Threat Intelligence Report: University Leak Exposes Russia’s Military Cyber Training Pipeline
A leaked cache of institutional files reveals that Department No. 4 at Bauman Moscow State Technical University operates as a structured force-generation pipeline for Russian military cyber operations, training roughly 250 students across specializations. Supervised directly by senior GRU leadership, the program blends offensive intrusion, malware analysis, financial-systems targeting, and cryptographic defense with field placements that feed graduates straight into GRU- linked cyber formations like APT28 (Unit 26165) and Sandworm (Unit 74455).
Executive Summary
Recently leaked records show that Bauman Moscow State Technical University’s Department No. 4 operated as a long-term training pipeline for Russian military intelligence and cyber operations. The department served several elements of the Russian General Staff and trained roughly 250 career and reserve students across three specialties: special intelligence (“Служба специальной разведки”), operational information-technical effects (“Применение сил и средств информационно-технического воздействия и защиты от информационно-технического воздействия”), and information-technology protection (”3ащита информационных технологий”). The curriculum combined both offensive and defensive techniques for cyber defense, as well as offensive doctrine for active measures campaigns and GRU activities. Field placements then moved students from classroom instruction into military units and academies aligned with their specialties, giving them supervised exposure to intelligence operations and preparing them for military and government operations careers.
Bauman Staff and Graduates Dept 4
Reporting identified graduates assigned to GRU Military Unit 26165 (associated with APT28) and Military Unit 74455 (associated with Sandworm), and linked senior officers, including former Unit 26165 commander Viktor Netyksho, to student oversight. A DarkForums account named “Losyash” may have helped distribute the leaked material, although its role in obtaining or first publishing the records remains unconfirmed.
The department focuses on cyber warfare activities and defense, as well as UAV and communications operations and technologies.The leak reveals a repeatable institutional system for producing Russian military cyber operators, analysts, planners, defenders, and reserve personnel.
The Bauman Leak
The documents, which have been examined by an international consortium of media outlets that included The Insider, The Guardian, Le Monde, Der Spiegel, Delfi, and VSquare, describe a concealed unit known as Department No. 4 (Кафедра № 4) inside Bauman’s Military Training Center. Published investigations connected the department to the Main Directorate of the Russian General Staff, commonly known as the GRU, and identified graduates assigned to military units associated with APT28 and Sandworm.
DTI reviewed the full leaked evidence separately circulated through ‘DarkForums RU’ on the darknet, a cybercrime forum used to advertise and distribute stolen databases, compromised accounts, malware, and other illicit material. DarkForums emerged as a prominent competitor to the RaidForums and BreachForums ecosystem and experienced substantial growth after the disruption of BreachForums in 2025. (S2W)
A DarkForums profile associated with the handle ‘Losyash’ provided the leak’s distribution. The account was created on June 25, 2026, and had recorded only one thread and one post when the profile was investigated. The account had accumulated four hours and twenty-seven minutes of forum activity and was last recorded as visiting the site on July 10, 2026, at 7:09 p.m.
The profile contained no biography, location, homepage, gender, reputation history, or prior username changes. It had referred no other members and had received no forum awards. This is consistent with a narrowly used or recently created account rather than an established DarkForums persona. The sole post only stated they had Russian military data for download and presented two links online to download the 1.8gb of data.
The internal consistency of the Bauman leak files, their personnel structures, curricula, military specialty codes, approval chains, internship records, and subsequent corroboration by journalists support the assessment that the collection contains authentic institutional material. The available evidence does not yet identify how the files were obtained; however, our assessment of the data itself as well as all of its attendant metadata, shows that the files do belong to Bauman University. The metadata investigation shows the actual systems, users, folder hierarchies, and other data linking individuals as well as infrastructure that the data came from.
FOCA Metadata Analysis servers connected to files
FOCA metadata analysis of users from files
Using tools such as FOCA, analysis was carried out on all of the 1600 files ranging from Word files, PowerPoint slide decks, PDF files, Excel spreadsheets, images, and .ics (calendaring/email) systems showing a full range of meetings and presentations carried out during the claimed leaks timeframe. The metadata analysis corroborates the assessment that the files originated within Bauman University’s administrative and technical environment.
