

The presence of explicit ideological messaging embedded within the binary further complicates interpretation. Decoded content referencing attacks on Israeli population centers introduces a clear narrative and psychological layer that is independent of technical execution. When combined with a payload that cannot activate and a second stage that cannot execute past the Windows host, this raises the possibility that the malware functions, at least in part, as a PSYOP-adjacent artifact, where the objective is to project capability, signal intent, and shape perception rather than achieve immediate operational effect.

From a capability perspective, ZionSiphon still reflects an early-stage attempt to approximate a Stuxnet-like attack model, leveraging a Windows foothold to influence industrial processes. However, the combination of incomplete ICS integration, execution fragility, and the XOR validation failure indicates that it falls well short of a reliable implementation. Whether this reflects immature development, operator error, or deliberate constraint remains unresolved, but it clearly places the malware within a mid-tier or experimental development context.

The most accurate interpretation is therefore layered:

  • Technical Layer: A real Windows-based malware implant with coherent targeting logic
  • Capability Layer: Non-functional as an ICS weapon due to a critical validation flaw
  • Development Layer: Likely a prototype or partially validated build, with possible assisted code generation elements
  • Psychological Layer: Potential signaling artifact, where perceived capability exceeds actual execution

ZionSiphon should therefore be understood as a conceptually mature but functionally broken ICS-targeting malware, whose significance lies less in its current operational capability and more in what it reveals about the evolving accessibility, modularity, and perception-driven use of cyber-physical attack tooling.

Malware Analysis: SCADA_SecurityPatch_v8.4.exe

ZionSiphon (SCADA_SecurityPatch_v8.4.exe), as understood by the malware sample from 2025, is best understood as a Windows-hosted operational malware implant built around explicit OT and water-sector targeting intent rather than a purely conceptual or symbolic artifact. The cumulative evidence gathered through static reverse engineering, sandbox telemetry, recovered string analysis, and vendor reporting materially reduces earlier uncertainty about the malware’s purpose and operational model. The sample is a PE32 Mono/.NET executable that relies on the Common Language Runtime (mscoree.dll) for execution, placing its logic entirely within the Windows host layer rather than within PLC firmware or native controller environments. Architecturally, this positions ZionSiphon as host-based OT intrusion tooling designed to compromise operator or engineering workstations as the pathway toward potential process disruption.

The malware’s execution workflow is internally coherent and operationally plausible. Embedded identifiers and execution strings including RunAsAdmin, SystemHealthCheck, Start-Process -Verb RunAs, target_verify.log, and delete.bat map to a structured lifecycle involving privilege escalation, persistence, environment validation, and cleanup. Hybrid Analysis telemetry confirmed that the sample stages itself into %LOCALAPPDATA%\svchost.exe, establishes persistence through the current-user Run registry key under SYSTEMHEALTHCHECK, and invokes cleanup routines through batch execution if execution conditions are not met. The masquerading of the payload as svchost.exe reflects recognizable adversary tradecraft intended to blend into legitimate Windows process naming conventions rather than functioning as a placeholder or incomplete concept.

The strongest evidence of deliberate targeting lies within the malware’s environment modeling and industrial process references. The binary contains extensive water-sector-specific configuration names and file paths including C:\ChlorineControl.dat, C:\DesalConfig.ini, C:\RO_PumpSettings.ini, C:\SalinityControl.ini, and C:\WaterTreatment.ini, alongside references to industrial and desalination-associated entities such as Schneider Electric, IDE Technologies, and WaterGenix. These are not generic enterprise strings or superficial theming elements. Instead, they reflect a logically structured representation of desalination and water-treatment operational environments. Additional managed-code identifiers including IncreaseChlorineLevel, IsDamDesalinationPlant, GetProcesses, and CreateUSBShortcut further demonstrate that the malware was designed to enumerate processes, validate target environments, and interact with removable media in ways consistent with industrial intrusion workflows.

The sabotage-oriented process logic embedded in the sample reinforces this assessment. Strings such as Chlorine_Dose=10, Chlorine_Flow=MAX, Chlorine_Pump=ON, Chlorine_Valve=OPEN, and RO_Pressure=80 define a conceptual model for manipulating chemical dosing and reverse-osmosis pressure systems. These parameters correspond to operationally sensitive functions within water-treatment infrastructure and imply an intent to push process variables into potentially disruptive or unsafe states. While there is no evidence that the malware contains mature PLC-specific payload delivery or ladder-logic manipulation capability, the embedded logic clearly moves beyond espionage-oriented collection tooling and into the domain of intended process interference.

At the same time, the malware remains technically constrained and immature when compared to fully operational ICS-native malware families such as Stuxnet, TRITON, Industroyer, or IOCONTROL. Although the sample references industrial protocols including Modbus and DNP3, there is still no evidence of complete protocol implementation, vendor engineering software integration, PLC firmware interaction, or safety-system manipulation. Hybrid Analysis telemetry also confirmed the absence of meaningful DNS resolution, outbound HTTP traffic, or operational command-and-control communications during execution. Despite containing networking functionality through .NET TcpClient, socket APIs, and connection-handling routines, the malware did not demonstrate active beaconing or remote tasking behavior. This strongly suggests an autonomous or pre-scripted execution model in which actions are triggered locally through environment validation rather than controlled dynamically through external infrastructure.

The detonated filename itself further reinforces this operational model. The use of naming the file SCADA_SecurityPatch_v8.4.exe strongly suggests deliberate masquerading as a legitimate industrial software update or maintenance utility. Combined with the extensive OT-themed naming conventions and water-sector references embedded throughout the sample, this creates a highly plausible watering-hole or trusted-update delivery scenario. Under such a model, attackers could establish a malicious website or compromised vendor portal advertising a supposed SCADA or water-treatment software patch and direct operators or engineers toward it through spear-phishing or industry-themed communications. Once executed, the malware could establish persistence, validate the target environment, and opportunistically seed removable media for downstream propagation into more sensitive operational enclaves.

Execution gating and cleanup behavior further support the conclusion that the malware was designed for selective deployment rather than indiscriminate execution. The presence of target_verify.log, environment-validation logic, Israeli IP-range geofencing, and cleanup mechanisms such as delete.bat indicate that the malware evaluates its environment before activating fully and removes artifacts if conditions are not satisfied. This reflects a controlled operational philosophy intended to minimize exposure and reduce forensic visibility outside intended targets.

Overall, ZionSiphon occupies an unusual position within the spectrum of OT malware. It is substantially more operationally coherent than simple propaganda or proof-of-concept malware and demonstrates a complete host-level intrusion lifecycle including privilege escalation, persistence, environment validation, removable-media interaction, and cleanup. At the same time, it lacks the mature ICS-native functionality associated with the most sophisticated cyber-physical malware families. The result is a malware framework that appears operationally credible at the Windows host layer and explicitly aligned toward water-sector disruption, while still remaining developmental, partially constrained, and dependent on contextual execution and human-assisted propagation to achieve meaningful operational impact.

Actor Assessment and Strategic Framing

Attribution remains unconfirmed. The available evidence supports a plausible Iranian nexus, but it does not prove that ZionSiphon was created or deployed by an Iranian state actor, an Iranian proxy, or any specific Iranian APT cluster. The malware’s target selection, embedded references to Israeli water infrastructure, and decoded anti-Israel messaging align with operational themes long associated with Iranian cyber activity directed at Israeli civilian infrastructure. Public reporting also places the malware in the context of Israeli water-treatment and desalination targeting.

Within that frame, the best technical fit is still a mid-tier, MOIS-aligned ecosystem such as MuddyWater or a related contractor/proxy environment, rather than a top-tier bespoke ICS weapons program. The sample’s architecture is a managed PE32 Mono/.NET executable that runs through mscoree.dll, stages itself as %LOCALAPPDATA%\svchost.exe, persists via the SystemHealthCheck Run key, elevates through PowerShell using Start-Process -FilePath ... -Verb RunAs, and cleans up through delete.bat and target_verify.log. That pattern is closer to commodity or lightly customized Iranian tradecraft than to a highly specialized controller-native platform. The Falcon Sandbox report also confirms a malicious score, registry persistence, self-deletion behavior, guarded-memory anti-analysis features, Base64 decoding capability, and the absence of relevant DNS, HTTP, or contacted-host infrastructure.

At the same time, the malware does not exhibit the hallmarks of a mature ICS weapon. It contains water-sector process logic, industrial vocabulary, and protocol references, but no demonstrated PLC-resident code, no ladder-logic manipulation, no vendor-specific engineering-stack abuse, no validated register maps, and no deterministic command path into real control systems. Public reporting similarly describes it as a targeted OT/ICS malware strain aimed at Israeli water systems, but not as a proven Stuxnet- or TRITON-class capability. The most defensible technical reading is that this is a Windows-hosted OT sabotage implant whose ICS layer is still incomplete, experimental, or intentionally simplified. (Darktrace)

The strongest evidence for an Iran-aligned framing comes from the decoded strings. The sample contains extensive water/OT targeting strings tied to Israeli infrastructure and desalination operations, including facility and environment markers such as Mekorot, Sorek, Hadera, Ashdod, Palmachim, Shafdan, and Eilat Desal, alongside control-oriented terms such as DesalPLC, OsmosisPLC, WaterPLC, ChlorineCtrl, ChlorineDose, RO_Pump, and BrineControl. More importantly, the decoded ideological content includes the explicit line “Poisoning the population of Tel Aviv and Haifa”, and the malware also contains an execution-guardrail message reading “Target not matched. Operation restricted to IL ranges. Self-destruct initiated.” These strings materially strengthen the assessment that the malware is framed as anti-Israel and specifically oriented toward Israeli water infrastructure.

However, those same strings are also the clearest reason not to overstate attribution. Ideological text that points toward Iran and against Israel can support an Iran-aligned hypothesis, but it can also function as attribution theater. An actor seeking to implicate Iran, exaggerate Iranian capability, or exploit existing expectations about Iranian cyber behavior could deliberately embed precisely these kinds of messages. The sample’s combination of overt anti-Israel language, Israeli geofencing, Mekorot branding, and incomplete ICS execution depth is consistent not only with a genuine Iranian capability in development, but also with a scenario in which another actor is muddying the water by constructing a malware artifact that looks Iranian on first inspection. In that sense, the ideological layer is evidentiary, but not dispositive.

That ambiguity is especially important because ZionSiphon also reads as an early attempt at a Stuxnet-like attack path against Israel, but without Stuxnet-like engineering maturity. The malware clearly models cyber-physical effects: it hunts for desalination and treatment artifacts, references Modbus and DNP3, and embeds static sabotage values such as Chlorine_Dose=10, Chlorine_Flow=MAX, Chlorine_Pump=ON, Chlorine_Valve=OPEN, and RO_Pressure=80. It is trying to move from a Windows foothold on operator or engineering systems into process disruption. That is strategically significant. But the implementation still falls well short of a real, deterministic industrial attack platform, which makes it plausible both as a prototype capability and as a signaling artifact meant to invoke the idea of an Iranian Stuxnet-for-Israel scenario.

The Falcon Sandbox findings reinforce the dual-use interpretation. The sample is operationally real at the host level: it persists, stages, executes, validates the environment, and self-cleans. But it shows no relevant DNS requests, no relevant HTTP traffic, and no relevant contacted hosts, which means there is no public evidence of a live C2-backed campaign around this sample. That absence supports the view that ZionSiphon is either a self-contained, pre-scripted sabotage implant or a demonstration artifact whose strategic value derives partly from being discovered and analyzed.

The most accurate conclusion is therefore deliberately layered. ZionSiphon may well be consistent with MOIS-linked Iranian operational patterns, and MuddyWater remains the closest tradecraft fit among known Iranian clusters. But there is still no real proof that an Iranian actor built it, and the available data also supports the possibility that another actor intentionally embedded Iran-supporting and anti-Israel text to create exactly that impression. In practical terms, ZionSiphon should be understood as a hybrid artifact: a real host-based malware implant with clear OT sabotage intent, a likely experimental or early-stage attempt to approximate a Stuxnet-like attack path against Israeli infrastructure, and a possible PSYOP or attribution-shaping tool whose ambiguity may itself be part of its operational effect.

Detection Profile and Operational Maturity Assessment

Integration of multi-source analysis including static reverse engineering of the uploaded samples, sandbox telemetry from ANY.RUN and Hybrid Analysis, and detection data from VirusTotal provides a consolidated view of ZionSiphon’s true position within the threat landscape. The resulting picture is not ambiguous: the malware is operationally real at the host-implant layer, but its ICS disruption capability remains unproven and likely immature in its current form.

From a detection standpoint, VirusTotal confirms that the sample is broadly recognized as malicious across multiple engines. However, the classification is inconsistent and generic, with most vendors labeling the file as a .NET or MSIL-based trojan, loader, or agent. There is no consensus naming, and critically, no engine identifies the sample as ICS malware or associates it with industrial protocol abuse. This absence is not incidental. It indicates that the malware’s OT-specific logic is not driving its detection profile. Instead, detection is triggered by conventional behaviors, such as PowerShell-based execution, registry persistence, process masquerading, and general suspicious activity, placing ZionSiphon firmly within the detection envelope of commodity Windows malware.

This observation aligns directly with the static and dynamic analysis of the binary. Reverse engineering confirms that the sample is a Mono/.NET executable with a minimal import table and all functional logic embedded internally. The malware establishes persistence through a Run key (SystemHealthCheck) pointing to a disguised payload (svchost.exe), relaunches itself with elevated privileges via PowerShell, and implements cleanup routines using delete.bat and target_verify.log. These behaviors are not theoretical; they are consistent across sandbox environments and embedded directly in the binary. The implant layer is therefore fully functional and operationally credible, with no indication of being a placeholder or decoy.

Where the assessment becomes more complex is at the ICS interaction layer. The binary contains extensive water-sector targeting artifacts, including configuration paths, process identifiers, and explicit manipulation strings such as Chlorine_Dose=10, Chlorine_Flow=MAX, and RO_Pressure=80. These elements demonstrate clear intent to interfere with water treatment processes, particularly chemical dosing and pressure regulation. However, the implementation lacks the depth required for reliable real-world execution

Dynamic analysis reinforces this limitation. Execution behavior varies significantly between sandbox runs, with some environments exhibiting full persistence and artifact creation, while others produce minimal activity or even a “no threat detected” verdict. This inconsistency suggests that the malware is highly dependent on environmental conditions, potentially due to validation gating, incomplete code paths, or anti-analysis mechanisms. While this behavior could be interpreted as evasive design, it also introduces uncertainty regarding execution reliability, particularly in non-laboratory conditions.

The broader implication is that ZionSiphon occupies a hybrid position between commodity malware and specialized OT tooling. Its underlying framework is indistinguishable from generic .NET malware, as confirmed by both imphash clustering and VirusTotal classification. Its distinguishing features, the ICS targeting logic and sabotage intent, are layered on top of this framework but are not yet expressed in a technically mature or reliably executable form. This architectural choice provides flexibility and ease of development but limits the malware’s ability to achieve consistent physical impact.

From an operational perspective, the malware is highly likely to succeed in compromising Windows-based systems, particularly those associated with engineering or supervisory functions in water-sector environments. It can persist, execute, and perform environment validation with high confidence. It may also disrupt local applications or introduce configuration inconsistencies that affect operator workflows. However, the probability that it can directly and reliably manipulate physical processes such as chlorine dosing or system pressure—remains low without further development or environment-specific customization.

This duality is central to understanding ZionSiphon. It is not a non-functional artifact, nor is it a mature ICS weapon. It is a functional host-based implant with embedded, but not yet fully realized, OT disruption logic. Its current form suggests either an early-stage capability under development or a modular framework intended for future enhancement. In either case, the gap between intent and execution is evident.

The most defensible conclusion is that ZionSiphon represents a transitional class of malware, bridging traditional IT compromise and potential OT impact. Its significance lies less in its immediate effectiveness and more in what it signals: that targeted, domain-aware cyber-physical tooling can be constructed using relatively accessible components. While it does not yet demonstrate the precision or reliability of established ICS malware families, it provides a clear indication of direction toward more modular, adaptable, and potentially proliferating OT-focused threats.

Strategic Assessment and Forward Outlook

ZionSiphon is best understood as a targeted ICS sabotage capability in development, combining deliberate, domain-aware targeting logic with a modular and reusable technical foundation. The accumulated evidence of static analysis, sandbox telemetry, and decoded string corpus confirms that the malware encodes a coherent conceptual model of water treatment operations, particularly chlorine dosing and reverse osmosis control. At the same time, it relies on a commodity Windows/.NET implant layer for execution, persistence, privilege escalation, and delivery. This hybrid construction places the malware in a transitional category: operationally real and credible at the host level, but not yet reliably effective at the control-system level.

The broader strategic context reinforces this interpretation, while also introducing a critical layer of ambiguity. Since 2025, Israeli water infrastructure, especially systems associated with Mekorot, has remained a recurring target in cyber operations and reporting. ZionSiphon fits squarely within that targeting pattern, including its geographic scoping to Israeli networks and its explicit references to desalination facilities and water-treatment processes. However, there is still no publicly confirmed instance of successful cyber-induced physical disruption to these systems in the current reporting cycle. This persistent gap between targeting intensity and observable impact is analytically significant. It highlights both the priority placed on this sector and the continued limitations of adversary capabilities.

ZionSiphon embodies that gap directly. Its embedded parameter manipulation strings, process-specific vocabulary, and environment validation logic clearly demonstrate intent to influence physical processes. Yet its reliance on static configuration assumptions, incomplete industrial protocol handling, absence of validated PLC interaction, and environment-dependent execution behavior indicate that it is not yet a mature or deterministic ICS weapon. In its current form, the malware is more likely to produce host-level compromise, configuration disruption, and operational friction than sustained or precise control over industrial processes.

At the same time, the sample introduces an additional dimension that materially affects its strategic interpretation: the presence of explicit ideological messaging and narrative cues embedded within the binary. These elements are not required for execution and instead serve a signaling function, shaping how the malware is interpreted once discovered. Combined with its Israeli targeting, they create an artifact that is not purely technical. This opens the possibility that ZionSiphon is functioning in part as a PSYOP-adjacent tool, where perception of capability and intent is itself an operational objective. Importantly, while the messaging aligns with Iran-aligned narratives, there is no definitive proof that the malware originates from an Iranian actor. The same elements that support an Iranian attribution hypothesis could also be deliberately constructed by another actor to mimic, exaggerate, or redirect attribution, effectively muddying the waters.

From a capability perspective, ZionSiphon also reads as an early-stage attempt to approximate a Stuxnet-like attack model, but within a far less mature development ecosystem. It follows the same broad conceptual pathway leveraging a Windows foothold to reach and influence physical processes but lacks the deep engineering integration, protocol precision, and reliability that defined earlier state-developed ICS weapons. It is therefore best characterized as a process-aware prototype, reflecting ambition and direction rather than fully realized capability.

Despite its current limitations, the malware’s architecture carries significant forward-looking implications. By decoupling ICS-specific logic from the underlying implant, ZionSiphon reflects a modular design philosophy that enables rapid iteration and reuse. The Windows-based execution layer provides a stable foundation onto which increasingly sophisticated OT-specific components can be layered. Future variants could therefore evolve quickly, incorporating:

  • More complete protocol implementations (e.g., Modbus, DNP3, or vendor-specific interfaces)
  • Improved environment detection and targeting precision
  • Greater execution reliability and error handling
  • Limited feedback mechanisms or controlled tasking capabilities

Such evolution would move the capability from conceptual disruption toward repeatable and controllable operational effects, narrowing the current gap between intent and execution.

The most significant implication is structural rather than purely technical. ZionSiphon signals that cyber-physical attack development is becoming more accessible. Unlike earlier ICS malware such as Stuxnet, which required extensive resources, specialized engineering knowledge, and tightly integrated development pipelines, this model leverages widely available tooling and incremental domain understanding. The barrier to entry is therefore lower, enabling a broader range of actors including contractors, proxy groups, or semi-professional operators to experiment with OT-oriented malware development.

This shift also increases the likelihood of proliferation and adaptation. The same architectural model could be repurposed across sectors by substituting environment-specific logic, extending beyond water infrastructure into energy, manufacturing, or transportation systems. Even if ZionSiphon itself remains limited, it represents a template for iterative development, where successive improvements progressively close the gap between conceptual capability and operational effectiveness.

Finally, the dual-use nature of the malware remains strategically important. In an environment where no confirmed physical attacks have occurred despite persistent targeting, artifacts like ZionSiphon may serve not only as technical tools but also as instruments of signaling and perception management. Their discovery, analysis, and public reporting contribute to an evolving perception of cyber-physical threat capability, influencing defensive postures, policy responses, and strategic calculations.

ZionSiphon should therefore be understood not as a fully realized ICS weapon, but as a directional indicator: a hybrid artifact that combines real host-level capability, emerging cyber-physical intent, and potential psychological or attribution-shaping effects.

Appendix A – Indicators of Compromise: ZionSiphon / SCADA_SecurityPatch_v8.4.exe

File Hashes

Primary sample
Type Value
Filename SCADA_SecurityPatch_v8.4.exe
SHA256 07c3bbe60d47240df7152f72beb98ea373d9600946860bad12f7bc617a5d6f5f
MD5 9f6265271f0b04e98ed28e414a8eee91
File size 100 KiB / 102400 bytes
Type PE32 Mono/.NET executable
Compiler Microsoft visual C# v7.0 / Basic .NET
imphash f34d5f2d4577ed6d9ceec516c1f5a744
Dropped payload
Type Value
Filename svchost.exe
Path %LOCALAPPDATA%\svchost.exe
SHA256 07c3bbe60d47240df7152f72beb98ea373d9600946860bad12f7bc617a5d6f5f
MD5 eb89f018e6c3a8e9de0a0452acb16e76
SHA1 7cdcb8f372ceb7f5d3c178d9649080106a932f9e
Dropped cleanup script
Type Value
Filename delete.bat
Path %TEMP%\delete.bat
Size 121 bytes
SHA256 2537628e68a35124cad1c935634e70c90a62801403cbb427b262ff9ced03384a
MD5 b18baa0a3bfcdf52bef58ded9402889b
Dropped validation log
Type Value
Filename target_verify.log
Path %TEMP%\target_verify.log
Size 79 bytes
SHA256 d3b4737095600c1d87f0354d8246a1d4a22c737b92a9ec62571f8330cfd03c05
MD5 6a27e9439fa40cb89ee341133b03e4db

Host-Based Indicators

Files and artifacts
C:\SCADA_SecurityPatch_v8.4.exe
%LOCALAPPDATA%\svchost.exe
%TEMP%\delete.bat
%TEMP%\target_verify.log
C:\SCADA_SecurityPatch_v8.4.exe.config
C:\SCADA_SECURITYPATCH_V8.4.EXE.CONFIG
C:\SCADA_SecurityPatch_v8.4.INI
Persistence
Registry key HKCU\Software\Microsoft\Windows\CurrentVersion\Run
Value SYSTEMHEALTHCHECK
Data %LOCALAPPDATA%\svchost.exe
Notes Hybrid observed the persistence copy from C:\SCADA_SecurityPatch_v8.4.exe to %LOCALAPPDATA%\svchost.exe and creation of the SYSTEMHEALTHCHECK Run key.

A.3 Execution and Runtime Indicators

RunAsAdmin cmd.exe /c "%TEMP%\delete.bat"
SystemHealthCheck CreateNoWindow
Start-Process -FilePath UseShellExecute
-Verb RunAs ProcessStartInfo
target_verify.log GetExecutingAssembly
delete.bat
Mutex
GUID {A1234567-B89C-40D1-ABCD-1234567890EF}
Path \Sessions\1\BaseNamedObjects\{A1234567-B89C-40D1-ABCD-1234567890EF}


A.4 Process and Environment Indicators

Process / host discovery
gethostname GlobalMemoryStatusEx
GetHostName QueryPerformanceCounter
GetCurrentProcess RtlGetVersion
GetProcesses GetVersionExA
get_ProcessName IsWow64Process
CreateToolhelp32Snapshot WindowsIdentity.GetCurrent
NtQuerySystemInformation CheckTokenMembership
GetSystemMetrics OpenProcessToken
GetSystemInfo
Environment and anti-analysis
IsDebuggerPresent OOBEINPROGRESS
NtQuerySystemInformation SYSTEMSETUPINPROGRESS
vboxguestadditions MACHINEGUID
VBoxGuest PREFERREDUILANGUAGES

Hybrid mapped the sample to execution guardrails, sandbox/VM checks, host discovery, process enumeration, and language/locale discovery.

A.5 Water / OT Targeting Indicators

Process name checks
DesalPLC OsmosisPLC
ROController DesalMonitor
SchneiderRO RO_Filter
DamRO ChlorineDose
ReverseOsmosis RO_Membrane
WaterGenix DesalFlow
RO_Pump WaterTreat
ChlorineCtrl SalinityCtrl
WaterPLC
SeaWaterRO
BrineControl
Directory checks
C:\Program Files\Desalination C:\Program Files\RO Systems
C:\Program Files\Schneider Electric\Desal C:\Program Files\DesalTech
C:\Program Files\IDE Technologies C:\Program Files\Aqua Solutions
C:\Program Files\Water Treatment C:\Program Files\Hydro Systems
Configuration file checks
C:\DesalConfig.ini C:\WaterTreatment.ini
C:\ROConfig.ini C:\ChlorineControl.dat
C:\DesalSettings.conf C:\RO_PumpSettings.ini
C:\Program Files\Desalination\system.cfg C:\SalinityControl.ini
Facility / sector strings
Mekorot Shafdan
Sorek Schneider Electric
Hadera IDE Technologies
Ashdod WaterGenix
Palmachim

Hybrid file metadata also lists ProductName and FileDescription as Mekorot, reinforcing the Israeli water-sector masquerade.

A.6 Configuration Manipulation Indicators

Chlorine_Dose 10
Chlorine_Pump ON
Chlorine_Flow MAX
Chlorine_Valve OPEN
RO_Pressure 80

These remain high-confidence impact-oriented strings tied to chlorine handling and reverse-osmosis pressure manipulation.

A.7 Network and Protocol Indicators

Network APIs and socket capability

Hybrid confirms socket capability but also reports:

Network APIs
System.Net NetworkStream.Read
System.Net.Sockets NetworkStream.Write
TcpClient TcpClient.Close
TcpClient.Connect WSAStartup
TcpClient.BeginConnect setsockopt
TcpClient.GetStream gethostbyname
GetAddrInfoW
Network activity
No relevant DNS requests
No relevant contacted hosts
No relevant HTTP requests

This supports the assessment that no operational C2 was observed during detonation.

Industrial protocol references

Protocol / pattern Bytes
Modbus
DNP3
S7comm
Modbus request pattern 01 03 00 00 00 0A
DNP3 partial pattern 05 64 0A 0C 01 02
S7comm partial pattern 03 00 00 13 0E 00
S7comm partial pattern 05 00 1C 22 1E

A.8 Targeting and Geofencing Indicators

IPv4 ranges observed in binary/memory
2.52.0.0 – 2.55.255.255
5.28.0.0 – 5.29.255.255
79.176.0.0 – 79.191.255.255
212.150.0.0 – 212.150.255.255

Hybrid directly reported the 2.52.0.0-2.55.255.255 and 5.28.0.0-5.29.255.255 ranges as potential IP ranges in binary/memory.

A.9 USB / Removable-Media Propagation Indicators

Recovered strings and behavioral primitives
CreateUSBShortcut SetAttributes
DriveInfo .lnk
GetLogicalDrives shell32.dll
GetFiles svchost.exe
CopyFileW
CopyFileExW
Assessed removable-media artifacts
\svchost.exe
*.lnk files in root of removable media
Shortcut TargetPath pointing to hidden executable
Icon spoofing via shell32.dll,4

Hybrid confirms GetLogicalDrives, file-copy behavior, and file-attribute capability, but did not capture a complete successful USB infection event during detonation. Therefore, USB propagation should be treated as strongly supported by strings and vendor reverse engineering, not as a fully observed sandbox behavior.

A.10 Self-Deletion and Cleanup Indicators

Cleanup artifacts
%TEMP%\delete.bat
cmd.exe /c "%TEMP%\delete.bat"
Observed deletion targets
C:\SCADA_SecurityPatch_v8.4.exe
%TEMP%\delete.bat

Hybrid observed cmd.exe executing %TEMP%\delete.bat and marking both the original sample and cleanup script for deletion.

A.11 MITRE-Relevant Behavioral Indicators

Technique ID Name
T1055 Process Injection
T1055.002 Portable Executable Injection
T1059.003 Windows Command Shell
T1070.004 File Deletion
T1070.009 Clear Persistence
T1082 System Information Discovery
T1083 File and Directory Discovery
T1105 Ingress Tool Transfer
T1106 Native API
T1112 Modify Registry
T1134 Access Token Manipulation
T1222 File and Directory Permissions Modification
T1480 Execution Guardrails
T1497.001 Virtualization/Sandbox Evasion
T1547.001 Registry Run Keys / Startup Folder
T1564.003 Hidden Window
T1622 Debugger Evasion


A.12 Negative Indicators / Absence-Based Intelligence

/

No confirmed C2 domains
No confirmed callback IPs
No observed DNS requests
No observed HTTP requests
No observed contacted hosts
No confirmed phishing infrastructure
No confirmed delivery infrastructure

No confirmed fully executed USB infection event in sandboxThese negative indicators suggest a constrained or pre-operational deployment model, likely centered on local execution, environmental validation, and workflow-assisted movement rather than remotely tasked command-and-control.

APPENDIX B Static Reverse Engineering of the Uploaded Sample

The uploaded file, identified by SHA-256 07c3bbe60d47240df7152f72beb98ea373d9600946860bad12f7bc617a5d6f5f, is a PE32 Mono/.NET executable, indicating that all operational logic is implemented in managed code rather than native binaries. The import table is minimal and limited to the CLR bootstrap (mscoree.dll via _CorExeMain), which is characteristic of .NET malware that delegates functionality to internal assemblies. This structural choice confirms that the sample is a Windows-hosted implant, not a controller-resident ICS payload, and that its operational model depends on execution within userland environments such as engineering workstations or operator systems.

The binary exhibits a coherent and internally consistent execution model. Embedded strings and method identifiers indicate that the malware initiates execution by attempting to relaunch itself with elevated privileges through PowerShell, using a command pattern consistent with Start-Process -FilePath ... -Verb RunAs. This is followed by persistence establishment via the Windows registry. Specifically, the malware is designed to write a Run key under Software\Microsoft\Windows\CurrentVersion\Run using the value name SystemHealthCheck, pointing to a staged payload masquerading as svchost.exe within the user’s local application directory. This persistence mechanism is operationally credible and aligns with common masquerade techniques intended to blend malicious binaries with legitimate system processes.

The sample’s most distinctive feature is its environment validation logic, which is explicitly tailored to water treatment and desalination systems. The binary contains numerous hardcoded file paths and configuration filenames associated with industrial processes, including chlorine control, reverse osmosis, salinity regulation, and water treatment operations. These include paths such as C:\ChlorineControl.dat, C:\DesalConfig.ini, C:\RO_PumpSettings.ini, and C:\WaterTreatment.ini, as well as vendor- or application-associated directories such as C:\Program Files\Schneider Electric\Desal\config.ini and C:\Program Files\WaterGenix\system.conf. The presence of these strings indicates that the malware performs host-based reconnaissance to determine whether it is executing within a relevant operational environment before proceeding.

This validation stage is further reinforced by recovered method names such as IsDamDesalinationPlant, GetProcesses, and DriveInfo, which suggest a structured approach to system classification. The malware likely enumerates running processes, inspects filesystem artifacts, and evaluates system characteristics to determine whether the host is associated with desalination or water treatment infrastructure. Only upon successful validation does the malware proceed to its impact phase, indicating a gated execution model designed to minimize noise and avoid unintended activation.

The impact logic itself is revealed through a set of explicit configuration strings embedded in the binary. These include Chlorine_Dose=10, Chlorine_Flow=MAX, Chlorine_Pump=ON, Chlorine_Valve=OPEN, and RO_Pressure=80. These values correspond directly to operational parameters within water treatment systems and suggest that the malware is designed to modify or inject configuration data affecting chemical dosing and pressure control. While static analysis cannot confirm whether these values map precisely to real-world control systems, their specificity and coherence indicate a clear intent to disrupt physical processes, particularly those related to water quality and system stability.

In addition to its primary payload, the malware includes functionality for removable media interaction, as evidenced by strings such as CreateUSBShortcut, .lnk, and shell32.dll, 4. This suggests the ability to create deceptive shortcut files on USB drives, potentially enabling lateral movement or execution in segmented environments where direct network propagation is not feasible. This feature is consistent with operational environments in ICS networks, where air gaps or limited connectivity often necessitate physical transfer mechanisms.

The sample also implements a cleanup and self-deletion routine, using artifacts such as target_verify.log and delete.bat. These components indicate that the malware logs the outcome of its environment validation and, if conditions are not met or execution fails, initiates a self-removal process via a batch script. This behavior aligns with a low-footprint operational model, where the malware seeks to avoid detection by minimizing residual artifacts on non-target systems.

From a tradecraft perspective, the binary demonstrates a functional and intentional design. It includes persistence, privilege escalation, environment validation, removable media handling, and process-specific manipulation logic. These elements collectively support the assessment that the sample is a real and operational Windows-based implant, not merely a decoy or string-based artifact. However, the malware does not exhibit the characteristics of a mature ICS platform. There is no evidence of PLC firmware interaction, vendor-specific engineering tool manipulation, or deep integration with industrial control protocols at the controller level.

The most accurate classification is that this sample represents a host-side OT sabotage implant, designed to operate within Windows environments that interface with water treatment systems. Its strength lies in its targeting logic and process awareness, rather than in advanced ICS exploitation techniques. This places it in a transitional category of malware that bridges traditional IT compromise and OT disruption, relying on access to engineering or supervisory systems to influence physical processes.

Appendix D – Source Citations and References

Primary Malware Analysis Sources

  1. BleepingComputer
    “ZionSiphon malware designed to sabotage water treatment systems”
    https://www.bleepingcomputer.com/news/security/zionsiphon-malware-designed-to-sabotage-water-treatment-systems/
  2. Darktrace
    “Inside ZionSiphon: Darktrace’s analysis of OT malware targeting Israeli water systems”
    https://www.darktrace.com/blog/inside-zionsiphon-darktraces-analysis-of-ot-malware-targeting-israeli-water-systems

Malware Sample and Sandbox Analysis

  1. VirusTotal
    Sample Analysis – SHA256: 07c3bbe60d47240df7152f72beb98ea373d9600946860bad12f7bc617a5d6f5f
    https://www.virustotal.com/gui/file/07c3bbe60d47240df7152f72beb98ea373d9600946860bad12f7bc617a5d6f5f/details
  2. Hybrid Analysis
    Sample Report (primary)
    https://hybrid-analysis.com/sample/07c3bbe60d47240df7152f72beb98ea373d9600946860bad12f7bc617a5d6f5f
  3. Hybrid Analysis
    Imphash clustering results
    https://hybrid-analysis.com/search?query=imphash%3A%22f34d5f2d4577ed6d9ceec516c1f5a744%22
  4. ANY.RUN
    Dynamic Analysis Report (Malicious Activity)
    https://any.run/report/07c3bbe60d47240df7152f72beb98ea373d9600946860bad12f7bc617a5d6f5f/eab8c32e-48a0-4333-a962-6e4dced301b8
  5. ANY.RUN
    Dynamic Analysis Report (No Threat Detected Variant Execution)
    https://any.run/report/07c3bbe60d47240df7152f72beb98ea373d9600946860bad12f7bc617a5d6f5f/438f6689-1006-4a88-a870-70a392ceeaf8

ICS / OT Malware Comparative References

  1. FrostyGoop – Dragos
    “FrostyGoop ICS Malware Targeting Operational Technology”
    https://www.dragos.com/blog/protect-against-frostygoop-ics-malware-targeting-operational-technology
  2. Industroyer2 – Google Cloud (Mandiant)
    “Industroyer2: Old Malware, New Tricks”
    https://cloud.google.com/blog/topics/threat-intelligence/industroyer-v2-old-malware-new-tricks
  3. INCONTROLLER – Google Cloud (Mandiant)
    “INCONTROLLER: State-Sponsored ICS Tool”
    https://cloud.google.com/blog/topics/threat-intelligence/incontroller-state-sponsored-ics-tool
  4. TRITON – National Cyber Security Centre
    “TRITON Malware Targeting Safety Controllers”
    https://www.ncsc.gov.uk/information/triton-malware-targeting-safety-controllers
  5. Stuxnet – National Security Archive
    “Stuxnet Dossier”
    https://nsarchive2.gwu.edu/NSAEBB/NSAEBB424/docs/Cyber-044.pdf

ICS / OT Protocol and Architecture References

  1. InfoSec Institute
    ICS Protocol Overview (Modbus, DNP3, S7)
    https://www.infosecinstitute.com/resources/scada-ics-security/ics-protocols/
  2. Team Cymru
    Industrial Cybersecurity and OT Exposure
    https://www.team-cymru.com/post/industrial-cybersecurity-for-ics-and-ot-devices

Infrastructure and IP Attribution Context

  1. RIPE NCC
    IPv4 Allocation and Registration Data (Israel)
    https://www.ripe.net
  2. Bezeq
    https://www.bezeq.co.il
  3. Partner Communications Company
    https://www.partner.co.il
  4. Cellcom
    https://www.cellcom.co.il

Water Infrastructure Context

  1. Mekorot
    https://www.mekorot.co.il
  2. Israel Water Authority
    https://www.gov.il/en/departments/water_authority

Learn More
Research
Threat Intelligence Report: The SDA / Structura / Doppelgänger, Influence Operations, Infrastructure, Reach, and Potential

How does the Doppelgänger influence campaign reach 5M+ users? Read DTI’s latest report on the SDA/Structura ecosystem, featuring a deep dive into narrative propagation, domain rotation tactics, and a 72-hour crisis influence timeline.

Executive Summary

The Doppelgänger (aka Social Design Agency (SDA)) campaigns are a coordinated series of online influence operations attributed to Russian-linked actors and associated with the technical operator, Structura. The campaign leverages a distributed ecosystem of spoofed media websites, Telegram amplification networks, and coordinated X/Twitter bot account clusters to disseminate political narratives targeting Western audiences.

The operational architecture is designed around a feeder-and-amplifier model. Controlled websites host narrative artifacts such as articles, memes, and commentary. These artifacts are distributed through Telegram channels with large subscriber bases and are subsequently injected into active discussions on X through coordinated reply swarms.

This architecture enables the campaign to scale rapidly while maintaining resilience against disruption. Domain infrastructure can be regenerated quickly, social accounts are disposable, and narratives can be redistributed through independent amplification channels.

Analysis of subscriber counts and documented campaign activity suggests that a typical Doppelgänger narrative wave exposes approximately 1.5 to 2.7 million users, with larger event-driven campaigns potentially reaching 3 to 5 million users.

The campaign’s objective is not necessarily direct persuasion but narrative saturation, in which repeated exposure across multiple platforms introduces and normalizes targeted narratives within the information ecosystem.

Actor and Organizational Structure

The operational structure of the Doppelgänger influence campaign reflects a coordinated system that combines strategic messaging organizations, technical infrastructure providers, and elements associated with Russia’s broader state-directed political communication environment. At the center of this ecosystem are two entities that appear to play complementary roles: the Social Design Agency (SDA) and Structura. Together, these organizations form the operational core of the campaign’s architecture, linking narrative development with the technical systems required to publish, distribute, and amplify influence content across multiple digital platforms.

The Social Design Agency (SDA) appears to function as the primary strategic and operational planning body behind the campaign. Open-source investigations and public reporting have associated the organization with a number of large-scale information operations targeting audiences in Europe and North America. Within the Doppelgänger ecosystem, SDA’s role is assessed to focus on the design and coordination of narrative components that underpin the campaign’s messaging. This includes the development of thematic narratives, the planning and timing of coordinated influence activities, and the orchestration of distribution through social 

media channels and affiliated amplification networks. SDA also appears to maintain relationships with technical service providers responsible for maintaining the infrastructure used to host and disseminate campaign content. In this capacity, the organization functions as the central coordinating entity that aligns narrative development, operational timing, and distribution strategies across the broader influence network.


Complementing this strategic function, Structura appears to provide the technical infrastructure that allows the campaign to operate at scale. Structura acts as the backbone of the Doppelgänger ecosystem by managing the digital assets used to publish, distribute, and track campaign narratives. Its responsibilities include the registration and administration of domains used for pseudo-media websites, the deployment and maintenance of the web infrastructure hosting campaign articles, and the operation of redirect systems that guide audiences from social media platforms to campaign-controlled sites. Structura is also believed to operate analytics and tracking capabilities that enable operators to measure engagement levels, monitor traffic patterns, and evaluate the performance of individual narratives. These capabilities support both operational resilience and adaptive campaign management, allowing infrastructure to be regenerated or replaced quickly when domains are seized, blocked, or otherwise disrupted.

Evidence from multiple public investigations further suggests that the Doppelgänger campaign operates within a broader ecosystem of Russian state-aligned information activities. Reporting has connected elements of the network to organizations and political communication structures associated with the Russian Presidential Administration, including the government-linked organization ANO Dialog and senior political figures such as Sergei Kiriyenko, who has been identified in public reporting as playing a significant role in coordinating domestic and international messaging initiatives. While the precise command relationships within this ecosystem are not fully transparent, these connections indicate that the operation likely functions within a wider strategic communications environment linked to Russian state interests.

Taken together, the interaction between SDA’s narrative planning and campaign coordination functions, Structura’s management of technical infrastructure, and the broader involvement of state-linked political communication structures suggests a coordinated operational model. Within this model, influence operations are integrated into a larger system of information confrontation. Inside the system, messaging strategy, technical infrastructure, and distribution networks are aligned to introduce and amplify narratives within the international information environment in ways that support broader geopolitical objectives.

Synthetic Media Personnel Structure (RRN Employee Layer)

Analysis of the ingested employee directory from Reliable Recent News provides direct insight into the constructed human layer underpinning the Doppelgänger ecosystem. In contrast to infrastructure or domain-based analysis, this dataset reveals how the operation systematically simulates a functioning media organization through a curated set of personnel, roles, and hierarchical relationships. This structure does not reflect a genuine workforce; rather, it constitutes a deliberately engineered organizational façade designed to support narrative attribution and reinforce perceived credibility.

The employee listing presents a fully developed newsroom hierarchy that closely mirrors legitimate Western media institutions, with an Editor-in-Chief at the apex, followed by senior and section editors, subject-matter analysts, and a base layer of journalists, correspondents, and contributors. The consistency and repeatability of this structure indicate a templated design rather than organic organizational growth, replicating the visual and procedural signals of editorial rigor, review, and domain expertise associated with credible outlets. In practice, these roles function primarily as perception management mechanisms: senior editors act as legitimacy anchors, analysts serve as authority proxies for geopolitical narratives, and journalists provide bylines that convert anonymous content into ostensibly reported material. Collectively, this framework simulates the full lifecycle of journalism analysis, reporting, editing, and publication without any underlying authentic process.

The identities themselves exhibit hallmarks of synthetic construction, including generic Western naming conventions, absence of external validation, and minimal or templated biographical detail, supporting their assessment as fabricated and designed for reuse. The uniform role structure enables rapid replication across domains, reinforcing consistent credibility signals while allowing personas to be reassigned or recycled without disrupting the façade of institutional integrity. Functionally, this layer operates as an intermediary between content and audience perception, transforming unattributed messaging into authored analysis extended across websites, Telegram channels, and social platforms to create a persistent identity presence. This demonstrates that the Doppelgänger operation incorporates identity fabrication as a core architectural component that is structured, reusable, and integral to delivery. It also means that effective disruption must address not only infrastructure but this portable persona layer, which can be rapidly redeployed to reconstitute credible media fronts.

Infrastructure Architecture

Feeder Website Network

The operational foundation of the Doppelgänger campaign is a distributed network of websites designed to host narrative content while closely mimicking legitimate news organizations. These sites function as the primary publishing layer of the campaign, providing the initial point of origin for narratives that are subsequently distributed across social media platforms.

Rather than relying exclusively on social media posts, the campaign infrastructure directs audiences to these external domains, which are designed to resemble independent media outlets. This approach provides several operational advantages. First, it allows operators to publish long-form narrative content that appears to originate from a news-style source rather than from social media accounts. Second, it creates a stable destination for links shared across Telegram channels and X/Twitter accounts, enabling narratives to persist even when individual social media posts are removed or accounts are suspended.

The feeder sites also serve an important operational security function. By hosting narrative content on controlled domains, operators create a layer of separation between the messaging infrastructure and the social media accounts used to distribute the content. This separation complicates attribution and allows narratives to circulate through secondary citation chains in which the original campaign infrastructure is no longer visible.

In addition to narrative hosting and attribution shielding, the feeder websites allow operators to collect traffic metrics and engagement data. By directing audiences to controlled domains, campaign operators can measure which narratives attract the greatest engagement and adjust future messaging accordingly.

Investigations into the Doppelgänger infrastructure have identified several representative domains associated with the campaign’s publishing network, including rrn[.]world *now an investigative site into SDA not an SDA  controlled domain*, memhouse[.]online, truemaps[.]info, tribunalukraine[.]info, and avisindependent[.]eu. Alongside these domains, the ecosystem includes numerous cybersquatted sites designed to resemble well-known Western news organizations. These domains typically replicate visual branding, layout, and naming conventions of legitimate media outlets in order to increase the perceived credibility of the hosted content.

Redirect and Tracking Infrastructure

Supporting the feeder website network is a layered redirect and traffic-management system that enables the campaign to control how audiences reach narrative content. This infrastructure provides several operational capabilities, including audience geo-targeting, detailed traffic analytics, link obfuscation, and rapid substitution of infrastructure when individual domains are disrupted.

Redirect chains allow campaign operators to route users through multiple intermediary links before they arrive at the final destination site. This technique serves both operational security and campaign optimization purposes. From an operational perspective, it obscures the relationship between the original distribution platform and the hosting domain, making attribution more difficult. From an analytics perspective, it allows operators to monitor user engagement and measure the performance of individual links and narratives.

Public investigations have identified the use of traffic-management platforms such as Keitaro, a software system widely used in affiliate marketing ecosystems to manage link routing and analyze traffic patterns. When applied within influence operations, tools of this type can provide operators with detailed information about audience behavior, including geographic distribution, referral sources, and click-through rates. These capabilities enable campaign managers to refine messaging and distribution strategies based on real-time engagement metrics.

Domain Rotation and Regeneration

A defining characteristic of the Doppelgänger infrastructure is its ability to regenerate quickly when individual domains are blocked or seized. The campaign employs a strategy of continuous domain rotation in which new websites are deployed to replace disrupted infrastructure with minimal delay.

Evidence from multiple investigations indicates that replacement domains can appear with rapidity after a disruption event. This rapid regeneration capability suggests the presence of an organized infrastructure management process capable of registering domains, deploying website templates, and integrating new sites into the existing redirect and distribution systems on short notice.

The ability to rapidly replace infrastructure significantly increases the resilience of the campaign. Even when individual domains are removed by platform enforcement actions or law enforcement interventions, the broader narrative distribution network can continue operating with minimal interruption. As a result, the campaign’s influence activities persist through a cycle of disruption and regeneration that allows operators to maintain a continuous presence within the information ecosystem.

Operational Distribution Model

The Doppelgänger campaign distributes narratives through a structured, multi-stage pipeline designed to move content from controlled publishing infrastructure into large-scale public exposure across social media platforms. Rather than relying on a single channel for dissemination, the campaign employs a layered distribution architecture in which each stage performs a distinct operational role. This structure allows operators to maintain separation between narrative creation, infrastructure hosting, and public amplification, increasing both the resilience and scalability of the campaign.

The process begins with content creation, where narratives are developed and formatted for publication. At this stage, messaging themes are crafted to align with broader campaign objectives and current geopolitical developments. The narratives are typically designed to resemble journalistic reporting or analysis in order to increase their credibility and shareability once introduced into public discourse.

Once created, the content is published on feeder websites controlled by the campaign infrastructure. These sites serve as the primary hosting layer for narrative material and provide a stable destination for links that will later be shared across social media platforms. By placing the content on standalone domains that mimic legitimate news outlets, operators create a degree of separation between the narrative source and the social accounts used for distribution.

Following publication, the narrative enters the Telegram amplification stage. Telegram channels with established audiences serve as the primary distribution engine for the campaign. These channels repost links to the feeder websites, exposing the narratives to large subscriber bases and creating the initial wave of engagement. Because many of these channels already maintain audiences interested in geopolitical or ideological content, Telegram functions as an efficient mechanism for rapidly spreading narratives to receptive communities.

After gaining traction within Telegram networks, the campaign proceeds to X/Twitter injection. At this stage, coordinated social media accounts begin posting links to the feeder sites or discussing the narratives within existing conversations on the platform. These posts often appear within replies to trending topics, political discussions, or posts from influential accounts. The goal of this stage is to introduce the narrative into broader public discourse, reaching users who are not directly connected to the Telegram amplification network.

The final stage of the pipeline is audience exposure, where the narrative reaches individuals across the wider information ecosystem. At this point, the content may be encountered through social media threads reposted by other users, or referenced in discussions across forums, blogs, and other digital platforms. Once a narrative reaches this stage, it may continue circulating independently of the original campaign infrastructure.

This multi-stage distribution model allows the Doppelgänger campaign to move narratives from controlled infrastructure into mainstream online discourse while maintaining operational flexibility. By separating narrative creation, hosting, and amplification across distinct layers, the campaign achieves both scalability and resilience, enabling it to sustain influence activities even when individual domains or accounts are disrupted.

Telegram Amplification Layer

Within the Doppelgänger campaign architecture, Telegram functions as the primary distribution engine and reach multiplier. While feeder websites host the narrative content and X/Twitter accounts inject the narratives into public conversation, Telegram channels provide the high-capacity amplification required to expose those narratives to large audiences quickly.

The platform’s structure makes it particularly well suited to this role. Telegram channels can accumulate very large subscriber bases and distribute content instantly to those audiences without the algorithmic filtering mechanisms present on many Western social media platforms. As a result, a single post in a high-subscriber channel can expose campaign narratives to hundreds of thousands of users within minutes.

The Doppelgänger campaign leverages this dynamic by utilizing established channels within the broader pro-Kremlin Telegram ecosystem. These channels function as distribution hubs, reposting links to feeder websites and circulating campaign narratives across interconnected networks of subscribers. Once a narrative appears in one of these large channels, it is frequently reposted by smaller affiliated channels, creating an amplification cascade that expands the narrative’s reach across the platform.

Several prominent Telegram channels have been identified as major amplifiers within this ecosystem. These include Readovka, SolovievLive, IntelSlava, Ukraina[.]ru, and OstashkoNews, each of which maintains a substantial subscriber base and regularly circulates geopolitical and war-related content aligned with pro-Kremlin messaging. Collectively, these channels represent a significant distribution network capable of reaching millions of users.

Combined subscriber counts across these channels exceed five million accounts. However, subscriber overlap between channels means that the total audience exposed to a given narrative is smaller than the raw subscriber numbers might suggest. Many users subscribe to multiple channels within the same information ecosystem, which reduces the number of unique individuals reached by each amplification wave.

Taking this overlap into account, the estimated unique exposure per narrative wave distributed through these major channels historically has approximately been up to 1.2 to 2.4 million viewers. This range reflects the realistic audience size likely to encounter a narrative during a typical amplification cycle.

Because of this reach, Telegram serves as the central amplification layer within the Doppelgänger campaign. The platform enables rapid dissemination of narratives from the feeder website network and provides the initial audience engagement that supports subsequent injection of those narratives into broader social media conversations on platforms such as X/Twitter.

X / Twitter Injection Layer

Within the Doppelgänger campaign architecture, X (formerly Twitter) serves a different operational function from Telegram. Whereas Telegram channels provide large-scale distribution to existing subscriber audiences, X is primarily used as a mechanism for narrative insertion into active public conversations. The platform’s role in the campaign is therefore less about direct reach through large follower bases and more about leveraging algorithmic visibility within ongoing discussions.

Unlike traditional influence campaigns that rely on prominent influencers or high-follower accounts, Doppelgänger operators typically deploy clusters of disposable social media profiles. These accounts are designed to be rapidly created, used for short operational periods, and replaced when suspended or detected. As a result, the accounts associated with these operations often exhibit several common characteristics.

Most have minimal follower counts, indicating that they are not intended to build long-term audiences. Many profiles are recently created, sometimes within days or weeks of their participation in coordinated posting activity. Usernames frequently consist of generic or randomly generated combinations of characters, and profile images are commonly drawn from stock photography or produced using AI-generated portrait tools. These traits collectively suggest that the accounts are designed primarily for operational utility rather than credibility or sustained engagement.

Instead of broadcasting content to followers, these accounts engage in coordinated reply behavior. Operators target posts that are already receiving significant engagement—such as political discussions, breaking news events, or posts from high-profile accounts—and insert replies containing links to feeder websites or narrative fragments aligned with campaign messaging. By appearing within existing conversation threads, the campaign attempts to expose the narrative to users who are already participating in or observing those discussions.

Investigations into the Doppelgänger campaign have documented several examples of this tactic. One operation targeting U.S. audiences involved approximately thirty-nine coordinated accounts posting replies within political discussions. Other investigations have identified larger botnet-style clusters consisting of more than one thousand coordinated accounts, indicating that the scale of these operations can vary significantly depending on the campaign objectives.

Within the overall influence architecture, the X layer therefore contributes algorithmic amplification rather than follower-based distribution. By inserting narratives into high-visibility discussion threads, the campaign can exploit platform algorithms that prioritize active conversations, allowing content posted by otherwise low-follower accounts to appear in front of large audiences. In this way, the X component of the campaign acts as a bridge between the controlled distribution channels of Telegram and the broader public information environment.

Narrative Propagation Mechanics

The spread of narratives within the Doppelgänger ecosystem follows a cascade-style propagation model in which content moves through a sequence of amplification stages. Each stage expands the potential audience and increases the likelihood that the narrative will enter broader online discourse. This cascading structure allows relatively small origin accounts or channels to generate large-scale exposure once the narrative reaches high-capacity distribution nodes.

The process typically begins with an origin post, which may appear either on a feeder website or within a smaller Telegram channel associated with the campaign ecosystem. At this stage, the narrative exists within a relatively limited audience environment and functions primarily as the initial seed for the distribution pipeline.

From there, the narrative is introduced into a Telegram origin channel, where it begins to circulate within networks of subscribers that regularly consume geopolitical or ideological content aligned with pro-Kremlin messaging. These origin channels often serve as staging points where narratives are prepared for broader amplification.

The critical expansion phase occurs when the narrative is reposted by a large Telegram amplifier channel with a substantial subscriber base. Channels operating at this level of the ecosystem can expose content to hundreds of thousands of users simultaneously. Once a narrative reaches this stage, it becomes highly visible across the Telegram information environment.

Following publication in a major amplifier channel, the narrative enters a secondary repost cascade. Smaller affiliated channels frequently repost content originating from large channels, either automatically or through loosely coordinated editorial behavior. This reposting activity produces a cascading effect in which the narrative spreads across interconnected Telegram communities, further expanding its reach.

After the narrative gains traction within Telegram, the campaign introduces the content into the X/Twitter layer through coordinated account activity. Clusters of disposable accounts begin posting links, excerpts, or commentary related to the narrative within active discussions on the platform. This step serves to insert the narrative into broader public conversations, particularly those involving political or geopolitical topics.

The final stage of the cascade occurs when the narrative achieves secondary discourse uptake. At this point, users outside the original campaign infrastructure begin referencing or discussing the narrative independently. The content may appear in comment threads, forums, blog posts, or other social media discussions, often without direct reference to the original source.

Through this cascade model, a narrative originating from a relatively small node within the campaign network can rapidly expand to reach a much larger audience. The combination of Telegram amplification and social media insertion enables the Doppelgänger ecosystem to convert limited initial publication into widespread exposure across multiple digital platforms.

Campaign Reach and Effects

Subscriber metrics from major Telegram amplification channels, combined with observed activity patterns, enable bounded estimates of reach for a typical Doppelgänger narrative wave. The distribution model using Telegram as the primary amplifier, followed by coordinated activity on X/Twitter means total exposure is driven by the number of participating channels and the intensity of downstream social amplification.

Operationally, narrative waves fall into three intensity tiers:

Baseline Campaign
The most common configuration. Narratives are pushed through multiple large Telegram channels, then reinforced by coordinated X/Twitter reply clusters. This layered amplification produces an estimated reach of 1.5–2.7 million users, with 100,000–300,000 interactions. Secondary uptake expands to 10,000–40,000 mentions, indicating spillover beyond controlled infrastructure into broader discourse.

Low-Intensity Campaign
A single major Telegram channel with limited X/Twitter support. The distribution cascade is constrained, yielding 800,000–1.3 million users reached, 40,000–120,000 interactions, and 2,000–5,000 secondary mentions. Despite lower scale, narratives still penetrate sizable audiences, particularly within high-interest topics.

High-Intensity Campaign
Aligned with major geopolitical events, leveraging elevated attention and search activity. Multiple high-capacity Telegram channels and dense X/Twitter coordination drive accelerated spread. Estimated reach increases to 3–5 million users, with 250,000–700,000 interactions and 40,000–100,000 secondary mentions. At this stage, narratives routinely escape campaign control and persist in wider information ecosystems.

Across all tiers, the architecture demonstrates consistent scaling behavior: small origin points are amplified through Telegram, reinforced via coordinated social activity, and ultimately propagated into broader public discourse.

Strategic Impact Assessment

The Doppelgänger campaign is engineered for visibility, not direct persuasion. Its architecture–feeder websites, Telegram amplification, and coordinated X/Twitter activity–prioritizes rapid distribution and repeated exposure across platforms to maximize encounter frequency.

The objective is to seed narratives into the information environment and sustain their circulation, rather than secure immediate belief. Repetition across multiple sources increases perceived relevance and can shape interpretation of events, even when claims remain contested.

A central mechanism is manufactured ubiquity. By injecting narratives into active discussions and amplifying them across channels, the campaign creates the appearance of widespread, organic debate. This perceived consensus elevates legitimacy, particularly when content surfaces simultaneously across domains and platforms.

Effectiveness does not require broad persuasion. Limited engagement is sufficient to generate secondary propagation mentions, reposts, and commentary that extend reach beyond controlled infrastructure. As these references accumulate, narratives diffuse into general discourse, producing a form of information contamination in which repeated exposure normalizes their presence.

Over time, this process increases perceived credibility and embeds narratives within the broader information ecosystem. The strategic outcome is not conversion, but contextual influence shaping how events are framed and understood.

Doctrinal Context: Doppelgänger Within Russian Information Confrontation Strategy

The operational architecture of the SDA / Doppelgänger campaign aligns closely with established Russian concepts of information confrontation (informatsionnoye protivoborstvo/информационное противоборство), a strategic doctrine that integrates information operations into broader geopolitical competition.

Rather than focusing solely on direct persuasion or propaganda in the traditional sense, Russian information confrontation doctrine emphasizes shaping the information environment itself. The objective is to influence how events are interpreted, weaken adversary cohesion, and introduce persistent uncertainty into public discourse.

The layered architecture observed in the Doppelgänger campaign, such as combined web infrastructure, social amplification networks, and rapid regeneration capabilities reflects this doctrinal emphasis on environmental influence rather than individual audience conversion.

Continuity With Soviet Active Measures

The operational structure of the Doppelgänger campaign demonstrates clear continuity with Soviet-era Active Measures, a category of covert influence operations historically conducted by the KGB and other Soviet intelligence services. Active Measures were designed to shape political perceptions abroad through the controlled dissemination of misleading or manipulated information. Rather than relying solely on overt propaganda channels, these operations frequently used covert or semi-covert mechanisms intended to obscure the origin of the messaging and create the appearance of independent sources.

Historically, Active Measures campaigns relied on a combination of forged publications, front organizations, and intermediary actors to introduce narratives into foreign information environments. Articles containing false or misleading claims were often placed in controlled outlets or sympathetic publications, where they could be cited by other media organizations without clear attribution to Soviet state actors. This layered dissemination model enabled narratives to circulate widely while masking their true origin in the same manner as the SDA/Doppelgänger campaigns do in the 21st century.

Several core techniques were characteristic of these operations. Soviet intelligence services frequently published fabricated or manipulated articles in outlets under their influence, ensuring that narratives appeared to originate from credible media sources. They also relied on intermediaries, sometimes sympathetic individuals or organizations, and sometimes unwitting participants to amplify and redistribute these narratives. Additionally, front organizations and proxy institutions were used to conceal the involvement of state actors, creating plausible deniability and complicating attribution.

The modern Doppelgänger ecosystem replicates many of these operational concepts but implements them through digital infrastructure rather than traditional print or broadcast channels. In place of forged newspapers or pamphlets, the campaign operates cloned media websites designed to resemble legitimate news organizations. Instead of proxy publications in foreign countries, the campaign relies on pseudo-journalistic domains that host narrative content while maintaining the appearance of independent media outlets.

Likewise, where Soviet Active Measures depended on diplomatic contacts, activist groups, or aligned publications to redistribute narratives, the Doppelgänger campaign utilizes Telegram amplification channels to perform a similar role. These channels function as distribution hubs that rapidly disseminate narratives to large subscriber bases. Finally, the rumor propagation networks historically used to circulate political claims have been replaced by coordinated X/Twitter reply swarms, which insert narratives into active discussions across social media platforms.

Although the underlying techniques remain conceptually similar, the digital environment dramatically increases the speed, scale, and reach of these operations. Where Cold War Active Measures might have taken weeks or months to propagate through traditional media channels, digital infrastructure allows narratives to circulate globally within hours. This acceleration enables modern influence campaigns such as Doppelgänger to achieve levels of audience exposure and message repetition that were difficult to achieve through earlier forms of covert propaganda.

Alignment With Contemporary Russian Hybrid Warfare Doctrine

The operational design of the Doppelgänger campaign also reflects principles associated with Russia’s contemporary hybrid warfare doctrine, which integrates informational influence with broader geopolitical strategy. Discussions of this doctrine frequently reference writings and strategic concepts attributed to Russian military leadership that emphasize the growing importance of non-military tools in modern conflict.

Hybrid warfare is characterized by the coordinated use of military, political, economic, and informational instruments to influence adversaries while avoiding direct conventional confrontation. Within this framework, influence operations play a central role in shaping public perception, undermining adversary cohesion, and influencing decision-making environments before or during geopolitical crises.

Information operations such as the Doppelgänger campaign function as one component of this broader strategic toolkit. By introducing and amplifying narratives across digital information environments, the campaign can affect political discourse and public perception in ways that complement diplomatic, economic, or military pressure. The architecture of the campaign–combining narrative development, infrastructure hosting, and multi-platform distribution–demonstrates how modern influence capabilities can operate continuously alongside other forms of geopolitical competition.

Within the context of hybrid warfare strategy, campaigns like Doppelgänger serve several strategic purposes. They can weaken public support for adversary policies, particularly in democratic societies where political legitimacy depends on public opinion. By amplifying internal political disagreements or contentious social issues, such operations may also intensify existing divisions within target societies, complicating unified responses to international crises.

Influence campaigns can also contribute to strategic ambiguity surrounding geopolitical events. By introducing multiple competing explanations or allegations into public discourse, the information environment becomes more difficult to interpret, increasing uncertainty about the causes or implications of major developments. In addition, these campaigns can help shape international narratives around conflicts, promoting interpretations that align with Russian strategic messaging while challenging competing perspectives.

The Doppelgänger campaign’s operational emphasis on narrative saturation rather than direct persuasion aligns closely with this doctrinal approach. Rather than focusing on convincing audiences of a single specific claim, the campaign introduces a large volume of narratives designed to circulate simultaneously across the information ecosystem. This proliferation of competing narratives can complicate consensus formation, increase confusion about the reliability of information sources, and ultimately influence how audiences interpret geopolitical events.

Information Environment Manipulation

Russian information confrontation doctrine prioritizes control of the interpretive context through which audiences understand events. Perception is shaped less by facts than by narrative frameworks that assign meaning, causality, and emotional weight. By manipulating these frameworks, influence operations can alter how events are interpreted without changing the underlying facts.

Accordingly, campaigns focus on reshaping context rather than advancing isolated claims. This is achieved by promoting alternative explanations, introducing conspiratorial interpretations, and amplifying emotionally charged narratives to influence perception and legitimacy.

The Doppelgänger campaign operationalizes this model through a repeatable distribution pipeline. Narratives are developed in alignment with strategic objectives, published on feeder websites designed to mimic legitimate media, amplified via Telegram channels, and then inserted into active discussions on X/Twitter. This sequence enables rapid, multi-platform injection of interpretive frames into public discourse.

The architecture is modular and resilient, allowing narratives to be redeployed across domains, channels, and account clusters even after disruption. This persistence sustains exposure over time, reinforcing narrative frames and embedding them within the broader information environment.

Strategic Persistence

A defining characteristic of Russian information confrontation strategy is operational persistence. Rather than relying on isolated or short-lived influence campaigns, Russian information operations are typically conducted as continuous activities designed to exert sustained pressure on the information environments of targeted societies. This approach recognizes that influence within complex media ecosystems is cumulative; narratives may gain traction gradually through repeated exposure rather than through a single high-impact campaign.

Within this framework, influence operations are structured to remain active over extended periods, allowing operators to continually introduce, reinforce, and adapt narratives in response to changing geopolitical conditions. The objective is not simply to deliver a single message but to maintain a persistent presence within public discourse, ensuring that strategically aligned narratives remain visible and repeatedly encountered by audiences.

The Doppelgänger ecosystem reflects this emphasis on persistence through several operational mechanisms embedded within its infrastructure and distribution architecture. One such mechanism is rapid domain regeneration, which allows operators to replace disrupted or seized feeder websites quickly. When a domain is taken offline, replacement sites can be deployed within a short time frame, allowing the narrative distribution pipeline to continue functioning with minimal interruption.

The campaign also relies heavily on disposable social media accounts, particularly on platforms such as X/Twitter. These accounts are typically created with minimal investment in long-term identity or follower growth, allowing them to be used for short operational cycles and replaced easily if they are suspended or detected. This disposable-account model reduces the impact of platform enforcement actions and enables the campaign to maintain continuous activity despite account removals.

Another key element of this persistence is the campaign’s integration with existing Telegram channels that already possess large subscriber bases. Because these channels operate as stable distribution hubs within the broader pro-Kremlin information ecosystem, they provide a consistent amplification platform that does not need to be rebuilt for each campaign wave. This existing infrastructure allows narratives to be circulated repeatedly through established audiences.

Finally, the campaign reinforces persistence through the repeated reintroduction of narratives across multiple operational cycles. Even after a particular narrative has circulated through the distribution pipeline, the same or slightly modified messaging may be reintroduced in later campaign waves, often in response to new geopolitical developments. This repetition increases the likelihood that the narrative will become embedded within broader online discourse.

Taken together, these mechanisms allow the Doppelgänger campaign to maintain long-term influence activity even when individual components of the infrastructure are disrupted. The persistence of the system ensures that the broader narrative themes promoted by the campaign remain present within the information environment, enabling influence operations to continue shaping discourse over time.

Strategic Implications

The Doppelgänger campaign represents a mature influence capability that fuses traditional propaganda methods with modern digital infrastructure. It operates as a coordinated ecosystem, producing, distributing, and reinforcing narratives across platforms, rather than as isolated disinformation activity.

This model aligns with state-level information confrontation, where influence operations are integrated into broader geopolitical strategy. Its architecture functions as a persistent mechanism for shaping external information environments.

These components form a scalable, resilient distribution system. Modular design enables rapid adaptation, infrastructure regeneration, and repeated campaign cycles despite disruption.

Effectiveness is not defined by direct persuasion, but by cumulative environmental impact. Through sustained narrative injection and amplification of controversy, the campaign degrades informational coherence, proliferates competing interpretations, and complicates consensus formation.

Detection Framework Development

The operational characteristics of the Doppelgänger campaign produce a number of recurring technical and behavioral indicators that can assist analysts in identifying active influence operations. Although individual domains, social media accounts, and distribution channels may change over time, the underlying structure of the campaign’s infrastructure and propagation mechanisms generates patterns that are observable across multiple campaign waves.

These indicators generally fall into three broad categories: infrastructure indicators, behavioral indicators, and cross-platform propagation indicators. Together, they provide a framework for identifying and tracking influence activity associated with the Doppelgänger ecosystem.

Infrastructure Indicators

Infrastructure indicators are the most consistent signals of the campaign. The feeder network relies on recently registered domains that mimic legitimate news or commentary sites, using media-style naming to project credibility.

A key pattern is rapid domain rotation: sites are replaced quickly after disruption, often reusing similar naming conventions, branding, and technical configurations. Redirect infrastructure is also common, routing users through intermediary links to obscure source relationships while enabling traffic tracking.

Repeated website templates further indicate standardization. Shared layouts, visual elements, and backend configurations suggest the use of prebuilt deployment packages that support rapid infrastructure regeneration.

Behavioral Indicators

Beyond infrastructure, the campaign exhibits clear behavioral indicators of coordination. Telegram repost cascades are the most visible signal, where identical narratives propagate rapidly across multiple channels from a small set of origin posts.

Synchronized posting is also common, with near-identical content appearing across channels and accounts within minutes, indicating centralized dissemination. Clusters of newly created social media accounts characterized by low followers, generic identities, and stock or AI-generated images support short, disposable operational cycles.

On X/Twitter, activity often takes the form of reply swarms, where coordinated accounts inject narrative fragments and links into active discussions to amplify visibility and reach.

Cross-Platform Indicators

A third category of indicators involves the cross-platform propagation patterns that characterize the campaign’s distribution pipeline. Narratives often follow a consistent sequence of appearance across platforms, beginning with publication on a feeder website and subsequently spreading through Telegram amplification channels.

Shortly after appearing on Telegram, the same narratives may be introduced into X/Twitter discussions through coordinated account activity. This sequence—feeder site publication followed by Telegram amplification and social media insertion—represents a recurring propagation pattern that can signal the presence of a coordinated influence operation.

By monitoring these infrastructure, behavioral, and cross-platform indicators together, analysts can identify emerging campaign waves and better understand the mechanisms through which the Doppelgänger ecosystem distributes narratives across the digital information environment.

Disruption Strategy

Disrupting the Doppelgänger ecosystem requires a multi-layered approach targeting both infrastructure and distribution channels. Its design of rapidly replaceable domains, disposable accounts, and persistent amplification hubs means mitigation must be continuous and coordinated, not episodic.

Domain seizures and infrastructure takedowns can interrupt the publishing pipeline, but must be repeated due to rapid regeneration. Collaboration with registrars and hosting providers, using identifiable patterns in domain naming and deployment, can slow replacement cycles.

Account removal is equally critical. Suspending coordinated clusters on platforms like X/Twitter reduces narrative insertion into high-visibility discussions, while botnet detection helps identify and disrupt amplification networks exhibiting synchronized behavior.

Monitoring Telegram channels provides early warning and visibility into narrative propagation, even when direct removal is constrained.

Because campaign assets are disposable by design, effective disruption depends on sustained, cross-platform pressure. This raises operational costs, degrades distribution efficiency, and incrementally reduces overall campaign impact.

Potential Operational Pivots During Major Geopolitical Crisis

The Doppelgänger architecture is highly adaptable and can be rapidly repurposed for influence operations during major geopolitical crises, including the U.S.–Iran conflict. By integrating narrative development, controlled web infrastructure, and multi-platform distribution, it provides a ready mechanism for injecting crisis narratives into Western information environments.

In such scenarios, the system would likely be used to frame events in real time. Feeder sites could publish alternative interpretations of incidents emphasizing escalation, civilian harm, or legal violations while Telegram and X/Twitter amplification insert these narratives into early-stage public discourse.

It can also be used to exacerbate domestic divisions, promoting skepticism about intervention, highlighting economic costs, or questioning strategic legitimacy. Concurrently, the system can introduce multiple, conflicting explanations for key events, generating uncertainty and complicating verification.

The infrastructure supports targeted messaging, enabling narratives tailored to specific audiences, such as economic risk for European audiences, and political or military costs for U.S. audiences across languages and regions. It also facilitates information laundering, where content from pseudo-journalistic sites is recirculated and cited beyond the originating network.

Overall, Doppelgänger functions as a rapid-deployment influence platform. In crisis conditions, it can shape initial interpretations, amplify divisions, and establish persistent narrative frames that influence how conflicts are understood.

Example Crisis Influence Timeline: Narrative Propagation During the First 72 Hours

In a major geopolitical crisis such as the recent military confrontation between the United States and Iran the Doppelgänger influence infrastructure could be rapidly activated to shape early interpretations of events. Because the campaign’s architecture integrates narrative development, feeder website infrastructure, Telegram amplification networks, and coordinated social media activity, it is capable of introducing narratives into the information environment within hours of a triggering event.

The following model outlines how a typical influence operation using the Doppelgänger ecosystem could unfold during the first seventy-two hours following a major geopolitical incident. While the precise timing and scale of each phase may vary depending on operational objectives, documented campaign behavior suggests that the propagation pipeline follows a predictable sequence.

Initial Event Window (0–6 Hours)

The first phase begins immediately after a major geopolitical event becomes public knowledge. During this period, information environments are highly volatile and public understanding of the event is still forming. This stage provides an opportunity for influence operations to introduce interpretive narratives before authoritative reporting stabilizes the factual narrative.

During this window, campaign operators can rapidly produce narrative content aligned with strategic messaging objectives. These narratives may frame the event as evidence of escalation, highlight alleged civilian impacts, question the legitimacy of military actions, or introduce competing explanations regarding responsibility for the event.

Once developed, the narrative is published on one or more feeder websites within the Doppelgänger infrastructure. These articles typically mimic the appearance of legitimate news reporting, enabling them to be shared in social media discussions without immediately revealing their origin within a coordinated campaign.

Amplification Phase (6–24 Hours)

Following initial publication, the narrative enters the Telegram amplification layer, where links to the feeder websites are reposted across established pro-Kremlin Telegram channels. Because many of these channels maintain large subscriber bases and distribute content without algorithmic filtering, this stage can expose the narrative to hundreds of thousands of users within a short period of time.

Large Telegram channels function as distribution hubs that initiate the amplification cascade. Once the narrative appears in one or more of these channels, smaller affiliated channels frequently repost the content, expanding its reach across interconnected communities. This cascade effect can rapidly increase the narrative’s visibility across the Telegram information ecosystem.

At this stage, the narrative begins generating engagement in the form of reposts, comments, and reactions, creating the appearance of active discussion around the topic.

Cross-Platform Injection Phase (24–48 Hours)

Once the narrative has gained traction within Telegram networks, the campaign typically proceeds to cross-platform injection, introducing the content into broader public discussions on platforms such as X/Twitter. Clusters of disposable accounts begin posting links, excerpts, or commentary related to the narrative within active political conversations.

Rather than broadcasting content to followers, these accounts frequently target high-visibility discussion threads, including posts by journalists, politicians, or commentators addressing the crisis. By inserting replies into these conversations, the campaign attempts to expose the narrative to audiences that are not directly connected to the Telegram ecosystem.

This stage significantly expands the potential audience and increases the likelihood that the narrative will be encountered by individuals participating in broader geopolitical discussions.

Secondary Uptake Phase (48–72 Hours)

During the final stage of the initial propagation cycle, the narrative may begin to achieve secondary uptake outside the campaign’s direct infrastructure. Users who encounter the narrative through social media discussions may reference or repeat the claims in additional posts, blogs, forums, or commentary threads.

At this point, the narrative can circulate independently of the original campaign infrastructure. Because the narrative now appears across multiple platforms and sources, it may begin to influence how audiences interpret the underlying geopolitical event.

Even when the narrative itself remains contested, the presence of repeated references and discussions can contribute to information contamination, where the narrative becomes embedded within the broader discourse surrounding the event.

Strategic Implication

This seventy-two-hour propagation model illustrates how the Doppelgänger infrastructure can function as a rapid-deployment influence platform during geopolitical crises. By introducing narratives early in the information cycle and amplifying them across multiple platforms, the campaign can shape initial interpretations of events and inject competing narratives into public discourse before authoritative accounts become widely established.

Because the campaign’s infrastructure is modular and persistent, the same narratives can also be reintroduced in subsequent cycles as new developments occur, allowing influence operations to remain active throughout the duration of a geopolitical crisis.

Analytical Judgment

The Doppelgänger campaign is a resilient, scalable influence system built for sustained, multi-platform operations. It integrates narrative development, controlled web infrastructure, and coordinated social amplification to repeatedly inject and reinforce strategic messaging.

Its durability derives from a modular design that separates creation, hosting, and distribution, enabling rapid replacement of disrupted domains and accounts with minimal impact on operations. Cross-platform amplification extends reach: feeder sites provide controlled publication, Telegram delivers high-volume exposure, and coordinated X/Twitter activity inserts narratives into broader discourse.

Rapid regeneration further reinforces persistence, allowing infrastructure and accounts to be reconstituted quickly after takedowns. Within this model, Telegram functions as the primary reach engine, while X/Twitter enables penetration into high-visibility Western discussions.

Overall, Doppelgänger exemplifies a modern influence architecture that combines traditional propaganda logic with flexible digital infrastructure, sustaining narrative presence despite continuous disruption.

Technical Appendix A: Full Infrastructure Map of the SDA / Structura Ecosystem

Appendix B: Known SDA Sites:

Domain Status Domain Status
rrn.worldTaken Downmilitarblatt.netTaken Down
rrn.com.trTaken Downpolitiquedelombre.orgTaken Down
memhouse.onlineTaken Downgeheimtor.comTaken Down
truemaps.infoTaken Downlesentiers.orgTaken Down
tribunalukraine.infoTaken Downjeunefrance.comTaken Down
avisindependent.euTaken Downallons-y.socialTaken Down
araldoitaliano.comTaken Downcandidat.newsTaken Down
araldoitaliano.euTaken Downlexomnium.suTaken Down
araldoitaliano.ioTaken Downlevinaigre.suTaken Down
notrepays.frTaken Downlebelligerant.suTaken Down
notrepays.todayTaken Downdeintelligenz.suTaken Down
parabellumfrance.comTaken Downonlinestogrety.topUnknown
lefrancophone.netTaken Downdenae.orgUnknown
legrandgallus.comTaken Downdenae.netUnknown
lesfrontieres.mediaTaken Downbesuchszweck.comUnknown
brennendefrage.comTaken Downostlicherwind.orgUnknown
brennendefrage.netTaken Downgrunehummel.netUnknown
brennendefrage.suTaken Downkolharrets.comUnknown
derrattenfanger.netTaken Downle-continent.orgUnknown
derrattenfanger.suTaken Downphrygien.comUnknown
tageswirtschaft.comTaken Downdeitmag.comUnknown
tageswirtschaft.newsTaken Downnunsport.comUnknown
wahlomacht.ioTaken Downultra-marin.netUnknown
stolzvolk.acTaken Downwanderfalke.netUnknown
kaputteampel.proTaken Downbesuchszweck.orgUnknown
polskicompas.netTaken Downmabatii.comUnknown
hadashotisrael.netTaken Downkitalararasi.org.trUnknown
israeliherald.netTaken Downrenefrance.comUnknown
ahshav.comTaken Downkriminalradar.comUnknown
alhiwar.wsTaken Downindicebaguette.comUnknown
herzheim.orgUnknownroserouge.orgUnknown
detechplus.comUnknowndmzeitung.comUnknown
derbayerischelowe.ioUnknown
Learn More
Research
MOIS Linked MOIST GRASSHOPPER / Homeland Justice / KarmaBelow80 / Handala Hackers / Campaigns and Evolution

Explore the evolution of MOIS-linked actors Homeland Justice, Karma, and Handala. Analysis of destructive malware, surveillance integration, and the 2026 Stryker incident.

Executive Overview

The evidence examined across this analysis spanning U.S. government reporting, private-sector threat intelligence research, passive DNS and infrastructure enrichment, and longitudinal review of archived web and Telegram content supports a high-confidence assessment that the personas Homeland Justice, Karma, and Handala do not represent discrete or ideologically independent hacktivist groups. Rather, they constitute a coordinated, MOIS-aligned cyber influence ecosystem operating under multiple branded identities that serve distinct but complementary operational roles.

This assessment is supported by multiple converging lines of evidence, including clear temporal continuity, operational consistency, infrastructure linkage, and behavioral alignment. Activity transitions seamlessly from Homeland Justice operations targeting Albania in 2022 to Karma campaigns against Israeli entities in late 2023, and subsequently to Handala-branded operations from 2024 onward. Across these phases, the actors consistently employ a repeatable pattern of intrusion, data exfiltration, disruptive or destructive action, and rapid public disclosure through controlled infrastructure. This is reinforced by shared or cross-referenced domains, persistent use of Telegram for amplification and coordination, and common hosting and obfuscation strategies. The personas also exhibit consistent rhetorical framing, target selection logic, and methods of psychological coercion. Taken together, these indicators support the conclusion that these identities function as operational layers applied to a single underlying capability, enabling segmentation of audiences and messaging while maintaining continuity of tradecraft. This modular branding approach aligns with broader state-aligned cyber operations that leverage multiple personas to project decentralization while masking centralized control.

Since its emergence in 2022, the campaign has evolved from a destructive intrusion operation into a multi-functional cyber influence framework. The initial Albania operation combined long-term compromise with ransomware-style encryption, disk wiping, and public attribution, already indicating that technical disruption was paired with narrative objectives. Over time, the campaign expanded to incorporate espionage, persistent access, structured data exfiltration, and coordinated hack-and-leak activity designed to shape perception and behavior. The addition of surveillance capabilities, particularly those leveraging Telegram-based command-and-control, marks a further shift toward continuous monitoring and transnational repression targeting both institutions and individuals. In its current form, the campaign represents a cohesive and adaptive system in which intrusion, disruption, surveillance, and information operations are integrated into a unified strategy aligned with MOIS objectives, capable of applying sustained pressure across both cyber and cognitive domains.

Ministry of Intelligence and Security (MOIS) Connection

The operational ecosystem encompassing Handala, Homeland Justice, and the persona cluster associated with Karma and KarmaBelow80 is most coherently understood not as a loose federation of ideologically aligned actors, but as a structured, state-directed campaign operating under the authority of Iran’s Ministry of Intelligence and Security (MOIS). When viewed through the lens of command-and-control, tradecraft consistency, and synchronized effects, the activity attributed to these brands reflects the hallmarks of an intelligence service executing coordinated cyber operations in support of national objectives rather than independent or purely proxy-driven behavior.

At the center of this structure is the reported involvement of Seyed Yahya Hosseini Panjaki, an individual assessed to be affiliated with MOIS and linked to its internal security and counter-terrorism apparatus. The significance of this attribution lies less in the identity of the individual operator and more in what it implies structurally. His role represents a command-level function within an institutional hierarchy, indicating that these cyber operations are subject to formal tasking, oversight, and strategic alignment. This shifts the analytical framing away from contractor-driven or semi-deniable activity and toward a model in which operations are integrated into the broader intelligence mandate of the Iranian state.

Within this framework, the distinct public-facing identities of Handala, Homeland Justice, and KarmaBelow80 function as operational veneers rather than discrete entities. Each brand aligns with a specific subset of MOIS objectives while drawing from a shared pool of capabilities, infrastructure, and tradecraft. Handala’s activity is most closely aligned with psychological and information operations, characterized by curated leaks, narrative shaping, and the deliberate amplification of politically resonant material. The timing and framing of these disclosures indicate coordination with broader messaging goals, suggesting that the technical intrusion component is only one phase of a larger influence cycle.

Homeland Justice, by contrast, represents the disruptive and punitive arm of this ecosystem. Its operations, particularly those conducted against Albanian government infrastructure, demonstrate a full-spectrum intrusion lifecycle in which long-term access is leveraged to enable data exfiltration, destructive deployment, and overt attribution. The combination of wiper activity, ransomware-style encryption, and coordinated public messaging reflects a model of calibrated escalation designed to impose both operational and reputational costs on the target. This is consistent with MOIS mandates involving internal security and retaliatory action against perceived adversaries.

The Karma and KarmaBelow80 personas introduce an additional layer of flexibility into the ecosystem. Rather than being tied to a single operational profile, these identities appear to function as adaptive interfaces that can be deployed across different phases of an operation. They enable the same underlying capability set to be presented under different contextual narratives, enhancing deniability while maintaining continuity of effect. This is particularly relevant in environments where attribution pressure is high, as it allows operators to fragment their public footprint without fragmenting their operational infrastructure.

The coherence across these actor clusters is most evident in the structure of their operations. Intrusions frequently follow a repeatable progression: initial access is established through credential compromise or exploitation of exposed services, followed by the deployment of webshells or other persistence mechanisms. Once footholds are secured, actors conduct internal reconnaissance and lateral movement using enterprise-scale tooling, enabling them to map the target environment and identify high-value data stores. Exfiltration is then carried out in a controlled manner, often staged to support subsequent public release. The final phase varies depending on strategic intent, ranging from silent intelligence collection to destructive action or coordinated leak publication.

What distinguishes this ecosystem is the degree to which these phases are integrated and interchangeable. The same intrusion can evolve from a covert surveillance operation into a disruptive attack or an influence campaign without requiring a fundamental shift in tooling or access. This reflects the modular architecture described earlier, but at an organizational level it also implies centralized capability management. MOIS oversight provides the mechanism through which these modules can be allocated, combined, and sequenced in accordance with mission objectives.

The involvement of a command-level figure such as Panjaki provides a unifying explanation for this consistency. It accounts for the alignment between technical operations and information effects, the disciplined escalation observed in target engagements, and the reuse of infrastructure and tooling across ostensibly separate actor brands. It also explains the resilience of the ecosystem. Disrupting one public-facing identity or infrastructure cluster does not degrade the underlying capability, because those assets are components of a larger, centrally managed system.

From an analytical standpoint, this structure necessitates treating Handala, Homeland Justice, and KarmaBelow80 as manifestations of a single operational apparatus rather than independent threat actors. Their differences are functional rather than organizational, reflecting the segmentation of roles within a coordinated campaign. The strategic value of this model lies in its flexibility: MOIS can conduct espionage, disruption, and influence operations in parallel, or transition between them as conditions dictate, all while maintaining a coherent operational footprint.

This convergence of command authority, modular capability, and multi-domain execution underscores the maturation of MOIS cyber operations into a fully integrated instrument of state power. It is not simply the presence of advanced tooling or destructive capability that defines this ecosystem, but the way in which those capabilities are orchestrated under centralized direction to produce layered, cumulative effects across technical and informational domains.

Campaign Expansion and Evolution

Initial Emergence in Albania (2022)

Homeland Justice[.]org website

The campaign first became publicly visible during the 2022 attacks against the Government of Albania, which established both its technical baseline and its enduring operational model. Iranian state actors operating under the Homeland Justice persona achieved initial access approximately fourteen months prior to public disclosure by exploiting an internet-facing Microsoft SharePoint vulnerability. This early foothold indicates a deliberate pre-positioning phase, consistent with long-dwell intrusion strategies observed across MOIS-aligned operations.

Following initial compromise, the actors transitioned into a structured post-exploitation workflow designed to ensure persistence, expand access, and map the target environment. Webshells were deployed on compromised servers, providing durable and low-friction access while enabling command execution without reliance on large malware payloads. From this foothold, operators conducted systematic internal reconnaissance, enumerating network topology, identifying key systems, and mapping trust relationships across the enterprise.

Credential harvesting was a central component of this phase. Through a combination of mailbox access, credential dumping, and account manipulation, the actors obtained privileged credentials that enabled lateral movement and escalation. Movement across the environment was conducted using standard administrative protocols, including Remote Desktop Protocol (RDP), Server Message Block (SMB), and File Transfer Protocol (FTP), allowing activity to blend with legitimate administrative traffic and reducing the likelihood of early detection.

The compromise of Microsoft Exchange infrastructure further expanded access. By leveraging Exchange, the actors were able to access and manipulate mailboxes, create or modify accounts, and extract large volumes of sensitive communications. This email corpus provided both intelligence value and material for later disclosure, aligning with the campaign’s hack-and-leak model.

Data exfiltration occurred in parallel with lateral expansion, with operators systematically staging and extracting large datasets from across the environment. Only after sufficient access, intelligence collection, and data acquisition had been achieved did the actors transition to the destructive phase. This sequencing – extended pre-positioning, comprehensive collection, and delayed disruption – demonstrates a disciplined operational approach in which technical compromise is leveraged to maximize both intelligence yield and downstream psychological impact.

Establishment of the Operational Model

The impact phase of the Albania operation combined ransomware-style encryption with destructive wiping, employing tools such as GoXML.exe and cl.exe, supported by propagation utilities and raw disk access drivers that enabled direct manipulation of underlying storage. These capabilities were deployed in a coordinated manner to maximize operational disruption, impair system recovery, and degrade institutional functionality. The sequencing of encryption followed by wiping reflects a deliberate approach designed not only to deny access to systems and data, but to ensure lasting damage and complicate remediation efforts.

More significant than the tooling itself, however, was the deliberate integration of public-facing infrastructure into the attack lifecycle. The Homeland Justice persona was used to claim responsibility, disseminate messaging, and frame the operation within a broader political and ideological narrative. Websites and Telegram channels functioned as controlled dissemination platforms through which the actors published statements, amplified claims, and selectively exposed information. This layer transformed what would otherwise have been a destructive cyber incident into a visible and ongoing influence operation.

This approach established a foundational operational model in which technical compromise and information operations were inseparably linked. Cyber intrusion and destruction served as enabling mechanisms for narrative exploitation, with the ultimate objective extending beyond disruption to include coercion, reputational damage, and behavioral influence. In this model, the value of the operation was realized not solely through the technical impact, but through the controlled release of information and the shaping of perception in the aftermath of the attack.

Continued Activity and Tooling Refinement (2023)

In late 2023, the Homeland Justice campaign re-emerged with renewed activity targeting Albanian entities, demonstrating clear continuity in both target selection and operational methodology. This phase reinforced that the earlier Albania operations were not isolated incidents, but part of a sustained and adaptive campaign. The actors maintained their focus on politically relevant targets while reapplying the same core model of intrusion followed by destructive impact, indicating both persistence of intent and retention of operational access or capability.

During this period, the introduction of the No-Justice Wiper marked a refinement in destructive tooling. Designed for rapid and irreversible disruption, the malware emphasized system incapacitation, including preventing successful operating system boot. The use of signed binaries suggests an increased emphasis on evasion and trust abuse, while PowerShell-based propagation reflects a growing reliance on native system capabilities to enable flexible and low-friction deployment. Together, these developments indicate an evolution toward more efficient, harder-to-detect operations while preserving the campaign’s core objective of high-impact disruption.

Geographic Expansion and Rebranding: Karma Phase (2023-2024)

Following the Israel-Hamas conflict in October 2023, the campaign expanded geographically and adopted the Karma persona.

Despite this rebranding, the underlying tradecraft remained consistent. Operations targeted Israeli organizations and employed a hybrid approach combining custom tooling with publicly available utilities, including bespoke webshells, credential validation tools, reverse SSH tunneling, and destructive mechanisms such as BiBi Wiper.

Actors increasingly relied on hands-on-keyboard techniques, including manual file deletion and disk formatting, prioritizing speed and operational impact. Evidence from this phase suggests a division of labor between intrusion and destructive operators, indicating a modular and coordinated ecosystem.

Maturation and Specialization: Handala Phase (2024 Present)

Handala-hack.tw 2026

The expansion of the Handala infrastructure set with the inclusion of handala-hack[.]ps and, more importantly, handala-hack[.]tw, provides a clearer view into how the actor operationalizes its domain layer over time. These domains are not isolated artifacts. They are part of a repeatable system in which naming conventions, narrative timing, and platform coordination matter more than persistence of any single asset. The repeated appearance of the handala-hack string across multiple TLDs indicates that the domain itself is not intended to endure. It is intended to be recognized, replaced, and reactivated, carrying forward an identity that survives takedown actions and jurisdictional pressure.


The .tw variant is particularly instructive when placed in historical context. Earlier iterations of the ecosystem relied heavily on .to infrastructure, which has long been associated with abuse-tolerant hosting and low-friction registration. The shift into .ps and .tw reflects both symbolic and operational adaptation. The .ps domain carries clear political signaling aligned with the actor’s ideological framing, reinforcing the Palestinian narrative embedded throughout the campaign. By contrast, handala-hack[.]tw appears to serve a different function: jurisdictional dispersion and operational redundancy. Taiwan’s namespace does not inherently carry the same ideological weight, which suggests its use is pragmatic rather than symbolic. In effect, the actor is separating message-layer signaling (.ps) from resilience-layer infrastructure (.tw).

When mapped against the historical leak cadence observed across the full archive, these domains align with distinct phases of campaign activity. Early in the lifecycle, Handala has relied on single-domain publication points tied to specific claim sets. These initial leaks focused on individual targets, often framed as penetrations of named Israeli intelligence or defense figures. The content emphasized access mailboxes, communications, and internal correspondence without attempting to demonstrate systemic reach. Domains in this phase acted as announcement boards, each tied to a discrete narrative event.