While the files show many users and other data that lend credence to the veracity of their provenance, investigation of them has yet to determine exactly what accounts might have been compromised to access these and to exfiltrate them from the university systems. However, this evidence does lead investigators to believe that this is not an effort to false intelligence on Russian operations.
The Contents of the Leak
The Bauman leak is a broad institutional archive rather than a single operational dossier. It includes personnel rosters, course schedules, examinations, attendance and fitness records, and medical screening files. It also includes force-planning tables, curriculum material, conference papers, and administrative correspondence. Together, the files show how Department No. 4 recruited, trained, evaluated, and placed career and reserve students across three specialties: VUS 093400 Special Intelligence Service, VUS 141600 information-technical effects, and VUS 751100 information-technology protection.The records reveal a stable population of roughly 250 students across all six university years, with 86 new trainees planned for 2024 and a substantial reserve component. Internship records place students at military units and academies in Moscow, Mosrentgen, Voronezh, Kursk, Bataysk, Sevastopol, Bugry, and Krasnodar.
Sampling of files from leak
Image files from leak of classes and graduates
The collection also includes malware-analysis and cyber threat intelligence research, manpower-planning documents, and a financial-sector cybersecurity specialization feeding into VUS 093400 (SIS). It further connects Bauman to Russian military research institutes, academies, and operational structures. Although the analyzed files do not provide every final graduate assignment, they expose the personnel, training, doctrine, and administrative system behind a durable Russian military cyber and technical-intelligence pipeline.
The Department No.4 Program
The files show that the Bauman University Department No. 4 was substantially broader than the shorthand description of a “GRU hacker school” purported in public reporting. It functioned as a force-generation institution serving several components of the Russian General Staff. Internal material states that the department prepared officers for the Main Directorate, the Main Operational Directorate, and the 8th Directorate, organizations associated with military intelligence, operational planning, classified communications, cryptography, and information protection (e.g. blue team functions including cryptographic systems, hardware, etc).
Bauman University Dept 4 Flow Diagram for Placement and Curricula
Students were divided among three numbered training groups, each aligned to a separate military occupational specialty and General Staff requirement.
Group No. 1, VUS 093400, was formally designated “Special Intelligence Service (SIS)” and operated under qualification requirements approved by the head of the Main Directorate of the General Staff.
Group No. 2, VUS 141600, was designated “Employment of Forces and Means for Information-Technical Effects and Protection Against Information-Technical Effects (EFMIT)”. This group trained personnel for operational cyber effects and defensive information-technical activity under requirements approved by the Main Operational Directorate.
Group No. 3, VUS 751100, was designated “Protection of Information Technologies” and appears to have prepared officers for secure military systems, classified information protection, communications security, or related technical-security functions.
Public reporting has concentrated on VUS 093400 (SIS) because it provides the clearest link to military intelligence. The leaked records indicate, however, that VUS 141600 (EFMIT) was the department’s largest program. Approximately 120 career and reserve students were enrolled in that stream during 2024, close to half of the department’s total population. VUS 141600 is Department No. 4’s operational cyber-warfare specialty, training officers to plan and employ information-technical effects and to defend military systems against equivalent adversary operations. (*note: this training for both blue team and red team planning and function is a feature of Russian military doctrine)
The scale indicates that Russia was not training only a small cadre of elite intrusion specialists. It was producing a wider workforce capable of integrating cyber operations into military planning.
GRU Cyberwarfare Curriculum
A Department No. 4 lecture described information-technical weapons as capabilities used to alter, destroy, copy, block, or steal information. The curriculum combines offensive intrusion, defensive security, technical intelligence, and psychological operations. Students received instruction in password attacks, server exploitation, software vulnerabilities, malware creation, penetration testing, technical surveillance, propaganda, and information manipulation.
Machine Translation: “Information-technical weapons are a collection of specially organized information, information technologies, methods, and means that make it possible to purposefully alter, destroy, distort, copy, or block information; overcome protection systems; restrict access by legitimate users; conduct disinformation; disrupt information-processing systems; and disorganize technical systems, computer systems, networks, and other high-technology infrastructure.”
The instructional material did not sharply separate offensive and defensive cyber operations. The inclusion of both offensive and defensive instruction trains operators to attack and defend all in one. Defensive measures included detection, blocking, concealment, diversion, technical deception, counterattack, and activity against adversary infrastructure intended to disrupt an ongoing operation.