As the campaign matured, the scale of claims expanded. The archive shows repeated assertions of large-volume email exfiltration, often in the range of tens of thousands to over one hundred thousand messages. These claims were accompanied by broader institutional framing, suggesting not just individual compromise but organizational penetration. It is in this phase that domain rotation becomes more pronounced. Rather than maintaining a single persistent site, the actor begins to distribute content across multiple similarly branded domains, each capable of hosting or referencing new disclosures. The emergence of domains like handala-hack[.]to and handala-redwanted[.]to reflect this shift toward functionally differentiated nodes, one for breach claims, another for intimidation or doxxing.

The introduction of handala-hack[.]tw appears to correspond with the later stages of this evolution, where the campaign moves beyond exposure into strategic signaling and maximalist claims. Posts associated with this period increasingly reference infrastructure targeting, large-scale destructive capability, and systemic access. Claims such as multi-petabyte data wipes or pre-mapped critical infrastructure targets emerge alongside continued email leak narratives. The domain layer, in this context, becomes less about hosting data and more about anchoring the claim itself. The presence of a new domain signals a new phase of activity, regardless of whether the underlying data is verifiable.

Historically, each wave of leaks follows a recognizable pattern. A new or resurfaced domain appears, often with the familiar handala-hack naming structure. Within a short time window, posts are published asserting compromise of a high-value target. These posts are then amplified through Telegram channels now including identifiers such as @HANDALA_INTEL and further propagated via X accounts. The domain serves as the canonical reference point, but the operational impact is generated through distribution. Even when domains are seized or taken offline, the narrative persists because it has already been exported to other channels.

The content associated with these domains consistently emphasizes three categories of disclosure. The first is email data, which remains the dominant theme across the archive. Whether targeting individuals like Eran Ortal or broader institutional mailboxes, the actor repeatedly frames access to communications as evidence of deep penetration. The second category is identity and contact data, including phone numbers and membership lists, often used in campaigns against dissidents or civilian networks. The third is strategic or infrastructural intelligence, where the actor claims to possess detailed knowledge of critical systems such as water and electricity networks. Each category serves a distinct psychological function: exposure, intimidation, and deterrence.


The inclusion of corporate targets, such as Stryker Corporation, marks another important shift visible in the historical record. Earlier phases of the campaign were tightly focused on Israeli state and intelligence entities. Later phases expand outward, incorporating Western corporate actors to demonstrate global reach. The claims associated with these targets are often the most extreme, including assertions of large-scale data destruction. Whether or not these claims are technically accurate is secondary to their narrative role. They signal that the actor’s reach is not confined to a single geography or sector.

Across all these phases, the domain layer including handala-hack[.]tw remains structurally consistent. The sites themselves are simple, often WordPress-based, with minimal technical sophistication. They do not host malware, nor do they expose command-and-control infrastructure. Instead, they function as narrative anchors, providing a stable URL that can be cited, shared, and referenced across platforms. The real operational activity occurs elsewhere, in the intrusion layer (which remains opaque) and the amplification layer (Telegram and X). The domain is simply the point where those layers intersect publicly.

What emerges from the full dataset, now augmented by the newly observed domains, is a clear pattern: Handala’s infrastructure is designed to be expendable, but its identity is designed to persist. Domains are created, used, and abandoned. Telegram channels are taken down and reconstituted. Yet the naming conventions handala-hack, HANDALA_ and the narrative structure remain constant. This allows the actor to survive disruption without losing coherence. Each new domain, including handala-hack[.]tw, is not a fresh start but a continuation of an ongoing campaign.

In historical context, the leaks themselves should be understood not as isolated incidents but as components of a sustained psychological operation. Early disclosures establish credibility, mid-phase leaks expand perceived capability, and later claims introduce strategic and deterrent messaging. The domain infrastructure evolves in parallel, moving from single-use publication points to a distributed, rotating set of narrative nodes. The result is a system in which the appearance of a new domain is itself a signal, an indication that the next cycle of claims, amplification, and psychological effect is underway.

Ultimately, the addition of handala-hack[.]tw does not represent a new capability. It represents the continued refinement of an existing model. The actor does not depend on any specific domain to achieve its objectives. Instead, it relies on the predictable regeneration of infrastructure combined with consistent narrative execution. In that sense, the domain is not the asset. The campaign is.

Adverse Effects and Real-World Impact of Handala Leak Operations

Analysis of the Handala archive, corroborated with external reporting, demonstrates a consistent divergence between claimed impact and verified operational consequences. While the group presents its activities as large-scale, destructive cyber intrusions, the observable real-world effects fall into a narrower set of categories: operational disruption (rare), exposure and reputational damage (common), and psychological or coercive effects (systematic).

The most clearly substantiated case of material operational impact is the attack against Stryker Corporation. Reporting indicates that the intrusion disrupted core business functions, including order processing, manufacturing, and shipment operations, with recovery extending over multiple days. The incident also reportedly resulted in the remote wiping of tens of thousands of devices, affecting employees across multiple regions and, in some cases, impacting personally owned devices enrolled in enterprise systems. This represents a genuine destructive and operational cyber event, distinguishing it from the majority of Handala’s activity. The scale and severity of this incident further triggered a law enforcement response, including domain seizures targeting Handala infrastructure, indicating that the event crossed the threshold from influence activity into infrastructure-level concern.

A second category of confirmed impact involves high-profile personal data exposure, exemplified by the breach of Kash Patel. In this case, the publication of personal emails, images, and documents created reputational harm and potential counterintelligence risk, even though the exposed material was not assessed as containing sensitive government information. The significance of this event lies less in technical compromise and more in its function as a public humiliation and signaling operation, consistent with Handala’s broader objectives of intimidation and reputational pressure against Western officials.

Other reported incidents fall into a more ambiguous category. The claimed attack against Hebrew University of Jerusalem, involving tens of terabytes of wiped and exfiltrated data, represents a credible, but not fully independently verified, destructive event. While multiple secondary sources describe the incident, there is limited primary confirmation of the full scale of impact. This pattern — where claims are partially supported but not conclusively validated — is characteristic of the Handala ecosystem and complicates direct attribution of operational consequences.

In contrast, some claims appear to have produced primarily reputational or narrative effects without technical confirmation. The alleged compromise of Verifone, for example, was publicly denied by the company, with no evidence of disruption or data loss. In such cases, the adverse effect is not system compromise but forced defensive communication, in which the targeted organization must respond to public allegations, thereby amplifying the narrative regardless of its validity.

A substantial portion of the archive consists of operations targeting individuals within the Israeli intelligence and security ecosystem, including Sima Shine, Ilan Steiner, Deborah Oppenheimer, and Eran Ortal. In these cases, the adverse effects are consistently limited to exposure of alleged communications, reputational damage, and intelligence-related pressure. Although large-scale email leaks are claimed, there is no strong independent evidence of downstream operational disruption, institutional failure, or policy impact. These incidents function primarily as hack-and-leak influence operations, designed to erode trust and project vulnerability rather than to degrade capability.

The campaign also includes a distinct category of identity exposure and intimidation, illustrated by the targeting of VahidOnline. The leak of tens of thousands of user identities and phone numbers associated with dissident networks constitutes a form of digital repression, exposing individuals to harassment, surveillance, or potential physical risk. Unlike corporate or institutional targets, the impact here is distributed across a population, amplifying fear and discouraging participation in opposition or media activities.

Beyond digital exposure, the archive and supporting reporting indicate a pattern of coercive escalation into the physical domain. Handala has been linked to doxxing campaigns against individuals such as defense-sector employees, including alleged exposure of personal details of engineers associated with defense contractors. These actions are often accompanied by explicit threats, transforming cyber activity into psychological coercion with potential real-world implications. Even when the accuracy of the leaked data is uncertain, the act of publication itself generates fear and imposes a defensive burden on victims.

Taken together, these cases demonstrate that Handala’s operational impact is best understood across three tiers. At the highest tier are rare but significant operational disruptions, such as the Stryker incident, which produce measurable effects on systems and services. At the intermediate tier are verified exposures of personal or organizational data, which create reputational and intelligence risks but do not necessarily disrupt operations. At the lowest tier are narrative-driven claims and unverified leaks, which nonetheless generate psychological and informational effects by forcing responses and sustaining uncertainty.

The overall pattern supports a clear analytical conclusion: Handala’s effectiveness does not depend on consistent technical success. Instead, it derives from the ability to convert a limited number of real or plausibly real intrusions into a sustained campaign of perception management, intimidation, and coercive signaling. The majority of adverse events observed are therefore not technical in nature, but psychological and reputational, aligning closely with the broader doctrine of cyber-enabled influence operations.

Parallel Surveillance and Influence Operations

Expansion into Surveillance (2023-2026)

In parallel with its destructive and hack-and-leak operations, the campaign expanded significantly into surveillance and transnational repression beginning in late 2023 and continuing through 2026. This shift represents a broadening of operational scope from institutional disruption to targeted monitoring of individuals, particularly dissidents, journalists, activists, and members of opposition networks. Rather than relying solely on network exploitation, the actors adopted a more tailored approach centered on social engineering and user-level compromise, indicating both improved targeting intelligence and a strategic intent to exert pressure beyond traditional cyber domains.

Access in this surveillance branch is typically achieved through trojanized applications masquerading as legitimate software, including messaging tools, password managers, and media utilities. These lures are often aligned with the expected behavior and digital environment of the target, suggesting prior reconnaissance and profiling. Upon execution, these files deploy staged malware chains that establish persistence and initiate communication with operator-controlled infrastructure. The second-stage implants are modular and designed for continuous data collection, including screen capture, audio interception (with specific capability to monitor conferencing platforms), file harvesting, and credential access. Data is often staged locally, compressed, and prepared for exfiltration in a manner that minimizes detection while maximizing collection efficiency.

A defining characteristic of this surveillance capability is its use of Telegram as a command-and-control channel, leveraging the legitimate Telegram API to transmit instructions and exfiltrated data. This approach allows malicious traffic to blend with normal user activity, complicating network-based detection while simultaneously enabling rapid, distributed control of infected hosts. In some cases, the same platform is used for both covert communication and overt messaging, reinforcing the campaign’s broader integration of technical and informational operations. Taken together, this surveillance expansion demonstrates a transition toward a persistent, person-centric operational model, in which intrusion, monitoring, and psychological pressure are applied in tandem to influence both institutional behavior and individual decision-making.

Telegram as Dual-Use Infrastructure

Telegram occupies a central and multifaceted role within this ecosystem, functioning simultaneously as a covert command-and-control (C2) channel and an overt platform for messaging, amplification, and audience engagement. This dual-use design is not incidental; it reflects a deliberate operational choice to consolidate multiple functions, control, communication, and influence within a single, widely trusted platform. By embedding operational activity within a legitimate and globally used service, the actors reduce their reliance on dedicated infrastructure while increasing resilience against disruption. At the same time, the platform’s scale and accessibility allow it to serve as a high-capacity distribution mechanism for narrative content, enabling rapid dissemination of messaging to both targeted and broad audiences.

From a technical perspective, the use of Telegram as C2 is enabled through abuse of the Telegram Bot API, which allows malware to communicate with operator-controlled bots over encrypted channels that are indistinguishable from normal application traffic. This design significantly complicates detection, as network telemetry alone is often insufficient to differentiate benign from malicious use. Implants can issue commands, upload exfiltrated data, and receive tasking through standard API calls, effectively turning Telegram into a low-cost, low-visibility control infrastructure. Because Telegram traffic is commonly permitted in enterprise and personal environments, this approach provides a reliable communication channel that blends seamlessly into expected user behavior, reducing the likelihood of interception or blocking.

Concurrently, Telegram channels associated with the campaign function as public-facing dissemination nodes, distributing propaganda, operational claims, and references to leaked data. Channels such as those linked to the Homeland Justice persona serve as hubs where messaging is curated, amplified, and framed within ideological or political narratives. The presence of archive files, named data releases, and coordinated messaging indicates that these channels are not passive outlets, but active components of the operational workflow. This convergence of covert C2 and overt communication within the same platform effectively bridges the technical and informational domains, allowing the actors to move seamlessly from intrusion and data collection to public exposure and psychological influence, all within a unified infrastructure.

Malware and Operational Evolution

Evolutionary Overview

The campaign demonstrates a progression from discrete, high-impact destructive events into a modular and adaptive operational toolkit capable of supporting a wide range of objectives across multiple target sets. Early activity, particularly during the Albania operations, was centered on singular, coordinated events in which long-term access culminated in ransomware-style encryption, wiping, and public attribution. Over time, however, these capabilities were not abandoned; instead, they were retained and integrated into a broader operational framework that supports espionage, surveillance, disruption, and influence operations in parallel.

This evolution is distinctly additive rather than substitutive. Earlier destructive tools and techniques  such as disk wiping, scripted propagation, and webshell-based persistence remain in active use, while newer capabilities have been layered on top. These include modular malware implants for surveillance, Telegram-based command-and-control, enterprise-scale tooling for network enumeration and control, and structured leak infrastructure for public disclosure. The result is a toolkit that can be dynamically assembled based on operational requirements, allowing actors to shift between stealthy collection, overt disruption, and psychological operations without fundamentally altering their underlying tradecraft.

The modular nature of this toolkit also enables operational flexibility and resilience. Components can be deployed independently or in combination, depending on the target environment and desired outcome. For example, an intrusion may begin as a surveillance operation, transition into data exfiltration, and culminate in either destructive action or controlled leak publication, all using elements of the same toolkit. This layered approach reduces dependency on any single capability and allows the campaign to adapt to defensive pressures, infrastructure disruption, or shifting strategic priorities while maintaining continuity of effect.

Phase I: Destructive Intrusion Model

The Albania campaign established a repeatable model centered on prolonged, covert access followed by synchronized destructive impact and overt attribution. Operators achieved initial entry well in advance of the impact phase, maintained persistence through webshells and credential reuse, and conducted systematic reconnaissance and lateral movement across the environment. During this period, they harvested credentials, mapped network topology, and accessed email systems, enabling large-scale data exfiltration and the prepositioning of tools required for coordinated execution. This extended preparation phase indicates a deliberate emphasis on operational depth and positioning, rather than opportunistic disruption.

The transition to the impact phase was tightly orchestrated. Encryption and wiping components were deployed in sequence to maximize disruption, degrade recovery options, and ensure sustained operational impact across affected systems. The use of propagation mechanisms and administrative access allowed the actors to execute these actions broadly and nearly simultaneously, amplifying the scale of disruption. This was not a simple ransomware event; it was a destructive operation designed to disable systems, disrupt services, and create immediate strategic effect, particularly within government infrastructure.

Equally important was the deliberate and immediate move to public attribution and narrative control. Under the Homeland Justice persona, the actors claimed responsibility, released messaging, and framed the attack within a political and ideological context. This transformed the operation from a purely technical incident into a hybrid cyber–influence event, where the technical damage served as the foundation for broader psychological and reputational impact. The Albania campaign thus established a durable operational model: gain long-term access, prepare the environment, execute coordinated destruction, and rapidly exploit the event through controlled public disclosure to achieve strategic influence.

Phase II: Iterative Destructive Refinement

The introduction of the No-Justice Wiper reflects a clear refinement in the actor’s destructive capability, emphasizing speed, reliability, and operational efficiency. Compared to earlier tooling that combined encryption and wiping in a more sequential and resource-intensive manner, the No-Justice variant appears optimized for rapid execution and immediate impact. Its design prioritizes system incapacitation, including corruption of critical structures required for operating system startup, thereby preventing recovery through conventional means. This shift indicates a move toward direct, irreversible disruption, reducing the time between execution and effect while minimizing the opportunity for defensive response.

At the same time, the use of signed binaries demonstrates an increased focus on evasion through trust abuse. By leveraging code-signing mechanisms, the actors are able to bypass or reduce scrutiny from endpoint protection systems that rely on signature-based trust models. This reflects a more sophisticated understanding of defensive controls and suggests that the tooling has been adapted based on prior detection and mitigation efforts. The combination of trusted execution and destructive functionality allows the malware to operate with a lower likelihood of immediate detection, increasing the probability of successful deployment across multiple systems.

The reliance on PowerShell-based propagation and execution further underscores a transition toward living-off-the-land techniques. By utilizing native system capabilities, the actors reduce their dependency on large or complex malware payloads, enabling more flexible and stealthy deployment within compromised environments. PowerShell scripts can be rapidly modified, obfuscated, and distributed using existing administrative channels, allowing for efficient lateral spread and coordinated execution. Together, these elements – streamlined destructive logic, trust-based evasion, and native execution – illustrate a broader evolution toward leaner, more adaptable tooling that enhances both effectiveness and survivability within contested network environments.

Phase III: Hybrid Operational Model

The Karma phase introduced a distinctly hybrid operational approach that combined bespoke tooling with hands-on-keyboard techniques and widely available utilities, enabling flexible execution across heterogeneous environments. Rather than relying exclusively on custom malware, operators blended lightweight webshells and purpose-built components with native administrative tools and publicly available software. This reduced development overhead, shortened deployment time, and allowed rapid adaptation to differences in target infrastructure  whether on-premises Windows domains, Linux servers, or mixed environments while preserving the ability to execute high-impact actions.

A defining feature of this phase was the increased emphasis on manual tradecraft and living-off-the-land techniques. Operators leveraged standard system utilities and administrative protocols such as RDP for lateral movement, built-in command-line tools, and common utilities like SDelete or disk formatting to perform destructive actions without introducing large, easily detectable binaries. Custom elements, including webshells (e.g., Karma Shell) and credential validation tools (e.g., do.exe), were used selectively to maintain access and verify privileges, while publicly available tools such as reGeorg enabled post-compromise control. This blend allowed operators to pivot quickly within compromised networks, execute tasks with minimal friction, and evade signature-based defenses by masking activity as legitimate administration.

The result was a modular, operator-driven execution model that prioritized flexibility, speed, and reliability over stealth alone. By combining custom implants with manual techniques and off-the-shelf tools, the actors could tailor operations to the specific constraints of each target, escalate privileges, propagate across systems, and initiate disruption with minimal dependency on a single capability. This hybridization also improved resilience: if one tool or method was detected or blocked, operators could readily substitute alternatives without disrupting the overall operation. In effect, the Karma phase marked a transition toward a more adaptable and scalable approach, capable of sustaining coordinated campaigns across diverse technical environments while maintaining alignment with the campaign’s broader objectives of disruption and influence.

Phase IV: Multi-Vector Destruction and Enterprise Tooling

Under the Handala persona, operations expanded into a coordinated, multi-method destruction model that reflects a clear increase in operational maturity and planning discipline. Rather than relying on a single payload or technique, actors began employing parallel destructive mechanisms, including custom wipers, PowerShell-based recursive deletion, and encryption via legitimate tools such as VeraCrypt. These methods were often executed in tandem across multiple systems, ensuring redundancy in effect and significantly reducing the likelihood of recovery. This approach demonstrates a shift from opportunistic disruption to deliberate, layered impact engineering, where multiple techniques reinforce one another to guarantee system failure and data loss.

At the same time, the incorporation of enterprise-scale tooling enabled the actors to operate more effectively within complex network environments. Tools such as NetBird facilitated persistent internal connectivity and remote control across segmented networks, while ADRecon provided comprehensive visibility into Active Directory structures, users, and permissions. This combination allowed operators to map target environments in detail, identify high-value systems, and coordinate execution across domains with greater precision. The use of Group Policy and administrative scripting further enabled centralized deployment of destructive actions, amplifying scale and synchronizing impact across large portions of the network.

These developments collectively indicate a transition toward a structured, scalable operational model capable of sustaining complex campaigns within enterprise environments. The reliance on both custom and legitimate tools, combined with coordinated execution and network-wide visibility, reflects an evolution beyond isolated incidents into systematic, organization-level disruption capability. Under Handala, the campaign demonstrates not only technical sophistication, but also an increased ability to integrate access, control, and destruction into a cohesive and repeatable operational framework aligned with broader strategic objectives.

Phase V: Surveillance Integration

Telegram-based malware campaigns introduced a persistent monitoring layer that materially expanded the campaign’s scope beyond episodic disruption into continuous intelligence collection. Initial access is commonly achieved through trojanized applications tailored to the target’s context, such as messaging clients, password managers, or media tools suggesting prior reconnaissance and profiling. Once executed, staged loaders deploy modular implants that establish persistence and enable ongoing telemetry collection, including screen capture, keystroke or clipboard capture, file harvesting, and, in some cases, audio interception of conferencing applications. Data is typically staged locally, compressed, and queued for exfiltration, allowing operators to control the cadence of collection and minimize anomalies that might trigger detection.

A defining feature of this capability is the use of Telegram’s Bot API as command-and-control, which allows implants to communicate over encrypted channels indistinguishable from normal Telegram traffic. This design provides a resilient, low-cost infrastructure that blends into expected network behavior and is difficult to block without disrupting legitimate use. Operators can issue tasking, retrieve data, and manage multiple hosts via bot commands, effectively turning Telegram into a distributed control plane. Because Telegram is widely permitted across enterprise and personal environments, this approach increases reliability while reducing dependence on bespoke infrastructure that is more easily identified and taken down.

Operationally, this surveillance layer supports transnational repression by enabling targeted, person-centric campaigns against dissidents, journalists, and opposition figures. Continuous monitoring yields sensitive personal and organizational insights that can be selectively disclosed, used to intimidate, or leveraged to shape narratives in subsequent leak operations. This tight coupling between covert collection and overt exposure allows actors to move seamlessly from surveillance to psychological pressure, aligning technical activity with influence objectives. The result is a persistent, adaptive capability that extends the campaign’s reach from network disruption to sustained coercion of individuals and communities across borders.

Phase VI: Convergence (Stryker-Era Operations)


Recent activity, particularly the Stryker incident (March 2026), demonstrates a clear convergence of destructive, surveillance, and influence capabilities into a unified operational model, while also marking a significant evolution in how these effects are delivered. Unlike earlier phases that relied heavily on malware deployment within compromised networks, emerging reporting indicates that Handala-linked actors achieved administrative access to enterprise management infrastructure, specifically Microsoft Intune, and used it as a force-multiplier for both disruption and scale. (Cyber Magazine)

In the Stryker case, investigators and multiple reports suggest that attackers compromised an Intune administrative account or management console, allowing them to issue remote commands directly to enrolled endpoints. Intune, as a cloud-based endpoint management platform, is designed to enforce policies, deploy software, and remotely wipe devices. By gaining privileged access to this system, the actors were able to bypass traditional malware deployment entirely and instead execute a centralized wipe command across tens of thousands of devices simultaneously. Reports indicate that as many as 80,000–200,000 devices, including laptops and mobile endpoints, were wiped, while approximately 50 terabytes of data were exfiltrated prior to the destructive action. (TechRadar)

This technique represents a fundamental shift in operational tradecraft. Rather than relying on endpoint-level persistence and execution, the actors targeted the control plane of the enterprise itself. With access to Intune, they effectively inherited the organization’s own administrative authority, allowing them to push destructive actions at scale with minimal friction and high reliability. As one analysis noted, once inside such a system, “an adversary… just need[s] to press a button,” highlighting how legitimate enterprise tooling can be weaponized for immediate, large-scale impact.

The implications of this approach are significant. First, it dramatically reduces the need for detectable malware artifacts, complicating traditional detection strategies that rely on endpoint indicators. Second, it enables near-instantaneous, synchronized disruption across globally distributed infrastructure, as seen in the simultaneous impact across dozens of countries in the Stryker event. Third, it allows actors to combine data exfiltration, destructive wiping, and public attribution within a tightly compressed timeline, reinforcing the campaign’s hack-and-leak model while increasing operational tempo. (Tenable)

Critically, this evolution does not replace earlier capabilities but integrates with them. The same ecosystem that previously relied on wipers, PowerShell scripts, and Telegram-based command-and-control now demonstrates the ability to pivot into identity and access compromise at the enterprise management layer, effectively collapsing the distinction between intrusion, execution, and impact. In this model, surveillance capabilities provide intelligence and targeting, administrative compromise enables execution at scale, and influence infrastructure  websites and Telegram amplify the effects through public messaging and data release.

Taken together, the Stryker incident illustrates the campaign’s progression into a fully converged operational framework, where destructive, surveillance, and influence capabilities are no longer sequential phases but simultaneous, interdependent components. The abuse of Intune marks a notable escalation in both technical sophistication and strategic impact, demonstrating that the actors are not only adapting their tooling, but are increasingly targeting the centralized control mechanisms of modern enterprise environments to achieve rapid, large-scale disruption aligned with broader geopolitical objectives.

Operational Model: Hack-and-Leak as Psychological Operations

The Homeland Justice and Handala campaigns are best understood as state-directed hack-and-leak operations engineered for psychological impact, in which technical intrusion serves as a means to produce exploitable narratives rather than an end in itself. From their earliest manifestation, these operations have been structured to convert access into influence: compromise enables collection, collection enables disclosure, and disclosure is shaped to achieve coercive or reputational effects. This framing distinguishes the activity from financially motivated ransomware or purely clandestine espionage, positioning it instead within a model of cyber-enabled information warfare aligned with state objectives.

From the Albania campaign onward, data theft has been systematically paired with controlled, curated public disclosure through actor-operated infrastructure, including websites and Telegram channels such as @Homeland Justice1. These platforms function as dissemination nodes where messaging is crafted, amplified, and aligned with political narratives. The release of stolen material, often selective, staged, or thematically framed, is designed to maximize audience impact, reinforce claims of legitimacy, and sustain attention over time. In this sense, the infrastructure is not merely a repository for leaked data, but an active component of the operational workflow, bridging the gap between technical compromise and public perception.

@Homeland Justice1 Telegram Channel

Within this model, destructive actions serve primarily to amplify visibility and urgency, creating conditions that heighten the impact of subsequent disclosures. Wiping, encryption, and service disruption draw attention to the incident and signal capability, but the strategic value is realized through narrative amplification of how the event is presented, interpreted, and circulated. The transition to the Handala persona reflects a further refinement of this approach, with increased segmentation of infrastructure to support distinct functions such as leak publication, propaganda, and targeted exposure of individuals. This specialization indicates a maturing operational framework in which success is measured less by persistence or financial return, and more by the ability to shape perception, apply pressure, and influence behavior across both institutional and individual targets.

Infrastructure and Domain Ecosystem

The infrastructure supporting the Homeland Justice and Handala campaigns reflects a deliberate, layered architecture designed to separate public-facing operations from backend control while enabling specialized functions across the ecosystem. Core domains such as Homeland Justice[.]org, handala-hack[.]to, handala-redwanted[.]to, and karmabelow80[.]org operate as visible nodes for messaging, leak publication, and intimidation, serving as the primary interface through which the actors communicate with both targets and broader audiences. These platforms are used to disseminate propaganda, frame narratives, and release or reference stolen data, transforming technical intrusions into publicly consumable events aligned with the campaign’s psychological objectives.

Behind this visible layer, additional domains such as homelandjustice[.]cx and Homeland Justice[.]ru likely function as alternate or backend infrastructure, supporting operational continuity and resilience. This separation suggests an architecture in which public-facing assets can be replaced or rotated without disrupting underlying capabilities, thereby reducing exposure while maintaining persistence. Within this system, each domain appears to serve a distinct and purpose-driven role, contributing to a modular framework that supports narrative framing, data publication, and targeted exposure. This functional segmentation reinforces the broader operational model, enabling the actors to coordinate technical compromise with controlled disclosure and messaging in a cohesive and scalable manner.

Tactics, Techniques, and Procedures (TTPs)

The campaign demonstrates a high degree of consistency in its tactics, techniques, and procedures (TTPs) across all observed phases, reflecting a mature and repeatable operational playbook. Initial access is typically achieved through a combination of exploitation of internet-facing services and targeted social engineering depending on the operational context. In earlier phases, actors leveraged vulnerabilities in externally exposed systems such as Microsoft SharePoint or Exchange to gain footholds within enterprise environments. In parallel, particularly in later surveillance-oriented activity, access has been obtained through user-centric compromise, including phishing and the delivery of trojanized applications tailored to specific targets. This dual approach allows the actors to flexibly pursue either broad network intrusion or highly targeted individual access depending on mission requirements.

Once access is established, persistence is maintained through a mix of webshell deployment and registry-based mechanisms, enabling continued control over compromised systems even in the face of remediation efforts. Webshells, often deployed on IIS or similar web servers, provide durable remote access and are frequently reused or redeployed as needed. Registry modifications and scheduled tasks are used to ensure execution at startup or at defined intervals, supporting long-term presence within the environment. Lateral movement is conducted using standard administrative protocols such as RDP, SMB, and Windows Management Instrumentation (WMI), often leveraging harvested credentials to blend activity with legitimate administrative behavior. This reliance on native protocols reduces the need for specialized tooling and helps evade detection by appearing consistent with normal network operations.

Credential access is a critical component of the campaign and is achieved through both credential harvesting and memory dumping techniques. Actors extract credentials from configuration files, email systems, and browser stores, while also leveraging native Windows components such as rundll32 and comsvcs.dll to dump LSASS memory and obtain plaintext credentials or hashes. These credentials are then used to escalate privileges and expand access across the network. Execution throughout the campaign frequently relies on PowerShell and command-line utilities, reflecting a strong preference for living-off-the-land techniques. PowerShell scripts are used for payload delivery, lateral movement, and destructive actions, and can be easily obfuscated or modified to evade detection while maintaining operational flexibility.

Data exfiltration is conducted using a combination of traditional methods and platform abuse, depending on the target environment and desired level of stealth. Files are typically staged locally, compressed, and transferred using standard protocols such as HTTP(S), FTP, or cloud storage services. In more advanced phases, particularly those involving surveillance, the actors leverage Telegram-based exfiltration, using the platform’s API to transmit data through encrypted channels that blend with legitimate traffic. This approach provides both resilience and deniability, as it reduces dependence on dedicated command-and-control infrastructure and leverages widely permitted network activity.

The impact phase integrates multiple destructive techniques, including disk wiping, file encryption, and manual system destruction, often executed in a coordinated manner across numerous endpoints. Custom wipers, PowerShell-based deletion scripts, and legitimate tools such as disk formatting utilities or encryption software are used in combination to maximize damage and complicate recovery. In some cases, actors manually execute commands to delete critical files or disable services, reinforcing the overall impact. This phase is frequently followed by immediate public disclosure, with the actors claiming responsibility and releasing messaging or data through controlled infrastructure. This rapid transition from technical action to public exposure is a defining characteristic of the campaign, linking operational execution directly to its broader objective of psychological influence and coercion.

Evolution of Personas

The progression from Homeland Justice to Karma and ultimately Handala reflects deliberate rebranding rather than a change in the underlying actor set. Core tradecraft, targeting logic, infrastructure patterns, and operational sequencing remain consistent, indicating continuity of capability and control. Homeland Justice was tightly aligned with the Albania campaign, emphasizing retaliation and coercive political messaging. As operations expanded, particularly after the Israel-Hamas conflict, the Karma persona enabled repositioning within a broader ideological frame while preserving the same methods. Handala represents a further evolution toward a durable, scalable identity suited for sustained, multi-theater activity.

These personas function as operational “skins” layered over a stable technical and organizational foundation. Each is tailored to specific audiences and narratives: Homeland Justice to Albanian political dynamics and the MEK (Mojahedin-e-Khalq), Karma to anti-Israeli messaging, and Handala to broader symbolic framing applicable across conflicts. This segmentation optimizes psychological resonance while complicating attribution by creating the appearance of distinct groups.

Multiple personas also manage exposure and risk. Branding shifts allow actors to distance current activity from prior campaigns, reset perception, and adapt to changing conditions without abandoning infrastructure or tradecraft. Parallel operations can run under different identities, reinforcing perceived decentralization. Despite this, consistent use of hack-and-leak workflows, Telegram and leak sites, and similar tooling confirms these are not separate entities but components of a unified, centrally directed ecosystem.

Strategic Assessment

These campaigns represent a state-directed, cyber-enabled influence capability that aligns closely with the operational doctrine of Iran’s Ministry of Intelligence and Security (MOIS), in which cyber operations are employed not solely for intelligence collection or disruption, but as instruments of coercion, signaling, and psychological pressure. The integration of intrusion, disruption, and narrative manipulation into a single operational system reflects a deliberate strategy in which technical access is leveraged to produce effects in the information domain. In this model, network compromise enables data acquisition and operational positioning; disruption amplifies visibility and urgency; and controlled disclosure shapes perception, imposes reputational cost, and pressures decision-making. These elements are not sequential but interdependent, forming a cohesive framework designed to influence both institutional behavior and individual actors across geopolitical contexts.


Recent infrastructure activity over the last several weeks provides direct, empirical support for this assessment and demonstrates that this capability remains active, adaptive, and operationally synchronized. Between 19 March and 23 March 2026, the actor cluster executed a compressed domain registration burst, provisioning at least eight new domains across all three personas: Handala, Karma/KarmaBelow80, and Homeland Justice. The majority of these domains are Handala-branded, including handala-hack[.]pro, handala-hack[.]shop, handala-hack[.]tw, handala-redwanted[.]cc, and handala-redwant[.]to, indicating that Handala remains the primary outward-facing operational identity. In parallel, the registration of karmabelow80[.]biz, karmabelow80[.]st, and notably Homeland Justice[.]info demonstrates that legacy personas are being actively reconstituted rather than retired.

This pattern is analytically significant. It indicates that personae evolution within this ecosystem is not linear but additive and concurrent. The actors are not transitioning from one identity to another; instead, they are maintaining multiple branded layers simultaneously, enabling them to pivot narratives, distribute operational risk, and complicate attribution. The near-simultaneous reactivation of Homeland Justice alongside active Handala expansion suggests deliberate attribution shaping and historical continuity signaling, reinforcing the perception of a persistent, ideologically driven campaign lineage.

The temporal characteristics of this activity further reinforce its operational intent. The tight clustering of registrations within a five-day window is consistent with pre-operational staging or infrastructure regeneration following disruption rather than routine domain churn. The inclusion of both “hack”-labeled domains and “redwanted”-style domains within this burst indicates parallel preparation for both intrusion-linked branding and leak-and-shame operations, which are central to this ecosystem’s influence model. This aligns with prior observed behavior in which compromised data is rapidly operationalized for public dissemination and psychological effect.

Comparable operational patterns can be observed in other state-aligned ecosystems, including Russian influence campaigns such as those associated with the Doppelgänger campaigns and hack-and-leak operations attributed to GRU-linked actors, and DPRK multi-cluster activity, where distinct operational units specialize in intrusion, financial operations, or disruption. However, the Homeland Justice / Handala ecosystem is distinguished by its consistent and tightly coupled integration of hack-and-leak operations with overt psychological messaging. Whereas Russian operations often separate intrusion from amplification, and DPRK activity frequently prioritizes financial or espionage outcomes, this campaign persistently merges technical compromise with immediate public attribution, curated disclosure, and ideological framing. The latest domain registrations reinforce this distinction by showing that infrastructure supporting both compromise and narrative dissemination is provisioned in parallel, not sequentially.

Accordingly, this activity should not be interpreted as a series of isolated incidents or campaigns, but as a persistent, evolving capability embedded within a broader state strategy. The newly observed domain registrations demonstrate that this capability can be rapidly reconstituted, expanded, and rebranded on demand, even in the face of prior takedowns or disruptions. The reuse of naming conventions, the continuity of tradecraft, the simultaneous operation of multiple personas, and the structured expansion of domain infrastructure all indicate an enduring operational framework rather than ad hoc activity. This capability can be activated, scaled, or redirected in response to changing geopolitical conditions, allowing it to remain relevant across multiple theaters and target sets. As such, it represents a sustained mechanism through which the state can project influence, apply pressure, and shape narratives in the cyber and information domains over time.

A.1 Albania Campaign (Homeland Justice)

Timeframe: ~May 2021–September 2022 (Initial Access → Impact)

Destructive / Encryption Malware

File Type Hash (MD5) Notes
GoXML.exe Ransomware / Encryptor bbe983dba3bf319621b447618548b740 Primary encryption payload
cl.exe Disk Wiper 7b71764236f244ae971742ee1bc6b098 Raw disk overwrite
mellona.exe Propagation Tool 78562ba0069d4235f28efd01e3f32a82 Lateral movement support

Webshells (Persistence)

File Type Hash (MD5) Notes
Error4.aspx Webshell 81e123351eb80e605ad73268a5653ff3 Initial persistence
ClientBin.aspx Webshell a9fa6cfdba41c57d8094545e9b56db36 IIS-based control
Pickers.aspx Webshell 8f766dea3afd410ebcd5df5994a3c571 Additional access vector

Supporting / Staging Tools

File Type Hash (MD5) Notes
disable_defender.exe Defense Evasion 60afb1e62ac61424a542b8c7b4d2cf01 AV disable
win.bat Script 1635e1acd72809479e21b0ac5497a79b Execution chain
win.bat (variant) Script 18e01dee14167c1cf8a58b6a648ee049 Variant
bb.bat Script 59a85e8ec23ef5b5c215cd5c8e5bc2ab Deployment
rwdsk.sys Driver 8f6e7653807ebb57ecc549cef991d505 Raw disk access
Goxml.jpg Decoy / Payload Carrier 0738242a521bdfe1f3ecc173f1726aa1 Masquerading artifact

A.2 Albania Follow-On Campaign (No-Justice Wiper)

Timeframe: Late 2023–Early 2024

Destructive Malware

File Type Hash (SHA-256) Notes
Ptable.exe / NACL.exe Disk Wiper 36cc72c55f572fe02836f25516d18fed1de768e7f29af7bdf469b52a3fe2531f Signed binary; prevents OS boot

Supporting Scripts

File Type Notes
p.ps1 PowerShell propagation script Lateral spread
zip.zip Archive Payload staging

A.3 Israel Campaign (Karma / Void Manticore)

Timeframe: October 2023–Mid 2024

Custom Tooling

Tool Type Notes
Karma Shell Webshell Disguised as error page
do.exe Credential validation tool Domain admin check
reGeorge Webshell Post-auth access

Destructive / Wiper Activity

Tool Type Notes
BiBi Wiper (Windows/Linux) Disk Wiper Multi-platform destruction
SDelete Secure deletion tool Living-off-the-land
format utility Disk formatting Manual destruction

A.4 Handala Campaign (Destructive Operations)

Timeframe: 2025–2026

Primary Wipers

File Type Hash (MD5) Notes
handala.exe Custom Wiper 5986ab04dd6b3d259935249741d3eff2 Core destructive payload
PowerShell Wiper Script 3cb9dea916432ffb8784ac36d1f2d3cd Recursive deletion

Supporting / Abuse of Legitimate Tools

Tool Type Hash (MD5) Notes
VeraCrypt Installer Encryption tool 3236facc7a30df4ba4e57fddfba41ec5 Destructive encryption
NetBird Installer Networking 3dfb151d082df7937b01e2bb6030fe4a Lateral connectivity
NetBird Networking e035c858c1969cffc1a4978b86e90a30 Persistence

A.5 MOIS Telegram C2 Malware Campaign

Timeframe: Fall 2023–2026

Stage 1 (Initial Access / Lures)

File Type Hash (MD5)
Telegram_Authenticator.exe Loader B9086413E7B6A0C6A11C25D14C22615F
KeePass.exe Loader 7402F2F9263782A4C469570035843510
Pictory_premium_ver9.0.4.exe Loader 1E6B601F733BC40EAA58916986BFC5B9
WhatssApp.exe Loader (filename observed, hash unknown)

Stage 2 (Persistence / Exfiltration)

File Type Hash (MD5) Notes
RuntimeSSH.exe Backdoor EBDD9595B79B39F53909D862499DBC94 Reverse SSH
RuntimeSSH.exe (variant) Backdoor E51FF37FB431767DCDEC0B5E6D2A786A Variant
MicDriver.exe Surveillance D70EBF20E3D697897BAD5BEBF72EA271 Audio capture
MicDriver.dll Support F8B5554808428291ACC65D1FD2EFE01C
MsCache.exe Data theft 3E7A2FCEF1D038D05B20148C573A6499 Cache extraction
winappx.exe Execution 481C5B5E69A08C3DF206C59FD8DDC0DC
smqdservice.exe Persistence 7E23FFADB664B0E53D821478A249D84C

Supporting Artifacts

File Type Hash (MD5)
rantom.txt Data artifact A3394EF7FFA7E88B2E7EFAEE4617FE04
rantom.txt (variant) Data artifact 2965817D063F1E8F9889F9126443D631

Command-and-Control

api.telegram.org

A.6 Cross-Campaign Observations

Malware Evolution Pattern

Phase Characteristic
2022 Custom ransomware + wiper combo
2023 Signed wipers + propagation scripts
2024 Hybrid manual + custom destruction
2025–2026 Modular wipers + LOTL tooling + mesh networking
Parallel Telegram-based surveillance malware

Key Trends

  • Increasing reliance on living-off-the-land tools
  • Use of signed binaries for evasion
  • Shift toward multi-method destruction
  • Expansion into surveillance + repression tooling
  • Persistent integration with information operations

Appendix B – MITRE ATT&CK Matrix by Campaign Phase

his appendix presents a matrix-style mapping of the Homeland Justice / Karma / Handala ecosystem across the MITRE ATT&CK Enterprise framework, broken down by campaign phase. It highlights how capabilities evolved while maintaining continuity across tactics.

B.1 Albania Campaign (2022) – Homeland Justice

Tactic Techniques
Initial Access T1190 Exploit Public-Facing Application
Execution T1059 Command Interpreter, T1059.001 PowerShell
Persistence T1505.003 Web Shell
Privilege Escalation T1078 Valid Accounts
Defense Evasion T1070 Indicator Removal
Credential Access T1003.001 LSASS Memory
Discovery T1087 Account Discovery
Lateral Movement T1021.001 RDP, T1021.002 SMB
Collection T1114.002 Remote Email Collection
Command & Control T1105 Ingress Tool Transfer
Exfiltration T1041 Exfiltration Over C2
Impact T1486 Data Encryption, T1561.001 Disk Wipe, T1485 Data Destruction

B.2 No-Justice Wiper Phase (Late 2023)

Tactic Techniques
Execution T1059.001 PowerShell
Persistence T1078 Valid Accounts
Defense Evasion T1218 System Binary Proxy Execution, T1036 Masquerading
Lateral Movement T1021 Remote Services
Command & Control T1105 Ingress Tool Transfer
Impact T1561.001 Disk Wipe, T1485 Data Destruction, T1490 Inhibit Recovery

B.3 Karma Phase (Israel Operations 2023–2024)

Tactic Techniques
Initial Access T1190 Exploit Public-Facing Application
Execution T1059, T1059.001 PowerShell
Persistence T1505.003 Web Shell
Privilege Escalation T1078 Valid Accounts
Defense Evasion T1070 File Deletion, T1562 Impair Defenses
Credential Access T1003.001 LSASS Memory
Discovery T1018 Remote System Discovery
Lateral Movement T1021.001 RDP, T1021.002 SMB
Collection T1005 Data from Local System
Command & Control T1105 Ingress Tool Transfer
Exfiltration T1041 Exfiltration Over C2
Impact T1485 Data Destruction, T1561 Disk Wipe

B.4 Handala Phase (2024–Present)

Tactic Techniques
Initial Access T1190, T1566 Phishing
Execution T1059.001 PowerShell, T1218.011 Rundll32
Persistence T1547 Boot/Logon Autostart
Privilege Escalation T1078 Valid Accounts
Defense Evasion T1036 Masquerading, T1562 Impair Defenses
Credential Access T1003.001 LSASS, T1555 Credential Stores
Discovery T1087 Account Discovery, T1069 Permission Groups
Lateral Movement T1021 RDP/SMB
Collection T1005 Local Data
Command & Control T1105 Tool Transfer
Exfiltration T1041 Exfiltration
Impact T1485 Data Destruction, T1486 Encryption, T1490 Inhibit Recovery

B.5 Telegram Surveillance Campaign (2023–2026)

Tactic Techniques
Initial Access T1566 Phishing, T1204 User Execution
Execution T1059.001 PowerShell
Persistence T1547 Registry Run Keys
Defense Evasion T1036 Masquerading
Credential Access T1555 Credential Stores
Discovery T1087 Account Discovery
Collection T1113 Screen Capture, T1123 Audio Capture, T1005 Data Collection
Command & Control T1071.001 Web Protocols (Telegram API)
Exfiltration T1041 Exfiltration via C2
Impact (Indirect – psychological/repression rather than system destruction)

B.6 Persona / Influence Infrastructure Layer

Tactic Techniques
Resource Development T1583.001 Domains, T1583.003 VPS
Establish Accounts T1585.001 Social Media Accounts
Stage Capabilities T1608 Upload/Stage Data
Command & Control T1102 Web Service (Telegram as platform)

B.7 Cross-Phase ATT&CK Heat Map (Summary)

Tactic Consistency Level
Initial Access High
Execution (PowerShell / CLI) Very High
Persistence High
Credential Access Very High
Lateral Movement Very High
Collection High
Command & Control High
Exfiltration High
Impact Very High
Influence / Persona Ops Unique / Defining


APPPENDIX C Leaks Impact

Victim Leak (Relative Timeline) Claimed Data Confirmed Adverse Event Impact Type Confidence
Stryker Corporation Late (T10) Large-scale data + "wipe" Operational disruption to manufacturing, ordering, and shipments; systems restoration required; ~80,000 devices reportedly wiped Operational + destructive HIGH
Kash Patel External (not in TW mirror but linked campaign) Emails, personal data Public exposure of personal emails and documents; reputational and counterintelligence risk Exposure / reputational HIGH
Hebrew University of Jerusalem Late (parallel campaign) 40–48 TB wiped, 23 TB exfil (claimed) Claimed destructive attack; partial reporting, no strong independent confirmation of full scale Operational (claimed) MEDIUM
Verifone Mid–late (external claim) Payment system compromise (claimed) Company denied breach; no confirmed disruption Reputational only LOW
VahidOnline Mid (T5) ~180,000 users + phone numbers Doxxing and exposure of identities; intimidation risk to dissident network Identity exposure / intimidation MEDIUM-HIGH
Sima Shine Mid (T4) ~100,000 emails (claimed) Public leak claims; reputational and intelligence exposure; no confirmed operational disruption Exposure / reputational MEDIUM
Ilan Steiner Early–Mid (T3) ~50,000 emails (claimed) Public leak claims; financial/internal exposure narrative; no confirmed secondary impact Exposure / reputational MEDIUM
Deborah Oppenheimer Early (T2) Private communications (claimed) Public exposure claims; limited external corroboration of downstream effects Exposure / reputational LOW-MEDIUM
Eran Ortal Early (T1) Strategic documents (claimed) Narrative exposure of military planning; no confirmed operational consequence Exposure / narrative LOW-MEDIUM
Israeli Security Institutions (aggregate) Mid–Late (T7) ~50,000+ emails (claimed) Systemic compromise narrative; no confirmed service disruption or institutional failure Exposure / perception MEDIUM
Mossad-linked "Treasury" Mid–Late (T6) Financial/internal documents (claimed) Corruption/financial exposure narrative; no confirmed operational impact Narrative / reputational LOW-MEDIUM
Israeli Water Infrastructure Late (T8) Target database (claimed) No confirmed breach; deterrence signaling only Strategic signaling LOW
Israeli Energy Grid Late (T9) Target database (claimed) No confirmed breach; deterrence messaging Strategic signaling LOW
Lockheed Martin engineers (Israel) External campaign Personal data (dox) Doxxing + threats; intimidation campaign; limited validation of dataset accuracy Physical intimidation MEDIUM
Learn More
Research
Handala: MOIS Linked Cyber Influence Ecosystem Threat Intelligence Assessment

Discover how Handala, Homeland Justice, and Karma function as a unified MOIS-linked cyber influence ecosystem. This threat intelligence assessment reveals how Iran uses "hack-and-leak" operations to weaponize perception over technical complexity.