Technical protection training covered cryptography and steganography, as well as code analysis and intrusion detection. Students were also trained in hardware inspection, the discovery of physical implants, and the identification of undocumented device functions. These subjects point to possible assignments in technical counterintelligence and supply chain security, as well as firmware analysis and embedded system inspection. Other likely functions include secure procurement and the protection of specialized military platforms.
The files also reveal an underreported malware-analysis and cyber threat intelligence program. A 2023 Bauman Military Training Center conference volume; “Current Issues Concerning the State and Prospects for the Development of Weapons, Military, and Special Equipment of the Aerospace Forces” (Актуальные вопросы состояния и перспектив развития вооружения, военной и специальной техники Воздушно-космических сил) contained research on malware triage, infrastructure mapping, anomaly detection, system-call monitoring, and attacker versus defender exercises.
Page 74 of tabletop exercise
Analysis of the Operational Methodology of a Pro-Ukrainian APT Group in Conducting Cyberattacks (Анализ методики работы проукраинской APT-группировки при реализации кибератак)
One paper in particular; ”Analysis of the Operational Methodology of a Pro-Ukrainian APT Group in Conducting Cyberattacks” (Анализ методики работы проукраинской APT-группировки при реализации кибератак), examined a campaign built around phishing and self extracting archives. In the campaign, the operators deployed renamed UltraVNC binaries and manually controlled infrastructure. They also reconstructed the execution chain, extracted configuration parameters, and mapped the command infrastructure. The paper offered limited support for its attribution theory (e.g. Ukraine), but its methodology still demonstrated practical training in malware analysis and open source intelligence collection. It also showed campaign clustering and script deobfuscation, with the authors reconstructing the intrusion from available evidence and reporting by others.
GRU Cyberwarfare Coursework
Department No. 4 combined classroom instruction with controlled attacker versus defender exercises. Students selected tactics and responded to opposing actions, assessing the effectiveness of each strategy. Related coursework covered intrusion detection and malware triage, including script analysis and remote access tooling. Students also studied infrastructure mapping and technical deception and learned to reconstruct cyberattack chains.
Based on this information, the program extended beyond theoretical cybersecurity instruction. It included cyber range training and adversary emulation, as well as incorporating incident response and operational planning. Students were expected to understand how attackers find and exploit weaknesses. They were also trained to prioritize limited defensive resources and place cyber activity within wider military operations.
Practical placements connected the coursework to military units and academies aligned with each specialty:
Group No. 1 trained under VUS 093400 for the Special Intelligence Service. Its trainees were sent to Kursk and Bataysk, with other placements including Sevastopol and Bugry. The distribution of these assignments points to exposure to intelligence units and collection functions. It also suggests contact with specialized military formations and operational environments supporting the Main Directorate of the General Staff. These placements likely gave students opportunities to apply intelligence tradecraft and network analysis. They may also have practiced technical collection and cyber enabled reconnaissance under the supervision of active military personnel.
Group No. 2 trained under VUS 141600 for information technical effects and protection against those effects. Students were primarily placed in Moscow and Mosrentgen, with others sent to Voronezh. These locations appear to be tied to military command and planning but also support communications and operational activity. The placements likely exposed students to the use of offensive and defensive cyber effects within headquarters functions. They may also have supported work involving automated command systems and information operations.
VUS 141600 was the department’s largest program. It appears designed to produce personnel who could support cyber operations at scale, extending beyond individual network intrusion.
Group No. 3 trained under VUS 751100 for the protection of information technologies. Its trainees were sent to the Krasnodar Higher Military School, which is associated with military communications and information security. It also supports the protection of command and control systems. This placement likely focused on secure networks and classified information protection.
Taken together, the placement pattern suggests that each numbered group followed a distinct operational pathway:
VUS 093400 supported military intelligence and special intelligence functions.
VUS 141600 supported cyber effects, defensive operations, and command-level integration.
VUS 751100 supported secure communications and information protection.
The combination of technical coursework, adversary-emulation exercises, and field placements created a structured progression from academic instruction to supervised military application, preparing graduates for assignments across Russia’s intelligence, cyber operations, command, and technical-security organizations.