Operational Structure and Attribution

The activity attributed to Homeland Justice, Karma/KarmaBelow80, and Handala is most accurately assessed as a single, coordinated cyber influence ecosystem aligned with Iran’s Ministry of Intelligence and Security (MOIS; وزارت اطلاعات جمهوری اسلامی ایران), rather than a collection of independent hacktivist groups. These personas function as interchangeable operational veneers applied to a consistent underlying capability. Their purpose is not to reflect organizational separation, but to enable segmentation of messaging, targeting, and attribution while preserving continuity of infrastructure and tradecraft.

The use of the name “Handala” itself reinforces the ideological framing of the campaign. Handala (حنظلة) is a well-known Palestinian symbol created by cartoonist Naji al-Ali, depicting a barefoot child who has turned his back on the world in protest of injustice and dispossession. Within the context of this cyber campaign, the adoption of the Handala identity serves to anchor operations within a broader “resistance” narrative, signaling alignment with anti-Israeli and anti-Western themes while providing a culturally resonant and emotionally charged brand for influence operations.

Across all observed phases, the actors exhibit clear temporal continuity, shared infrastructure patterns, and a repeatable operational workflow. The persistence of these elements, despite rebranding, indicates centralized direction and capability management. The use of multiple identities is therefore best understood as a mechanism for narrative flexibility and operational deniability, rather than evidence of distinct actor groups.

Evolution of the Operational Model

The campaign first became visible under the Homeland Justice brand during the 2022 Albania operations, which established its foundational model: long-term access, structured data exfiltration, destructive or disruptive action, and immediate public disclosure. From the outset, technical operations were tightly coupled with messaging, indicating that disruption alone was not the objective. Instead, cyber activity was used to enable narrative exploitation and psychological impact.

Homeland Justice 2023 aka Handala Albanian Operations

Subsequent phases reflect an additive evolution rather than a replacement of capabilities. The Karma phase introduced a hybrid execution model combining custom tooling, publicly available utilities, and hands-on-keyboard tradecraft. This increased operational flexibility and reduced reliance on bespoke malware. The Handala phase further expanded this model into a multi-vector framework integrating destruction, surveillance, and influence operations. The addition of Telegram-based command-and-control and surveillance tooling marked a shift toward persistent, person-centric targeting, extending the campaign’s reach beyond institutions to individuals.

Convergence of Capabilities

Recent activity demonstrates a convergence of previously distinct operational components into a unified framework. Intrusion, surveillance, disruption, and influence are no longer sequential phases, but simultaneous and interdependent functions. The Stryker incident illustrates this evolution, where large-scale data exfiltration, enterprise-level disruption through administrative control systems, and immediate narrative amplification were executed in a tightly integrated manner.

This shift reflects a broader transition away from malware-centric operations toward identity and access compromise at the control-plane level, enabling rapid, scalable impact with minimal reliance on detectable artifacts. It also demonstrates an increased ability to align technical execution with strategic messaging in near real time.

Infrastructure and Amplification Model

The ecosystem is supported by a layered infrastructure designed to separate operational functions while maintaining resilience. Public-facing domains and Telegram channels act as dissemination and amplification nodes, where messaging is curated, claims are published, and stolen data is selectively exposed. These platforms are integral to the operational workflow, bridging the gap between technical compromise and public perception.

Twitter April 2026 Amplification acct

Telegram Amplification Accounts Over Time

Infrastructure is intentionally ephemeral. Domains are frequently rotated, and personas are rebranded or reactivated as needed. However, naming conventions, messaging patterns, and distribution channels remain consistent, allowing the campaign to maintain coherence despite disruption. This results in a system where infrastructure is disposable, but identity and narrative persist.

Operational Effects and Impact

The observable impact of this ecosystem reveals a consistent divergence between claimed and verified outcomes. While the actors present their operations as large-scale destructive intrusions, confirmed system-level disruption is relatively rare. Instead, the majority of activity produces data exposure, reputational damage, and psychological pressure, often targeting both institutions and individuals.

Media hype cycle of low hanging fruit hack of FBI director’s 2009 email account

Sensationalized Reward Offer for Trump or Netanyahu 2026

Many claims remain partially verified or unverified, yet still generate significant downstream effects. Organizations are compelled to investigate and respond, media coverage amplifies the narrative, and uncertainty is sustained. In practice, the perception of compromise often produces effects equivalent to confirmed compromise, enabling the actors to achieve disproportionate impact relative to their demonstrated technical capability.

Role of Telegram and Surveillance Integration

Telegram plays a central role within this ecosystem as both a command-and-control channel and a public dissemination platform. By leveraging a widely trusted service, the actors reduce infrastructure overhead and increase operational resilience. Malware can communicate with operator-controlled bots using encrypted channels indistinguishable from legitimate traffic, while Telegram channels simultaneously serve as hubs for messaging and amplification.

The integration of surveillance capabilities further expands the campaign’s scope. Trojanized applications and user-targeted lures enable persistent monitoring of individuals, particularly dissidents and opposition networks. This allows the actors to move seamlessly from covert collection to overt exposure, reinforcing the link between technical activity and psychological pressure.

Strategic Assessment

This ecosystem represents a state-directed instrument of cyber-enabled influence, in which technical operations are tightly integrated with narrative manipulation and media amplification dynamics to achieve coercive and strategic effects. Intrusion enables access, access enables collection, and collection enables controlled disclosure. However, the decisive phase is the conversion of that disclosure into a high-visibility narrative event. Incidents such as the compromise of Kash Patel demonstrate how relatively limited technical access can be operationalized through the modern news cycle, where rapid reporting, social media propagation, and secondary analysis amplify the perceived scale and significance of the breach. In this model, the hype cycle is not incidental; it is a core component of the operation, transforming modest compromises into strategic effects.

The maintenance of multiple concurrent personas, the rapid regeneration of infrastructure, and the consistent integration of cyber and information operations indicate a mature and adaptive capability optimized for this environment. These personas allow the actors to continuously seed new events into the information ecosystem, while disposable domains and Telegram channels ensure persistence of messaging even as infrastructure is disrupted. Each operation is effectively designed as a trigger for a predictable amplification loop: initial claim, media pickup, public discourse, and institutional response. This loop imposes reputational and operational costs on targets regardless of the underlying technical depth.

As a result, the system can be activated, scaled, or redirected in response to geopolitical conditions with minimal reliance on sustained intrusion capability. Its effectiveness lies in the ability to synchronize cyber activity with the tempo of the information environment, using the hype cycle to magnify impact across multiple theaters and target sets. In practical terms, this means that perception, attention, and narrative momentum are treated as operational objectives on par with access and disruption, allowing the actors to remain effective even when technical outcomes are limited.

Conclusion

Homeland Justice, Karma, and Handala should be treated as components of a unified operational apparatus, not discrete threat actors. Their effectiveness does not derive from sustained technical superiority or advanced intrusion tradecraft, but from their ability to fuse low-to-moderate cyber capability with disciplined psychological and informational operations to create a cohesive and scalable system.

Across observed incidents, the underlying modus operandi is consistent with opportunistic, identity-layer compromise rather than sophisticated exploitation. Initial access is frequently achieved through relatively low-complexity methods such as password guessing, credential stuffing, phishing, exploitation of weak or reused credentials, and poor security hygiene in externally exposed services. Even in higher-impact cases such as Stryker Corporation, the available indicators suggest that compromise likely originated from weak identity and access controls or misconfigured management infrastructure, rather than novel vulnerabilities or advanced malware deployment. This aligns with a broader pattern in which targets are selected not for hardened defenses, but for accessible attack surfaces and exploitable operational gaps.

In this sense, these actors operate closer to low-tier intrusion crews or access brokers in their technical execution. However, what differentiates them is not how they gain access, but what they do with it. Limited footholds – often no more than a compromised account, exposed dataset, or peripheral system – are systematically transformed into hack-and-leak operations designed for maximum psychological and media impact. Small or ambiguous datasets are framed as large-scale breaches; partial access is presented as systemic compromise; and unverified claims are released in ways that ensure rapid amplification.

This is where the integration with influence operations becomes decisive. The ecosystem relies heavily on timing, narrative construction, and media exploitation to convert low-level technical events into high-visibility incidents. The breach and leak involving Kash Patel is illustrative: a compromise of a personal account technically limited in scope was rapidly elevated into a widely covered event, generating disproportionate attention relative to its technical impact. This reflects a deliberate strategy in which the news cycle functions as an extension of the operation, amplifying reach and reinforcing perceived capability.

Targets are therefore often targets of opportunity, selected for their symbolic value, media relevance, or potential to generate secondary effects. The objective is not persistent access or long-term control, but event generation creating moments that can be exploited for narrative gain. Each operation is structured to trigger a predictable response cycle: disclosure, media coverage, public reaction, and institutional response. This cycle imposes real costs on victims and defenders, regardless of the underlying technical depth of the compromise.

The result is a model in which technical simplicity coexists with strategic effectiveness. Low-level intrusions, when paired with coordinated amplification and ambiguity, produce outcomes typically associated with more advanced actors. The distinction between hacking and influence is therefore not incidental but intentional. Cyber activity provides the entry point, but the primary objective is the shaping of perception, the erosion of confidence, and the projection of capability.

This approach reflects a broader evolution in state-aligned cyber operations. Rather than investing exclusively in high-end capabilities, actors can achieve comparable strategic effects by combining accessible intrusion techniques with sophisticated information operations. In this framework, success is measured not by the depth of compromise, but by the ability to control the narrative surrounding that compromise.

Accordingly, Homeland Justice, Karma, and Handala should be understood not as elite intrusion actors, but as hybrid operators leveraging low-cost cyber access to generate high-impact psychological effects. Their significance lies in demonstrating that, in the current information environment, perception can be weaponized as effectively as technical capability. Furthermore, it demonstrates that even modest breaches can be scaled into strategic events when amplified through media and narrative control.

Learn More
Research
DPRK Malware Modularity: Diversity and Functional Specialization

Explore the DPRK’s modular malware architecture. Analyze how North Korea uses compartmentalized toolchains for espionage, crypto theft, and strategic signaling.

Executive Summary

North Korea’s cyber program has evolved into a deliberately fragmented malware ecosystem, optimized for mission specialization, operational resilience, and attribution resistance. Analysis of multiple vendor, government, academic, and secondary reporting confirms that what appears externally as a “fracture” is, in practice, a mature portfolio model: parallel malware development pipelines aligned to discrete strategic objectives.

This structure enables the DPRK to conduct simultaneous espionage, revenue generation, and disruptive operations without cross-contaminating tooling, infrastructure, or exposure. Compartmentalization and diversity is therefore assessed as a feature of program maturity, not decentralization or degradation.

Strategic Drivers

The current compartmentalization and diversity of North Korea’s malware ecosystem is not an accidental byproduct of growth or internal disorder; it is a rational response to sustained and cumulative strategic pressure. Over more than a decade, international sanctions have progressively constricted the regime’s access to hard currency, elevating cyber operations from an auxiliary intelligence function to a core mechanism of economic survival. At the same time, increasingly coordinated law-enforcement actions and intelligence disclosures have reduced the lifespan of individual campaigns, forcing DPRK operators to assume that any exposed tool, infrastructure cluster, or technique will eventually be neutralized.

This pressure has been compounded by the repeated public exposure of specific malware families and campaign narratives. Once-effective tools are now rapidly fingerprinted, attributed, and disseminated across defensive communities, collapsing their operational utility. Parallel to this, target environments particularly in finance, technology, and government have become more defensively mature, with improved telemetry, faster incident response cycles, and greater cross-sector information sharing. In aggregate, these factors have raised the cost of persistence and reduced the viability of monolithic, long-lived malware platforms.

In response, the DPRK has adapted by restructuring its cyber program around principles of resilience rather than longevity. Malware development and operations are increasingly compartmentalized, both technically and organizationally, ensuring that exposure in one mission area does not cascade across the entire program. Toolchains are treated as consumable assets: designed to be burned, replaced, and reconstituted with minimal strategic loss. This loss-tolerant posture enables multiple teams to operate in parallel, pursuing espionage, revenue generation, and disruptive objectives simultaneously without competing for the same infrastructure or codebase.

Crucially, this model also maximizes ambiguity. By separating tooling, infrastructure, and operational patterns along mission lines, the DPRK complicates attribution and slows defender decision-making. What emerges is not compartmentalization and diversity as weakness, but compartmentalization and diversity as control: a cyber apparatus engineered to absorb pressure, survive exposure, and continue functioning even as individual components are repeatedly stripped away.

Compartmentalized Malware Architecture

Espionage Oriented Malware Track

The espionage-oriented malware track represents the most traditional and strategically conservative pillar of the DPRK cyber program. Its purpose is not disruption or immediate financial return, but the quiet, sustained extraction of intelligence from institutions that shape policy, security planning, and strategic decision-making. Targets are selected for their informational value rather than their economic utility, encompassing government ministries, defense contractors, academic research centers, think tanks, and organizations operating at the margins of policy formation.

Operations within this track are characterized by restraint and patience. Activity is deliberately low-noise, with operators prioritizing extended dwell time over rapid exploitation. Initial access is leveraged to establish durable footholds that enable credential harvesting, mailbox surveillance, and systematic document collection. Once embedded, the objective is to observe, monitor, and siphon information continuously, often for months or years, with minimal operational disruption to the victim environment. Destructive actions and monetization are intentionally avoided, as they increase detection risk and prematurely terminate access.

Technically, this restraint is reflected in the tooling. Malware associated with espionage missions favors script-heavy loaders, most commonly PowerShell or VBS that blend into normal administrative activity and reduce the need for large, easily detected binaries. Backdoors are frequently memory-resident, minimizing on-disk artifacts and complicating forensic recovery. Initial access commonly relies on weaponized documents or carefully crafted lures tailored to the professional context of the target, reinforcing the emphasis on social engineering over exploit development.

Once access is established, trusted cloud services are routinely abused for command-and-control and staging. By operating through platforms already embedded in enterprise workflows, operators obscure malicious traffic within legitimate usage patterns and benefit from the implicit trust afforded to major service providers. This approach further reduces operational noise while extending persistence in environments with increasingly mature perimeter defenses.

This espionage track is most commonly associated with Kimsuky, which has long been assessed as a primary intelligence-collection component within the DPRK cyber ecosystem. Its campaigns exemplify the regime’s preference for slow, methodical access to high-value information streams, reinforcing the view that espionage remains a foundational mission even as financial and disruptive cyber operations expand alongside it.

Financial Operations Malware Track

The financially oriented malware track reflects the most adaptive and economically consequential arm of the DPRK cyber program. Its overriding purpose is revenue generation: converting access into currency in order to blunt the effects of international sanctions and directly fund regime priorities, including strategic weapons development. Unlike espionage operations, success in this track is measured not in persistence or insight, but in speed, scale, and yield.

Operations in this category are characterized by a markedly faster tempo. Campaigns are designed to move quickly from initial access to monetization, accepting shorter dwell times and higher exposure risk in exchange for financial return. Targeting is broad and opportunistic, with a pronounced focus on cryptocurrency exchanges, blockchain developers, decentralized finance platforms, and the software supply chains that underpin them. Rather than selecting victims for their strategic influence, operators select ecosystems where a single compromise can yield outsized financial gain or cascade into downstream access.

This operational urgency is mirrored in infrastructure management. Hosting, domains, and delivery mechanisms are treated as disposable, with rapid churn used to stay ahead of takedowns and blacklist propagation. Infrastructure longevity is not a priority; instead, it is optimized for brief windows of effectiveness before inevitable exposure. This burn-and-replace mindset distinguishes financial campaigns from the more conservative espionage track and underscores their role as an economic instrument rather than a long-term intelligence platform.

Technically, tooling within this track is purpose-built for theft. Wallet stealers and browser injectors are used to intercept credentials, private keys, and transaction workflows directly at the user layer. Clipboard hijacking exploits habitual behaviors to silently redirect cryptocurrency transfers. Increasingly, operators have demonstrated sophistication in compromising trust boundaries within the developer ecosystem itself, embedding malicious code into open-source packages or trojanizing software updates relied upon by exchanges and development teams. By inserting malware upstream, they convert trusted tooling into a scalable access vector.

Compromise of exchange infrastructure and developer environments further amplifies impact, allowing attackers to move laterally across platforms, users, and assets with minimal additional effort. These techniques reflect a deep understanding of how modern financial and crypto ecosystems are built and where their implicit trust assumptions can be subverted.

This revenue-focused track is most commonly associated with Lazarus Group, which has evolved from a primarily espionage-linked actor into a central pillar of the DPRK’s sanctions-evasion strategy. Its operations illustrate how malware has been weaponized not just as a tool of intrusion, but as a mechanism of state finance, tightly coupled to the regime’s broader strategic objectives.

Disruptive / Coercive Malware Track

The disruptive and coercive malware track represents the most overt and politically expressive component of the DPRK cyber program. Unlike espionage or financially motivated operations, its primary purpose is not persistence or profit, but strategic signaling. These operations are designed to demonstrate capability, impose costs, or deliver retaliation during periods of heightened geopolitical tension, serving as a cyber analogue to more traditional forms of state messaging and coercion.

Operationally, this track prioritizes impact over longevity. Dwell times are intentionally short, as operators expect rapid detection once payloads are deployed. Rather than avoiding attention, these campaigns are constructed to generate it, producing effects that are immediately visible to victims, governments, and, in some cases, the broader public. Tooling and infrastructure are treated as expendable, with a clear willingness to burn assets in exchange for a decisive, time-bound outcome.

The technical execution of these operations reflects this mindset. Payloads frequently take the form of wipers or ransomware-like tools capable of inflicting widespread disruption across enterprise environments. Once initial access is achieved, operators emphasize rapid lateral movement to maximize reach before containment measures can be enacted. Domain-wide execution is a common objective, enabling simultaneous impact across large portions of a target organization and amplifying both operational and psychological effect.

Timing is a critical element. Deployments are often aligned with external political, military, or diplomatic events, reinforcing the interpretive link between the cyber operation and broader state intent. This temporal coordination strengthens the signaling function of the attack, ensuring that the disruption is read not as isolated cybercrime, but as an intentional act within a wider strategic context.

This disruptive track is most commonly associated with Andariel, which has been linked to campaigns emphasizing sabotage, rapid execution, and overt impact. Within the fragmented DPRK malware ecosystem, this track functions as the regime’s blunt instrument: less subtle than espionage, less financially focused than theft, but uniquely suited to delivering unmistakable signals when strategic conditions demand it.

Cross-Track Technical Invariants

Despite the visible compartmentalization and diversity of tooling and operations, analysis across the full body of known malware reporting reveals a set of persistent unifying elements that cut across mission lines. These commonalities indicate that divergence at the payload and campaign level does not equate to independence at the development or strategic level. Instead, they point to shared standards, reuse patterns, and centralized oversight shaping how disparate malware tracks are built and deployed.

At the technical layer, recurring cryptographic routines and packing styles appear across otherwise distinct malware families. While implementations are often modified to frustrate signature-based detection, the underlying design choices remain recognizable, suggesting common developer playbooks or shared internal libraries. Similarly, loader architectures show strong familial resemblance: lightweight initial components designed to stage or decrypt secondary payloads, reused across campaigns with incremental variation rather than wholesale redesign.

Infrastructure analysis reinforces this picture. Even as domains and servers are rapidly rotated at the campaign level, overlap persists at lower layers of the stack, including registrars, hosting providers, and preferred geographic regions. This reuse reflects both operational convenience and institutional familiarity, revealing constraints and preferences that are difficult to fully obfuscate even in a fragmented model.

Perhaps most importantly, all tracks continue to rely heavily on social engineering as the primary initial access vector. Whether the objective is espionage, financial theft, or disruption, operators consistently exploit human trust rather than novel technical exploits. This dependence underscores a strategic assessment that human-mediated access remains more reliable, scalable, and adaptable than vulnerability-driven intrusion, particularly against increasingly hardened technical defenses.

Once access is achieved, there is a consistent preference for operating within trusted ecosystems. Cloud platforms, developer tooling, and collaboration services are repeatedly abused for command-and-control, staging, or lateral movement. By embedding malicious activity within environments already sanctioned and trusted by enterprises, operators reduce detection risk and leverage the implicit legitimacy of widely used services.

Taken together, these patterns demonstrate that compartmentalization and diversity exists primarily at the operational and payload level, not at the level of governance or development philosophy. The DPRK malware ecosystem is best understood as a collection of specialized instruments built from a common toolkit, governed by shared standards and strategic direction, even as execution diverges to meet distinct mission objectives.

Why Compartmentalization and Diversity Matters

Operationally, compartmentalization and diversity confers a high degree of resilience on the DPRK cyber program. Because malware families, infrastructure, and delivery mechanisms are compartmentalized by mission, the exposure or neutralization of one toolchain has limited impact beyond its immediate operational context. When a specific malware family is detected, attributed, and burned, the loss is contained; parallel mission tracks continue to function largely unaffected. This loss tolerance allows operators to assume compromise as a routine condition rather than an exceptional failure, encouraging aggressive use of tooling without risking systemic degradation of the broader program.

This resilience is reinforced by deliberate attribution friction. Divergent malware families, distinct infrastructure clusters, and varying tradecraft across campaigns complicate efforts to collapse activity into a single coherent actor model. Defenders and analysts are forced to disentangle overlapping indicators, slowing attribution and increasing uncertainty about scope and intent. Campaign clustering becomes more difficult as shared characteristics are diluted by intentional variation, while residual commonalities remain subtle enough to require sustained analytic effort to identify.

At the policy level, this ambiguity has concrete effects. Unclear attribution complicates decision-making around response options, escalation thresholds, and public messaging. When activity cannot be cleanly assigned to a single actor or mission set, responses tend to be slower, more cautious, and less coordinated. In this way, compartmentalization and diversity functions not only as a technical or operational safeguard, but as a strategic instrument shaping how adversary actions are interpreted while also constraining the speed and confidence with which states and organizations can respond.

Parallel Execution

Compartmentalization and diversity enables the DPRK cyber program to operate on multiple fronts simultaneously without the internal friction that would otherwise arise from shared tooling, infrastructure, or operational dependencies. By separating malware families and operational workflows along mission lines, distinct teams can pursue diplomatic, financial, and technological targets in parallel, each optimized for its own objectives and risk profile. This structure avoids the bottlenecks and trade-offs inherent in monolithic campaigns, where a single exposure can force a pause or redesign across all activity.

Against diplomatic and policy-oriented targets, espionage-focused operations can proceed patiently, maintaining long-term access and information flow without being disrupted by the higher-noise activities of financial theft or disruptive attacks. At the same time, financially motivated campaigns can move aggressively against cryptocurrency exchanges, developer communities, and related infrastructure, burning tooling and infrastructure as needed without jeopardizing sensitive intelligence footholds elsewhere. Disruptive operations, when activated, can deliver rapid and visible impact without revealing or contaminating the quieter channels of access maintained in parallel.

This separation of concerns allows the DPRK to treat its cyber operations as a portfolio of independent but strategically coordinated efforts. Each mission track operates according to its own tempo, tolerance for exposure, and technical requirements, yet all contribute to overarching state objectives. The result is a cyber apparatus capable of sustained, multi-domain engagement across diplomatic, economic, and technological domains without mutual interference or cascading operational risk.

Defender Implications

The fragmented structure of the DPRK malware ecosystem fundamentally alters the detection problem for defenders. Static malware signatures degrade rapidly as tooling is routinely modified, re-packed, or replaced altogether. Even when individual samples are successfully identified, their utility is short-lived, offering only fleeting defensive value before variants emerge. Similarly, campaign-level indicators of compromise once effective for clustering activity no longer generalize across operations, as distinct mission tracks deliberately minimize shared surface indicators.

As a result, malware-focused detection in isolation is increasingly insufficient. Focusing on payloads alone risks missing the broader operational context in which access is gained, maintained, and exploited. In a segmented model, the absence of a known malware signature does not imply the absence of DPRK activity; it may simply reflect a different mission track employing different tooling, infrastructure, or delivery mechanisms.

Effective defense therefore requires a shift in priorities. Behavioral analytics become critical for identifying anomalous patterns of access, execution, and data movement that persist regardless of specific malware families. Identity and access monitoring is particularly important, as many DPRK operations across espionage, financial, and disruptive tracks depend on credential abuse and trusted account usage rather than exploit-driven compromise. Strengthening security around supply chains and developer ecosystems is equally essential, given the regime’s demonstrated willingness to compromise upstream tooling to achieve scalable access. Cloud telemetry correlation, spanning authentication events, API usage, and cross-service activity, provides the visibility necessary to detect abuse within trusted platforms.

Organizations that frame DPRK activity too narrowly by treating it exclusively as espionage or, alternatively, as financial cybercrime risk creating analytical blind spots. The segmented nature of the threat means that focusing defenses on a single “type” of activity can leave other mission tracks undetected. Instead, a holistic approach, grounded in behavior, identity, and ecosystem trust relationships, is required to account for the full breadth of DPRK cyber operations.

Malware compartmentalization and diversity in the Broader APT Landscape

The deliberate burn-and-replace approach observed in DPRK malware campaigns is not without precedent among advanced state-aligned threat actors. However, comparative analysis shows that while similar tactics exist elsewhere, the degree of institutionalization and mission coupling seen in DPRK operations is unusually pronounced.

Several other APT actors have adopted rapid malware turnover, modular tooling, and payload rotation to evade detection and extend campaign viability under defensive pressure.

Russian intelligence–linked actors, such as APT29, have repeatedly evolved malware families over time, transitioning from early Duke variants to successive, distinct frameworks. These shifts demonstrate intentional tool refresh cycles designed to defeat signature-based detection, but they largely occur within a single strategic mission space of long-term espionage rather than across parallel, economically distinct objectives.

Similarly, APT28 has historically rotated between multiple malware families across campaigns, adapting tooling to geopolitical context and operational exposure. While this reflects a willingness to abandon burned tools, the activity remains more campaign-reactive than structurally segmented.

Chinese-linked APT41 presents a closer analogue in that it has demonstrably conducted both state-aligned espionage and financially motivated operations, often with overlapping personnel and infrastructure. APT41’s use of supply-chain compromise, rapid tool replacement, and diverse malware frameworks mirrors aspects of the DPRK model. However, public reporting indicates less rigid separation between mission toolchains, with greater reuse across objectives.

Iranian actors such as Charming Kitten likewise exhibit frequent shifts in malware payloads and delivery mechanisms, particularly in response to exposure. These changes improve survivability but do not rise to the level of a fully articulated portfolio model; tool churn here appears tactically driven, rather than strategically compartmentalized.

Finally, disruptive-focused Russian activity attributed to Sandworm demonstrates an extreme willingness to burn tooling entirely, particularly in wiper and destructive campaigns. However, this behavior is episodic and event-driven, rather than embedded in a standing, multi-mission cyber architecture.

Below is a comparative table showing how DPRK actors stand relative to other major nation-state APT actors (Russia, China, and Iran) in terms of tool churn, mission separation, and burn tolerance. This is based on multiple public sources outlining state-aligned cyber capabilities, campaign evolution, and malware practices.

Comparative Table   APT Malware Strategy & Burn Dynamics

Attribute DPRK
e.g., Lazarus / Kimsuky / Andariel
Russia
e.g., APT29 / Gamaredon / Sandworm
China
e.g., APT41 / ShadowPad Actors
Iran
e.g., APT33 / OilRig / Infy
Tool Churn / Malware Refresh High — Frequent tool replacement across multiple distinct malware families; new tooling expected as exposed. Part of intentional program design (burn/rebuild). Moderate — Malware families evolve (e.g., MiniDuke → OnionDuke → CosmicDuke), but changes are often adaptive rather than systematic churn.
Wikipedia
Moderate to High — Some modular platforms (ShadowPad) persist with evolving variants; APT41 leverages diverse malware and reuses components across operations.
SentinelOne
Low to Moderate — Generally stable toolsets with iterative updates; malware families deployed repeatedly across campaigns rather than replaced entirely.
Picus Security
Mission Separation (multiple distinct operational streams) High — Clear mission-aligned malware portfolios (espionage, financial, disruption) acting concurrently. Low–Moderate — Primarily espionage and disruption; mission roles are contextual but not structurally separated as distinct portfolios.
Wikipedia
Moderate — APT41 uniquely combines espionage + financial operations, but toolsets are often reused between missions.
TerraZone
Low — Focused primarily on espionage; mission separation is less pronounced.
Picus Security
Burn Tolerance (willingness to discard tools) Very High — Tool loss anticipated and baked into design; "burn and replace" is normative. Moderate — Tools are refreshed when detection risk becomes too high, but not as a planned operational norm. Moderate — Tools evolve to evade detection; often reused rather than fully discarded; some long-lived frameworks. Low–Moderate — Tools persist across campaigns; not typically discarded unless externally exposed.
Malware Modularity High — Early-stage loaders, persistence, and mission payloads frequently have distinct and individual modules. High — Uses modular backdoors and plugin architectures (e.g., Cozy Bear's Duke variants).
Wikipedia
High — Both modular backdoors (ShadowPad) and custom/third-party tools used.
SentinelOne
Moderate — Modular in some groups (e.g., OilRig's PowerShell modules) but less generalized than for large nation actors.
Picus Security
Cross-Campaign Reuse of Family Low — Malware families are mission distinct and often unique to a given operational track. Moderate — Reuse of older frameworks with evolution; variants often retain lineage.
Wikipedia
Moderate to High — Some core backdoors reused across different campaign objectives.
SentinelOne
High — Smaller toolsets reused across multiple campaigns with minor updates.
Picus Security
Integration with Financial Crime Explicit — Financial malware track is part of the core strategy to generate revenue. Rare — Russian state groups typically avoid financially focused malware as a strategy. Present — APT41 engages in some financially motivated activity alongside state espionage.
TerraZone
Minimal — Iranian actors mostly focus on espionage or disruption, not economic theft or revenue generation.

Analytic Distinction: Why the DPRK Model Is Different

What distinguishes the DPRK cyber program is not the existence of malware rotation itself, but how completely burn-and-replace logic is integrated into program design.

Across other APT ecosystems, rapid malware turnover is typically:

  • A response to detection,
  • Confined to a single mission domain, or
  • Implemented unevenly across campaigns.

By contrast, DPRK operations demonstrate:

  • Standing parallel malware portfolios, not ad-hoc replacements,
  • Mission-aligned toolchains (espionage, revenue, disruption),
  • Acceptance of tool loss as routine, not exceptional,
  • And centralized strategic coordination despite decentralized execution.

This places DPRK activity closer to an industrialized cyber production model, where malware is treated as a consumable input rather than a prized asset.

In contrast, espionage tooling is expected to retain its emphasis on low-noise persistence. Malware supporting intelligence collection will continue to prioritize stealth, credential abuse, and cloud-based living-off-the-land techniques that enable extended dwell times even in increasingly monitored environments.

Taken together, these trends indicate that compartmentalization and diversity is not a transitional phase but a durable feature of the DPRK cyber program. As defensive pressure increases, diversification by mission will deepen, further entrenching a model built to absorb exposure, frustrate attribution, and sustain operations across multiple strategic domains.

Summary Findings

The DPRK malware ecosystem is not simply more prolific or more chaotic than that of its peers; it is more deliberately structured at a fundamental, programmatic level. Where many advanced persistent threat actors treat malware as a semi-durable asset to be preserved and refined over time, the DPRK treats malware as an inherently expendable input. Tool exposure is not regarded as a failure state; it is an assumed outcome. As a result, operational planning begins from the premise that any given toolchain will eventually be detected, attributed, and neutralized.

This assumption fundamentally reshapes how the DPRK designs and deploys cyber capabilities. Malware is engineered for utility within a limited lifespan rather than for long-term survivability. Development pipelines emphasize speed, modularity, and replaceability over elegance or longevity. When a tool is burned, it is not mourned or patched indefinitely; it is discarded and superseded, often by a parallel or already-prepared alternative. In this sense, compartmentalization and diversity is not a defensive reaction to disruption, but the default state of the ecosystem.

By contrast, many other APT actors burn tools reluctantly and reactively. Russian, Chinese, and Iranian groups typically rotate malware families after exposure, but such decisions are often tied to specific campaigns or incidents. The underlying assumption remains that tools should persist as long as possible, evolving incrementally to preserve prior investment. The DPRK departs from this logic entirely. Its cyber operations reflect an acceptance that persistence at the tool level is illusory, and that strategic continuity must instead be achieved through organizational design and operational redundancy.

Seen in comparative context, DPRK cyber operations are therefore best understood not as an anomaly, but as a mature instantiation of a broader trend among advanced threat actors pushed to its logical extreme by unique economic and political constraints. Persistent sanctions, direct linkage between cyber activity and state revenue, and sustained international scrutiny have compressed the DPRK’s tolerance for operational pause or degradation. Under these conditions, a cyber program built around long-lived platforms would be brittle. A program built around compartmentalization and diversity, parallel execution, and consumable tooling is resilient.

Malware diversity, rapid churn, and concurrent mission execution are not symptoms of disorder or indiscipline. They are the visible mechanics of a system engineered to function under constant pressure, where exposure is continuous and inevitability assumed. In this model, coherence does not reside in individual tools, but in strategy: centralized intent, mission-aligned portfolios, and an operational architecture designed to endure even as its individual components are repeatedly destroyed.

APPENDIX A: Representative DPRK Malware IOCs  

Government-Published Malware Variants & Names

These malware families have been documented in U.S. government malware reports and advisories associated with North Korean state actors (often referred to collectively as HIDDEN COBRA by U.S. agencies): (CISA)

  • BLINDINGCAN – Remote access tool used to maintain persistence and network exploitation. (CISA)
  • COPPERHEDGE – Manuscrypt family variant attributed to North Korean APT targeting exchanges/crypto ecosystems. (CISA)
  • TAINTEDSCRIBE – Full-featured beaconing implant used by DPRK actors. (CISA)
  • PEBBLEDASH – North Korean beaconing implant family. (CISA)
  • BISTROMATH – Remote access implant with multiple versions observed. (CISA)
  • SLICKSHOES – Dropper with beaconing capabilities. (CISA)
  • CROWDEDFLOUNDER – Beaconing payload with packing protections. (CISA)
  • HOTCROSSIANT – Full-featured beaconing implant. (CISA)
  • ARTFULPIE – Downloader implant that decodes and executes secondary payloads. (CISA)
  • BUFFERLINE – Full-featured beaconing implant. (CISA)
  • ELECTRICFISH – Proxy malware for tunnelled traffic. (CISA)
  • BADCALL – Proxy server malware with Fake TLS methods. (CISA)
  • Joanap – RAT enabling botnet management and secondary payload execution. (Wikipedia)

Note: CISA malware analysis reports (MARs) frequently include sample hashes, file Thatnames, network indicators, and signatures for these variants. (CISA)

Appendix B:   Malware Linked Activities and Attribution Context

Cryptocurrency-Facilitating Malware

  • AppleJeus – Malware family used to facilitate cryptocurrency theft, often distributed under the guise of fake trading platforms or wallets. (CISA)

Operational Artifacts & TTP Context

While specific IOCs vary by incident and campaign, the following patterns are relevant to detection and triage:

  • Botnet infrastructure IPs associated with DDoS and proxy relays used by DPRK actors. (CISA)
  • Credential harvesting and session token theft in spearphishing campaigns (e.g., mobile-delivered QR code phishing vectors). (Internet Crime Complaint Center)
  • Proxy and beaconing communication over Fake TLS or tunneled channels seen in BADCALL/ELECTRICFISH series. (CISA)

Appendix C: Known Malware Families by Associated Actor

Malware Family Common Attribution / Actor Lineage Source
BLINDINGCAN DPRK state-linked APT variants CISA
Manuscrypt / COPPERHEDGE Currency theft and exchange targeting CISA
AppleJeus Cryptocurrency facilitation malware CISA
Joanap / Brambul ecosystem RAT + worm infrastructure tied to Hidden Cobra / HIDDEN COBRA Wikipedia
Multiple beaconing implants (TAINTEDSCRIBE, CROWDEDFLOUNDER, etc.) DPRK APT variants CISA

Appendix D:  Additional IOC Sources and Hunting References

For operational deployment, consult the following sources with downloadable IOC datasets:

  • CISA North Korea State-Sponsored Threat Advisories   Includes malware reports, sample hashes, and network indicators. (CISA)
  • Unit42 Threat Assessment  North Korean Groups Malware Arsenal   Contains telemetry on recent malware families across OS platforms. (Unit 42)
  • Acronis TRU Alliance DPRK Malware Infrastructure Mapping   Includes IOCs and hunting guidance for Lazarus and Kimsuky clusters. (Acronis)

Appendix E: Exemplar File Hashes by “Hydra Head” (SHA256)

F.1 Head 1   LABYRINTH CHOLLIMA (Espionage / Industrial, logistics, defense)

Primary exemplars (CrowdStrike community-tracking hashes): (CrowdStrike)

  • Dozer   7dee2bd4e317d12c9a2923d0531526822cfd37eabfd7aecc74258bb4f2d3a643 (CrowdStrike)
  • Brambul   d2359630e84f59984ac7ddebdece9313f0c05f4a1e7db90abadfd86047c12dd6 (CrowdStrike)
  • Joanap   4fe3c853ab237005f7d62324535dd641e1e095d1615a416a9b39e042f136cf6b (CrowdStrike)
  • KorDLL Bot   73edc54abb3d6b8df6bd1e4a77c373314cbe99a660c8c6eea770673063f55503 (CrowdStrike)
  • Koredos   a795964bc2be442f142f5aea9886ddfd297ec898815541be37f18ffeae02d32f (CrowdStrike)
  • Hawup RAT   453d8bd3e2069bc50703eb4c5d278aad02304d4dc5d804ad2ec00b2343feb7a4 (CrowdStrike)
  • Hoplight   05feed9762bc46b47a7dc5c469add9f163c16df4ddaafe81983a628da5714461 (CrowdStrike)
  • Manuscrypt   dced1acbbe11db2b9e7ae44a617f3c12d6613a8188f6a1ece0451e4cd4205156 (CrowdStrike)
  • HTTPHoplight   ceccb2339088fa2d6337082704bbf67f84eeb0d0b60ce5ab0ab7e1824002fa4c (CrowdStrike)
  • OpenSSL Downloader   f749c7e84809ffc3939eaed06ad90e15b0e11375f98d7348c0aa1bf35d3f0b8e (CrowdStrike)
  • UnderGroundRAT   f9586fdf4e0a65b17ee32bc3c3f493a055409abde373720d594d27fd24adffa0 (CrowdStrike)
  • NedDnLoader   512877c98fd83cd51bb287da4462b44f9d276d7ce51890f4ded1b915a6d2d5e1 (CrowdStrike)
  • Stackeyflate   d2e743216d17e97c8d1913d376d46095b740015f26a3c62a05e286573721d26c (CrowdStrike)
  • HiberRAT   58f2972c6a8fc743543f7b8c4df085c5cf2c6e674e5601e85eec60cd269cfb3c (CrowdStrike)
  • WinWebDown   fc885b323172106ab6f2f0cc77b609987384a38e3af41ad888d5389610d29daf (CrowdStrike)
  • FudModule   cbd1634cf7c638f2faf5e3ec79137db6704ec9de8df798fc46aeeed38de3da9b (noted as shared with GOLDEN) (CrowdStrike)

Supplemental “legacy DPRK MAR-derived” hashes (bridging set; keep as non-exclusive DPRK nexus):
Use these as heritage/overlap indicators for “DPRK malware ecosystem” rather than hard-binding them to LABYRINTH specifically.

  • BLINDINGCAN (multiple SHA256)
  • BISTROMATH (multiple SHA256)
  • SLICKSHOES, CROWDEDFLOUNDER, BUFFETLINE, BADCALL (SHA256)
    (These remain useful as “DPRK malware portfolio” IOCs, but they are not the cleanest proof of the three-unit split without additional clustering work.)

PRESSURE CHOLLIMA (High-payout crypto theft operations)

Primary exemplars (CrowdStrike community-tracking hashes): (CrowdStrike)

  • Scuzzyfuss   b9f6a9d4f837f5b8a5dc9987a91ba44bc7ae7f39aa692b5b21dba460f935a0ae (CrowdStrike)
  • MataNet   357c9daf6c4343286a9a85a27bc25defdc056877ce1be2943d2e8ede3bce022c (CrowdStrike)
  • SwDownloader   a61ecbe8a5372c85dcf5d077487f09d01e144128243793d2b97012440dcf106e (CrowdStrike)
  • SparkDownloader   9ba02f8a985ec1a99ab7b78fa678f26c0273d91ae7cbe45b814e6775ec477598 (CrowdStrike)
  • TwoPence Electric   081804b491c70bfa63ecdbe9fd4618d3570706ad8b71dba13e234069648e5e48 (CrowdStrike)
  • MagikCookie   1579347265f948f9646931335d57e7960fe65dd429394be84b4ae15bca73dfde (CrowdStrike)
  • StatusSymbol   666c50b8b772101b0e2e35ff1de52a278c2727027b54858e457571d296fec50b (CrowdStrike)
  • GhostShip   56e51244e258c39293463c8cf02f5dddb085be90728fab147a60741cf014aa4d (CrowdStrike)
  • AlertConf   e0aa5ef3af26681a8c8b46d95656580779d0ff3c2fe531b95a59ee918686e443 (CrowdStrike)

GOLDEN CHOLLIMA (Baseline revenue / consistent tempo, fintech & crypto)

Primary exemplars (CrowdStrike community-tracking hashes): (CrowdStrike)

  • Jeus   fe948451df90df80c8028b969bf89ecbf501401e7879805667c134080976ce2e (CrowdStrike)
  • HTTPHelper   ff32bc1c756d560d8a9815db458f438d63b1dcb7e9930ef5b8639a55fa7762c9 (CrowdStrike)
  • SnakeBaker   b6995c31a7ee88392fc25fd6d1a3a7975b3cb4ec3a9a318c3fcfaaf89eb65ce1 (CrowdStrike)
  • NodalBaker   0518a163b90e7246a349440164d02d10f31d514a7e5cce842b6cf5b3a0cc1bfa (CrowdStrike)
  • PipeDown   2ef212f433b722b734d80b41a2364a41ca0453dbfe3e6ec8b951eca795075a02 (CrowdStrike)
  • DevobRAT   fde50c3a373ebc2661e08c99c1cb50dc34efc022a3880c317ab5b84108ef83aa (CrowdStrike)
  • Anycon   2110a6e89d98a626f846ec8deccbac057300d194933ae0cbf1ef4831a4cc829e (CrowdStrike)
  • CitriLoader   d0cf9c1f87eac9b8879684a041dd6a2e1a0c15e185d4814a51adda19f9399a9b (CrowdStrike)
  • FudModule (shared access noted)   cbd1634cf7c638f2faf5e3ec79137db6704ec9de8df798fc46aeeed38de3da9b (CrowdStrike)

APPENDIX F: ANY RUN and VIRUS TOTAL LINKS

LABYRINTH CHOLLIMA (Espionage Head)

Dozer

VT: https://www.virustotal.com/gui/file/7dee2bd4e317d12c9a2923d0531526822cfd37eabfd7aecc74258bb4f2d3a643
ANY.RUN: https://any.run/search/?query=7dee2bd4e317d12c9a2923d0531526822cfd37eabfd7aecc74258bb4f2d3a643

Brambul

VT: https://www.virustotal.com/gui/file/d2359630e84f59984ac7ddebdece9313f0c05f4a1e7db90abadfd86047c12dd6
ANY.RUN: https://any.run/search/?query=d2359630e84f59984ac7ddebdece9313f0c05f4a1e7db90abadfd86047c12dd6

Joanap

VT: https://www.virustotal.com/gui/file/4fe3c853ab237005f7d62324535dd641e1e095d1615a416a9b39e042f136cf6b
ANY.RUN: https://any.run/search/?query=4fe3c853ab237005f7d62324535dd641e1e095d1615a416a9b39e042f136cf6b

KorDLL Bot

VT: https://www.virustotal.com/gui/file/73edc54abb3d6b8df6bd1e4a77c373314cbe99a660c8c6eea770673063f55503
ANY.RUN: https://any.run/search/?query=73edc54abb3d6b8df6bd1e4a77c373314cbe99a660c8c6eea770673063f55503

Koredos

VT: https://www.virustotal.com/gui/file/a795964bc2be442f142f5aea9886ddfd297ec898815541be37f18ffeae02d32f
ANY.RUN: https://any.run/search/?query=a795964bc2be442f142f5aea9886ddfd297ec898815541be37f18ffeae02d32f

Hawup RAT

VT: https://www.virustotal.com/gui/file/453d8bd3e2069bc50703eb4c5d278aad02304d4dc5d804ad2ec00b2343feb7a4
ANY.RUN: https://any.run/search/?query=453d8bd3e2069bc50703eb4c5d278aad02304d4dc5d804ad2ec00b2343feb7a4

Hoplight

VT: https://www.virustotal.com/gui/file/05feed9762bc46b47a7dc5c469add9f163c16df4ddaafe81983a628da5714461
ANY.RUN: https://any.run/search/?query=05feed9762bc46b47a7dc5c469add9f163c16df4ddaafe81983a628da5714461

Manuscrypt

VT: https://www.virustotal.com/gui/file/dced1acbbe11db2b9e7ae44a617f3c12d6613a8188f6a1ece0451e4cd4205156
ANY.RUN: https://any.run/search/?query=dced1acbbe11db2b9e7ae44a617f3c12d6613a8188f6a1ece0451e4cd4205156

HTTPHoplight

VT: https://www.virustotal.com/gui/file/ceccb2339088fa2d6337082704bbf67f84eeb0d0b60ce5ab0ab7e1824002fa4c
ANY.RUN: https://any.run/search/?query=ceccb2339088fa2d6337082704bbf67f84eeb0d0b60ce5ab0ab7e1824002fa4c

OpenSSL Downloader

VT: https://www.virustotal.com/gui/file/f749c7e84809ffc3939eaed06ad90e15b0e11375f98d7348c0aa1bf35d3f0b8e
ANY.RUN: https://any.run/search/?query=f749c7e84809ffc3939eaed06ad90e15b0e11375f98d7348c0aa1bf35d3f0b8e

UnderGroundRAT

VT: https://www.virustotal.com/gui/file/f9586fdf4e0a65b17ee32bc3c3f493a055409abde373720d594d27fd24adffa0
ANY.RUN: https://any.run/search/?query=f9586fdf4e0a65b17ee32bc3c3f493a055409abde373720d594d27fd24adffa0

NedDnLoader

VT: https://www.virustotal.com/gui/file/512877c98fd83cd51bb287da4462b44f9d276d7ce51890f4ded1b915a6d2d5e1
ANY.RUN: https://any.run/search/?query=512877c98fd83cd51bb287da4462b44f9d276d7ce51890f4ded1b915a6d2d5e1

Stackeyflate

VT: https://www.virustotal.com/gui/file/d2e743216d17e97c8d1913d376d46095b740015f26a3c62a05e286573721d26c
ANY.RUN: https://any.run/search/?query=d2e743216d17e97c8d1913d376d46095b740015f26a3c62a05e286573721d26c

HiberRAT

VT: https://www.virustotal.com/gui/file/58f2972c6a8fc743543f7b8c4df085c5cf2c6e674e5601e85eec60cd269cfb3c
ANY.RUN: https://any.run/search/?query=58f2972c6a8fc743543f7b8c4df085c5cf2c6e674e5601e85eec60cd269cfb3c

WinWebDown

VT: https://www.virustotal.com/gui/file/fc885b323172106ab6f2f0cc77b609987384a38e3af41ad888d5389610d29daf
ANY.RUN: https://any.run/search/?query=fc885b323172106ab6f2f0cc77b609987384a38e3af41ad888d5389610d29daf

FudModule

VT: https://www.virustotal.com/gui/file/cbd1634cf7c638f2faf5e3ec79137db6704ec9de8df798fc46aeeed38de3da9b
ANY.RUN: https://any.run/search/?query=cbd1634cf7c638f2faf5e3ec79137db6704ec9de8df798fc46aeeed38de3da9b

PRESSURE CHOLLIMA (High-Payout Crypto)

Scuzzyfuss

VT: https://www.virustotal.com/gui/file/b9f6a9d4f837f5b8a5dc9987a91ba44bc7ae7f39aa692b5b21dba460f935a0ae
ANY.RUN: https://any.run/search/?query=b9f6a9d4f837f5b8a5dc9987a91ba44bc7ae7f39aa692b5b21dba460f935a0ae

MataNet

VT: https://www.virustotal.com/gui/file/357c9daf6c4343286a9a85a27bc25defdc056877ce1be2943d2e8ede3bce022c
ANY.RUN: https://any.run/search/?query=357c9daf6c4343286a9a85a27bc25defdc056877ce1be2943d2e8ede3bce022c

SwDownloader

VT: https://www.virustotal.com/gui/file/a61ecbe8a5372c85dcf5d077487f09d01e144128243793d2b97012440dcf106e
ANY.RUN: https://any.run/search/?query=a61ecbe8a5372c85dcf5d077487f09d01e144128243793d2b97012440dcf106e

SparkDownloader

VT: https://www.virustotal.com/gui/file/9ba02f8a985ec1a99ab7b78fa678f26c0273d91ae7cbe45b814e6775ec477598
ANY.RUN: https://any.run/search/?query=9ba02f8a985ec1a99ab7b78fa678f26c0273d91ae7cbe45b814e6775ec477598

TwoPence Electric

VT: https://www.virustotal.com/gui/file/081804b491c70bfa63ecdbe9fd4618d3570706ad8b71dba13e234069648e5e48
ANY.RUN: https://any.run/search/?query=081804b491c70bfa63ecdbe9fd4618d3570706ad8b71dba13e234069648e5e48

MagikCookie

VT: https://www.virustotal.com/gui/file/1579347265f948f9646931335d57e7960fe65dd429394be84b4ae15bca73dfde
ANY.RUN: https://any.run/search/?query=1579347265f948f9646931335d57e7960fe65dd429394be84b4ae15bca73dfde

StatusSymbol

VT: https://www.virustotal.com/gui/file/666c50b8b772101b0e2e35ff1de52a278c2727027b54858e457571d296fec50b
ANY.RUN: https://any.run/search/?query=666c50b8b772101b0e2e35ff1de52a278c2727027b54858e457571d296fec50b

GhostShip

VT: https://www.virustotal.com/gui/file/56e51244e258c39293463c8cf02f5dddb085be90728fab147a60741cf014aa4d
ANY.RUN: https://any.run/search/?query=56e51244e258c39293463c8cf02f5dddb085be90728fab147a60741cf014aa4d

AlertConf

VT: https://www.virustotal.com/gui/file/e0aa5ef3af26681a8c8b46d95656580779d0ff3c2fe531b95a59ee918686e443
ANY.RUN: https://any.run/search/?query=e0aa5ef3af26681a8c8b46d95656580779d0ff3c2fe531b95a59ee918686e443

GOLDEN CHOLLIMA (Baseline Revenue Track)

Jeus

VT: https://www.virustotal.com/gui/file/fe948451df90df80c8028b969bf89ecbf501401e7879805667c134080976ce2e
ANY.RUN: https://any.run/search/?query=fe948451df90df80c8028b969bf89ecbf501401e7879805667c134080976ce2e

HTTPHelper

VT: https://www.virustotal.com/gui/file/ff32bc1c756d560d8a9815db458f438d63b1dcb7e9930ef5b8639a55fa7762c9
ANY.RUN: https://any.run/search/?query=ff32bc1c756d560d8a9815db458f438d63b1dcb7e9930ef5b8639a55fa7762c9

SnakeBaker

VT: https://www.virustotal.com/gui/file/b6995c31a7ee88392fc25fd6d1a3a7975b3cb4ec3a9a318c3fcfaaf89eb65ce1
ANY.RUN: https://any.run/search/?query=b6995c31a7ee88392fc25fd6d1a3a7975b3cb4ec3a9a318c3fcfaaf89eb65ce1

NodalBaker

VT: https://www.virustotal.com/gui/file/0518a163b90e7246a349440164d02d10f31d514a7e5cce842b6cf5b3a0cc1bfa
ANY.RUN: https://any.run/search/?query=0518a163b90e7246a349440164d02d10f31d514a7e5cce842b6cf5b3a0cc1bfa

PipeDown

VT: https://www.virustotal.com/gui/file/2ef212f433b722b734d80b41a2364a41ca0453dbfe3e6ec8b951eca795075a02
ANY.RUN: https://any.run/search/?query=2ef212f433b722b734d80b41a2364a41ca0453dbfe3e6ec8b951eca795075a02

DevobRAT

VT: https://www.virustotal.com/gui/file/fde50c3a373ebc2661e08c99c1cb50dc34efc022a3880c317ab5b84108ef83aa
ANY.RUN: https://any.run/search/?query=fde50c3a373ebc2661e08c99c1cb50dc34efc022a3880c317ab5b84108ef83aa

Anycon

VT: https://www.virustotal.com/gui/file/2110a6e89d98a626f846ec8deccbac057300d194933ae0cbf1ef4831a4cc829e
ANY.RUN: https://any.run/search/?query=2110a6e89d98a626f846ec8deccbac057300d194933ae0cbf1ef4831a4cc829e

CitriLoader

VT: https://www.virustotal.com/gui/file/d0cf9c1f87eac9b8879684a041dd6a2e1a0c15e185d4814a51adda19f9399a9b
ANY.RUN: https://any.run/search/?query=d0cf9c1f87eac9b8879684a041dd6a2e1a0c15e185d4814a51adda19f9399a9b

FudModule (Shared)

VT: https://www.virustotal.com/gui/file/cbd1634cf7c638f2faf5e3ec79137db6704ec9de8df798fc46aeeed38de3da9b
ANY.RUN: https://any.run/search/?query=cbd1634cf7c638f2faf5e3ec79137db6704ec9de8df798fc46aeeed38de3da9b

Learn More
Research
No items found.
Exposure of TLS Private Key for Myclaw 360 in Qihoo 360 “Security Claw” AI Platform

DTI analysis of a leaked TLS private key from Qihoo 360's AI security platform, covering cryptographic validation, threat scenarios, and incident response.

Executive Summary

DTI analyzed the confirmed exposure of a Transport Layer Security (TLS) private key associated with the wildcard certificate *.myclaw[.]360[.]cn, which appears tied to the Security Claw (安全龙虾) artificial-intelligence assistant platform developed by Qihoo 360. Earlier public discussion of the issue relied primarily on screenshots and reposted commentary claiming that the certificate and private key were embedded in the platform’s installer package. The material provided for this investigation includes the full X.509 certificate and corresponding private key. Cryptographic validation confirms that the supplied private key matches the public key contained in the certificate, establishing that the exposed credential is authentic and operational rather than a placeholder or decoy.

The certificate is issued by WoTrus CA Limited under the issuing chain WoTrus RSA DV SSL CA 2. It is a wildcard certificate covering both *.myclaw[.]360[.]cn and myclaw[.]360[.]cn and was originally issued with a validity period spanning 12 March 2026 through 12 April 2027. Because wildcard certificates authenticate any host within the domain namespace, possession of the corresponding private key would allow an attacker to impersonate services across the entire Security Claw infrastructure if the certificate remained trusted and unrevoked.

Subsequent certificate-transparency analysis conducted during this investigation indicates that the certificate has since been rotated and replaced as part of an apparent incident-response action. CT log entries show that on 16 March 2026, a new wildcard certificate for *.myclaw[.]360[.]cn was issued with a new RSA key pair and shortened validity period, replacing the originally exposed certificate. The rapid issuance of the replacement certificate and the change in key material strongly suggest that Qihoo 360 detected the credential exposure and executed emergency key rotation to invalidate the compromised trust material.

Infrastructure analysis further confirms that the parent domain ecosystem (360[.]cn) is registered to Beijing Qihoo Technology Co., Ltd. (北京奇虎科技有限公司) and uses internally controlled DNS and mail infrastructure. This strongly supports attribution of the myclaw[.]360[.]cn namespace to Qihoo 360’s operational domain environment. The exposure therefore represents a confirmed cryptographic trust-material leak, with potential consequences including server impersonation, TLS interception, credential theft, and malicious update delivery within the Security Claw ecosystem. Although the certificate appears to have been rotated following discovery of the issue, the operational impact ultimately depends on whether the compromised key was actively deployed in production services and whether any adversary obtained the key prior to remediation.

Background: Qihoo 360 and the Security Claw Platform

Qihoo 360 is widely recognized as one of China’s largest cybersecurity and internet-technology companies, operating across both consumer and enterprise security markets. Since its founding in the early 2000s, the company has developed a broad portfolio of security and software products that include antivirus platforms, endpoint protection suites, web browsers, vulnerability-scanning tools, and large-scale threat-intelligence services. Through these products, Qihoo 360 has established an extensive user base spanning hundreds of millions of individual users as well as corporate and government customers. Much of the company’s security ecosystem is built around large telemetry pipelines that collect threat data from deployed endpoints and feed it into centralized analytics systems used to detect malware, exploit campaigns, and network intrusions.

In recent years the company has increasingly invested in artificial-intelligence technologies as part of its broader cybersecurity strategy. Like many large security vendors, Qihoo 360 has begun integrating machine-learning models and generative AI capabilities into its defensive tools, both to automate analysis tasks and to provide interactive interfaces for users and analysts. This effort has produced a range of AI-enabled assistants and intelligent agents designed to augment traditional security workflows. These systems typically allow users to query threat data, analyze malware samples, or receive automated recommendations through natural-language interfaces powered by backend AI models.

However, they have started pulling back on this, as they have begun learning about the pitfalls.

The Security Claw (安全龙虾) platform appears to be one of the products emerging from this initiative. Based on publicly available information and artifacts analyzed during this investigation, Security Claw functions as a locally installed client application that interacts with remote services operated by Qihoo 360. Rather than performing all processing locally, the client appears to act as a front-end interface that communicates with cloud-hosted AI infrastructure. These backend services operate within the myclaw.360.cn domain namespace, which appears to serve as the central network environment for the platform’s API endpoints and inference services.

Reports associated with the platform indicate that the client software connects to at least one backend endpoint located at https://myclaw[.]360[.]cn:19798, a service running on a non-standard port rather than the default HTTPS port 443. The use of such ports is common in internal service architectures where applications communicate directly with API gateways or service nodes without passing through standard web-server front ends. The presence of this endpoint suggests that the client communicates with a specialized service interface rather than a conventional public website.

Architecturally, this design reflects a hybrid deployment model commonly used by modern AI assistant platforms. In this model, a lightweight local application acts as a wrapper that manages user interactions, authentication, and system integration while delegating computationally intensive tasks such as natural-language processing, model inference, and large-scale data retrieval to cloud infrastructure. The client collects user prompts and contextual information from the local system and forwards these requests to backend services where AI models perform the actual analysis or generate responses.

Systems built on this architecture typically consist of multiple interconnected backend components. These may include authentication services responsible for validating client identities, API gateways that route requests to the appropriate services, telemetry collectors that gather usage and performance data from deployed clients, and inference endpoints hosting the machine-learning models used to generate responses. Additional components often include update services responsible for delivering model updates or configuration files to the client software. All of these elements operate together to create the user-facing experience of an AI assistant while relying on centralized cloud infrastructure to perform the majority of processing tasks.

Technical Findings

Certificate Structure

Analysis of the certificate associated with the Security Claw infrastructure indicates that it is a standard X.509 server authentication certificate issued for the wildcard domain namespace *.myclaw[.]360[.]cn. The certificate’s Common Name (CN) is configured as *.myclaw[.]360[.]cn, enabling it to authenticate any host operating under that subdomain space. In addition to the wildcard identifier, the certificate’s Subject Alternative Name (SAN) extension explicitly includes both *.myclaw.360[.]cn and the root host myclaw[.]360[.]cn. This configuration allows the certificate to be used by both the base domain and any subordinate services, a design pattern typically employed in microservice architectures where multiple backend services operate under a single domain namespace.

The certificate was issued by WoTrus RSA DV SSL CA 2, a certificate authority chain operated by WoTrus CA Limited, a Chinese certificate authority widely used within domestic cloud infrastructure and enterprise platforms. The certificate’s validity window begins on 12 March 2026 and extends through 12 April 2027, reflecting a relatively long operational lifespan typical of domain-validated certificates used in application backends. Cryptographically, the certificate employs an RSA 2048-bit public key, a widely adopted key size for TLS server authentication that provides an established balance between security strength and compatibility across client platforms.

The certificate is uniquely identified by the serial number 98dfeafdc4c32371f0ab490c8a3c7819, which serves as the certificate authority’s internal identifier for the issued credential. Its cryptographic fingerprint, calculated using the SHA-256 hashing algorithm, is 5a0a0df9695395223a1d342d2ccf82f449b342a281ed056dfa7880965bcbe3ca. This fingerprint provides a reliable mechanism for identifying the certificate across transparency logs, passive TLS telemetry, and network monitoring systems.

Functionally, the certificate is a domain-validated TLS certificate intended solely for server authentication. It does not contain certificate authority privileges and cannot be used to sign subordinate certificates or create additional trust anchors. Instead, its purpose is to enable servers operating under the myclaw[.]360[.]cn namespace to prove domain ownership during TLS handshakes, allowing clients to establish encrypted connections that they believe originate from legitimate Security Claw infrastructure.

The provided certificate is an X.509 server certificate with the following key attributes:

Common Name: *.myclaw.360.cn
Subject Alternative Names: *.myclaw.360.cn myclaw.360.cn
Issuer: WoTrus RSA DV SSL CA 2
Organization: WoTrus CA Limited
Validity Period: Not Before: 2026-03-12 Not After : 2027-04-12
Public Key Algorithm: RSA 2048-bit
Certificate Serial Number: 98dfeafdc4c32371f0ab490c8a3c7819
The certificate’s SHA-256 fingerprint is: 5a0a0df9695395223a1d342d2ccf82f449b342a281ed056dfa7880965bcbe3ca

Private Key Validation

Cryptographic analysis confirms that the private key provided in the dataset corresponds directly to the public key embedded within the associated TLS certificate. This relationship was verified by extracting and comparing the RSA modulus from both the certificate and the private key. The modulus values match exactly, demonstrating that the two artifacts form a valid cryptographic key pair.

This verification establishes that the exposed private key is the genuine operational key associated with the certificate rather than unrelated or fabricated data. In other words, the key is capable of performing the cryptographic operations required to authenticate servers presenting the certificate during Transport Layer Security (TLS) negotiations.

Within TLS architecture, the private key represents the confidential element of the certificate pair and functions as the mechanism by which a server proves its identity to connecting clients. During the TLS handshake process, the server must demonstrate possession of this secret key in order to validate that it legitimately controls the certificate presented to the client. If the server successfully performs this proof, the client accepts the certificate as authentic and proceeds to establish an encrypted communication channel.

Consequently, possession of the private key enables any system holding it to complete TLS handshakes that appear fully legitimate to clients relying on standard certificate validation. This capability effectively allows the holder of the key to impersonate servers operating under the certificate’s domain namespace and establish encrypted connections that clients would normally interpret as trusted communications with the genuine service.

Infrastructure Attribution

To assess ownership and operational control of the namespace, passive DNS intelligence and domain-registration data indicate that the namespace is part of the broader Qihoo 360 domain ecosystem. This determination provides strong evidence that the infrastructure supporting the Security Claw platform is operated directly within the company’s network environment.

The parent domain 360[.]cn is registered to 北京奇虎科技有限公司 (Beijing Qihoo Technology Co., Ltd.), a major Chinese cybersecurity and internet-technology firm. Domain registration records show that the domain was originally created on 17 March 2003 and is maintained through the registrar Xiamen eName Technology Co., Ltd. These details align with long-standing records identifying Qihoo 360 as the primary operator of the 360[.]cn domain space and its associated services.

The use of dedicated DNS and mail infrastructure under corporate-controlled domains strongly suggests that Qihoo 360 manages its core network services internally rather than outsourcing these functions to third-party providers. This pattern is typical of large security vendors that maintain tight operational control over their infrastructure for security, reliability, and compliance reasons.

Additional enrichment data indicates that the 360.cn domain environment routinely deploys wildcard TLS certificates issued by WoTrus, the same certificate authority responsible for the *.myclaw.360.cn certificate examined in this investigation. The reuse of this certificate authority and wildcard certificate deployment pattern across the broader Qihoo domain ecosystem reinforces the conclusion that the MyClaw certificate originates from the company’s established PKI practices rather than from an unrelated or externally managed infrastructure.

Taken together, the domain registration data, passive DNS records, and PKI deployment patterns provide strong attribution linking the myclaw.360.cn namespace to Qihoo 360’s operational infrastructure, supporting the assessment that the exposed TLS credentials were associated with a service environment under the company’s direct control.

Threat Analysis

The exposure of a Transport Layer Security (TLS) private key associated with a wildcard certificate introduces several potential attack scenarios that could compromise both the integrity and confidentiality of communications within the affected service environment. Because TLS certificates serve as the cryptographic mechanism through which clients authenticate remote servers and establish encrypted channels, possession of the corresponding private key effectively allows an attacker to masquerade as legitimate infrastructure. In this case, the affected certificate covers the wildcard namespace *.myclaw[.]360[.]cn, meaning that any service operating under that domain could theoretically be impersonated if the certificate remained trusted and unrevoked.

One of the most direct risks presented by such an exposure is server impersonation. An attacker in possession of the private key could deploy a malicious server configured to present the same certificate during TLS negotiation. Because the certificate chains to a publicly trusted certificate authority and matches the expected domain namespace, client applications connecting to the attacker’s infrastructure would likely complete the TLS handshake successfully and treat the connection as legitimate. The wildcard nature of the certificate significantly amplifies this risk, as it would allow the attacker to impersonate any host within the myclaw[.]360[.]cn namespace rather than a single specific service endpoint.

A related and potentially more damaging scenario involves man-in-the-middle (MITM) interception. If an attacker were able to manipulate DNS responses, compromise a local network, or otherwise redirect client traffic, they could route requests intended for legitimate MyClaw infrastructure to servers under their control. Because the attacker possesses the correct private key, the TLS handshake would succeed and encrypted sessions would be established without triggering certificate warnings. Under such circumstances, the attacker could decrypt and inspect traffic passing through the connection. Data potentially exposed through such interception could include authentication credentials, session cookies, API tokens used by the application, and the contents of AI prompts or conversation logs exchanged between the client and backend inference services.

Another risk concerns malicious update distribution. Many modern software platforms retrieve updates, configuration files, or model components from backend servers under their operational domain namespace. If the Security Claw client retrieves such resources from endpoints within myclaw[.]360[.]cn, an attacker capable of impersonating those endpoints could deliver modified update packages or configuration files. In the worst case, this could allow the distribution of malicious binaries to client systems, effectively transforming the incident into a supply-chain compromise affecting all users receiving the spoofed updates.

Finally, the exposure creates the possibility of AI response manipulation within the Security Claw platform itself. Because the platform functions as an AI assistant that communicates with backend inference services, impersonating those services could allow attackers to alter responses returned by the AI system. This could enable injection of malicious prompts, manipulation of analysis results, or the insertion of misleading security guidance into automated workflows. In environments where the AI system assists with security analysis or operational decision-making, such manipulation could have cascading effects on downstream processes.

Taken together, these scenarios illustrate how the compromise of TLS trust material, particularly a wildcard certificate, can extend beyond simple traffic interception and potentially affect software distribution mechanisms, AI service integrity, and user trust in the platform’s infrastructure.

Potential AI-Enabled Attack Scenarios Leveraging Compromised Security Claw Infrastructure

The exposure of a private key associated with the wildcard TLS certificate for *.myclaw[.]360[.]cn introduces not only traditional network security risks such as impersonation and interception, but also a set of potential AI-enabled attack vectors that could exploit the architecture of the Security Claw platform itself. Because the platform appears to function as a locally installed AI assistant communicating with cloud-hosted inference services, control over the cryptographic trust boundary between client and backend services could enable adversaries to manipulate the AI system’s behavior in ways that extend beyond conventional software compromise. The integration of AI inference services into the operational workflow effectively creates a new attack surface in which model outputs, prompts, and analytic results become potential targets for adversarial manipulation.

One plausible attack scenario would involve AI response manipulation at the inference layer. If an attacker were able to impersonate backend inference services using the compromised certificate, they could intercept requests from the Security Claw client and return modified outputs generated by a malicious or modified AI model. In practice, this could allow the adversary to alter the results of automated security analyses performed by the platform. For example, malware samples submitted for analysis could be falsely classified as benign, while legitimate system components could be flagged as malicious. Such manipulations could degrade the reliability of the platform’s analytic output and undermine trust in automated security recommendations generated by the system.

Logic Diagram for Potential Attacks From Mistake

Another potential attack vector involves prompt-injection attacks targeting the AI interaction pipeline. Modern AI assistant architectures often rely on structured prompts sent from the client to backend models, where contextual instructions and system policies guide the model’s behavior. An adversary positioned within the communication channel could modify these prompts before they reach the inference service or inject additional instructions into the prompt stream. By manipulating these inputs, attackers could influence the behavior of the AI model, potentially causing it to disclose sensitive data, generate misleading analyses, or execute unintended actions within automated workflows. This type of attack is conceptually similar to adversarial prompt injection techniques observed in other large-language-model deployments.

A related scenario involves model poisoning or model-substitution attacks. If the Security Claw platform retrieves model components, configuration files, or inference instructions from backend servers under the myclaw[.]360[.]cn namespace, an adversary capable of impersonating those endpoints could distribute modified model weights or configuration artifacts to client systems. Such modifications could subtly alter the behavior of the AI system over time. For instance, the modified model might consistently downgrade the severity of certain classes of threats, ignore specific indicators of compromise, or generate outputs designed to mislead analysts reviewing the results. Because AI models often behave probabilistically rather than deterministically, detecting such manipulation could be significantly more difficult than identifying conventional malware.

The compromise could also enable data exfiltration through the AI interaction channel. Security Claw appears to operate as an assistant capable of processing user prompts, system telemetry, and potentially sensitive security data. If adversaries intercepted or controlled the backend inference endpoint, they could capture large volumes of input data sent from client systems. This data could include malware samples, internal network information, security logs, configuration data, or investigative notes submitted by analysts interacting with the AI assistant. Over time, such data collection could yield valuable intelligence about organizational networks, defensive tools, and investigative workflows.

Another possible attack vector would involve AI-driven social engineering and influence operations directed at analysts using the platform. If attackers controlled the AI responses returned to users, they could craft outputs designed to subtly influence human decision-making. For example, the AI might recommend specific remediation steps that inadvertently weaken security controls, suggest the dismissal of legitimate alerts, or provide misleading threat-intelligence summaries. Because users may perceive AI-generated recommendations as authoritative, particularly when the platform is marketed as a cybersecurity assistant, such manipulation could have cascading operational consequences within security operations centers or incident-response teams.

The exposure could further facilitate autonomous reconnaissance and exploitation capabilities embedded within the AI service architecture. If the adversary were able to modify backend AI services rather than merely impersonate them, they could theoretically integrate automated reconnaissance capabilities into the system itself. In this scenario, the AI service might analyze telemetry collected from client systems and automatically identify exploitable vulnerabilities or network configurations. Rather than simply returning analytic results to the user, the compromised system could covertly transmit reconnaissance data to attacker infrastructure or generate tailored exploit payloads targeting discovered weaknesses.

Finally, there is the possibility of supply-chain amplification through AI-driven automation. Security Claw’s architecture suggests that it may be integrated with broader Qihoo security services, potentially including threat-intelligence feeds, malware analysis pipelines, or automated defensive tooling. If attackers were able to manipulate the AI system at the backend level, they could leverage this integration to propagate malicious outputs across multiple connected services. For example, manipulated threat classifications could influence automated detection signatures distributed to endpoint security products, potentially degrading detection capability across a large installed base of users.

Taken together, these scenarios illustrate how the compromise of cryptographic trust material in an AI-enabled platform could enable attack techniques that extend beyond traditional network security threats. In conventional systems, the theft of a TLS private key primarily enables impersonation or interception attacks. In AI-integrated architectures, however, control over the communication channel between client and inference service also enables adversaries to manipulate the informational outputs of the system itself. Because users increasingly rely on AI-generated analysis to support operational decisions, such manipulation could have downstream effects that propagate through automated workflows, investigative processes, and defensive strategies.

Root Cause Assessment

The most plausible explanation for the exposure of the TLS private key is a failure within the software build and packaging pipeline used to produce the Security Claw client installer. Evidence associated with the incident indicates that the certificate and its corresponding private key were present within files bundled in the application’s installation package, suggesting that sensitive credential material was inadvertently included during the software build process.

In contemporary software development environments, application installers are frequently generated automatically through continuous integration and continuous delivery (CI/CD) pipelines. These pipelines often assemble installation packages directly from development repositories or build directories that may contain configuration files, test certificates, and other credentials used during internal development and debugging. If the build pipeline does not explicitly exclude such files through filtering rules or packaging controls, sensitive artifacts can unintentionally become part of the final distribution bundle.

This type of exposure is consistent with a broader class of supply-chain vulnerabilities in which development credentials are mistakenly distributed alongside production software. Similar incidents have been documented across the software industry, including cases where application installers or container images contained embedded API keys, code-signing certificates, or cloud service credentials. In each case, the root cause typically involved insufficient separation between development assets and production build artifacts, allowing confidential materials to propagate into publicly accessible software packages.

Analytical Assessment

The exposure of a private key associated with a wildcard TLS certificate constitutes a serious failure in the protection of cryptographic trust material. Within modern internet security architecture, TLS certificates serve as the foundation of authenticated encrypted communication between clients and servers. The corresponding private key is the critical secret that enables a server to prove its identity during the TLS handshake process. When this key is exposed outside of controlled infrastructure, the integrity of the entire trust relationship established by the certificate is compromised. In this case, the risk is amplified by the fact that the certificate is a wildcard credential for the domain namespace *.myclaw[.]360[.]cn, meaning that the key could theoretically authenticate any service operating under that domain hierarchy. As a result, possession of the private key could allow an attacker to impersonate multiple services across the platform rather than a single isolated endpoint.

Although the ultimate operational consequences depend on several factors including whether the certificate was actively deployed in production infrastructure and how quickly the credential was revoked or replaced, the discovery of the key in a publicly accessible software artifact strongly suggests that sensitive trust material was mishandled during the platform’s build or distribution process. Software installers and packaged binaries should never contain cryptographic secrets intended for server-side authentication. Their presence in distributed software indicates that development or deployment environments likely included credential files that were not properly excluded during packaging. Such mistakes are typically symptomatic of weaknesses in build pipeline controls, including insufficient separation between development assets and production artifacts, inadequate secret-scanning procedures, or a lack of automated checks designed to prevent sensitive files from being included in release builds.

The incident is particularly notable because it involves Qihoo 360, a company whose core business is cybersecurity. As a major provider of antivirus software, enterprise security tools, and threat-intelligence services, Qihoo 360 operates infrastructure that supports hundreds of millions of users. Organizations of this scale are expected to maintain mature security engineering practices, including strict credential management policies, secure build pipelines, and rigorous release validation procedures. The appearance of operational cryptographic material in distributed software raises questions about the robustness of those internal controls.

Even if the certificate was never deployed in production systems or if the exposure window was short due to rapid incident response and key rotation, the leak nonetheless highlights systemic risks associated with credential management within modern software development environments. Large-scale platforms frequently rely on numerous certificates, API keys, and other authentication secrets to operate complex distributed architectures. Without strong safeguards, these secrets can inadvertently propagate through development repositories, build directories, or installer packaging processes.

In this context, the exposure should be understood not only as a discrete technical vulnerability but also as an indicator of broader process weaknesses. Effective security engineering requires strict segregation of sensitive credentials, automated detection mechanisms for secrets in build artifacts, and clear procedures for revocation and rotation when exposure occurs. The presence of a valid TLS private key in publicly distributed software suggests that at least some of these controls were insufficiently implemented or failed during the platform’s release cycle. As AI-enabled platforms like Security Claw become more deeply integrated into security workflows and enterprise environments, ensuring the integrity of the cryptographic infrastructure underpinning these systems becomes increasingly critical.

Conclusion

Cryptographic validation confirms that the exposed material is a legitimate and operational TLS key pair for *.myclaw[.]360[.]cn. The RSA modulus in the certificate and private key match exactly, proving authenticity. The certificate chains to WoTrus RSA DV SSL CA 2, a publicly trusted authority, meaning any server using this key would be accepted as legitimate by clients.

The certificate’s structure aligns with Qihoo 360’s broader PKI practices, which rely on WoTrus-issued, domain-validated wildcard certificates to secure microservice-based architectures. As such, compromise of the private key represents a direct breach of the platform’s cryptographic trust boundary.

If deployed in production, the impact is substantial. An attacker with the key could impersonate any host within the myclaw.360.cn namespace, enabling seamless TLS-authenticated connections that appear legitimate. This extends beyond single-host compromise to full namespace-level impersonation. Under traffic redirection conditions (e.g., DNS or network manipulation), the same capability enables decryption and inspection of encrypted sessions, exposing credentials, tokens, and AI interaction data.

The risk also extends into platform integrity. Impersonated endpoints could deliver malicious updates or configuration data, while spoofed inference services could manipulate AI outputs or inject instructions into the interaction pipeline.

Impact ultimately hinges on deployment status and response timing. Evidence indicates the certificate was rapidly rotated, suggesting effective incident response and a potentially limited exposure window. However, if the key was obtained prior to rotation, exploitation during that interval remains plausible.

Further analysis should focus on certificate transparency logs, passive DNS telemetry, and any vendor disclosures to establish timeline, exposure scope, and whether the compromised certificate was ever actively used.

Appendix A: Data

360Claw的SSL证书泄漏

-----BEGIN CERTIFICATE-----
MIIGJjCCBI6gAwIBAgIRAJjf6v3EwyNx8KtJDIo8eBkwDQYJKoZIhvcNAQELBQAw
SjELMAkGA1UEBhMCQ04xGjAYBgNVBAoTEVdvVHJ1cyBDQSBMaW1pdGVkMR8wHQYD
VQQDExZXb1RydXMgUlNBIERWIFNTTCBDQSAyMB4XDTI2MDMxMjAwMDAwMFoXDTI3
MDQxMjIzNTk1OVowGjEYMBYGA1UEAwwPKi5teWNsYXcuMzYwLmNuMIIBIjANBgkq
hkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA6GoA3XNAfUmduNst6xvYGphkmWpMKTC9
RCJpvKoKSuFylOwY+tGm8vmKl4Uc4SYUp3a8TdFjFtEzCuRqEo3IVYRdenk94K8G
jqg09hGg87MmUbI+PDzXJYZiCjrIHib+VK9V1RyBypA78ju6Gnpw4F4EFa3PjM1+
BUYpU3yxqx7gALSJLu6fuia+jV+LnawxB2ZVyoEgcYZYoJFQ9l9MuO6K9Wy7FK9e
MLgVwkB/ZFYl3olAJonkgmtopdWSJtort9bUxD4Oqbs6sc2YBLfcrXyX4cp3KGAr
3UfhptKlKyA0MZJJaT4NOvXrAlSd6JF3Gu6rfj/+G4x7hPCpKuIOXQIDAQABo4IC
tTCCArEwHwYDVR0jBBgwFoAU2LPS8kwDXVRDQ6AmyEVq9BSUg8gwHQYDVR0OBBYE
FD+ZRI/zTmye9mMCFP7QOfIIGC6gMA4GA1UdDwEB/wQEAwIFoDAMBgNVHRMBAf8E
AjAAMBMGA1UdJQQMMAoGCCsGAQUFBwMBMBMGA1UdIAQMMAowCAYGZ4EMAQIBMGsG
CCsGAQUFBwEBBF8wXTA3BggrBgEFBQcwAoYraHR0cDovL2NydC5jcmxvY3NwLmNu
L1dvVHJ1c1JTQURWU1NMQ0EyLmNydDAiBggrBgEFBQcwAYYWaHR0cDovL29jc3Au
Y3Jsb2NzcC5jbjApBgNVHREEIjAggg8qLm15Y2xhdy4zNjAuY26CDW15Y2xhdy4z
NjAuY24wggGNBgorBgEEAdZ5AgQCBIIBfQSCAXkBdwB1AByfaCzp+vBFaVD4G5aK
h93bMhDYTObIsuOCUkrEz1mfAAABnOD5fqQAAAQDAEYwRAIgav6fXo4u77J/Ta2T
OdvnF7C/t4My7dmaGFQ7aQ4JzvQCIB66E+kdquRt2EZ/2QqbdOTqMscgGVpV7Gnn
WXLNmY2hAH8AjspHC6zeavOiBrCkeoS3Rv4fxr+VPiXmm07kAkjzxugAAAGc4PmA
zgAIAAAFAAMZgWAEAwBIMEYCIQDSKSYgaC6oG7l2yjSbwtqdCtQ0Hi7Mz8yWWrUr
W5edNQIhAKQMvy6g0naB/IOEDihyq4nNejnufZ7kwDh76GnNxFnJAH0AWW5sM4aU
sllyolbIoOjdkEp26Ag92oc7AQg4KBQ87lkAAAGc4Pl96QAIAAAFAAA48LcEAwBG
MEQCIEFrHnt8cRycbZpEngvZmTa2LnOUHKmrdfX4ElNDnMyuAiAw8aUn7hWtqT58
+HI2rZBu/BCtX+6q6YjQ/eeX7LfhDjANBgkqhkiG9w0BAQsFAAOCAYEAg09UAgUz
HzknfmUBH4FGGXYKurPZh3BPyDzaA1LPJVIYfseEhR6N7+iDSDt9tSez/H0aW0sm
rzP942kUe/afF827P3h5I8qsbqrfJVKCAdFfMHqYeb4JA6um/MFWBT0Av1SpcO1y
ewBPDn+xDbsDJe5UQ8gT2N6q/ktspiA/h4AgLfIsdY/4OxcpuKubht6enzUJSzsr
0I/TF0j/G7fFtSn3a2AwQSafuuClfPeX2Dt1oiDiLhqYpGQ1ZYGIAEutVJEHbW0G
Z4CBNy+OQ8U0FeRp5UdKZxCz9ZkFg7RNUc63UP0oKpKEZhBQ8ftb2C/H0Zd1uUiJ
ayL1E4Qy80vt2XMTjNacCAF5l8T6MmfJI4w2zWsggoV6wsLxcd/AfUzXlZFQezKg
jGUSfm4dYVXoSda/lB+BZSsgfx5DCC2N6bOMazNDqCT2C23S6nLOt9TdpjaUVe4T
zuwrbXc0Rtr2iLTmZAeGET5GJWib8Zb63zqo52OzBgydQaCt3bcQVfZZ
-----END CERTIFICATE-----

key

Learn More
Research
Doppelgänger / RRN Disinformation Infrastructure Ecosystem 2026

Analysis of the Doppelgänger / RRN disinformation ecosystem. Learn how this DevOps-style infrastructure uses automated media impersonation, TLD rotation, and cloud-native hosting to target global audiences and evade enforcement.

Executive Summary

The Doppelgänger / RRN ecosystem (RRN = Reliable Recent News) constitutes a new iteration of the Social Design Agency (SDA),  a structurally mature, infrastructure-centric disinformation architecture that has been operating continuously from 2022 through 2026. Rather than functioning as a loose collection of spoofed websites or transient propaganda outlets, the network exhibits the hallmarks of a coordinated, professionally managed influence apparatus. Its design prioritizes infrastructure resilience, scalability, and operational continuity over short-term visibility.

At its core, the ecosystem relies on systematic media brand impersonation executed at scale. Recognizable Western news outlets are replicated through domain substitution, typo variants, and semantic extensions, producing a high-volume impersonation layer that mimics legitimate journalism. These impersonation domains are not isolated artifacts; they are anchored to a centralized narrative constellation built around the RRN brand family, which functions as a clearinghouse and coordination node for messaging.

rrn[.]com[.]tr current iteration of Researchers & Reporters Network (aka Doppelganger Disinfo Network)

Domain acquisition patterns indicate batch provisioning during defined campaign waves, most notably in mid-2022 and again in late-2024. These bursts reflect deliberate staging cycles rather than organic domain accumulation. Complementing this provisioning model is a deliberate top-level domain diversification strategy. The operation leverages low-cost and low-scrutiny TLDs, rotates extensions in response to enforcement actions, and preserves second-level domains across TLD swaps to maintain continuity. This enforcement-aware migration pattern demonstrates pre-positioned redundancy and lifecycle planning.

Hosting and delivery architecture further reinforce the operation’s sophistication. The ecosystem is cloud-native and heavily fronted by content delivery networks that obscure origin infrastructure. Backend services are distributed across hyperscaler platforms, including Google Cloud and to a lesser extent AWS, along with static asset reuse from legitimate domains, with micro-clustering patterns that distribute risk and reduce single points of failure. The absence of concentrated Russian hosting infrastructure suggests attribution resistance through geographic neutrality rather than lack of coordination.

Backend artifacts reveal structured CMS management. WordPress deployments exhibit role-based segmentation, coordinated account provisioning, and SEO-oriented publishing controls. These features indicate centralized backend governance and editorial workflow discipline. The infrastructure also reflects automated domain variant generation, employing scripted logic for brand tokens, typographical alterations, and semantic suffix combinations. This level of automation is consistent with a provisioning pipeline rather than manual spoofing. Assistance from Amazon Web Services Threat Intelligence enriched the presence of AWS IP addresses, identifying primarily legitimate assets being reused in off-AWS infrastructure.

The campaign demonstrates deliberate geographic micro-targeting across European Union member states and the United States. Infrastructure segmentation mirrors narrative segmentation, with country-specific impersonation clusters aligned to regional political contexts. This coupling of technical segmentation and messaging strategy underscores a hybridization of cyber infrastructure tradecraft and psychological operations.

Taken together, these characteristics indicate DevOps-style provisioning discipline and resilience engineering. Domains are stockpiled, rotated, and redeployed with minimal disruption. Infrastructure is compartmentalized, diversified, and rapidly replaceable. Such operational maturity is consistent with institutional backing and sustained management, rather than opportunistic or freelance activity.

Campaign Architecture Model

Across both structural reporting and dataset analysis, the campaign exhibits a deliberately layered and modular operational model. The architecture is not flat, nor is it improvisational. Instead, it reflects clear functional segmentation, with each tier responsible for a distinct operational objective.

At the apex sits an operator coordination layer. This tier likely manages provisioning workflows, narrative timing, infrastructure deployment, and enforcement response. It is the command-and-control plane of the information operation, though not in the malware sense; rather, it orchestrates domain registration cycles, publishing cadence, and geographic targeting priorities. This also shows the banality of disinformation being just a process driven means to a larger end in the global war on reality.

Beneath this layer resides the core narrative hub, anchored by the RRN domain family. This constellation functions as a central content repository and thematic synchronization point. It consolidates narratives, standardizes messaging frames, and acts as a reference anchor for downstream properties. When seizures occur, this hub migrates in controlled fashion, preserving continuity through second-level domain retention and TLD substitution.

Below the hub tier are country-specific narrative front domains. These properties localize messaging for particular audiences, adapting tone, framing, and political emphasis according to national context. They provide plausible deniability by presenting themselves as independent outlets, while remaining structurally tethered to the broader ecosystem.

The next layer consists of media impersonation domains. These are the most visible components of the campaign, designed to replicate established Western media brands with high visual fidelity. Their purpose is brand deception: to exploit audience trust in recognizable outlets and to embed narratives within seemingly legitimate editorial environments.

Supporting these front-facing elements is a redirect and tracking layer. This tier manages traffic flow, referral routing, and possibly engagement analytics. It enables flexible amplification pathways and allows operators to shift traffic patterns without modifying core content nodes.

Above distribution sits the SEO optimization layer. Search visibility is engineered through keyword structuring, backlink strategies, and metadata tuning. This layer ensures that impersonation domains surface within search ecosystems, increasing organic discovery and enhancing perceived legitimacy.

Finally, social media amplification functions as the outermost dissemination ring. Coordinated accounts, paid promotion, or content seeding strategies drive traffic toward the impersonation domains. Social platforms act as accelerants, extending reach into geographically segmented audiences.

At the terminus of this layered model are the audiences themselves, segmented by geography and political context. Messaging is not broadcast uniformly; it is calibrated. German audiences receive different narrative emphasis than U.S. or French audiences, even when core themes remain aligned.

This architecture separates content generation, brand deception, distribution mechanics, and resilience engineering into discrete but interconnected layers. The result is a modular influence system capable of rapid reconfiguration. When one layer is disrupted, such as through domain seizure, the remaining tiers persist to enable continuity. This structural separation is a defining feature of the campaign’s operational maturity.

Domain Corpus & Structural Clustering

The domain ecosystem resolves into three principal structural tiers: core hubs, narrative fronts, and media impersonation clusters. Each tier performs a distinct operational role within the broader influence architecture.

The core RRN hubs function as the gravitational center of the campaign. Observed anchors include rrn[.]world (2022-2025 * as of 2026 domain re-purposed by unknown entities exposing the  doppelganger/SDA group), the previously seized rrn.media, its post-enforcement successor rrn[.]so, rrn[.]com[.]tr, and the earlier rrussianews[.]com. These domains operate as centralized narrative clearinghouses. They provide thematic consistency, content staging, and coordination continuity. When enforcement actions occur, the transition between domains preserves second-level naming conventions, indicating planned migration rather than reactive improvisation. The hub tier is not simply a publishing site; it is the synchronization layer for the ecosystem’s messaging and lifecycle management.

Beneath this central constellation sit the narrative front domains. Properties such as 50statesoflie., acrosstheline., avisindependent.eu, artichoc[.]cc, levinaigre[.]so, ukrlm[.]so, and shadowwatch[.]us are structured to appear as independent editorial outlets. Their purpose is reframing. Rather than overtly presenting RRN branding, they repackage aligned narratives under the veneer of autonomous journalism. This layer introduces plausible deniability and audience-specific tonality while remaining structurally tethered to the broader system. The naming conventions are less overtly imitative than the impersonation tier, but they are thematically suggestive, often invoking investigative or oppositional framing.

The largest and most visible component of the ecosystem is the media impersonation cluster, comprising approximately sixty percent of the observed domain corpus. This tier includes clones of prominent Western outlets such as Spiegel, Bild, Süddeutsche Zeitung, FAZ, Welt, T-Online, The Guardian, Daily Mail, ANSA, and variants referencing Fox News. These domains are engineered to replicate the visual and structural appearance of legitimate news brands, exploiting pre-existing public trust.

Impersonation within this cluster follows consistent technical patterns. Top-level domain substitution replaces primary brand extensions with lower-cost or less scrutinized alternatives. Typosquatting mechanisms include letter duplication, omission, and phonetic substitution, creating visually plausible but technically distinct domains. Additional variants employ brand-semantic suffixes or geographic modifiers to enhance credibility while maintaining differentiation from the authentic domain. The repetition and systematic variation across these brand families strongly suggest automated or scripted domain generation logic rather than manual, ad hoc spoofing.

Taken together, these three tiers illustrate a graduated deception model. The core hubs centralize narrative control. The narrative fronts contextualize and reframe messaging under independent branding. The impersonation clusters maximize credibility exploitation through high-fidelity replication. The structural coherence across all three layers reinforces the conclusion that this is a coordinated provisioning ecosystem rather than isolated instances of media spoofing.

Temporal analysis of the 48-domain dataset reveals that domain acquisition did not occur as a continuous or organic process. Instead, registrations cluster into two distinct provisioning bursts, each aligned with identifiable geopolitical inflection points.

The first wave occurred in mid-2022, coinciding with the escalation phase of the war in Ukraine. During this period, domain registrations expanded rapidly across multiple brand families and narrative fronts. The timing suggests synchronization with heightened geopolitical tension and intensified information competition. Rather than opportunistic spoofing, the burst reflects pre-coordinated deployment intended to support sustained narrative operations during a critical phase of the conflict.

The second wave emerged in September 2024. This provisioning cycle aligns with Western electoral timelines and follows public enforcement actions targeting earlier Doppelgänger infrastructure. The pattern indicates both narrative refresh and infrastructure regeneration. Domains registered during this period show evidence of replacement logic, TLD diversification, and continued brand-family clustering, consistent with an adaptive response to seizure activity.

Across both waves, several structural characteristics remain consistent. Registration timestamps fall within narrow windows, suggesting batch provisioning rather than independent acquisition. Multiple domains tied to the same media brand families appear within close temporal proximity, reinforcing the likelihood of centralized control. The recurrence of identical naming logic across separate waves further indicates a reusable deployment pipeline.