The Personnel Pipeline
The consortium’s reporting identified graduates who entered two named GRU cyber formations. Military Unit 26165 is the 85th Main Special Service Center of the GRU, commonly associated with APT28, also tracked as Fancy Bear, Forest Blizzard, and several other vendor designations. The unit conducts military intelligence collection, cyber espionage, influence-support operations, and intrusions against government and strategic targets.
Military Unit 74455 is the GRU’s Main Center for Special Technologies, the organization associated with Sandworm, also tracked as APT44. Its function centers on disruptive and destructive cyber operations, including attacks against critical infrastructure, military targets, government networks, and operational technology.
The data also connected senior GRU officers to the supervision and evaluation of Bauman students. Viktor Netyksho, the former commander of Unit 26165 and the 85th Main Special Service Center, is part of the department’s teaching and oversight structure. Netyksho was among the GRU officers indicted by the United States for operations connected to the theft and release of material during the 2016 U.S. presidential election. The presence of officers from Unit 26165, together with graduate placements into Units 26165 and 74455, links Department No. 4 directly to both the GRU’s espionage-focused cyber apparatus and its destructive operational arm.
GRU Financial Systems Protection and Adversarial Programs
The records identify a specialized academic pathway that connected financial-sector cybersecurity training directly to Group No. 1, VUS 093400, Special Intelligence Service. The program focused on the security of automated systems used in the credit and financial sector. This suggests that students entered the military intelligence track with prior technical knowledge of banking platforms, payment infrastructure, transaction-processing systems, identity controls, fraud detection, and the protection of sensitive financial data.
The available material does not define the operational purpose of this specialization or identify the units that ultimately received its graduates. Its placement under the Special Intelligence Service, however, indicates that the training was likely intended for more than conventional compliance or civilian banking security. The pathway could have prepared personnel to collect intelligence on foreign financial networks, assess the resilience of payment systems, analyze transaction flows, or identify dependencies within banking and economic infrastructure.
Specialization: Безопасность автоматизированных систем в кредитно-финансовой сфере (специального назначения) | “Security of Automated Systems in the Credit and Financial Sector, Special Purpose”
SIS Automated Systems and Credit and Financial Special Purpose Track
A defensive mission is also plausible. Graduates may have been assigned to protect military financial systems, salary and procurement platforms, defense-industrial payment networks, or other automated systems used to fund and sustain Russian military activity. Such responsibilities would require expertise in access control, cryptography, database security, fraud monitoring, incident response, and the continuity of financial operations during conflict or sanctions pressure.
However, the same knowledge would have clear offensive or adversarial value. Personnel familiar with financial-system architecture could support reconnaissance against foreign banks, payment processors, clearing systems, cryptocurrency services, or government revenue platforms. They could identify weak authentication mechanisms, exposed applications, third-party dependencies, and operational choke points that might be exploited for espionage, disruption, manipulation, or theft.
The pathway may also have supported broader economic intelligence missions. Financial data can reveal procurement activity, defense spending, sanctions exposure, supply-chain relationships, and the movement of funds between governments, contractors, and strategic industries. Access to such systems could provide insight into military readiness, covert financing, industrial capacity, and foreign policy priorities.
This specialization therefore appears to bridge financial cybersecurity and military intelligence. It may have produced personnel capable of protecting Russian financial and military-support systems while also assessing or targeting the economic infrastructure of foreign states. The precise mission remains an intelligence gap, but its inclusion within VUS 093400 indicates that financial systems were treated as an operational intelligence and national-security domain rather than a civilian cybersecurity concern.
Operators Teaching Directly Linked to Russian Intelligence Services
The analysis of the Bauman files identify several individuals with direct or strongly documented connections to the Main Directorate of the Russian General Staff, commonly known as the GRU. No comparably substantiated direct personnel links to the Federal Security Service (FSB) or the Foreign Intelligence Service (SVR), were identified in the material reviewed to date. References to domestic security, counterintelligence, surveillance, or foreign intelligence functions should therefore not be treated as proof of FSB or SVR affiliation. The documented personnel network is overwhelmingly GRU-centered.
*Note* The dump also has a full listing of professors and graduates for this period and their GRU placements (MOS) which may be of interest for others in the IC. We have not listed them all here but the documents are available.