This temporal clustering model is incompatible with organic domain growth. Instead, it reflects planned campaign staging cycles in which infrastructure is provisioned in anticipation of narrative events or in response to enforcement disruption. The pattern is consistent with structured influence operations that operate in defined phases rather than continuous improvisation.

TLD Strategy & Enforcement Evasion

Analysis of top-level domain selection reveals a deliberate concentration in a specific family of extensions. Dominant TLDs across the ecosystem include .media, .agency, .ltd, .today, .life, .ws, .cc, .so, .beauty, .expert, .vip, .pics, and .top. The distribution is neither random nor purely aesthetic; it reflects operational utility.

These extensions share several characteristics. They are generally low in acquisition cost, widely available at scale, and subject to comparatively limited scrutiny relative to legacy TLDs. Many also carry news-semantic or quasi-professional connotations such as .media, .agency, .today, or .expert which enhance surface credibility when paired with recognizable media brand tokens. This semantic plausibility increases the likelihood that users will perceive the domains as legitimate news outlets rather than synthetic replicas.

The selection pattern also supports rapid provisioning and replacement. Because these TLDs are typically less saturated than primary brand equivalents, operators can register multiple variants quickly and in batch. This flexibility is critical to enforcement resilience.

Observed seizure-to-migration behavior reinforces this assessment. When rrn[.]media was disrupted, operations pivoted to rrn[.]so while preserving the second-level domain. Similarly, 50statesoflie[.]com reappeared under .cc and .so variants, and acrosstheline[.]press transitioned to a .cc counterpart. In each case, the second-level domain remained intact while only the top-level extension changed.

Preservation of the second-level domain across new TLDs constitutes a very high-confidence linkage signal. It demonstrates continuity of operator control and planning rather than independent replication. The pattern indicates that alternate TLDs were likely pre-positioned or rapidly provisioned using the same deployment pipeline. This TLD substitution model is therefore not merely a branding choice; it is a resilience mechanism embedded within the infrastructure strategy.

Registrar & Registration Patterns

Registrar-level analysis indicates deliberate diversification rather than consolidation. Domains within the ecosystem are distributed across multiple commercial registrars, including Cloudflare, GoDaddy (Jomax), Namecheap, Dynadot, and Porkbun. No single registrar dominates the corpus. This dispersion reduces the likelihood of centralized administrative exposure and complicates straightforward clustering based on registrar account identifiers alone.

Privacy shielding is applied almost universally. Registrant information is redacted or routed through privacy services, limiting direct attribution vectors. Registration durations are typically short, most commonly one- to two-year terms, reinforcing the disposable nature of the infrastructure. There is no evidence of long-term brand cultivation or multi-year strategic retention of primary domains. Instead, domains appear engineered for limited operational lifespan, with replacement assumed as part of the lifecycle model.

Taken together, these characteristics support a strategy of attribution resistance through registrar diversification. By spreading registrations across multiple providers, the operators reduce the impact of any single registrar-level disruption or investigative pivot. This also suggests compartmentalization: different domain clusters may be provisioned under separate registrar accounts to prevent a single compromise from exposing the full network.

The lifecycle management model is explicitly disposable. Domains are provisioned for campaign phases, used for narrative dissemination, and abandoned or replaced following enforcement pressure or strategic refresh cycles. This is consistent with burst registration waves and TLD substitution behavior observed elsewhere in the ecosystem.

Hosting & IP Space Analysis

Infrastructure analysis reveals a consistent architectural pattern built around layered hosting abstraction. At the outermost layer, domains are fronted by Cloudflare, which provides edge delivery, caching, and origin masking. This CDN fronting obscures backend IP exposure and complicates direct attribution through simple DNS resolution. Behind this edge layer, backend services are deployed across hyperscale cloud providers, principally Google Cloud, where individual sites resolve to distributed virtual instances. At the application layer, disposable WordPress nodes function as the publishing engine, allowing rapid content deployment and replacement without persistent infrastructure commitments.

The dataset supports this model. Across 48 domains, 34 unique IP addresses were observed, indicating distributed backend allocation rather than centralized hosting. A substantial portion of domains resolved through Cloudflare address space in the 104.x range, reinforcing the prevalence of CDN masking. Backend nodes and functions appeared in Google Cloud 34.x ranges as well as some lesser activity in AWS 15.x ranges, often in small micro-clusters of related domains sharing hyperscaler infrastructure or repurposing static assets or content from legitimate websites. A minor presence of European hosting providers exists, but without concentration sufficient to suggest geographic anchoring.

This configuration reflects a cloud-native deployment strategy optimized for flexibility and resilience. Hyperscaler infrastructure provides rapid provisioning, geographic neutrality, and scalable bandwidth, while CDN masking reduces visibility into origin servers. The distributed IP footprint and lack of single-ASN concentration further enhance survivability and reduce detection risk.

Notably, there is no observable concentration of infrastructure within Russian autonomous systems. This absence should not be interpreted as contradictory to Russian-aligned tradecraft. On the contrary, reliance on Western hyperscalers and CDN masking aligns with evolved attribution-resistant design principles. By operating within globally reputable cloud ecosystems, the campaign blends into high-volume commercial traffic, leveraging legitimate infrastructure to reduce investigative friction.

The resulting hosting posture is deliberately attribution-resistant. It prioritizes redundancy, geographic neutrality, and rapid redeployment capacity over static hosting stability. This design is consistent with a professionally managed influence operation engineered for persistence under enforcement pressure rather than a transient spoofing campaign.

DNS & Nameserver Linkage

DNS-layer analysis provides several high-probability linkage indicators that may offer stronger structural correlation than hosting data alone. While IP addresses can shift due to CDN fronting or cloud migration, nameserver configurations often persist across operational changes and therefore provide a more durable pivot.

One primary indicator would be the reuse of identical nameserver pairs across multiple brand families. If domains impersonating unrelated outlets such as Spiegel, Bild, and Süddeutsche share the same NS records, the likelihood of independent registration diminishes substantially. Shared nameserver infrastructure across distinct media brands would suggest centralized DNS provisioning rather than coincidental overlap.

A related signal would be reliance on the same DNS provider across otherwise unrelated impersonation domains. When domains targeting different national audiences or brands resolve through a common DNS control environment, it implies coordination at the administrative level. Similar time-to-live (TTL) values across domains can further reinforce this signal, as TTL configurations often reflect default settings applied at the account or template level rather than individually tuned parameters.

Consistency in Start of Authority (SOA) structure such as identical formatting conventions, refresh intervals, or authoritative contact placeholders would provide additional evidence of centralized DNS management. SOA artifacts are rarely manipulated for cosmetic purposes and often reveal provisioning templates used by operators.

If nameserver reuse were observed across the Spiegel, Bild, Süddeutsche, and RRN domain families, it would strongly indicate a unified DNS control plane underpinning both narrative hubs and impersonation properties. Such convergence would demonstrate that, despite registrar dispersion and TLD diversification, domain resolution remains orchestrated from a common administrative layer.

In comparative evidentiary strength, nameserver clustering is likely a more robust attribution signal than IP overlap. IP infrastructure can be transient, especially in cloud-native deployments. Nameserver configurations, by contrast, frequently reflect centralized provisioning logic and are less susceptible to routine backend rotation. As a result, DNS-layer commonality may provide the clearest structural linkage within a distributed, attribution-resistant hosting environment.

Backend CMS Artifact Analysis

Forensic review of recovered WordPress artifacts provides insight into backend governance and operational discipline. The earliest observable provisioning activity indicates bootstrap configuration using a Yandex-linked email account, suggesting centralized initial setup rather than distributed contributor onboarding. Following this bootstrap phase, multiple accounts associated with the @rrn[.]com[.]tr namespace were rapidly provisioned, reflecting coordinated account creation within a defined administrative domain.

User roles within the CMS exhibit structured segmentation. Accounts labeled with function-specific identifiers such as “seoadmin” and “RRN_Staff” indicate differentiated permissions and workflow responsibilities. This separation of duties is characteristic of managed editorial environments rather than informal publishing collectives. The presence of search-engine-optimization–focused accounts further demonstrates that visibility engineering was embedded into backend operations, not treated as an afterthought.

Artifacts dated to 2025 reveal application-password configurations, which are typically associated with API integrations, automated publishing pipelines, or credential compartmentalization for security control. The continued presence of such artifacts indicates ongoing maintenance and lifecycle management rather than abandonment of infrastructure following enforcement pressure.

Collectively, these backend signals imply centralized coordination of publishing workflows, structured SEO integration, and sustained operational oversight. The pattern reflects a professionalized content management hierarchy with defined roles, controlled credential distribution, and repeatable provisioning logic. Such characteristics are inconsistent with decentralized volunteer activism or loosely organized advocacy networks. Instead, they align with a managed, institutionally structured information operation.

Automated Domain Generation Model

Domain naming patterns across the ecosystem reveal consistent construction logic indicative of automation rather than manual registration. The observed formats follow repeatable templates. The most straightforward pattern replicates the core brand token directly as a second-level domain paired with an alternate top-level extension. A second pattern appends semantic qualifiers to the brand, often news-oriented or temporal terms before applying a conventional TLD. A third variation incorporates geographic modifiers, creating localized variants that maintain brand recognition while implying regional relevance. Additional structures involve typographical manipulation of the brand token itself or preservation of the second-level domain during TLD migration events.

Typographical techniques follow predictable methods. Letter duplication produces visually plausible variants such as “bildd.” Letter omission removes characters to create near-identical strings, for example “blld.” Phonetic substitution alters spelling while retaining recognizability, as in “build.” Semantic suffixes such as “-today,” “-live,” or “-life” introduce news-related framing, while geographic modifiers like “-eu” or “-asia” imply localized legitimacy. These manipulations are systematic and repeat across multiple brand families, reinforcing the likelihood of template-based domain generation.

The preservation of the second-level domain across new TLDs during enforcement events further supports the presence of structured provisioning logic. Rather than improvising new names, operators maintain core tokens and rotate extensions, suggesting preplanned substitution pathways embedded within the registration pipeline.

The consistency and recurrence of these patterns strongly suggest a scripted bulk provisioning mechanism. Domain creation appears to follow predefined logic trees, enabling rapid generation of multiple variants per target brand. This automation facilitates scalability, redundancy, and rapid replacement following seizure or suspension.

Based on the observed logic, predictive domain templates can be modeled. Likely future variants would include constructions such as brand paired with “.media,” “.agency,” or “.today.” Hyphenated semantic extensions appended to established brands such as brand-live or brand-life are also probable. Additionally, migration to lower-scrutiny country-code or generic TLDs such as “.cc” or “.so” remains consistent with prior behavior.

Monitoring Certificate Transparency logs against these structured templates is recommended as an early-warning mechanism. Because automated pipelines often generate certificates shortly after registration, template-based CT monitoring may identify new impersonation domains before large-scale amplification occurs.

Geographic Target Segmentation

Geographic segmentation within the ecosystem reflects deliberate alignment between infrastructure deployment and narrative emphasis. Targeting is not uniform across regions; instead, infrastructure tactics and messaging themes are calibrated to local political contexts and audience sensitivities.

Germany emerges as the most extensively targeted environment. The infrastructure footprint there is dominated by high-volume media impersonation, particularly of prominent national outlets. The corresponding narrative focus centers on anti-NATO themes, criticism of sanctions policy, and efforts to widen domestic political divisions. The scale and density of impersonation domains associated with German brands indicate prioritization beyond incidental inclusion.

In France, the operational model blends media clones with narrative front domains. Messaging frequently emphasizes the economic costs of sanctions and promotes themes of Ukraine-related fatigue. The infrastructure suggests a strategy aimed at reframing policy debates through domestically contextualized narratives rather than direct geopolitical confrontation.

The United States is approached through narrative front properties combined with election-cycle framing. Rather than relying exclusively on high-fidelity impersonation of national outlets, the ecosystem leverages independently branded sites to question institutional legitimacy and amplify distrust in democratic processes. Timing of domain provisioning aligns with electoral periods, reinforcing the assessment of politically sensitive targeting.

In the United Kingdom, media impersonation remains the dominant tactic. Messaging themes concentrate on skepticism toward NATO policy and criticism of foreign engagement. The structure parallels the German model but appears narrower in scope.

Italy is targeted primarily through impersonation of ANSA and related institutional brands. The emphasis shifts toward undermining institutional trust and reinforcing domestic dissatisfaction narratives. This indicates adaptation to national media ecosystems and audience trust structures.

Across the broader European Union, the campaign employs an amplification mesh model. Rather than focusing exclusively on single-country impersonation clusters, domains and social distribution mechanisms propagate narratives across borders, fostering cross-national polarization and reinforcing pan-European fissures.

The relative density of impersonation domains, narrative alignment, and provisioning volume suggests that Germany represents the highest-priority target within the ecosystem. Infrastructure investment and thematic emphasis converge most heavily in that information environment, indicating strategic weighting rather than incidental inclusion.

Germany appears highest-priority target.

What the Infrastructure Is Not

Infrastructure analysis reveals a consistent absence of indicators typically associated with financially motivated cybercrime or intrusion-focused operations. There is no evidence of malware command-and-control coordination embedded within the observed domains. The hosting architecture, DNS behavior, and certificate issuance patterns do not reflect infrastructure designed to manage implants, beacon traffic, or staged payload delivery.

Similarly, there are no artifacts suggesting phishing kit reuse or credential-harvesting frameworks. The domains do not exhibit structural similarities to common phishing templates, nor do they display the rapid redirect logic or form-handling mechanics associated with account compromise campaigns. The absence of credential collection endpoints or kit fingerprint overlap further distinguishes this ecosystem from conventional fraud operations.

There is also no observable affiliate monetization structure. The infrastructure does not show integration with traffic arbitrage networks, affiliate referral programs, or performance-based revenue systems. Domain lifecycles are short and aligned with narrative waves rather than revenue optimization windows. Likewise, there is no evidence of ad network integration, programmatic advertising infrastructure, or content-farming strategies designed to generate advertising impressions at scale.

Hosting patterns further differentiate the operation from typical criminal infrastructure. The ecosystem does not rely on bulletproof hosting providers or obscure offshore ASNs commonly associated with malware distribution or fraud. Instead, it leverages mainstream hyperscaler platforms and CDN fronting, prioritizing camouflage within legitimate cloud ecosystems rather than protection from law enforcement through hardened criminal service providers.

Collectively, these absences are analytically significant. The infrastructure is optimized for narrative dissemination, brand impersonation, and audience influence rather than financial extraction or technical exploitation. Its design reflects an information operation architecture engineered for credibility manipulation and distribution resilience. This is narrative delivery infrastructure, not cybercrime infrastructure.

Operational Maturity Assessment

The Doppelgänger ecosystem exhibits operational characteristics consistent with disciplined infrastructure engineering rather than ad hoc domain deployment. Provisioning behavior reflects DevOps-style methodology: domains are registered in coordinated bursts, deployed in structured waves, and integrated into a repeatable pipeline that supports rapid staging and replacement. Infrastructure is treated as code: scalable, replicable, and disposable.

Campaign activation appears synchronized with geopolitical or electoral inflection points, indicating burst staging rather than continuous organic growth. Domains are stockpiled in advance of use, enabling operators to activate replacement nodes with minimal latency following enforcement actions. This pre-positioned redundancy reduces operational downtime and demonstrates forward-planned lifecycle management.

Rapid pivoting in response to seizures further illustrates enforcement-aware design. When domains are disrupted, second-level identifiers are preserved and redeployed under alternate top-level domains. Hosting and DNS configurations are rotated without altering the broader narrative framework. The system absorbs disruption without collapsing, reflecting modular segmentation that isolates functional layers from single points of failure.

The architecture’s reliance on CDN masking, hyperscaler backend infrastructure, and distributed IP allocation demonstrates cloud-native proficiency. Deployment choices prioritize camouflage within legitimate commercial cloud environments, reducing attribution risk and complicating network-level blocking strategies. Infrastructure components are loosely coupled yet centrally coordinated, reinforcing resilience.

Attribution minimization is embedded throughout the lifecycle. Registrar dispersion, privacy shielding, and geographic hosting neutrality collectively reduce direct linkage signals. Operational design favors structural ambiguity while maintaining internal coherence.

The campaign’s evolution reflects increasing sophistication under pressure. During Phase I (2022–2023), the model centered on a relatively centralized RRN hub supported by impersonation spokes. Phase II (2024) introduced enforcement disruption through domain seizures, testing the resilience of the architecture. In Phase III (2024–2025), the ecosystem adapted into a more distributed modular mesh, reducing reliance on singular hubs and expanding TLD diversification.

Rather than diminishing under enforcement pressure, the infrastructure matured. Redundancy increased, segmentation deepened, and migration pathways became more seamless. The trajectory indicates learning and adaptation, reinforcing the assessment that the operation is professionally managed and strategically sustained rather than episodic or opportunistic.

Strategic Assessment

The Doppelgänger ecosystem exhibits characteristics consistent with industrialized influence infrastructure rather than episodic or improvised activity. Its provisioning discipline, redundancy planning, and lifecycle management imply sustained funding and coordinated oversight. The infrastructure is treated as a strategic asset, engineered for persistence under scrutiny and adaptable under enforcement pressure. This reflects a model in which infrastructure is not merely a vehicle for messaging but the foundation of the influence operation itself.

The operational posture aligns with an infrastructure-first influence warfare framework. Domains are provisioned in waves, diversified across TLDs, shielded behind CDN layers, and redeployed with minimal latency following disruption. Backend publishing environments are structured and role-segmented. DNS and hosting choices prioritize camouflage within legitimate hyperscaler ecosystems. These attributes collectively indicate that technical architecture is central to the campaign’s design, not secondary to narrative content.

Psychological operations are embedded within this technical foundation. Messaging is geographically segmented, timed to political cycles, and distributed through impersonation layers engineered to exploit audience trust. The technical and narrative components are integrated rather than siloed. DevOps-style provisioning supports narrative agility, enabling rapid amplification, replacement, or recalibration in response to geopolitical developments.

The campaign represents a hybridization of multiple strategic disciplines. Cyber infrastructure strategy provides resilience, obfuscation, and scalability. Narrative warfare supplies thematic direction and audience targeting. Search ecosystem manipulation ensures discoverability and legitimacy through SEO optimization. Election-cycle timing introduces temporal precision, aligning infrastructure activation with moments of heightened political sensitivity.

Taken together, these characteristics distinguish the operation from opportunistic spoofing or isolated propaganda efforts. The ecosystem reflects structured, enforcement-aware influence engineering. Its design anticipates disruption, incorporates redundancy by default, and integrates technical and psychological components into a cohesive operational model.

Editor’s Note: DomainTools Investigations engaged in pre-publication collaboration with both Google Threat Intelligence Group and Amazon Web Services Threat Intelligence on this material. Both teams were immediately responsive, engaging in analysis in their respective areas and providing helpful feedback. We appreciate their partnership.

Appendix A Domain Data Assessed Map (48 domains)

Domain constellation map

Domains Researched

20minuts[.]com
50statesoflie[.]cc
50statesoflie[.]com
50statesoflie[.]so
acrosstheline[.]cc
acrosstheline[.]press
ansa[.]ltd
artichoc[.]cc
avisindependent[.]eu
bild-d[.]beauty
bild[.]beauty
bild[.]expert
bild[.]llc
bild[.]pics
bild[.]work
bild[.]ws
bildd[.]beauty
bildd[.]lol
blld[.]live
build[.]vip
build[.]ws
dailymail[.]cfd
faz[.]agency
faz[.]life
fox-news[.]in
fox-news[.]top
levinaigre[.]so
rrn[.]com[.]tr
rrn[.]media
rrn[.]so
rrn[.]world
rrussianews[.]com
shadowwatch[.]us
spiegel[.]agency
spiegel[.]fun
spiegel[.]ltd
spiegel[.]media
spiegel[.]today
spiegeli[.]life
spiegeli[.]today
sueddeutsche[.]cc
sueddeutsche[.]co
sueddeutsche[.]me
theguardian-com[.]com
ukrlm[.]so
welt[.]ltd
welt[.]media
welt[.]ws

Appendix B Bibliography

Correctiv. 2024. “Inside Doppelganger: How Russia Uses EU Companies for Its Propaganda.” July 22, 2024. https://correctiv.org/en/fact-checking-en/2024/07/22/inside-doppelganger-how-russia-uses-eu-companies-for-its-propaganda/.

Der Spiegel. 2026. “Im Inneren der russischen Propagandamaschine.
https://www.spiegel.de/politik/hacktivist-infiltriert-desinformationskampagne-im-inneren-der-russischen-propagandamaschine-a-265fd485-1d0d-45b6-b0b3-4fd46091ddfa.   

Digital Forensic Research Lab (DFRLab). 2024a. “How Doppelganger and Other Russia-Linked Operations Target U.S. Elections.” September 6, 2024. https://dfrlab.org/2024/09/06/how-doppelganger-and-other-russia-linked-operations-target-us-elections/.

Digital Forensic Research Lab (DFRLab). 2024b. “Doppelganger Websites Persist One Month Following U.S. Government Seizures.” October 9, 2024. https://dfrlab.org/2024/10/09/doppelganger-websites-persist/.

European Digital Media Observatory (EDMO). 2024. “Doppelganger Investigations Bring Russian Propaganda Campaign to a Halt.” November 18, 2024. https://edmo.eu/publications/doppelganger-correctiv-investigations-bring-russian-propaganda-campaign-to-a-halt/.

European External Action Service (EEAS). 2024. “Doppelganger Strikes Back: Unveiling FIMI Activities Targeting European Parliament Elections.” June 2024. https://euvsdisinfo.eu/doppelganger-strikes-back-unveiling-fimi-activities-targeting-european-parliament-elections/.

EU DisinfoLab and Qurium. 2022. Doppelganger: Media Clones Serving Russian Propaganda. September 27, 2022. https://nsarchive.gwu.edu/sites/default/files/documents/semon9-giki0/2022-09-27-EUDisinfoLab-Qurium-Doppelganger.pdf.

European Centre for Press and Media Freedom (ECPMF). 2024. “Actions Must Be Taken to Address Mass Pro-Russian Spoofing of Legitimate Media Outlets.” September 30, 2024. https://www.ecpmf.eu/actions-must-be-taken-to-address-mass-pro-russian-spoofing-of-legitimate-media-outlets/.

Lawfare. 2024. “Making Sense of the Doppelganger Disinformation Operation.” October 16, 2024. https://www.lawfaremedia.org/article/lawfare-daily--making-sense-of-the-doppelganger-disinformation-operation--with-thomas-rid.

Rid, Thomas. 2024. “The Lies Russia Tells Itself.” Foreign Affairs, September 30, 2024. https://www.foreignaffairs.com/united-states/lies-russia-tells-itself.

STRATCOM COE. 2024. The Doppelganger Case: Assessment of Platform Regulation on the EU Disinformation Environment. https://stratcomcoe.org/publications/the-doppelganger-case-assessment-of-platform-regulation-on-the-eu-disinformation-environment/304.

U.S. Cyber Command. 2024. “Russian Disinformation Campaign ‘DoppelGänger’ Unmasked.” September 3, 2024. https://www.cybercom.mil/Media/News/Article/3895345/russian-disinformation-campaign-doppelgnger-unmasked-a-web-of-deception/.

U.S. Department of Justice. 2024. “Justice Department Disrupts Covert Russian Government-Sponsored Foreign Malign Influence Operation.” September 4, 2024. https://www.justice.gov/archives/opa/pr/justice-department-disrupts-covert-russian-government-sponsored-foreign-malign-influence.

Learn More
Research
No items found.
Lotus Blossom (G0030) and the Notepad++ Supply-Chain Espionage Campaign

How Lotus Blossom (G0030) compromised the Notepad++ update pipeline in a precision supply-chain espionage campaign targeting high-value organizations.

Executive Summary

In late 2025 and early 2026, a series of independent disclosures by software maintainers, security researchers, and national cyber authorities converged on an unsettling conclusion: for months, the update mechanism of one of the world’s most widely used open-source text editors had been quietly subverted. What initially appeared to be an isolated infrastructure anomaly was ultimately revealed to be a sustained compromise of the Notepad++ update pipeline, stretching back roughly six months. As investigators reconstructed the timeline, tracking unauthorized access to hosting infrastructure, lingering credentials that outlived initial remediation, and selectively altered update responses, a far more deliberate operation came into focus. This report is the product of analysis and parallel reconstruction of all public reporting on Lotus Blossom with additional research by DTI, drawing together technical forensics, victimology, and strategic context to assess both the campaign and the actor behind it.

The evidence points to a quiet, methodical intrusion rather than a blunt supply-chain smash-and-grab. From their foothold inside the update infrastructure, the attackers did not indiscriminately push malicious code to the global Notepad++ user base. Instead, they exercised restraint, selectively diverting update traffic for a narrow set of targets, organizations and individuals whose positions, access, or technical roles made them strategically valuable. Taken together, the operational choices, tooling, and victim profile support attribution, with moderate to high confidence, to the China-aligned espionage actor commonly tracked as Lotus Blossom (G0030) in concurrence with other organizations assessment.

What most clearly distinguishes this campaign is its precision. The malicious updates were tailored, the delivery carefully gated, and the operational noise deliberately kept low. There is no evidence of ransomware, financial theft, destructive activity, or influence operations. That absence is itself a signal. Everything about the intrusion, from the limited number of victims to the patient dwell time, points to an intelligence-gathering mission oriented toward quietly acquiring insight rather than extracting immediate material gain. The inferred objectives align closely with state intelligence priorities, encompassing political decision-making, economic and financial visibility, and access to telecommunications and technical environments.

Viewed in a broader historical context, the Notepad++ compromise represents a clear evolution in Lotus Blossom’s tradecraft. Earlier campaigns relied heavily on spear-phishing and bespoke backdoors delivered directly to victims. Rather than compromising end-user systems through conventional infrastructure attacks, such as opportunistic abuse of widely trusted software updates, the actors shifted the locus of trust toward the developer ecosystem itself. By abusing a legitimate update mechanism relied upon specifically by developers and administrators, they transformed routine maintenance into a covert entry point for high-value access. Yet despite this technical evolution, the strategic logic remains consistent. The campaign reflects continuity in purpose, a sustained focus on regional strategic intelligence, executed with more sophisticated, more subtle, and harder-to-detect methods than in prior iterations.

Actor Overview: Lotus Blossom (G0030)

Lotus Blossom is best understood as one of the more durable and methodical Chinese cyber-espionage clusters, with activity traced by multiple vendors and government-linked research groups back to at least 2009–2010. Over more than a decade of operations, the group has appeared under a shifting set of aliases, reflecting differences in vendor telemetry and analytic frameworks, but those naming inconsistencies mask a striking continuity beneath the surface. Across campaigns separated by years, Lotus Blossom exhibits the same core patterns: recurring malware families, stable operational rhythms, and a highly consistent choice of targets. This continuity is one of the strongest indicators that analysts are observing a single, long-lived espionage program rather than a loose collection of short-term intrusion efforts.

At its core, Lotus Blossom is a mission-driven intelligence actor, not a financially motivated threat group. There is no credible reporting tying the cluster to ransomware, extortion, cryptomining, or large-scale fraud. Instead, its operations consistently prioritize access, visibility, and persistence. In multiple documented campaigns, compromised environments remained under observation for months or even years, with operators carefully enumerating systems, staging data locally, and maintaining footholds through understated persistence mechanisms. The absence of monetization artifacts, such as payment infrastructure, monetization tooling, or public-facing impact, strongly reinforces the assessment that Lotus Blossom’s mandate is intelligence collection rather than profit.

Geographically, the group’s center of gravity has long been Southeast Asia, a region that aligns closely with Chinese strategic, diplomatic, and security interests. Vietnam, the Philippines, Hong Kong, Taiwan, and neighboring states recur repeatedly in public reporting. Over time, however, there is clear evidence of measured expansion beyond this core theater. More recent campaigns, including the Notepad++ supply-chain operation, show activity extending into Central America and Oceania, suggesting either broadened tasking or an adaptive response to evolving intelligence priorities. Importantly, this expansion has not come with a change in tempo or style; the group applies the same low-noise tradecraft regardless of geography.

One of Lotus Blossom’s defining traits is its tolerance for long dwell times and multi-year campaigns. Unlike vulnerability-driven actors that move rapidly from exploitation to exit, Lotus Blossom appears comfortable maintaining access with minimal interaction, sometimes returning to environments long after initial compromise. This patience is reflected in how the group manages infrastructure and malware lifecycles. Tooling is not rapidly discarded after exposure; instead, families are iterated and refined over years, with new variants introduced only when necessary. This approach reduces operational risk and supports sustained intelligence collection.

Operationally, the group shows a strong preference for quiet persistence over disruption. Techniques documented across campaigns emphasize blending in rather than standing out: registry-based persistence, Windows services, DLL sideloading, and the use of legitimate administrative utilities. Command-and-control traffic is frequently disguised as normal web or API activity, and in some cases tunneled through legitimate platforms. This tradecraft minimizes alerts and allows the actor to remain embedded in sensitive networks without triggering incident response thresholds.

A key throughline across Lotus Blossom’s history is its reliance on custom backdoors that evolve but remain recognizably related. Early campaigns made use of backdoors such as Elise, followed by the long-running Sagerunex family, which has been observed in multiple variants since at least 2016 and is widely regarded as uniquely associated with the group. The emergence of Chrysalis in the Notepad++ supply-chain campaign represents the latest iteration of this lineage: a bespoke implant designed for stealth, flexibility, and long-term access. The persistence of these families across years underscores both development continuity and institutional knowledge within the operator set.

Within the broader Chinese APT ecosystem, Lotus Blossom occupies a regional strategic espionage tier. It is less globally expansive than groups such as APT10 or APT41, which have conducted large-scale, worldwide operations against managed service providers, supply chains, and intellectual property targets. At the same time, Lotus Blossom is markedly more disciplined and persistent than opportunistic or vulnerability-driven clusters that surge around new exploits and then fade. Its niche is sustained regional intelligence collection: quieter, narrower in scope, but exceptionally durable. That combination – longevity, patience, and restraint – has made Lotus Blossom one of the more consistently effective, and correspondingly harder to uproot, espionage actors operating in the Chinese cyber landscape.

Historical Operations and Tradecraft Evolution

Lotus Blossom’s operational history can be understood as a gradual but deliberate evolution, marked by clear phases in tooling, targeting, and delivery mechanisms, each building on lessons learned from the last.

In its early era, roughly spanning 2012 to 2015, Lotus Blossom was first brought into clear view through campaigns documented by multiple security vendors. During this period, the group focused heavily on government and military organizations across Southeast Asia, reflecting a tightly scoped intelligence mandate aligned with regional political and defense priorities. Access was typically achieved through spear-phishing, often using carefully crafted, weaponized documents designed to appear relevant to the recipient’s official duties. Once opened, these lures delivered a custom backdoor known as Elise, which gave the operators persistent access to compromised systems. The objectives in this phase were relatively unambiguous: the collection of political and defense intelligence, including insight into policy deliberations, military posture, and regional security relationships. The tradecraft was effective but conventional, relying on social engineering and direct victim interaction to establish initial footholds.

The middle era, from approximately 2016 through 2024, marks a period of consolidation and professionalization. During this time, Lotus Blossom transitioned away from Elise and adopted the Sagerunex backdoor family, which would become a defining element of its operations for nearly a decade. Sagerunex was not simply a replacement implant but a more flexible and durable platform, iterated across multiple variants and tailored for long-term persistence. Alongside this tooling shift, the group expanded its target set. While government entities remained important, campaigns increasingly encompassed telecommunications providers, media organizations, and manufacturing or industrial firms. This broader victimology suggests an intelligence remit that had widened to include information flows, public narratives, supply chains, and industrial capacity.

Technically, this era is notable for Lotus Blossom’s growing reliance on legitimate third-party services as covert command-and-control channels. By tunneling communications through cloud platforms, webmail, and other widely used services, the group was able to blend malicious traffic into normal enterprise activity, significantly reducing detection risk. At the same time, operators invested in improved operational security and persistence mechanisms, favoring low-visibility techniques such as Windows services, registry modifications, and careful privilege management. These choices enabled long dwell times and multi-year access to sensitive environments, reinforcing the group’s reputation for patience and discipline.

The modern era, beginning in 2025 and extending into 2026, represents the most pronounced shift in Lotus Blossom’s tradecraft. In this phase, the group adopted supply-chain compromise as a primary delivery vector, moving upstream to exploit trusted software distribution mechanisms rather than targeting victims directly. This approach dramatically reduced reliance on social engineering and increased the likelihood of execution in privileged, trusted contexts. Central to this period was the development and deployment of Chrysalis, a previously undocumented backdoor that fits within the group’s established lineage but reflects contemporary defensive realities, emphasizing stealth, flexibility, and survivability.

Operational focus in this era also shifted toward developer and administrator tooling, applications and environments used by individuals with elevated privileges and deep visibility into organizational systems. Even when positioned to affect a broad population, Lotus Blossom demonstrated highly selective victim delivery, carefully gating malicious updates to a narrow set of high-value targets. This restraint underscores the intelligence-driven nature of the activity and the group’s continued aversion to unnecessary exposure.

Viewed end to end, the Notepad++ supply-chain campaign stands as the clearest and most mature expression of this evolution. It combines the group’s longstanding strategic focus on regional intelligence with a modern delivery mechanism that exploits trust itself, integrating bespoke tooling, blended command-and-control, and disciplined selectivity into a single, tightly executed operation.

Targeting Patterns Across Lotus Blossom’s Operational History

Across more than a decade of observed activity, Lotus Blossom’s targeting patterns reveal a high degree of consistency in strategic intent, even as the specific sectors and access methods have evolved. Rather than pursuing breadth or opportunistic exploitation, the group has repeatedly demonstrated a preference for narrow, high-value target sets aligned with enduring state intelligence requirements.

Geographically, Lotus Blossom’s center of gravity has remained firmly anchored in Southeast Asia since its earliest documented campaigns. Countries such as Vietnam and the Philippines recur across multiple reporting periods, reflecting their geopolitical relevance, proximity to contested maritime regions, and the importance of regional security dynamics. Over time, the group’s targeting expanded outward in a measured fashion rather than a sudden global surge. East Asian entities, particularly in Hong Kong and Taiwan, appear during periods of heightened political sensitivity, while more recent operations show selective activity in Oceania and Central America. This pattern suggests deliberate tasking tied to evolving diplomatic, security, and economic priorities rather than indiscriminate global reach.

Sectorally, Lotus Blossom’s targeting history shows a clear progression from core state institutions toward broader strategic enablers. In its early years, the group focused heavily on government ministries and military or defense-adjacent organizations, consistent with a mandate centered on political and defense intelligence. As the group matured, it expanded into telecommunications providers, a shift that provided insight into information flows, network dependencies, and potential downstream access. Subsequent targeting of media organizations indicates an interest in narrative awareness and public messaging, while incursions into manufacturing and industrial sectors point to intelligence collection related to supply chains, industrial capacity, and economic resilience.

A notable and recurring theme is Lotus Blossom’s focus on access multipliers, entities or roles that provide visibility beyond their immediate organizational boundaries. Telecommunications operators, IT service providers, and managed service environments appear repeatedly because they offer the potential to observe or pivot into multiple downstream networks. This logic is further reinforced in the group’s most recent campaigns, which emphasize developer and administrator environments. By targeting the tools and systems used by highly privileged technical staff, Lotus Blossom maximizes intelligence yield while minimizing the number of compromises required.

Equally important is what the group does not target. There is little evidence of sustained activity against consumer sectors, retail organizations, or entities primarily associated with direct financial gain. Even when financial institutions appear in victimology, the surrounding indicators point toward financial intelligence and relationship mapping, not theft or fraud. This restraint reinforces the assessment that Lotus Blossom’s targeting is governed by intelligence value rather than monetization potential.

Finally, Lotus Blossom’s targeting is characterized by selectivity and patience. Campaigns routinely involve small numbers of victims, long dwell times, and repeated engagement with the same regions or sectors over many years. The Notepad++ supply-chain campaign exemplifies this approach: despite access to a potentially massive user base, the group limited malicious delivery to a tightly controlled subset of targets. This pattern is consistent with an actor that values sustained insight and low exposure over rapid or dramatic effects.

Taken together, Lotus Blossom’s targeting history reflects a disciplined, intelligence-driven model. Geography, sector, and individual victim selection all serve a coherent strategic purpose, supporting the conclusion that the group functions as a long-term regional intelligence collector rather than a broad-spectrum or opportunistic threat actor.

Campaign Overview: Notepad++ Supply-Chain Compromise

Campaign Overview: Notepad++ Supply-Chain Compromise

The Notepad++ campaign represents a deliberate and technically mature supply-chain operation built around the exploitation of trust, rather than the compromise of software code itself. Instead of tampering with the Notepad++ application or its publicly available source, the attackers targeted third-party hosting infrastructure responsible for distributing software updates. By positioning themselves within this upstream delivery path, they were able to influence what end users received without altering the integrity of the project’s codebase or repositories.

Central to the operation was the abuse of WinGUp (GUP.exe), the legitimate updater mechanism used by Notepad++. Under normal conditions, GUP.exe is responsible for periodically checking for updates and retrieving them from trusted servers. The attackers subverted this process by selectively redirecting update requests from chosen systems to attacker-controlled servers. To the end user, and to most security controls, the process appeared indistinguishable from a routine update transaction.

A critical distinguishing feature of this campaign is that the Notepad++ source code was never modified. This choice conferred several operational advantages. By avoiding source-level tampering, the attackers bypassed source-code reviews, integrity checks, and the scrutiny of the open-source community. The malicious payloads were delivered in the form of trojanized installers, injected only at the point of distribution, allowing the operation to remain invisible to developers and maintainers focused on the code itself.

This approach also enabled a high degree of plausible deniability. Because the compromise occurred within hosting and delivery infrastructure rather than the project’s repositories, attribution was obscured and initial investigations could plausibly attribute anomalies to misconfiguration or transient infrastructure issues. Most importantly, the attackers exercised tight control over victim selection. Update redirection was applied only to specific targets, ensuring that malicious installers were delivered to a narrow, high-value subset of users while the vast majority of the Notepad++ user base continued to receive legitimate updates without incident.

Taken together, these elements reflect a campaign characterized by advanced planning, privileged access, and operational restraint. The selective nature of delivery, the avoidance of unnecessary exposure, and the exploitation of infrastructure trust rather than code vulnerabilities are all hallmarks of Lotus Blossom’s established tradecraft. The Notepad++ supply-chain compromise stands as a clear example of how the group has adapted its methods to modern software ecosystems while remaining true to its long-standing emphasis on stealthy, intelligence-driven operations.

Infection Chains and Malware Deployment

Analysis of the Notepad++ supply-chain incident reveals that the operation was not built around a single, static infection pathway, but rather multiple distinct infection chains deployed over the course of several months. Each chain showed minor variations in tooling, payload composition, and supporting infrastructure, suggesting active management and iteration by the operators. This modularity allowed Lotus Blossom to adapt to changing conditions, rotate infrastructure, and selectively tailor implants to different victims, all while preserving a consistent operational framework.

Despite these variations, the infection chains shared a set of core behavioral elements that define the campaign’s execution. In every observed case, the process began with a legitimate Notepad++ update request, handled by the WinGUp (GUP.exe) updater. For selected targets, this trusted process was subverted to launch a malicious installer delivered from attacker-controlled infrastructure. From the perspective of the operating system and the user, the execution chain appeared routine, inheriting the trust and execution context of a normal software update.

Once execution was achieved, the malware performed initial reconnaissance to situate itself within the environment. Commands such as whoami and tasklist, along with broader system enumeration routines, were used to identify the current user context, running processes, and basic system characteristics. This early situational awareness informed subsequent decisions, including which payloads to deploy and how aggressively to establish persistence.

The next phase involved the staging of artifacts within user application data directories, a deliberate choice that balanced accessibility and stealth. By operating within per-user paths rather than system-wide locations, the malware reduced the likelihood of triggering security controls tied to protected directories, while still maintaining reliable execution and storage. These directories served as temporary holding areas for loaders, configuration files, and auxiliary components.

From this staging environment, the operation progressed to the deployment of a custom loader, responsible for orchestrating the remainder of the infection chain. The loader acted as a pivot point, handling decryption, unpacking, and execution of the final payloads. Depending on the target and the specific chain in use, this culminated in the installation of either Cobalt Strike–based implants or the Chrysalis backdoor. The presence of both options indicates a flexible approach: Cobalt Strike offered a mature, feature-rich post-exploitation framework, while Chrysalis provided a bespoke, lower-profile alternative aligned with Lotus Blossom’s preference for custom tooling.

In all observed chains, post-compromise communications were conducted using encrypted, low-frequency outbound connections over HTTPS. Beaconing intervals were deliberately sparse, and traffic was structured to resemble legitimate web or API interactions, minimizing anomalies in network telemetry. This communications model prioritized stealth and survivability over responsiveness, reinforcing the broader pattern of restraint and long-term access that characterizes Lotus Blossom’s operations.

Collectively, these infection chains demonstrate a disciplined, repeatable deployment model that balances adaptability with consistency. The variations across chains reflect active operational oversight, while the shared elements underscore a well-established playbook optimized for covert, intelligence-driven access rather than rapid exploitation or overt impact.

Tradecraft Observed in the Notepad++ Supply-Chain Operation

In analyzing the Notepad++ supply-chain compromise and correlating it with broader reporting on Lotus Blossom operations, a consistent theme emerges. The group relies on stealthy, evasive techniques that blend malicious activity into normal system behavior rather than overt exploitation that would draw defensive attention. This section explains the key tradecraft elements that enabled the campaign’s success and situates them within broader patterns observed in similar Chinese state-aligned espionage activity.

A foundational aspect of Lotus Blossom’s technique set is the frequent use of living-off-the-land (LOTL) utilities, trusted, legitimate system tools that are co-opted to execute malicious logic under the guise of normal administrative or maintenance tasks. In LOTL attacks, adversaries leverage binaries that are already present on the target system (such as command interpreters or native utilities) to perform reconnaissance, lateral movement, or privilege escalation. Because these tools are part of the standard operating environment, their invocation often escapes traditional signature-based defenses and is not flagged by endpoint security as anomalous behavior. This approach is deliberately evasive, allowing an attacker to achieve foothold and persistence while minimizing the generation of new, suspicious artifacts. (Kiteworks | Your Private Data Network)

Another sophisticated tactic documented in the Notepad++ intrusion was the abuse of DLL sideloading, an established evasion technique that enables malicious code to be loaded by a legitimate host process. In the Notepad++ case, researchers found that a renamed legitimate utility (the Bitdefender Submission Wizard) was used as the initial execution context. A malicious companion DLL, placed in the same directory with the same name expected by the host process, was then loaded in place of the legitimate library. This technique allows the adversary to inject custom payloads without directly executing an executable they control, further blending with normal system activity and reducing the footprint seen by defensive tools. (Security Affairs)

Once executed, many of the campaign’s implants communicated with remote infrastructure using API-style command-and-control (C2) endpoints designed to resemble benign web traffic. These endpoints often expose paths that mimic legitimate update, telemetry, or cloud service APIs rather than raw sockets or obvious HTTP beaconing. By shaping communications in this way and by hosting them behind domains or services that appear innocuous, operators improve the chances that their traffic will traverse restrictive egress filters and escape detection by network intrusion detection systems. This API-like pattern of C2 infrastructure has been observed not only in the Notepad++ campaign but also in prior Lotus Blossom activity where third-party services (e.g., Dropbox, Twitter, or webmail) were repurposed as covert tunnels for beaconing and data exfiltration. (Cisco Talos Blog)

Finally, Lotus Blossom’s infrastructure usage patterns demonstrate rotation and redundancy without abandoning operational grammar. Rather than hard-coding a static set of servers or domains, the group periodically shifts hosting providers, domain names, and IP space while maintaining consistent behavioral identifiers in their implants and C2 protocols. This approach complicates blunt IP-blocklist defenses while preserving the recognizable telemetry that seasoned defenders use to attribute activity over time. The result is an operational posture that is resilient to takedown and resistant to simple detection heuristics, yet still exhibits an identifiable signature across campaigns and years of activity.

Collectively, these tradecraft elements illustrate a highly disciplined adversary that prioritizes stealth, persistence, and low noise. By blending malicious activity into the fabric of normal system and network behavior, Lotus Blossom not only evaded detection during the Notepad++ campaign but also reaffirmed the group’s long-standing preference for covert intelligence collection over disruptive or noisy exploitation.

Victimology and Target Base

The victimology observed in the Notepad++ supply-chain campaign reinforces the assessment that this operation was tightly scoped and intelligence-driven, rather than opportunistic or indiscriminate. Public reporting and forensic analysis identify a small, carefully selected set of confirmed or strongly suspected victims, each of which aligns with Lotus Blossom’s historical targeting logic.

Among the confirmed or observed targets were a government organization in the Philippines, a financial institution in El Salvador, and an IT service provider in Vietnam. In addition, individual technical users were identified in Vietnam, Australia, and El Salvador. While the total number of victims was limited, the diversity of roles and sectors represented is significant. Each victim category provides a disproportionate intelligence return relative to the number of compromises required.

Geographic Pattern

The geographic distribution of victims is coherent and strategically consistent, rather than random. Southeast Asia remains the clear center of gravity, with Vietnam and the Philippines reflecting long-standing intelligence priorities for China. These countries sit at the intersection of contested maritime regions, regional security cooperation, and shifting diplomatic alignments, making them enduring targets for political, military, and economic intelligence collection.

Australia’s appearance in the victim set is also notable. As a Five Eyes intelligence partner, Australia represents a high-value target for insight into allied policy coordination, defense posture, and intelligence sharing frameworks. Even limited access to technical users in this environment can yield significant contextual intelligence.

The inclusion of El Salvador and, more broadly, Central America reflects a more recent but increasingly visible pattern. While not traditionally viewed as a primary cyber-espionage theater, the region functions as a financial and diplomatic intelligence gateway, offering visibility into international financial relationships, development financing, and external influence dynamics. The presence of both a financial institution and individual technical users in this geography suggests deliberate tasking rather than incidental spillover.

Sectoral Focus

Across all geographies, the sectoral composition of victims follows a consistent pattern. Targets cluster around government and policy-relevant institutions, financial systems and intermediaries, and IT and technical service providers. In the most recent phase of operations, particular emphasis is placed on developers and system administrators, individuals whose roles grant them privileged access and broad situational awareness within their organizations.

These targets function as access multipliers. A single compromised developer workstation or IT service provider can expose configuration data, credentials, network topologies, and downstream customer environments. Similarly, access to financial institutions or government agencies provides insight into policy deliberations, economic conditions, and institutional relationships that extend well beyond the compromised endpoint itself.

Taken together, the victimology of the Notepad++ campaign underscores Lotus Blossom’s disciplined targeting philosophy. The group consistently favors high-leverage roles and institutions that maximize intelligence value while minimizing operational exposure. The limited number of victims, combined with their strategic placement across regions and sectors, reinforces the conclusion that this campaign was designed to support sustained intelligence collection rather than broad access or immediate impact.

Why Notepad++?

Notepad++ occupies a uniquely advantageous position within technical environments, which helps explain its selection as a delivery vector in this campaign. The application is ubiquitous among technical users, including developers, system administrators, network engineers, and security analysts. In many organizations, it is installed by default on workstations used for infrastructure management, application development, and operational support. As a result, systems running Notepad++ often belong to users who possess elevated privileges, deep contextual knowledge of internal systems, and routine access to sensitive resources.

From an intelligence perspective, compromising such a tool offers an unusually high return on investment. Technical users commonly rely on Notepad++ to view, edit, and temporarily store credentials, configuration files, and infrastructure details in plaintext. Scripts and automation logic, used to manage servers, networks, cloud resources, and security controls, are frequently authored or reviewed within the editor. Access to these materials can reveal VPN endpoints, cloud service credentials, API keys, internal naming conventions, and operational workflows, providing insight far beyond the confines of a single endpoint. In many cases, these artifacts also reference institutional documentation, internal procedures, and architectural diagrams that are not otherwise externally visible.

Equally important is the trust relationship inherent in the software’s update mechanism. The Notepad++ updater is a routine, background process that users expect to run without intervention or scrutiny. By abusing this mechanism, the attackers were able to inherit the implicit trust that users and operating systems place in legitimate updates. This eliminated the need for phishing emails, malicious attachments, or other forms of overt social engineering that might raise suspicion or trigger defensive controls. The act of updating the software, normally a security-positive behavior, became the point of compromise.

In effect, the update process itself functioned as the lure. Rather than persuading users to take risky actions, the attackers embedded themselves in a workflow that users already regarded as safe and necessary. This inversion of trust reflects a sophisticated understanding of how technical users operate and underscores why Notepad++ was such an effective and strategically chosen access vector for an intelligence-focused campaign.

Political, Economic, Financial, and Espionage Motives

Intelligence Objectives and Strategic Rationale

The intelligence objectives underlying the Notepad++ supply-chain campaign align closely with long-standing state priorities, particularly in the political, economic, and strategic domains. The operation’s design and execution suggest a deliberate effort to build situational awareness rather than to achieve immediate operational effects.

Political Intelligence.

A central aim of the campaign appears to be sustained monitoring of government policy direction in Southeast Asia, a region where diplomatic alignment, security cooperation, and maritime disputes remain fluid. Access to technical users and institutions in this environment provides insight into policy deliberations, inter-agency coordination, and shifts in national posture that may not be visible through public channels. Closely related is the collection of intelligence on defense cooperation and maritime strategy, including how regional governments coordinate with one another and with external partners. The presence of targets linked to allied ecosystems further suggests an interest in alignment with U.S. and partner positions, offering indirect visibility into broader coalition dynamics and strategic intent.

Economic and Industrial Intelligence.

Beyond politics and defense, the campaign reflects a clear focus on economic and industrial intelligence. Access to financial institutions and technical service providers enables visibility into indicators of economic stability, capital flows, and institutional dependencies. Similarly, targeting entities involved in infrastructure and technology operations supports an understanding of modernization efforts, procurement cycles, and industrial capacity. Monitoring regulatory discussions and trade posture, often embedded in internal documentation, draft policies, and technical planning materials provides advanced awareness of economic decisions that can shape regional competitiveness and resilience.

Financial Intelligence (Non-Theft).

Notably, while financial institutions appear in the victim set, there is no evidence of fraud, theft, or fund diversion associated with this campaign. Instead, the activity is consistent with financial intelligence collection: mapping relationships between institutions, understanding transaction flows at a structural level, and identifying dependencies within national and regional financial systems. This distinction is important. The absence of monetization artifacts reinforces the assessment that the objective was insight, not profit, and places the activity firmly in the realm of state intelligence rather than cybercrime.

Strategic Espionage Doctrine.

Taken together, these objectives reflect a strategic espionage doctrine that prioritizes access over action, patience over disruption, and information dominance without escalation. The campaign was designed to quietly position the operator for long-term understanding, not to coerce, signal, or destabilize. By avoiding destructive activity and limiting exposure, the operation preserved freedom of action while minimizing diplomatic or political risk. In this sense, the Notepad++ supply-chain compromise represents intelligence preparation, laying the groundwork for informed decision-making rather than attempting to shape outcomes directly through cyber means.

Attribution Assessment

The totality of available evidence supports attribution of the Notepad++ supply-chain campaign, with moderate to high confidence, to Chinese actors, and specifically Lotus Blossom (G0030). This assessment is not based on any single indicator, but on the convergence of multiple independent factors that, taken together, form a coherent and internally consistent attribution picture.

First, the campaign aligns closely with Lotus Blossom’s longstanding geographic focus on Southeast Asia. Vietnam and the Philippines, both represented among confirmed or observed victims, have appeared repeatedly in the group’s historical operations over more than a decade. This persistent regional focus distinguishes Lotus Blossom from more globally oriented Chinese APT clusters and reinforces continuity with prior tasking rather than a one-off expansion by a different actor.

Second, the tooling lineage observed in this campaign is consistent with Lotus Blossom’s established development patterns. The deployment of Chrysalis, a previously undocumented backdoor, fits cleanly within the group’s historical reliance on bespoke implants such as Elise and Sagerunex. The design philosophy, custom code, low noise, and flexibility for long-term access, mirrors earlier Lotus Blossom tooling rather than the commodity frameworks or mixed criminal–espionage toolsets associated with other Chinese clusters.

Third, the selective nature of targeting and low infection counts strongly support this attribution. Despite access to an update mechanism capable of affecting a massive global user base, the attackers constrained delivery to a narrow set of high-value victims. This restraint is characteristic of Lotus Blossom’s operational model, which consistently favors precision and intelligence yield over scale. It contrasts sharply with campaigns conducted by other Chinese APTs that have demonstrated a willingness to pursue broad, high-volume access when aligned with their objectives.

Fourth, the campaign demonstrates mature operational security and infrastructure discipline. The use of infrastructure-level compromise, API-style command-and-control endpoints, low-frequency encrypted communications, and careful infrastructure rotation without abandoning recognizable campaign grammar reflects a level of planning and tradecraft that Lotus Blossom has exhibited repeatedly in past operations. These elements point to an actor experienced in sustaining access over long periods while minimizing detection and attribution risk.

Finally, the victimology aligns closely with historical Lotus Blossom target sets. Government entities, financial institutions used for intelligence rather than theft, IT service providers, and privileged technical users all fall squarely within the group’s established targeting preferences. This continuity in “who” is targeted is as significant as the technical “how,” reinforcing the conclusion that the campaign represents an evolution of an existing program rather than the work of a different group adopting similar techniques.

When weighed collectively, these factors form a strong attribution case. While other Chinese APT clusters share individual characteristics, such as supply-chain access, custom tooling, or regional interest, no other known group fits the full combination of geography, tradecraft, restraint, tooling lineage, and victimology as closely as Lotus Blossom.

Defensive and Strategic Implications

The Notepad++ supply-chain compromise carries implications that extend well beyond this single incident, both for network defenders and for policymakers concerned with national and economic security. The campaign highlights structural weaknesses in how trust is established, maintained, and defended in modern software ecosystems.

Implications for Defenders.

First, the operation underscores that open-source software is not inherently low risk. Transparency of code does not automatically translate into security when the distribution and update mechanisms sit outside the codebase itself. In this case, the source remained intact while the delivery path was subverted, demonstrating that trust can be undermined upstream of any code review or integrity check. Defenders should treat open-source tools with the same rigor applied to proprietary software, particularly where update mechanisms rely on third-party infrastructure.

Second, the campaign highlights updating infrastructure as a critical attack surface. Software updaters are privileged by design, frequently allowed through endpoint and network controls, and trusted to execute code without user scrutiny. When compromised, they provide an attacker with a reliable and stealthy execution path. Securing update pipelines through stronger integrity validation, monitoring of anomalous update behavior, and defense-in-depth around hosting and distribution, is therefore as important as securing the software itself.

Third, the targeting logic reinforces that developer and administrator workstations are among the highest-value espionage targets in modern environments. These systems often aggregate credentials, scripts, configuration files, and architectural knowledge that can expose entire networks or multiple downstream organizations. Traditional security models that focus primarily on servers or perimeter assets risk overlooking these high-leverage endpoints.

Finally, the campaign demonstrates the limits of indicator-driven defense. Behavioral detection and contextual analysis are more reliable than static IOCs against a patient, low-noise adversary. Infrastructure rotation, bespoke tooling, and selective targeting render simple blocklists and hash-based detection insufficient. Defenders are better served by focusing on anomalous process chains, unexpected updater behavior, unusual DLL loading patterns, and deviations in network communication profiles such as perimeter DNS or packet inspection, even when individual indicators appear benign in isolation.

Implications for Policy and National Security.

At a strategic level, the campaign illustrates that supply-chain compromise has become a primary vector for state-level espionage. As articulated in the work of Jian Tan on software supply-chain trust, capable actors increasingly avoid the cost of penetrating targets individually and instead position themselves inside trusted ecosystems that provide scalable, repeatable access to high-value users. This shift complicates deterrence and response, as such compromises can persist undetected for extended periods and propagate across multiple sectors simultaneously through a single poisoned trust relationship.

The victimology also highlights that smaller and mid-sized states are frequently targeted as intelligence gateways. Access to institutions in these countries can yield disproportionate insight into regional dynamics, allied relationships, and international financial or diplomatic flows. This reality challenges assumptions that only major powers or headline geopolitical rivals face sustained cyber-espionage pressure.

Finally, the incident reinforces that trust relationships within software ecosystems are now contested terrain. Developers, maintainers, hosting providers, and users all participate in chains of trust that adversaries actively seek to exploit. Protecting these ecosystems is both a technical and strategic challenge, requiring coordination between private industry, open-source communities, and governments to harden shared infrastructure without undermining the openness and collaboration that make these ecosystems valuable in the first place.

Taken together, these implications point to a future in which defending against espionage is less about patching individual vulnerabilities and more about protecting trust itself, in software, in infrastructure, and in the relationships that bind modern digital systems together.

Outlook and Forward Assessment

Looking ahead, the patterns observed in the Notepad++ campaign and in Lotus Blossom’s historical operations provide a useful basis for anticipating how this actor is likely to operate in the near to medium term. The group’s evolution has been incremental rather than abrupt, suggesting continuity of mission and tradecraft rather than experimentation for its own sake.

Likely Future Activity

Lotus Blossom is likely to continue targeting developer and administrator tooling, particularly applications and platforms that are widely deployed in technical environments and implicitly trusted by their users. These tools offer consistent access to privileged contexts and aggregate high-value information such as credentials, automation scripts, configuration data, and architectural documentation. As long as developers and administrators remain central to modern infrastructure operations, they will remain attractive espionage targets.

Geographically, future activity is expected to involve measured expansion into adjacent regions with strategic relevance, rather than a dramatic shift toward global saturation. Southeast Asia will almost certainly remain the core theater, but selective operations in regions that function as diplomatic, economic, or intelligence gateways, similar to the activity observed in Oceania and Central America, are likely to continue. Such expansion reflects evolving intelligence requirements rather than a change in operational philosophy.

From a delivery perspective, the group’s demonstrated success with the Notepad++ compromise strongly suggests an ongoing preference for supply-chain and trust-based access. Compromising distribution infrastructure, update mechanisms, or widely trusted platforms reduces reliance on social engineering and increases the likelihood of execution in high-trust environments. This model is efficient, stealthy, and well aligned with Lotus Blossom’s emphasis on low-noise, long-term access.

Warning Indicators

Defenders should be alert to a set of warning indicators that are subtle in isolation but meaningful in combination. Selective update anomalies, where only a small subset of systems receive unexpected update behavior, may indicate upstream manipulation rather than benign error. Similarly, low-volume, API-style beaconing that blends into normal HTTPS traffic can signal command-and-control activity designed to evade traditional network detection.

Another important indicator is the compromise of “boring but trusted” tools: utilities that are widely used, rarely scrutinized, and considered operationally mundane. These applications often sit outside the focus of security monitoring precisely because they are perceived as low risk, making them ideal vehicles for trust exploitation. Finally, defenders should treat long dwell times without overt impact as a potential red flag rather than a sign of benign activity. In Lotus Blossom’s operating model, the absence of disruption is often an intentional feature, not an accident.

Taken together, these indicators point to an adversary that values patience, precision, and invisibility. Future campaigns are likely to look unremarkable at first glance, blending into routine operational noise. Recognizing and responding to them will depend less on spotting dramatic events and more on detecting subtle deviations in how trusted systems behave over time.

Bottom-Line Judgment

The Notepad++ supply-chain campaign is a textbook example of modern Chinese state-aligned cyber-espionage, optimized for discretion, persistence, and strategic intelligence collection.

Lotus Blossom remains one of China’s most quietly effective APTs, less visible than headline actors, but deeply embedded in regional intelligence operations.

Confidence Ratings

  • APT involvement: High
  • Espionage motive: High
  • Lotus Blossom attribution: Moderate–High

Appendix A: Indicators of Compromise (IOCs)

Actor: Lotus Blossom (G0030)
Campaign: Notepad++ Supply-Chain Compromise (2025–2026)

Analyst note: This appendix consolidates publicly reported and analytically derived IOCs associated with Lotus Blossom and the Notepad++ supply-chain campaign. The list is intended for threat hunting and contextual correlation, not as a stand-alone blocklist. The actor demonstrates frequent infrastructure rotation, selective delivery, and low-noise operations; therefore, behavioral correlation remains essential.

A.1 Campaign-Specific Network IOCs (Notepad++ Supply-Chain)

Command-and-Control Domains (observed in reporting):

  • cdncheck[.]it[.]com
  • wiresguard[.]com
  • Skycloudcenter[.]com

cdncheck.it.com

  • This domain has been observed as a command-and-control endpoint used by malicious payloads delivered in the Notepad++ supply-chain campaign; Cobalt Strike Beacons were configured to communicate with it, and attackers used paths like /api/update/v1 and /api/FileUpload/submit for C2 traffic. 
  • It is deployed in multiple infection chains as a C2 domain, not a legitimate service; security analysts note its inclusion in IoCs tied to the Notepad++ compromise. 
  • There is no public indication that cdncheck.it.com is associated with any legitimate “cdncheck” project such as the ProjectDiscovery tool named cdncheck (which is an open-source asset scanning tool). The similarity in names appears coincidental. 

Summary: Used as attacker-controlled infrastructure; no publicly known legitimate service.

2. wiresguard.com (referred to in C2 contexts)

  • The domain api.wiresguard.com appears in Notepad++ campaign IoCs collected by security researchers—Beacons and API paths like /update/v1, /api/FileUpload/submit, and /api/getInfo/v1 were observed being used by Cobalt Strike implants and other payloads. 
  • There is no evidence from public OSINT that the domain is linked to the WireGuard VPN project (the legitimate technology is spelled WireGuard). It is widely assessed to be an attacker-controlled domain imitating a plausible service name to blend into developer traffic. 
  • Analysts treat this domain as part of malicious infrastructure rather than a trusted service provider.

Summary: Likely malicious C2 domain mimicking a benign service name; no legitimate affiliation found in open OSINT.

3. skycloudcenter.com

  • The subdomain api.skycloudcenter.com is identified in multiple IoC lists from incident analysis—it appears in URLs such as /a/chat/s/{GUID} used by the Chrysalis backdoor for encrypted communications. 
  • Reporting notes that this domain is part of the API-style command-and-control infrastructure rather than a known cloud provider or mainstream SaaS platform. 
  • There is no clear legitimate service tied to this domain in publicly indexed OSINT; its naming seems intended to resemble a cloud service but lacks authoritative footprint (no major product, published service, or corporate identity in searchable records).

Summary: Appears exclusively as attacker infrastructure used for backdoor C2; no confirmed legitimate service.

Associated IP Addresses (observed during campaign window):

  • 45.77.31[.]210
  • 59.110.7[.]32:8880
  • 124.222.137[.]114:9999

45.77.31[.]210 (HTTPS)

Role in campaign: Hosted second-stage Cobalt Strike Beacon shellcode and exposed API-style C2 endpoints used by the Beacon (GET/POST patterns). (Securelist)

Observed paths / IOCs:

  • https://45.77.31[.]210/users/admin (Beacon shellcode retrieval) (Securelist)
  • https://45.77.31[.]210/api/update/v1 (Beacon HTTP-GET) (Securelist)
  • https://45.77.31[.]210/api/FileUpload/submit (Beacon HTTP-POST) (Securelist)

Hosting / network ownership (OSINT):

  • rDNS indicates Vultr-hosted infrastructure (e.g., 45.77.31.210.vultrusercontent.com). (IPinfo)
  • Vultr’s public ASN is AS20473 (The Constant Company). (IPinfo)

Analytic note: Securelist describes a later shift where the same “grammar” (paths, updater chain) persists while delivery/C2 pivots toward domains (e.g., cdncheck[.]it[.]com)—classic “rotate infra, keep protocol shape” tradecraft. (Securelist)

59.110.7[.]32:8880 (HTTP)

Role in campaign: Hosted a Cobalt Strike Beacon and implemented API-like endpoints for GET/POST comms (directly referenced as part of the Notepad++ supply-chain operation telemetry set). (Securelist)

Observed paths / IOCs:

  • http://59.110.7[.]32:8880/uffhxpSy (Beacon staging/hosting URL) (Rapid7)
  • http://59.110.7[.]32:8880/api/getBasicInfo/v1 (Beacon HTTP-GET) (Rapid7)
  • http://59.110.7[.]32:8880/api/Metadata/submit (Beacon HTTP-POST) (Rapid7)

Hosting / network ownership (OSINT):

  • Mapped to AS37963 (Hangzhou Alibaba Advertising Co., Ltd.), i.e., Alibaba Cloud–linked hosting. (IPinfo)
  • Also appears in Abuse.ch ecosystem tracking as malicious-host infrastructure (additional corroboration signal, not attribution by itself). (urlhaus.abuse.ch)

124.222.137[.]114:9999 (HTTP)

Role in campaign: Hosted a Cobalt Strike Beacon with the same “API façade” pattern (update/status/info submission), and is listed by both Securelist (campaign IOC list) and Rapid7 (Chrysalis/related tooling context). (Securelist)

Observed paths / IOCs:

  • http://124.222.137[.]114:9999/3yZR31VK (Beacon staging/hosting URL) (Rapid7)
  • http://124.222.137[.]114:9999/api/updateStatus/v1 (Beacon HTTP-GET) (Rapid7)
  • http://124.222.137[.]114:9999/api/Info/submit (Beacon HTTP-POST) (Rapid7)

Hosting / network ownership (OSINT):

  • The 124.222.137.0/24 netblock is shown as AS45090 (Shenzhen Tencent Computer Systems Company Limited), i.e., Tencent Cloud–linked hosting. (IPinfo)

What these three IPs imply (campaign-level assessment)

  • All three are consistent with the campaign’s low-volume, high-control delivery model: they’re not mass-distribution nodes; they’re purpose-built staging/C2 with “benign enterprise API” URL shapes (/api/*/v1, /submit, etc.). (Securelist)
  • The hosting mix (Vultr + Alibaba Cloud + Tencent Cloud) is consistent with infrastructure agility and cost-effective rotation without changing the operational “grammar” (paths, beacon profile style). (Securelist)

C2 Characteristics:

  • HTTPS-based communication
  • API-style URI paths (update/telemetry-like)
  • Low-frequency beaconing
  • Small request/response payloads
  • Consistent URI grammar across rotating domains

Appendix A.2 (Expanded): Malware & Tooling IOCs

Actor: Lotus Blossom (G0030)
Campaign: Notepad++ Supply-Chain Compromise (2025–2026)

A.2.1 Custom Backdoors / Implants

1. Chrysalis – Custom Backdoor (Campaign-specific)

  • Description: A previously undocumented custom backdoor deployed via malicious Notepad++ updates. It’s feature-rich, implements structured C2, and uses advanced loader obfuscation and API hashing techniques. It was delivered after DLL sideloading via renamed Bitdefender binaries and NSIS installer abuse.
  • Observed in: Multiple security reports on the Notepad++ supply-chain compromise confirm Chrysalis as the primary bespoke implant in the most recent execution chain. Chrysalis replaces or augments Cobalt Strike payloads in some infection conduits. (Rapid7)
Sample Name or Artifact Type Observed Role Notes / Citation
update.exe NSIS installer Initial dropper for backdoor Rapid7 analysis discussed multiple NSIS bundles delivering Chrysalis components. (Rapid7)
BluetoothService.exe Legitimate loader renamed DLL sideload host Rapid7 cites the renamed Bitdefender utility abused for sideloading log.dll. (Help Net Security)
log.dll Loader DLL Decrypts/executes the backdoor Rapid7 notes that log.dll loads and decrypts Chrysalis. (Help Net Security)

Sample Hash Indicators:
(These are candidate hashes observed in threat-hunting discussions associated with Chrysalis–type activity; use with contextual correlation)

Notes: Chrysalis is associated with multi-stage loading and encrypted communications and is explicitly tied to the Notepad++ compromise in Rapid7 technical analysis. (Rapid7)

2. Sagerunex – Historical Lotus Blossom Backdoor Family

  • Description: A long-standing backdoor family consistently linked with Lotus Blossom operations in Southeast Asia prior to the Notepad++ incident. Sagerunex appears in multiple variants over years and is part of the group’s standard espionage toolkit. (Picus Security)
  • Behavior: Often installed as a Windows service or registry persistence component; connects to C2 via encrypted or tunneled channels; used for long-term access and data exfiltration. (Picus Security)

Sample Hash Indicators:
(Historical Sagerunex variants are well documented in vendor telemetry but specific public hashes for this campaign have not been widely published. The below hashes are examples drawn from public threat intelligence discussions tied to earlier variants.)

Notes: Sagerunex’s variants may not be directly linked to the Notepad++ campaign but represent the broader Lotus Blossom backdoor lineage. (Picus Security)

3. Elise – Early Custom Backdoor (Historic, Pre-Campaign)

  • Description: An older custom backdoor associated with early Lotus Blossom campaigns (circa 2012–2015), widely referenced in historic vendor analysis. (Picus Security)
  • Behavior: Provided persistence and remote access, often delivered via spear-phishing lures targeting government and defense institutions.

Public Hashes:
There are no widely published hashes specifically tied to Elise in the context of the Notepad++ campaign. Historical Elise variants appear in older vendor IOC sets but are not directly cited in current Notepad++ analyses.

Notes: Elise remains part of the Lotus Blossom malware ecosystem but is not directly observed in the Notepad++ supply-chain campaign in available public reporting. (Picus Security)

A.2.2 Ancillary / Supporting Artifacts

Loaders / Execution Components Observed:

  • NSIS installer artifacts (e.g., update.exe) — utilized to bootstrap malicious payload delivery. (Rapid7)
  • Renamed legitimate utilities (e.g., Bitdefender Submission Wizard / BluetoothService.exe) — used for DLL sideloading of malicious components. (Help Net Security)

Note on Hash Interpretation:
Several hashes circulating in public hunting forums are included above for Chrysalis and Sagerunex, but these should be used only in conjunction with behavioral and contextual evidence (e.g., execution lineage, process ancestry, file paths, registry persistence) due to the non-global nature of the Notepad++ campaign.

A.2.3 Confidence Levels

Malware/Tool Campaign-Relevant Hash Availability
Chrysalis Backdoor High Partial public hunting hashes available
Sagerunex Backdoor Moderate (historical) Yes (historical lists)
Elise Backdoor Low (historical) Limited public hashes

Post-Exploitation Frameworks:

  • Cobalt Strike–based implants (selective deployment)

Execution & Loading Techniques:

  • DLL sideloading via legitimate executables
  • Custom loaders responsible for decrypting/unpacking final payloads

A.3 File System Artifacts

Observed / Common Staging Locations:

  • %APPDATA%\ProShow\load
  • %APPDATA%\Adobe\Scripts\alien.ini
  • %APPDATA%\Bluetooth\BluetoothService\

General Patterns:

  • Use of user-writable directories
  • Non-descriptive filenames
  • Configuration files masquerading as benign application data
  • Loader and payload separation

A.4 Process & Execution Indicators

Suspicious Parent/Child Relationships:

  • GUP.exe (WinGUp updater) spawning non-standard installer binaries
  • Legitimate signed executables loading unsigned or anomalous DLLs

Reconnaissance Commands Observed:

  • whoami
  • tasklist
  • System and environment enumeration commands
  • Network configuration discovery

A.5 Persistence Indicators

Persistence Techniques (Observed Historically):

  • Windows services created for backdoor execution
  • Registry modification for auto-start
  • DLL search-order hijacking
  • Loader-based persistence chained from user context

A.6 Infrastructure & Operational Patterns (Campaign Grammar)

These are higher-order IOCs useful for hunting beyond static indicators:

  • API-like C2 endpoints mimicking update or cloud services
  • Infrastructure rotation without change in URI structure
  • Selective delivery (only a subset of update requests redirected)
  • Long dwell times with no visible disruption
  • Absence of ransomware, cryptomining, or fraud tooling

A.7 Historical Lotus Blossom Targeting Context (Non-Exhaustive)

Geographies Recurrently Associated with Activity:

  • Southeast Asia (Vietnam, Philippines, Indonesia)
  • East Asia (Hong Kong, Taiwan)
  • Oceania (Australia)
  • Central America (El Salvador)

Target Entity Types:

  • Government ministries and agencies
  • Defense-adjacent organizations
  • Telecommunications providers
  • Financial institutions (intelligence, not theft)
  • IT service providers / MSPs
  • Developers and system administrators

A.8 Defensive Guidance for IOC Use

  • Do not rely solely on blocklists. Many IOCs are short-lived.
  • Correlate with behavioral indicators:
    • Unexpected updater behavior
    • DLL sideloading chains
    • API-like HTTPS beaconing
    • Long-term low-noise persistence
  • Treat developer and admin endpoints as high-priority hunt targets.
  • Monitor update infrastructure and third-party hosting dependencies.

A.9 Confidence Statement

The IOCs listed above align with public vendor reporting and multi-source analysis of Lotus Blossom activity. While individual indicators may overlap with other actors or benign infrastructure, the combined presence of these IOCs with Lotus Blossom tradecraft patterns provides a strong basis for attribution and threat-hunting.

Appendix B: Sources and Citations

This appendix consolidates all primary reporting, technical analyses, and authoritative reference material used to support the assessments, attribution, and narrative in this report. Sources are grouped by function (technical analysis, media reporting, and reference frameworks) to allow readers to distinguish between direct forensic evidence, journalistic corroboration, and contextual intelligence baselines.

B.1 Primary Technical Analysis and Vendor Research

These sources form the core evidentiary basis for the campaign analysis, infection chains, victimology, and tradecraft assessment.

  1. Kaspersky Securelist
    “Notepad++ supply-chain attack”
    Comprehensive technical analysis detailing infection chains, infrastructure abuse, victim categories, and malware behavior.
    https://securelist.com/notepad-supply-chain-attack/118708/
  2. Kaspersky Press and Research Materials
    Supplemental summaries and clarifications derived from Securelist reporting and telemetry.
    https://www.kaspersky.com/about/press-releases
  3. MITRE ATT&CK – Lotus Blossom (G0030)
    Authoritative reference for historical tooling, targeting patterns, and known techniques associated with Lotus Blossom.
    https://attack.mitre.org/groups/G0030/

B.2 Media and Independent Reporting

These sources provide external corroboration, contextual framing, and confirmation of selectivity, attribution hypotheses, and geopolitical relevance.

  1. Ars Technica
    “Notepad++ updater was compromised for 6 months in supply-chain attack”
    Reporting on duration, infrastructure compromise, and selective delivery.
    https://arstechnica.com/security/2026/02/notepad-updater-was-compromised-for-6-months-in-supply-chain-attack/
  2. Reuters
    “Popular open-source coding application targeted in Chinese-linked supply-chain attack”
    Independent confirmation of selective targeting, suspected Chinese state linkage, and expert commentary.
    https://www.reuters.com/technology/popular-open-source-coding-application-targeted-chinese-linked-supply-chain-2026-02-02/
  3. Tom’s Hardware
    “Notepad++ update server hijacked in targeted attacks”
    Coverage of update infrastructure compromise and threat actor speculation.
    https://www.tomshardware.com/tech-industry/cyber-security/notepad-update-server-hijacked-in-targeted-attacks
  4. TechRadar Pro
    “Notepad++ hit by suspected Chinese state-sponsored hackers – what we know so far”
    Summary reporting and confirmation of supply-chain vector and victim selectivity.
    https://www.techradar.com/pro/security/notepad-hit-by-suspected-chinese-state-sponsored-hackers-heres-what-we-know-so-far

B.3 Tradecraft, Techniques, and Supporting Intelligence

These sources provide background validation for techniques observed in the campaign and historical Lotus Blossom operations.

  1. Cisco Talos Intelligence
    “Lotus Blossom espionage group”
    Historical overview of Lotus Blossom tooling, C2 behavior, and targeting.
    https://blog.talosintelligence.com/lotus-blossom-espionage-group/
  2. Security Affairs
    Coverage of DLL sideloading, infrastructure compromise, and China-linked APT analysis relevant to the Notepad++ campaign.
    https://securityaffairs.com/
  3. Living-off-the-Land (LOTL) Reference
    Background on LOTL techniques leveraged by advanced threat actors.
    https://www.kiteworks.com/risk-compliance-glossary/living-off-the-land-attacks/

B.4 Attribution and Analytical Confidence Notes

  • Attribution to Lotus Blossom (G0030) is based on multi-factor correlation, including:
    • Geographic and sectoral victimology
    • Custom malware lineage (Elise → Sagerunex → Chrysalis)
    • Operational selectivity and restraint
    • Infrastructure and C2 grammar continuity
  • No single source alone asserts attribution with certainty; confidence derives from convergent analysis across multiple independent sources.

B.5 Citation Handling Notes

  • No specific victim organizations are named in publicly available technical reporting; all victim references are sector- and country-level, consistent with source disclosures.
  • Indicators of Compromise (Appendix A) are drawn from public reporting and are time-bound and perishable.
  • This appendix reflects sources available as of February 2026; subsequent disclosures may refine or expand attribution and victimology.
Learn More
Research
THE KNOWNSEC LEAK: Yet Another Leak of China’s Contractor-Driven Cyber-Espionage Ecosystem

Leaked Knownsec documents reveal China’s cyberespionage ecosystem. Analyze TargetDB, GhostX, and 404 Lab’s role in global reconnaissance and critical infrastructure targeting.

EXECUTIVE SUMMARY

In November of 2025, an allegedly massive leak of data from Chinese company “KnownSec” was posted to a github account. The initial leak was covered by Wired Magazine, and a few other outlets. The leak has since been pulled off of Github and downloaded by very few, and of those few who gained access, only one uploaded 65 documents as a primer to the leak elsewhere for others to see. DTI was able to get the 65 document images and this report is derived from this slice of a much larger leak that is out there but not available.

On December 31 2025, platform and threat intelligence company Resecurity published an excellent analysis of the full leak. As we’ve been working through the 60+ available screenshots from the leak since early November, Resecurity’s post provides additional context in a few areas, especially targeting, that compliment the depth to which we analyzed Knownsec’s technical capabilities.

Ostensibly, KnownSec appeared to be just another security company, but this is only a half truth. In reality, like other reports we have written on Chinese firms, it has a shadow organization that works for the PLA, MSS, and the organs of the Chinese security state. This leak exposes a state-aligned cyber contractor that operates far beyond the role of a typical cybersecurity vendor. Its internal documents, product manuals, and data repositories show a company engineered to support Chinese national security, intelligence, and military objectives. Tools like ZoomEye and the Critical Infrastructure Target Library give China a global reconnaissance system that catalogs millions of foreign IPs, domains, and organizations mapped by sector, geography, and strategic value. Massive datasets containing real names, ID numbers, mobile phones, emails, and credentials allow Knownsec and its government clients to correlate infrastructure with people, enabling rapid deanonymization, targeting, and social engineering.

On top of this data foundation, Knownsec’s offensive products; GhostX, Un-Mail, and Passive Radar purport to provide a full intrusion and surveillance pipeline. GhostX delivers browser exploitation, routing manipulation, credential theft, and endpoint monitoring. Un-Mail enables covert takeover and continuous exfiltration of email accounts across major global providers. Passive Radar ingests PCAP data via local uploads, FTP, or SSH to reconstruct internal network topologies, user communication patterns, and service inventories. These tools work together to support long-term access, DNS hijack, admin takeover, and infrastructure control across foreign government, telecom, financial, and energy networks.

Organizational charts, customer lists, and internal briefings reveal Knownsec’s primary clients as Public Security Bureaus, defense research institutes, and likely the MSS, positioning it within China’s industrialized cyber-operations ecosystem. Its products are marketed directly to law enforcement and military customers, with teams explicitly labeled for “military industry,” “intelligence,” and “public-security support.” The leaked data shows a vertically integrated espionage stack for reconnaissance, exploitation, collection, and persistence, designed for both domestic surveillance and foreign intelligence operations, making Knownsec a central enabler of China’s modern cyber strategy.

Background

Knownsec (知道创宇), headquartered in Beijing, presents itself to the outside world as a familiar figure in the Chinese cybersecurity landscape, a company selling vulnerability assessments, penetration testing, and defensive solutions. It has long been framed as one of the country’s “white-hat” pillars, a firm dedicated to patching security gaps and strengthening networks. But the leaked internal documents, product manuals, work breakdown structure (WBS) project sheets, personnel directories, and vast infrastructure datasets tell a much more complex and far more consequential story. Beneath its public branding, Knownsec operates as an offensive intelligence contractor whose day-to-day work aligns directly with the operational needs of China’s security and military apparatus.

In practice, Knownsec functions within a tight constellation of state-aligned cyber contractors, a network that includes outfits like 404 Lab (internal to Knownsec) , Qi-An-Xin, Venustech, and i-SOON (安洵). These entities form a parallel ecosystem to China’s formal intelligence services, separate on paper, but woven into the broader machinery of state surveillance and cyberespionage. Together, they develop and maintain the tools, datasets, and capabilities required for large-scale identity tracking, offensive reconnaissance, infrastructure enumeration, and targeted intrusion. What sets Knownsec apart within this constellation is the degree of integration seen across its product lines: it does not merely produce one tool or one dataset, but rather an entire operational pipeline spanning discovery, exploitation, reconnaissance, persistence, and human-layer correlation.

The leaked materials reveal that Knownsec maintains some of the most extensive foreign targeting datasets yet seen in a contractor leak, covering Taiwan, Japan, South Korea, India, and multiple Western nations. Its clients include Public Security Bureaus at the provincial and national levels, defense research institutes, and intelligence-adjacent technical units. The company’s organizational charts and internal communications make clear that these relationships are not incidental; they are foundational to Knownsec’s business model and technical direction. In this light, Knownsec emerges not as a private security firm in the Western sense, but as a core node in China’s contractor-driven cyber state, a strategic architecture in which commercial entities serve as the research, development, and operational arms of state cyber power.

ACTOR TAXONOMY

Organizational Structure

Knownsec’s internal architecture per this dump, resembles less a commercial technology company and far more a defense integrator calibrated to state needs. The organizational hierarchy is sharply defined, layered, and optimized for the production of offensive cyber capabilities. Each division has a narrowly tailored mandate that fits into a larger operational machine, an arrangement that mirrors the compartmentalization and task specialization typical of state-sponsored research institutes and weapons contractors.

At the technical core is the 404 Security Lab (404 实验室), a unit responsible for offensive research, exploitation development, and deanonymization, including stewardship of the GhostX tooling family. This is the engine room where browser exploits, network manipulation modules, and deanonymization workflows are built. Surrounding it is the Product Technology R&D Center, which transforms raw offensive ideas into stable, deployable products (most notably Passive Radar), protocol-analysis frameworks, and related reconnaissance systems. Feeding these tools is the Data Business Division, which curates massive datasets, foreign breach archives, and credential repositories, effectively forming the human intelligence layer of Knownsec’s cyber operations. Where state-aligned priorities shift toward military readiness or battlefield cyber support, the Military Products Division (军工) adapts and reconfigures Knownsec’s core technologies – ZoomEye, Radar, GhostX – into militarized variants suitable for defense research institutes and specialized units. Meanwhile, the ZoomEye Team maintains the company’s most publicly recognizable asset: a continuous internet-wide scanning and exposure fingerprinting platform. Once all these tools are built, the Beijing Testing Group ensures they meet stability and operational-readiness requirements before deployment to customers.

This hierarchy fractures into distinct functional strata. At the strategic layer, executive leadership and cost-center directors coordinate funding, long-term planning, and alignment with state-customer requirements. The operational layer, project managers, planners, and supervisors – turns those directives into executable work, assigning tasks across teams and ensuring compliance with delivery timelines. The technical layer comprises exploit developers, reverse engineers, protocol analysts, “radar specialists” (aka those working with the platform dealing with internet scale sensing/detection), and data scientists, the hands-on specialists who build Knownsec’s offensive capabilities. Beneath them, the support layer handles content review, security inspection, documentation, and QA critical roles that ensure continuity and polish across the toolchain.

Viewed holistically, the internal structure mirrors the logic of a Chinese cyber-weapons manufacturer: program management offices overseeing multi-year development tracks; governance systems controlling scope, deliverables, and interdepartmental dependencies; and specialized teams that collaborate, integrate, and refine capabilities in parallel. The result is not a loose assemblage of researchers, but a multi-team, multi-layered production line, where offensive tools move from concept to deployment with the discipline and scale of an industrial operation aligned to national strategic priorities.

Org Structure per leak 2025

Role Characterization

Knownsec’s internal personnel structure forms a tiered hierarchy that resembles the command-and-control model of a state-linked defense contractor rather than a commercial cybersecurity vendor. At the top sits the strategic layer, composed of executive leadership, business-unit heads, and cost-center directors who set long-term priorities, allocate resources, and ensure alignment with the missions of Public Security Bureaus, military research institutes, and other government stakeholders. Their role is not merely administrative; they define the operational direction of Knownsec’s offensive tooling, selecting which capabilities to develop, which foreign networks to map, and which datasets to prioritize for correlation.

Beneath them churns the operational layer, populated by project managers, planners, and supervisors responsible for translating strategic objectives into actionable engineering programs. These individuals oversee WBS tasking, cross-team coordination, and delivery timelines. They determine how GhostX (“GhostX Framework” offensive cyber platform) modules integrate with Un-Mail (email interception tool), how Passive Radar ingests or parses PCAP data, and how TargetDB updates synchronize with ZoomEye (search engine) output. In effect, they are the connective tissue that binds Knownsec’s sprawling toolchain into a coherent, predictable development pipeline.

The technical layer of exploit developers, radar engineers, data analysts, infrastructure specialists is the skilled workforce that turns those plans into operational capabilities. These teams build the browser exploitation chains, protocol-analysis engines, deanonymization classifiers, and dataset-correlation tools that make Knownsec’s products function as integrated intrusion systems. Supporting them is a broad support layer of content reviewers, security inspectors, and test engineers who ensure data quality, operational safety, and readiness for customer deployment. This division of labor reinforces Knownsec’s resemblance to a Chinese cyber defense integrator, featuring programmatic control structures, specialized technical teams, and multi-layer orchestration designed to reliably produce offensive cyber capabilities at scale.

FULL CAPABILITY ANALYSIS

Global Reconnaissance Layer

Knownsec’s offensive operations begin with a global reconnaissance layer, a foundation built on visibility rather than exploitation. At the heart of this layer is ZoomEye, the company’s internet-wide scanning and fingerprinting platform. Externally marketed as a security research tool, ZoomEye in practice functions as a persistent intelligence sensor grid, one capable of mapping the exposed surfaces of entire nations. Unlike Shodan or FOFA, which rely on hybrid community indexing and slower crawl cycles, ZoomEye conducts full IPv4-space scanning, generating a continuously refreshed portrait of devices, services, and vulnerabilities across the global internet.

ZoomEye’s detection capabilities are unusually granular. Its internal documentation highlights a library of 40,000+ component fingerprints, allowing it to identify not just common servers but also specialized firewalls, industrial controllers, VPN concentrators, and software versions critical for exploitation targeting. The platform recrawls its indexed universe every 7–10 days, making its data nearly real-time, a crucial requirement for Chinese security organs that depend on freshness for both censorship enforcement and foreign operations. Every newly exposed port, misconfigured appliance, or unpatched system becomes visible to Knownsec’s analysts before many national CERTs are even aware of the shift.

The true power of ZoomEye emerges in its integration with Knownsec’s TargetDB (关基目标库: Key Target Library), a classified-style infrastructure database that cross-references ZoomEye results with sector, geographic, and organizational metadata. Raw IPs and banners from ZoomEye become tagged entries in a structured intelligence map identifying which systems belong to ministries, power companies, telecom operators, banks, or military units. In this way, ZoomEye doesn’t merely scan the internet; it prioritizes it, funneling raw exposure intelligence directly into China’s national-level targeting workflows.

ZoomEye

A global cyberspace search engine equivalent to Shodan/FOFA but with:

  • Full IPv4-space scanning
  • 40,000+ component fingerprints
  • Rapid recrawl cycles (7–10 days)
  • Cross-integration with TargetDB
Zoom Eye aka “Eye of Zhong Kui” (Zhong Kui is a mythological demon-hunter; the name implies threat detection and purification.)

TargetDB (关基目标库)

Knownsec’s TargetDB (关基目标库) is the analytical backbone of its reconnaissance capability, an immense, curated intelligence repository that transforms raw internet data into a structured map of global critical infrastructure. Far more than a simple asset index, TargetDB resembles a state-run targeting platform: a system designed to catalog, classify, and prioritize foreign networks according to strategic value. The scale alone is staggering. Internal documentation lists 24,241 organizations, 378,942,040 IP addresses, and 3,482,468 domains, all tagged with metadata that places them within specific industries, national sectors, and operational categories. These entries span 26 geographic regions, covering not only China’s immediate neighbors but also major economies and political rivals across Asia, Europe, and the West.

What gives TargetDB its strategic potency is the precision of its annotations. Each organization and network block is mapped to sector designations such as military, military-industrial, government ministries, telecom operators, energy providers, financial institutions, transportation networks, media outlets, and educational institutions. This transforms an anonymous IP range into a clearly identified target: a ministry of foreign affairs server in Tokyo, a regional power-grid node in Kaohsiung, a financial-trading gateway in Mumbai, or a satellite uplink belonging to a Korean telecom. The database does not simply list assets; it assigns them meaning, aligning infrastructure with strategic objectives and intelligence requirements.

In practice, TargetDB functions as a foreign-target prioritization engine, allowing Chinese state clients to focus their operations on the most consequential systems. When paired with ZoomEye’s continuous scanning, TargetDB becomes a living intelligence reference that highlights newly exposed systems belonging to sensitive entities. This fusion of raw exposure data with organizational and geopolitical context gives Knownsec and its customers a ready-made blueprint for cyber campaigns identifying who matters, where they are located, and precisely which services are vulnerable at any given moment.

This database is a foreign-target prioritization engine.

The Critical Infrastructure Target Library contains:

  • 24,241 organizations
  • 378,942,040 classified IPs
  • 3,482,468 domains
  • Sector mappings across 26 geographic regions

It annotates:

  • Military units
  • Government ministries
  • Telecom operators
  • Energy companies
  • Financial institutions
  • Media and education networks

Data Lake (o_data_*)

Knownsec’s o_data_ data lake* represents one of the most revealing and troubling components of the entire leak. Beneath the polished surface of its security products lies a sprawling, carefully indexed archive of global breach data, sourced from criminal markets, prior compromises, open leaks, and internal acquisitions. These datasets include LinkedIn collections from Brazil and South Africa, Taiwan Yahoo account dumps, Indian Facebook user sets, and extensive Chinese national datasets ranging from railway passenger manifests to banking records and ID-card tables. Layered atop this are telecom subscriber databases, often containing phone numbers, IMSI/IMEI identifiers, addresses, and account metadata. Each dataset is catalogued with schema details including username, password, id_card, mobile, email, real_name, address, investment_style, and more, making the data lake a high-resolution, global directory of human digital traces.

Within Knownsec’s operational ecosystem, this data lake is not a passive archive; it functions as an identity-correlation engine. When a TargetDB entry identifies an exposed service or a ZoomEye scan reveals a misconfigured endpoint, analysts can pivot into the o_data_* records to uncover the real-world individuals associated with that IP, email, or domain. A VPN endpoint in Osaka becomes a person with a name, mobile number, and password reuse history. A Taiwanese banking server becomes an enumerated list of employees with matching emails, credential pairs, and personal details. These correlations enable credential replay attacks, account takeover attempts, and highly tailored social-engineering operations long before any exploit payload is deployed.

But the most powerful function of the data lake is its role in deanonymization. Modern cyber operations often hinge on identifying the human behind the machine, and the o_data_* archives allow Knownsec and by extension its state customers to strip away anonymity across borders. By linking breached credentials, phone numbers, and identity documents to technical infrastructure, the data lake fuels a range of offensive workflows: spearphishing campaigns, targeted malware delivery, behavioral profiling, and covert influence operations. In effect, the o_data_* collection serves as the human-intelligence layer of Knownsec’s cyber apparatus, turning scattered breach records into a structured intelligence resource that drives foreign espionage, domestic tracking, and precision targeting at scale.

A massive archive of global breach data:

  • LinkedIn Brazil, South Africa
  • Taiwan Yahoo email/password datasets
  • Indian Facebook sets
  • Chinese national ID/railway/banking data
  • Telecom subscriber DBs

Purpose:

  • Correlate human identities
  • Enable credential replay
  • Enable deanonymization
  • Power targeted phishing and social engineering

Access Layer

Knownsec’s Access Layer is embodied most clearly in its flagship offensive toolkit, GhostX, a system designed not merely to breach endpoints but to reduce, reconstruct, and ultimately control digital identity. GhostX operates at the intersection of browser exploitation, network manipulation, and host persistence. It begins with browser fingerprinting, gathering granular details, plugins, fonts, extensions, power telemetry, and rendering quirks to create a durable identity signature that follows a user across VPNs, proxies, and devices. Once a target is profiled, GhostX can be set to escalate into active compromise: extracting browser-stored passwords, siphoning cookies and session tokens, and deploying keylogging modules that capture input in real time. These capabilities allow operators to pivot immediately into email accounts, internal dashboards, or social platforms without requiring traditional exploit chains.

But GhostX’s reach extends well beyond the endpoint. The suite includes tools for internal service identification, mapping what the compromised machine can see inside a network database, ports, admin interfaces, intranet portals, and shared resources. From there, GhostX can manipulate the network environment itself through routing attacks and DNS hijacking, redirecting traffic or impersonating internal systems. The ability to create new admin accounts on routers or internal services turns a momentary foothold into a durable position within the victim’s infrastructure, enabling stealthy lateral movement or long-term monitoring. Operators can also invoke remote command execution, screenshot capture, and webpage cloning, giving GhostX a Swiss-army-knife versatility normally found in high-end, nation-state-grade intrusion platforms.

Central to GhostX’s design is its suite of anti-forensic mechanisms and techniques such as code mixing, behavior shaping, and signatureless execution explicitly described in internal product briefs. These features aim to frustrate defenders, slow incident response, and complicate attribution. When combined, GhostX becomes a multi-vector exploitation and persistence framework, engineered to collapse anonymity, extract access, and maintain covert presence across both user endpoints and network infrastructure. It is a foundational component of Knownsec’s offensive cycle, bridging the gap between reconnaissance and deeper operational penetration.

GhostX   Virtual Identity Reduction & Exploitation Suite

GhostX a multi-vector exploitation and persistence framework.

Capabilities include:

  • Browser fingerprinting
  • Password extraction
  • Cookie and credential theft
  • Keylogging
  • Website cloning
  • Screenshot monitoring
  • Internal service identification
  • Routing manipulation
  • DNS hijacking
  • Admin user creation
  • Command execution
  • Anti-forensics (code mixing, signature evasion)

Un-Mail Webmail Takeover & Persistent Collection

Knownsec’s Un-Mail platform is the company’s dedicated engine for webmail takeover and long-term communications exploitation, effectively turning inboxes into intelligence feeds. Unlike traditional phishing tools or standalone password stealers, Un-Mail is built to compromise webmail ecosystems at the application layer, beginning with XSS-based exploitation of major mail portals. These injection points allow attackers to intercept login sessions, capture live session tokens, or inject malicious scripts directly into a victim’s browser workflow. Once access is established, Un-Mail seamlessly transitions into session hijacking and cookie replay, bypassing MFA or password-change events and ensuring operators maintain continuous entry even as the victim continues to use their account.

The platform’s most powerful capability is its ability to perform IMAP/POP mailbox replication, silently downloading the entire mailbox including archived, deleted, or years-old communications into a local datastore under operator control. This “first sync” is typically followed by ongoing incremental collection, with Un-Mail monitoring for new messages and exfiltrating them in real time. Operators can configure keyword triggers for sensitive terms, automate alerts when certain contacts communicate, and selectively forward or clone messages without user visibility. Internal product slides emphasize full inbox exfiltration and customizable monitoring dashboards, indicating a mature COMINT-oriented architecture rather than a simple webmail attack script.

Un-Mail’s reach is expanded by its cross-provider compatibility, with explicit support for Gmail, Outlook/Hotmail, Yahoo, AOL, and major Chinese providers such as 163, 126, TOM, and Yeah.net. This broad compatibility allows Knownsec and its state clients to conduct communications intelligence collection across national borders, harvesting diplomatic correspondence, corporate strategy emails, and internal government mails for targeting purposes. The result is a tool purpose-built for persistent surveillance, supporting intelligence requirements ranging from domestic monitoring to foreign espionage, further evidence that Knownsec’s operational mission extends deep into offensive state-cyber tradecraft.

Capabilities:

  • XSS exploitation of webmail portals
  • Session hijacking
  • Cookie replay
  • IMAP/POP mailbox replication
  • Full inbox exfiltration
  • Real-time keyword monitoring
  • Cross-provider compatibility (Gmail, Outlook, Yahoo, 163, 126, etc.)

This enables communications intelligence collection (COMINT) across national borders.

Internal Network Discovery

Knownsec’s Passive Radar (无源雷达) is designed for the phase immediately following initial access, when the operational priority shifts from intrusion to comprehension. While tools such as GhostX focus on endpoints and Un-Mail captures communications, Passive Radar illuminates the internal network environment those systems inhabit. Its purpose is not exploitation in isolation, but the reconstruction of the operational terrain inside a compromised organization.

Unlike active scanners that generate detectable traffic, Passive Radar relies exclusively on the ingestion and analysis of packet capture (PCAP) data. This passive approach allows operators to observe a network as it actually behaves, without altering traffic patterns or triggering defensive controls. The system accepts PCAPs through three primary ingestion paths: direct offline uploads, remote retrieval via FTP, and secure acquisition over SSH. These mechanisms allow traffic to be sourced from compromised servers, misconfigured storage systems, network taps, or siphoned repositories without requiring live interaction with the target environment.

Once ingested, Passive Radar automatically extracts and classifies the network’s technical structure. It identifies IP addressing schemes, port usage, protocol signatures, service banners, device types, and traffic flows, assembling these elements into a coherent model of internal communications. By correlating flows over time, the platform reveals which systems communicate persistently, how authentication and directory services are organized, where data is aggregated or forwarded, and which services function as internal chokepoints.

This process exposes high-value internal assets that are often invisible from the perimeter: domain controllers, mail gateways, internal content-management systems, financial platforms, and management interfaces. Behavioral flow analysis highlights trust relationships, reused credentials, and open administrative paths that can be leveraged for lateral movement. Device classification further identifies unmanaged servers, weakly configured firewalls, and embedded or IoT systems that present escalation opportunities.

Through this transformation of raw packet data into structured internal intelligence, Passive Radar provides the situational awareness required to move beyond an initial foothold and toward sustained control of a target network.

Passive Radar (无源雷达)

The strategic significance of Passive Radar lies not merely in what it observes, but in how it collapses uncertainty for offensive operators. By deriving intelligence from real traffic rather than inferred exposure, the platform reveals how a network truly functions under normal conditions. This traffic-derived perspective exposes dependencies, trust boundaries, and operational habits that conventional vulnerability scanning cannot reliably detect.

Viewed through an offensive lens, Passive Radar functions as an internal reconnaissance and targeting system. Its outputs identify viable lateral-movement routes, uncover unencrypted administrative channels, and surface shared authentication paths that enable quiet expansion through a network. Instead of probing for weaknesses, it allows operators to exploit the structure that already exists, reducing noise while increasing precision.

This capability is particularly valuable in state-aligned operations, where persistence, attribution control, and long-term access outweigh speed. Passive Radar turns captured network traffic into operational intelligence that supports methodical expansion, selective exploitation, and planned data extraction. In effect, it converts the interior of a victim network from an opaque risk space into a charted environment suitable for controlled maneuver.

For Knownsec’s government and military customers, Passive Radar serves the same role in cyberspace that reconnaissance and terrain analysis serve in conventional operations. It enables planners to study internal infrastructure, anticipate defensive responses, and design lateral movement and persistence strategies with confidence. In this sense, Passive Radar is not simply a security product, but a foundational intelligence capability that bridges access and dominance within the digital battlespace.

A PCAP-based internal situational awareness tool:

3 ingestion modes:

  • Offline PCAP
  • FTP
  • SSH

Extracts:

  • IPs
  • Ports
  • Protocols
  • Behavioral flows
  • Services
  • Device types

Purpose:

  • Map internal networks
  • Identify critical hosts
  • Reveal lateral-movement opportunities
  • Build operational intelligence for deeper compromise

Persistence & Exfiltration Layer

Knownsec’s Persistence & Exfiltration Layer represents the phase of an operation where intrusion shifts from momentary access to steady, renewable intelligence collection. Once an endpoint or infrastructure node has been compromised through GhostX, Un-Mail, or Passive Radar–assisted lateral movement, Knownsec’s tooling activates a suite of mechanisms designed to keep the operator embedded indefinitely. At the user level, this includes keylogging and clipboard capture, which harvest credentials, sensitive text, and operational behavior with granular precision. These seemingly simple functions become powerful when combined with GhostX’s browser and routing manipulation: every password typed, every copied token, every pasted URL becomes part of the attacker’s internal map of the victim’s digital life.

Beyond user surveillance, Knownsec’s tools enforce persistence by manipulating the environment itself. Forced browsing modules can redirect users to attacker-controlled sites to refresh payloads or harvest updated cookies, while webshell interaction provides a remote backdoor for issuing commands and staging follow-up operations. The ability to perform DNS hijacking ensures long-term redirection and covert traffic interception, allowing Knownsec’s operators or their state clients to control access to internal or external resources without needing continuous endpoint presence. When this is combined with admin account creation on routers or internal network appliances, attackers gain durable infrastructure-level footholds that survive password changes, system updates, and even some forms of incident response.

Communication exfiltration remains a central pillar of Knownsec’s persistence strategy. Through Un-Mail, compromised inboxes can be synchronized via ongoing IMAP replication, creating a live copy of the user’s communications outside the victim network. New messages are silently collected, sensitive terms trigger alerts, and historical archives can be mined for strategic value. When all these elements operate together keystroke capture, environmental manipulation, infrastructure control, and communications replication they form a persistent intelligence foothold. This foothold is not just durable; it is regenerative, enabling long-term espionage, strategic monitoring, and operational leverage across months or even years, well after the initial compromise has been forgotten by the victim.

Includes:

  • Keylogging
  • Clipboard capture
  • Forced browsing
  • Webshell interaction
  • DNS hijack for long-term redirection
  • Admin account creation on routers
  • IMAP-based ongoing mailbox replication

This creates persistent intelligence footholds.

OPSEC & Anti-Forensics

Knownsec’s toolchain incorporates a mature OPSEC and anti-forensics layer, reflecting the needs of an organization that expects its operations to face scrutiny from both corporate defenders and national incident-response teams. Rather than treating stealth as an afterthought, Knownsec designs its offensive tools to actively manipulate the investigative environment, reshaping the forensic trail and degrading the defender’s ability to reconstruct what happened. This begins with proxy chain deployment, allowing operators to route traffic through multilayered, frequently shifting intermediaries that obscure the true origin of commands, payloads, or callback traffic. By automating these routing changes, Knownsec ensures that attribution efforts are diluted across ranges of unrelated IP space.

Beyond network obfuscation, Knownsec incorporates behavior-shaping and code-mixing techniques, which alter how malicious scripts behave on compromised systems. Instead of producing predictable logs or recognizable execution patterns, operations are blended into normal system activity or fragmented across modules that only reveal their true function when combined under specific conditions. These methods frustrate heuristic detection and force analysts to piece together sequences of behavior that appear benign in isolation.

Perhaps most challenging for defenders is the emphasis on signatureless execution and anti-tracing modules, which remove or modify indicators that typically reveal compromise. Malware components are often polymorphic or dynamically assembled, leaving no stable signatures for endpoint security tools to match. Meanwhile, anti-tracing features interfere with monitoring hooks, logging frameworks, and analyst tools, making post-incident reconstruction incomplete or misleading. Together, these OPSEC and anti-forensic capabilities signal that Knownsec’s offensive products are built not only to infiltrate networks but to survive inside them, resisting detection long enough to achieve intelligence objectives and complicating attribution even after an intrusion is discovered.

Capabilities:

  • Proxy chain deployment
  • Behavior obfuscation
  • Code mixing
  • No-signature execution
  • Anti-tracing modules

Designed to degrade defender and investigator visibility.

TRADECRAFT & TTPs

Knownsec’s operational workflow reflects a fully realized, contractor-engineered APT intrusion lifecycle, blending state objectives with commercial development discipline. What emerges from the leak is not a set of disconnected tools, but a coherent tactic-to-technology pipeline, where each stage of intrusion is supported by a purpose-built product or dataset. The tradecraft reads like a synthesis of China’s most capable threat actors APT31, APT41, Mustang Panda yet polished through a corporate engineering lens that emphasizes stability, modularity, and reuse across diverse missions.

The intrusion sequence begins with reconnaissance, powered by ZoomEye’s internet-wide scanning and the TargetDB attribution system, which labels millions of global IPs by organization, sector, and geopolitical relevance. Once a target is identified, Knownsec pivots into its human-layer intelligence using the o_data_* collections: massive breach datasets that reveal who operates which systems, how they authenticate, and which credentials or identities overlap across services. These datasets feed directly into resource development, where credential harvesting, identity correlation, and exploit development (largely through 404 Lab) prepare the ground for an intrusion tailored to the target’s technical and human profile.

Initial access is typically obtained through GhostX’s browser exploitation modules, social-engineering campaigns crafted through breach data, or Un-Mail’s XSS-based webmail compromise. Once inside, Knownsec’s operators transition smoothly into execution, deploying JavaScript payloads, browser implants, or DNS manipulation scripts to deepen footholds. The tooling then shifts into persistence mechanisms creating admin accounts on routers, setting up IMAP mailbox replication, and establishing proxy chains that ensure continued access even as environments shift.

From there, intrusions expand through privilege escalation and discovery, guided by routing manipulation and Passive Radar’s PCAP-derived intelligence to illuminate the structure of internal networks. Defense evasion occurs continuously through code mixing, signatureless execution, and behavioral obfuscation. Credential access is achieved via browser password extraction and keylogging, enabling lateral movement into systems that would otherwise require separate exploitation. As operators explore the victim environment, they perform service fingerprinting, internal command execution, and webshell interaction to propagate their influence.

Finally, intrusion objectives manifest through collection and exfiltration, with Knownsec tools capturing screenshots, siphoning mailboxes, and sending stolen data out via IMAP or DNS-hijacked channels. Command and control remains flexible and resilient, relying on web-based callbacks and multi-hop proxy chains that obscure operational origins. Taken together, this lifecycle reveals a level of integration rarely seen outside state intelligence services: a full-spectrum intrusion pipeline where reconnaissance, exploitation, persistence, and exfiltration are engineered as interoperable modules within a single contractor-driven ecosystem.

The Knownsec pipeline mirrors a modern APT intrusion lifecycle:

This aligns with APT31, APT41, Mustang Panda, but with a commercial-engineering polish.

SUPPLY-CHAIN INTELLIGENCE

Knownsec’s operational footprint is supported by a sophisticated and multilayered supply chain, one that mirrors the procurement logic of government-backed defense contractors rather than private-sector cybersecurity firms. Internal documents show that Knownsec does not restrict its infrastructure to domestic providers; instead, it strategically procures European hosting infrastructure, including services from companies such as EDIS and Impreza. These foreign VPS and storage nodes provide staging grounds for scanning operations, payload delivery, redirection infrastructure, and exfiltration endpoints. Their geographic dispersion reduces attribution risk and increases operational reach, aligning with the needs of state customers who require global coverage and plausible deniability.

Financial organization within Knownsec also reflects a formalized, state-integrated structure. Leaked WBS project sheets reveal clearly defined cost centers, funding lines, and project sponsors, which are exactly the type of internal accounting frameworks used in China’s defense-industrial enterprises. Dedicated budgets exist for offensive R&D, data acquisition, infrastructure hosting, and specialized tools like GhostX and Passive Radar as seen in the excel images from the dump. This financial governance ensures continuity across long-term development cycles and indicates that Knownsec’s offensive tooling is not an ad-hoc initiative but an institutionalized capability sustained by predictable funding streams.

A crucial component of the supply chain is the data acquisition ecosystem. Knownsec’s massive o_data_* archives encompassing foreign breach dumps, credential collections, telecom subscriber databases, and national-ID repositories come from a mix of purchases, criminal-market harvesting, and internal scraping operations. These datasets form the human-intelligence substrate upon which exploitation and social-engineering operations depend. Similarly, Knownsec’s PCAP supply chain relies on compromised machines, operator-controlled servers, or cooperation from state entities to provide raw network captures that feed Passive Radar’s analytical engine. The success of ZoomEye likewise depends on a distributed scanning infrastructure, sustained by supporting nodes, bandwidth, and hardware that Knownsec maintains across multiple jurisdictions.

Taken together, these elements show that Knownsec’s supply chain is not incidental; it is deliberately constructed to serve national offensive cyber objectives. Its infrastructure procurement resembles the logistical patterns of government-funded cyber units; its data ingestion relies on pipelines typical of intelligence services; and its budgeting and work breakdown structures parallel those of state research contractors. Whether through hosting arrangements abroad, civilian data lakes turned into intelligence assets, or long-term PCAP sourcing, Knownsec’s dependencies align closely with Chinese government procurement cycles and strategic priorities, underscoring its role as an embedded component of the PRC’s broader cyber operations ecosystem.

Evidence from internal documents shows:

  • They maintain internal cost centers for offensive tooling.
  • WBS projects show formal funding lines with project sponsors.
  • External datasets are purchased or harvested from criminal markets.
  • Infrastructure procurement mirrors government-funded contractor operations.

Dependencies

  • PCAP supply chain (victim or operator-controlled hosts)
  • ZoomEye sensor infrastructure
  • Data lake ingestion pipelines
  • Chinese-government procurement cycles

GLOBAL TARGETING

Knownsec’s leaked infrastructure data reveals a clear pattern of structured, high-value targeting focused on the critical infrastructure of strategically significant nations. Even in the limited-resolution tables available, the indicators of compromise (IOCs) point to a deliberate and methodical mapping of Taiwan’s financial, telecommunications, and energy sectors. The sample extracted entries illustrate this well: exposed Fortinet firewalls at Nan Shan Life Insurance and Hua Nan Commercial Bank, publicly reachable Sophos XG appliances at Chunghwa Telecom, and a vulnerable Check Point service tied to Taipower, Taiwan’s national energy provider. These enumerated services tagged by IP, port, device type, and application banner function as prevalidated targets, ready for exploitation by GhostX, network-fingerprinting modules, or customized military tooling. Although these samples represent only a fraction of the full dataset, they demonstrate the precision with which Knownsec cataloged foreign infrastructure exposure.

When these IOCs are contextualized within the broader leak, a picture of systematic targeting emerges. Taiwan is disproportionately represented across the leak, with evidence of interest not only in major telecom operators and financial institutions but also in power grid, nuclear-energy, and ISP-level assets. This coverage aligns closely with PRC strategic priorities and suggests an intent to build comprehensive operational knowledge of Taiwan’s connectivity fabric, resilience posture, and critical dependencies. Similar patterns appear in Knownsec’s datasets for Japan, where telecom providers, energy-sector nodes, and major industrial corporations are cataloged; and in South Korea, where financial institutions, telecom networks, and industrial infrastructure feature prominently.

Beyond East Asia, the targeting footprint widens. Knownsec’s o_data_* records include Indian telecom subscriber databases, Facebook identity datasets, and infrastructure ranges associated with Indian ministries. This mirrors Beijing’s intelligence interest in India’s digital ecosystem and supports operations requiring identity correlation or demographic profiling. Meanwhile, portions of the dataset referencing European or Western entities appear more fragmented, but they nonetheless indicate indirect exposure: customer lists and sector-tagged entries suggest an intelligence appetite for global critical infrastructure and multinational corporations, even if not yet operationalized at the same scale as East Asia.

Taken together, these patterns show that Knownsec’s targeting is strategic, multi-regional, and overtly political, aligning with the geopolitical interests of the PRC. The infrastructure data is not random reconnaissance; it is a curated map of cyber terrain that would enable espionage, influence, and potentially pre-positioning for disruptive operations. Each IOC and sector-tagged asset represents not just a point of exposure but a node in an intelligence-gathering architecture designed to give Chinese state clients deep visibility into the operational backbone of foreign nations.

This represents strategic, multi-region, politically aligned targeting.

Internal Data Exposure: Email Addresses, Employee Identities, and Functional Roles

The Knownsec leak provides an unusually clear view into the human architecture of a Chinese cyber-contractor supporting national security, public-security bureaus, telecom regulators, and critical-infrastructure stakeholders. Unlike previous contractor leaks such as i-SOON (Anxun) which focused primarily on tools and client lists, the KnownSec corpus reveals a segment of internal personnel structures, spanning project owners, planners, cost-center sponsors, WBS task leads, and supporting engineers.

This internal data forms a blueprint of how Knownsec organizes and distributes responsibility across its offensive research, cyberspace-mapping, radar-engineering, and data-fusion programs. It offers a rare look at the people behind these capabilities, and exposes the specific functional chains by which projects move from concept to FOC (full operational capability).

Employee Identity Data

The leak contains a complete cross-section of Knownsec personnel across multiple divisions:

  • 404 Security Lab (exploit research, offensive engineering, pentesting)
  • Product Technology R&D Center (platform R&D, cyberspace mapping)
  • Product Technology Department (hardware radar, UI/UX, testing)
  • Product Technology Center 141 (high-level technical governance)
  • Public-Security Research Institute (entity fusion, PSB analytic systems)

A total of 22 named employees appear in the materials, each tied to specific organizational units and assigned responsibilities inside multi-stage research or engineering efforts. These employees represent a spectrum of roles from senior leadership with strategic authority to WBS task owners responsible for tactical implementation details.

This personnel visibility is valuable for understanding:

  • Internal tasking mechanisms
  • Operational structure beneath Knownsec’s capabilities
  • Which individuals enable offensive, defensive, or fusion-support tasks
  • How work is distributed across government-sponsored projects

Where relevant, email addresses and internal accounts allow correlation with procurement records, code repositories, or external infrastructure should those indicators surface elsewhere.

Internal Email Address Patterns

Every email address in the dump uses one of two company formats:

  • @knownsec.com → Headquarters operational accounts
  • @xm.knownsec.com → Xiamen-based R&D and engineering offices

No personal external addresses appear for employees; only official Knownsec accounts are used inside project governance systems.

The following email addresses were recovered from the leak so far:

  • zouxy2@knownsec.com
  • suig@knownsec.com
  • mas@knownsec.com
  • wangcp2@knownsec.com
  • chenc6@knownsec.com
  • hey5@knownsec.com
  • raosh@knownsec.com
  • anyh@knownsec.com
  • liuj13@knownsec.com
  • xuc2@knownsec.com
  • niexy2@knownsec.com
  • chenrl@xm.knownsec.com
  • chenjz@xm.knownsec.com
  • wangll@xm.knownsec.com
  • chenh4@xm.knownsec.com
  • liwc@xm.knownsec.com
  • wangl8@xm.knownsec.com
  • yangwh2@knownsec.com
  • zhanghj@knownsec.com

These addresses correspond directly to organizational positions inside Knownsec’s secure research and engineering divisions. There are no “throwaway” or operational aliases (e.g., Gmail/QQ/ProtonMail), which underscores that these individuals are internal employees, not contractors or external operators.

Functional Role Taxonomy

The personnel records reveal a clear hierarchy divided into strategic, operational, technical, and support layers.

Strategic Layer

These individuals control cost centers, approve research direction, and supervise multi-year programs. They connect Knownsec’s products to state-level requirements.

Key personnel:

  • 李伟辰 (Li Weichen) – Head of Product Technology Center 141

These roles align with PRC state-integration patterns, where strategic decision-makers balance customer obligations with core R&D investment.

Operational Layer

Project managers, planners, and supervisors who translate strategic objectives into executable WBS chains.

Examples:

  • PM and supervisor for 404 Security Research 2023
  • PM/Planner for AW Detection (Project 391)
  • PM/Planner for Hardware Radar 2022 V3
  • PM of 404 Lab Pentest Research
  • Project planners for Cyberspace Mapping (Carrier Platform)

These individuals operationalize multi-team engineering efforts, reflecting the governance model observed in defense integrators.

Technical Layer

Engineers responsible for exploitation, radar algorithms, system optimization, and data fusion.

Representative technical staff:

  • WBS task owner for AW exploit and discovery chain
  • Owner of AW 3.5 system testing
  • Radar v3 implementation
  • Radar optimization and stability
  • Asset-identification system optimization
  • User and functional testing tasks
  • Data-fusion task execution for PSB
  • Lead engineer for network-entity fusion research

This tier performs the core offensive and analytic development that Knownsec markets to PRC state customers.

Support Layer

Personnel performing QA, compliance, test engineering, and administrative approvals.

Notable roles:

  • Beijing Testing Group (unnamed individuals except task owners)
  • Default approver across R&D workflows

These roles ensure Knownsec’s platforms (Radar, Carrier Platform, offensive tooling) meet regulator and PSB deployment conditions.

Organizational Insight Derived from Internal Personnel Records

The internal data paints a clear picture of Knownsec as a multi-division cyber contractor seamlessly embedded within the broader security and intelligence ecosystem of the People’s Republic of China. Its organizational structure, personnel assignments, and project governance models demonstrate a company that is not merely providing commercial cybersecurity services but is directly supporting national cybersecurity mandates, public-security operations, and critical-infrastructure oversight. Every major division within Knownsec aligns with a corresponding state need, creating an operational architecture that mirrors the functions of a state-affiliated defense integrator.

This alignment is particularly visible in how technical departments map to specific government tasking. The 404 Lab serves as the offensive research and exploit-development hub, producing capabilities that directly support public-security bureaus and the national CERT apparatus. Meanwhile, the Product Technology Centers operate as the engineering backbone for large-scale cyberspace-mapping platforms used by telecom regulators such as Ministry of Industry and Information Technology (MIIT) and Critical Infrastructure Intelligence Center (CNNIC). Parallel to these, the Public-Security Research Institute builds data-fusion and analytic systems tailored for police units, reflecting a tight coupling between Knownsec’s internal R&D efforts and the investigative workflows of law-enforcement agencies.

Even the company’s internal email domains reinforce these functional distinctions. Accounts using @xm.knownsec.com cluster around engineering-heavy roles located in Xiamen, supporting platform development, radar systems, and systems integration. In contrast, @knownsec.com addresses are associated with research, data-fusion, offensive tooling oversight, and leadership responsibilities in Beijing. These boundaries reveal an internal trust and specialization model consistent with sensitive state-oriented development work.

Knownsec’s work-breakdown-structure (WBS) governance further shows a degree of engineering discipline typically found in military-industrial contractors. Projects are organized under formal sponsorship, with named approvers, supervisory layers, and sequenced deliverables. Every task has a clearly identified owner, and responsibilities cascade through planners, supervisors, and technical implementers. This hierarchy captures operational accountability at each stage, ensuring that sensitive tooling and large-scale platforms move through development in a controlled, auditable way.

Personnel mapping highlights how deeply the company depends on specialized, interoperable technical units. Offensive engineers in the 404 Lab, radar architects in the Product Technology Department, large-scale mapping engineers in the R&D Center, and data-fusion specialists in the Public-Security Research Institute all operate in defined silos. However, these silos are not isolated; they form a layered production pipeline that transforms exploit research into operational platforms capable of national-scale reconnaissance, targeting, and surveillance. In this way, Knownsec operates not just as a security vendor but as a critical node in China’s state-aligned cyber ecosystem, where human expertise, organizational structure, and strategic intent converge into a cohesive operational capability.

Key observations:

  1. Departments align to state tasking
    • 404 Lab produces exploit and offensive research for PSB and national CERT.
    • Product Tech Centers deliver cyberspace-mapping platforms for telecom regulators (MIIT, CNNIC).
    • Public-Security Research Institute builds fusion systems directly for police units.
  2. Email domains reinforce internal trust boundaries
    • @xm.knownsec.com maps to engineering-heavy functions.
    • @knownsec.com maps to research, fusion, and leadership roles.
  3. WBS governance reveals engineering maturity
    • Workflows mirror military-industrial contractors with formal sponsorship, deliverable tracking, and internal approvals.
    • Each task has a named owner, capturing chains of operational accountability.
  4. Personnel mapping exposes internal specialization
    • Offensive engineering, radar systems, cyberspace mapping, and data fusion are isolated but interoperable teams.
    • These silos reflect a layered pipeline that moves from exploit research to national-scale targeting platforms.

Strategic Significance of the Internal Data Exposure

The personnel information exposed in the Knownsec leak provides an unusually rich foundation for adversarial intelligence analysis. Instead of viewing Knownsec through the limited lens of tools, platforms, or public-facing capabilities, analysts can now reconstruct the company’s true operational architecture by tracing projects, responsibilities, and decision-making authority back to named individuals. This transforms Knownsec from an abstract corporate entity into a map of people, teams, and functions revealing how its internal machinery supports the broader PRC cyber apparatus.

With individual identities tied directly to work-breakdown structures, cost centers, and project leadership roles, analysts can identify exactly who drives offensive research and development. Names connected to GhostX, Radar 2022V3, the Cyberspace Mapping “Carrier Platform,” and data-fusion systems allow a clear understanding of which personnel shape the direction of core offensive and reconnaissance tools. Decision-making chains also emerge: who authors budget proposals, who approves them, who signs off on deliverables, and who assumes technical ownership of the most sensitive tasks. These insights expose how Knownsec manages risk, allocates resources, and governs the development of capabilities that ultimately serve national-level customers.

The data also closes the loop between Knownsec’s internal operations and China’s public-sector clients. Analysts can now link specific individuals to the ministries, state-owned enterprises, and provincial public-security bureaus they support. Whether developing mapping infrastructure for MIIT, vulnerability research for PSB, or reconnaissance tooling for State Grid or the national telecom operators, the personnel lists clarify which engineers and managers are responsible for executing state-directed work. This creates a direct, traceable line from human operators to cyber capabilities used by the PRC government.

Granular operator-level visibility of this kind is almost never present in Chinese contractor leaks. Typical disclosures provide tools, artifacts, or billing records, but rarely full mappings of engineers, planners, cost-center owners, and project supervisors. The Knownsec leak stands apart in that it reveals not only what the company builds, but who builds it, who authorizes it, and who ensures its integration into the state security ecosystem. For analysts, this level of detail offers an unprecedented window into the human and organizational architecture of one of China’s most capable cyber contractors.

State Security and Intelligence Organizations Identified in the Knownsec Leak

The Knownsec leak provides direct insight into the company’s relationship with the national security, cyber-regulation, and public-security ecosystems of the People’s Republic of China. The documents show that Knownsec does not operate as a conventional cybersecurity vendor but instead as a tightly integrated contractor supporting multiple layers of the PRC’s intelligence and public-security infrastructure. The presence of specific ministries, bureaus, CERT bodies, and state-owned enterprises across internal worksheets and customer tables reveals a contractor ecosystem that mirrors the organizational structure of the Chinese cyber state.

The Ministry of Public Security (MPS) emerges as the most prominent stakeholder in Knownsec’s operations. Multiple internal project sheets reference public-security intelligence requirements, entity-fusion deliverables, and policing-oriented research, suggesting that Knownsec’s tools such as Network Entity Data C fusion systems and analytics platforms feed directly into law-enforcement intelligence workflows. The inclusion of the Beijing Municipal Public Security Bureau as a direct customer reinforces that Knownsec supports both national and regional PSB units, providing technical capabilities that underpin investigatory, surveillance, and cyber-intelligence missions. The company’s Public-Security Research Institute acts as an intermediary, developing analytic systems specifically designed for MPS use, including the “30 Institutes” project, which historically links to police intelligence research centers.

Beyond policing, the documents show that Knownsec’s platform technologies align with the needs of China’s cyber governance infrastructure. The MIIT and CNNIC, which oversee network resources, DNS infrastructure, and telecom regulation, appear in customer lists. These associations suggest that Knownsec’s large-scale cyberspace-mapping platforms and radar systems contribute to regulatory visibility across the national network space. Similarly, the presence of CNCERT/CC and CCERT indicates that Knownsec plays a role in the country’s coordinated incident response and vulnerability-management programs. These organizations sit at the intersection of defensive coordination and intelligence-informed cyber situational awareness, and Knownsec’s products appear to support both domains.

Several state-owned enterprises also appear in the dataset, including State Grid, China Mobile, and China Telecom. While not intelligence agencies in name, these entities represent critical-infrastructure and telecommunications networks of high strategic value to Chinese state security. Their appearance in Knownsec’s internal documentation implies that Knownsec provides reconnaissance, mapping, or defensive monitoring capabilities that directly support national requirements for energy grid protection, telecom oversight, and large-scale network exposure assessment. These relationships blur the line between commercial engagement and state-aligned intelligence support, reflecting the dual-use nature of Knownsec’s core platforms.

Taken together, the organizations referenced in the leak form a coherent picture of how Knownsec embeds itself in the state’s cyber and intelligence apparatus. The company’s divisions and product lines align closely with the functional needs of public-security bureaus, national regulators, telecom carriers, and critical infrastructure operators. The network of relationships visible across the documents illustrates a contractor deeply woven into China’s national security architecture. It confirms that Knownsec’s internal operations, research programs, and platform developments are not random or commercially opportunistic but are systematically shaped by the requirements of the PRC’s intelligence and regulatory ecosystem.

Summary: Intelligence / Security Org List

OrganizationTypeRole in DumpMPS – Ministry of Public SecurityNational Police / IntelligencePrimary stakeholder for offensive, data-fusion, and entity analytics systemsBeijing Public Security BureauMunicipal PSBDirect consumer of Knownsec platforms and analysisPublic-Security Research Institute (internal Knownsec)PSB-aligned R&DBuilds fusion tech for PSB intelligence unitsMIITTelecom & Cyber RegulatorOversight for mapping platforms, radar outputsCNNICNational DNS AuthorityDomain-level surveillance & infrastructure mappingCNCERT/CCNational CERTNational-level vulnerability, incident intelCCERTEducation & Research CERTSupporting CERT node“30 Institutes” (PSB Research Institutes)Public-Security Intelligence R&DEntity fusion, data pipelines, analytic systemsState GridStrategic CII targetIncluded for reconnaissance and mappingChina Mobile / China TelecomTelecom carriersInfrastructure mapping and metadata pipelines

APPENDICES

Appendix A  Combined IOC List (Knownsec Leak Corpus)

Indicator of Compromise Summary  Knownsec TargetDB, Radar, and Foreign CI Mapping

Below is the unified IOC dataset extracted from all Knownsec screenshots, TargetDB tables, Radar 2022V3 outputs, and CI-targeting images provided in this project.

High-Confidence IP-Level IOCs (Critical Infrastructure Targets)

(All derived from Knownsec’s internal TargetDB screenshots for Taiwan CII)

country,organization,ip,port,service,device_type,notes

Taiwan,Nan Shan Life Insurance,210.242.194.198,443,httpd,Fortinet FortiGate,Listed as critical asset in CII table

Taiwan,Nan Shan Life Insurance,210.242.194.198,80,httpd,Fortinet FortiGate,Same host over HTTP

Taiwan,Hua Nan Commercial Bank,219.80.43.14,443,httpd,Fortinet FortiGate,Banking-sector firewall target

Taiwan,Hua Nan Commercial Bank,219.80.43.14,80,httpd,Fortinet FortiGate,Appears twice in Knownsec radar slices

Taiwan,Chunghwa Telecom,220.130.186.202,10443,httpd,Sophos XG,Telecom-edge gateway in CII targeting

Taiwan,Chunghwa Telecom,220.130.186.203,10443,httpd,Sophos XG,Sister device to above; separate PoP

Taiwan,Bank of Taiwan,103.21.60.3,8080,httpd,Fortinet FortiGate,Core financial gateway

Taiwan,Taipower,61.65.236.240,18264,httpd,Check Point SVN,Energy-sector firewall; high-value infrastructure

Medium-Confidence IOCs (Region-Expansion & Mapping Targets)

From Knownsec’s internal WBS expansion directives (WBS 7 & 8):

region,ip_range,notes

United States,100000_new_ips,Expansion directive: increase target coverage by 100k IPs

Taiwan,10000_new_ips,Expansion directive: +10k key Taiwan IP segments

YN_region,expansion_flag,New coverage region in platform WBS

MD_region,expansion_flag,New coverage region in platform WBS

WL_region,expansion_flag,New coverage region in platform WBS

ELS_region,expansion_flag,New coverage region in platform WBS

Data-Lake / Credential-Dump Indicators

From the o_data datasets referenced in the Knownsec HDFS export list:

dataset_name,country_or_sector,notes

o_data_taiwanahooemailpwd_tw,Taiwan,Credentials (Yahoo TW email/password dump)

linkedin_brazil,Brazil,LinkedIn identity dataset

linkedin_southafrica_202305,South Africa,LinkedIn identity dataset

o_data_facebookuserinfo_in,India,Facebook identity dump

o_data_telecom_info_india,India,Telecom subscriber dataset

o_data_royalenfield_india,India,Automotive customer dataset

o_data_shopping_order_vietnam,Vietnam,E-commerce customer dataset

o_data_shopping_vip_vietnam,Vietnam,VIP commerce dataset

o_data_insuranceindia_data,India,Insurance records dataset

o_data_sms_active_ru,Russia,SMS/telecom activity dataset

o_data_telderi_ru,Russia,Marketplace dataset

o_data_skolkovo,Russia,Skolkovo-related dataset

o_data_github,Global,GitHub developer dataset for targeting correlation

o_data_telegram_user_info,Global/Regional,Telegram identity dataset

o_data_instagram_temp,Global/Regional,Instagram scraped temp dataset

Organizational Targets & Associates (Based on Internal “典型客户” / TargetDB Sector Lists)

The following organizations appear repeatedly in Knownsec’s internal customer lists, procurement docs, or radar/TargetDB slices. These constitute strategic targeting and cooperation indicators even when no IP/IaaS attributes were provided.

country,organization,type,notes

China,Ministry of Public Security,State Client,Internal security customer consuming Knownsec platforms

China,People’s Bank of China,Financial Regulator,Monitored via PKI-linked infrastructure

China,CFCA (Financial Certification Authority),Financial PKI Infrastructure,High-value crypto/identity target

China,State Grid Corporation of China,Critical Infrastructure,Energy/SCADA mapping

China Mobile,Telecom,Carrier mapping and radar integration

China Telecom,Telecom,Carrier mapping and radar integration

China Education & Research CERT (CCERT),Academic CERT,Emergency-response alignment

China,State Council Procurement Network,Government ops,Procurement and surveillance-aligned workload

China,Beijing Public Security Bureau,Policing/LEO,Multiple contract purchases in ledger

Taiwan,Bank of Taiwan,Financial institution,Direct firewall mapping (See A.1)

Taiwan,Hua Nan Commercial Bank,Financial institution,Direct firewall mapping (See A.1)

Taiwan,Nan Shan Life Insurance,Insurance/Financial,Direct firewall mapping (See A.1)

Taiwan,Chunghwa Telecom,Telecom,Edge infrastructure fingerprinted (See A.1)

Taiwan,Taipower,Energy/Nuclear,Check Point SVN asset identified

India,Telecom Companies,Telecom,Featured in o_data_telecomcompanies_in

India,Ministry-adjacent IP ranges,Government,Identified in mapping directives

Vietnam,Shopping-order and VIP datasets,E-commerce / social profiling,Used for persona correlation

Russia,Skolkovo / Telderi / SMS datasets,Industrial / Social,Used for identity correlation

Global,GitHub developer data,Developer ecosystem,Used for deanonymization & target pivoting

Tooling-Linked IOC Classes (High-Level Indicators)

Where specific domains/servers were not provided, Knownsec tooling reveals classes of IOCs that defenders should track.

category,indicator_type,example,notes

GhostX,Persistence IOCs,admin account creation on routers,Indicates long-term foothold

GhostX,Network Manipulation,DNS hijack configurations,Used for redirect/exfil

Un-Mail,Webmail compromise,XSS injection points on webmail portals,High-risk COMINT vector

Passive Radar,Internal reconnaissance,PCAP ingestion servers,Victim-owned or attacker-controlled

Carrier Platform,Recon infrastructure,ZoomEye-linked scanners,High-volume scanning nodes

Radar 2022V3,Protocol-fingerprinting output,service banners/flows,Used to classify assets for later exploitation

Data-Fusion Projects,Identity correlation,IAM/credential merges,Used by Public-Security clients

These are behavioral indicators, not atomic IOCs, but they are directly tied to Knownsec’s operational tooling.

Appendix B   MITRE ATT&CK Map

Appendix C   Organizational Schema (Text)

State Ministries

  ↓

Knownsec Executive Leadership

  ↓

404 Lab | Product R&D | Military Division | Data Division

  ↓

Project Managers → Engineers → Operators

  ↓

Toolchain Deployment

Appendix D   Master File List from Dump

Here is a consolidated file list of all Knownsec-related uploads in this project, reconstructed from the conversation history, OCR references, system logs, and tool notes.

This includes images, PDFs, spreadsheets, and indexes you uploaded for the Knownsec leak analysis.

MASTER FILE LIST OF UPLOADED FILES (Knownsec Project)

PDFs (Leak Documents & Articles)

Leak Documentation

  • 关基目标库说明文档_V202309.pdf (multiple screenshots provided)
  • 无源雷达–产品文档 (Passive Radar Product Manual) (screenshots extracted)
  • *404安全研究2023 – internal sheets (as images, WBS pages)
  • 网空云测绘-网空航母平台-2022 (Carrier Platform 2022 WBS sheets)
  • 硬件雷达2022V3.0.0.0 主力项目 (Radar Project 2022V3 WBS)
  • 网络实体数据C与融合关键技术研究 (PSRI / “30 Institutes” project sheets)

Spreadsheets & Data Index Files

1. Personnel / Department / Project Indexes

  • master index departments and projects.xlsx
  • master index emails and people.numbers
  • Untitled.xlsx (additional personnel / dept mappings)

2. Internal Project/Deliverable Sheets

(Uploaded via screenshots but constitute distinct files)

  • 404 Lab WBS summary sheets (≈ 10 images)
  • 391 AW Detection Project sheets (≈ 10 images)
  • Carrier Platform WBS sheets (Product Technology R&D) (≈ 10+ images)
  • Radar 2022V3 WBS sheets (Product Tech Dept) (≈ 10+ images)
  • Public-Security Research Institute fusion project sheets (≈ 10 images)

C. Image Files (Screenshots)

Knownsec Internal Documents (numbered 1–64)

1.png

3.png

4.png

5.png

6.png

7.png

8.png

9.png

10.png

11.png

12.png

13.png

14.png

15.png

16.png

17.png

18.png

19.png

20.png

23.png

24.png

25.png

26.png

28.png

29.png

30.png

31.png

32.png

33.png

34.png

35.png

36.png

37.png

38.png

39.png

40.png

41.png

42.png

43.png

44.png

45.png

46.png

47.png

48.png

49.png

50.png

51.png

52.png

53.png

54.png

55.png

56.png

57.png

58.png

59.png

60.png

61.png

62.png

63.png

64.png.

Reconstructed File Descriptions (1–64)

1–11: Public-Security Research Institute (PSRI) – “Network Entity Data C & Fusion Key Tech Research”

These files corresponded to the “30 Institutes” fusion project, showing:

  • PSB-driven data-fusion research
  • Entity correlation pipelines
  • Multi-dataset integration workflows
  • WBS tasking for Zhang Huijie and Yang Guihui
  • Deliverables tied directly to Public Security Bureau (公安三所) requirements

Typical page contents:

File Description
1.png Title page or high-level summary of the Fusion Research Project
3.png WBS structure showing key tasks (data ingestion, entity resolution)
4.png PSB-facing deliverables used in law-enforcement analytics
5.png Cross-dataset linkage models
6–11 Technical diagrams, task ownership tables, and PSRI resource allocations

12–20: 404 Security Research 2023 (404实验室) / AW Detection Project 391

These images included:

  • 404 Lab internal research objectives
  • Vulnerability mining tasks
  • AW (Asset & Weakness) detection research
  • Exploit-related WBS
  • Roles for Ma Shuai, Wang Cuiping, Chen Cheng, He Yan
  • Related pentest research flows

Typical mapping:

File Description
12.png 404 Lab project summary page
13.png 0-Day research pipeline
14.png Emergency vulnerability response tasks
15.png Battle Pigeon (战鸽) support tasks
16–18 AW detection WBS (3.1–3.6), including system testing
19.png Supervisor/approver fields
20.png Overall AW research deliverables list

23–36: Product Technology R&D Center – Cyberspace Mapping Platform (“Carrier Platform 2022”)

These images belonged to the 网空航母平台-2022 project, showing:

  • Region-coverage expansion goals
  • US/Taiwan key IP-range mapping
  • Platform WBS tasks
  • System component diagrams
  • Planning roles for Chen Ruili, Chen Jinzhan, Wang Lili, Chen Hai
  • Cost-center oversight by Li Weichen

Representative:

File Description
23.png Carrier Platform project overview
24.png New coverage region expansion task (WBS 7)
25.png Capacity and optimization goals (US +100k IPs, TW +10k IPs)
26–30 Platform module integration steps
31–33 WBS assignments indicating planners and supervisors
34–36 Region-by-region mapping and industrial coverage tables

37–45: Hardware Radar 2022 V3 (产品技术部)

These files came from the Radar 2022V3 core project, including:

  • Subsystem optimization tasks
  • Feature development (vuln PoC ingestion, configuration checking)
  • UI/UX tasks
  • User testing and functional testing
  • Technical owner mappings for An Yaxuan, Liu Xun, Xu Chao, Nie Xinyu

Mapping:

File Description
37.png Radar 2022V3 master WBS summary
38–40 Exploit intelligence module features (5.5–5.6)
41.png Asset-ID system optimization (5.3)
42–43 Compliance and configuration checking tasks
44–45 User test case creation and functional test reporting

46–54: TargetDB / Critical Infrastructure Target Library

These screens captured the 关基目标库 (Critical Infrastructure Target Library):

  • Sector classifications (military, telecom, energy, finance)
  • IP counts (378,942,040)
  • Regional coverage (26 geographies)
  • Domain and asset listings
  • Example targets: Taiwan banks, power grid, telecoms

Representative:

File Description
46.png TargetDB region overview
47.png Sector-by-sector breakdown
48.png Example foreign target dataset
49–52 Asset tables (IP, port, service, role)
53–54 Classified organization lists and country coverage

55–64: Data Business Division – HDFS o_data Datasets

This batch corresponds to the o_data_* dataset listings you uploaded, including:

  • Indian telecom subscriber DBs
  • Vietnam shopping-order datasets
  • Russia SMS/telecom datasets
  • Taiwan Yahoo credential dumps
  • LinkedIn Brazil / South Africa
  • GitHub user dataset
  • Telegram data sets
File Description
55.png HDFS directory listing summary
56–60 Dataset list pages for India, Russia, Taiwan
61.png LinkedIn and GitHub dataset references
62–63 Telegram user-info dataset pages
64.png Combined o_data index with HDFS paths

Miscellaneous Internal Dataset References (via screenshots)

Not files themselves, but documented inside uploads:

  • o_data_royalenfield_india
  • o_data_rusnod_ru
  • o_data_school_test
  • o_data_shopping_order_vietnam
  • o_data_shopping_vip_vietnam
  • o_data_skolkovo
  • o_data_sms_active_ru
  • o_data_taiwan_uhq
  • o_data_taiwanahooemailpwd_tw
  • o_data_telderi_ru
  • o_data_telecom_info_india
  • o_data_telecomcompanies_in
  • o_data_telegram_data
  • o_data_telegram_user_info
  • o_data_facebookuserinfo_in
  • o_data_github
  • o_data_instagram_temp
  • o_data_insuranceindia_data
  • linkedin_brazil
  • linkedin_southafrica_202305

These were extracted from HDFS paths visible in the screenshots.

Learn More