Personnel Dossiers
Lieutenant Colonel Kirill Stupakov
Kirill Stupakov was the educational director and deputy head of Department No. 4. Consortium reporting identifies him as a GRU officer who designed parts of the curriculum and managed the department’s relationship with military intelligence. Leaked instructional material attributed to his program covered cyber operations as well as technical surveillance and information warfare. His position placed him between Bauman’s academic administration and the GRU organizations responsible for directing training requirements and receiving graduates.
Stupakov’s résumé reportedly states that he commanded a GRU unit for three years and remained in that position until July 11, 2025. The files also show him preparing evaluations and correspondence for senior GRU officers, indicating that his duties extended beyond classroom teaching. He appears to have managed personnel reporting and student assessment while ensuring that Department No. 4 produced graduates who met operational requirements.
Major General Viktor Borisovich Netyksho
Viktor Netyksho is a senior GRU officer and former commander of Military Unit 26165. The unit is the GRU’s 85th Main Special Service Center and is publicly associated with APT28 and Fancy Bear. Its missions include cyber espionage and credential theft against political and military targets. The United Kingdom identifies Unit 26165 as a long-standing GRU malware-development and intrusion organization.
A Department No. 4 letter dated February 16, 2024 carried Netyksho’s initials and signature. Other correspondence sent departmental staffing and training information to him. These records place him within the program’s evaluation and oversight structure.
The United States indicted Netyksho in July 2018. Prosecutors alleged that he commanded Unit 26165 during operations against U.S. political organizations and the subsequent release of stolen material. The U.S. Treasury designated him in December 2018, and the United Kingdom imposed additional sanctions in July 2025.
Colonel Yuriy Leonidovich Shikolenko
No independently verified public photograph was identified during this research
Yuriy Shikolenko is identified by the United Kingdom as a senior GRU officer. The UK sanctioned him on July 18, 2025 for responsibility for, or support to, malicious cyber activity and his continuing GRU service.
Leaked data shows Shikolenko’s signature on Department No. 4 correspondence concerning student evaluations. The reporting does not establish his exact command position or daily administrative role. His involvement nevertheless shows that senior GRU personnel reviewed the readiness of students expected to enter military intelligence service.
Former Students
Daniil Alekseyevich Porshin
Image of Porshin, born June 26th 2000 from Bauman League Football (Bauman State Tech)
Daniil Porshin attended Bauman University from 2018 through 2024. The leak describes him as one of the strongest students in his cohort and states that he completed Department No. 4 training in subjects that included cryptography and network security as well as offensive techniques such as password attacks and server exploitation.
After graduating in 2024 Porshin was reportedly assigned to GRU Military Unit 26165. No public evidence reviewed links him to a named cyber operation. He should therefore be characterized as a reported unit assignee rather than an established APT28 operator.
Aleksey Stanislavovich Kondrashov
Aleksey Kondrashov graduated from Department No. 4 in 2024 and reportedly received the rank of lieutenant. The leak shows him in his post-graduation assignment with Military Unit 74455. The unit is publicly identified with Sandworm and destructive GRU cyber operations. The UK attributes major disruptive activity to Unit 74455, including operations against Ukrainian telecommunications infrastructure.
The reviewed public record contains little independent biographical information about Kondrashov. No official indictment or public attribution links him personally to a specific Sandworm campaign.
Ivan Makarov / Mark Fisher
Ivan Makarov was born in Moscow in 2001 and enrolled in a Department No. 4 track described by leaked data as counterintelligence-related. In April 2023 he legally changed his name to Mark Fisher. The change reportedly involved replacement identity documents and was reflected in Bauman’s administrative records (МК- Гибкость итог-1.pdf).
Makarov’s father shared a registered address with Military Unit 26165. Journalists have compared the adoption of a generic Western name with identity-development methods used in previous Russian intelligence cases.
No public evidence establishes that Fisher received a foreign assignment or operated under an illegal intelligence cover.
Vladislav Yevgenyevich Borovkov
Vladislav Borovkov is a Bauman University graduate and a GRU officer assigned to Military Unit 29155. The United States charged him and four other GRU officers in September 2024 with conducting cyber operations against Ukraine and organizations in at least 26 NATO countries. The alleged activity included vulnerability scanning and destructive operations associated with the WhisperGate campaign.
Unit 29155 is associated with sabotage and covert action. Western governments have also identified a cyber component within the unit that conducts destructive operations against critical infrastructure and government targets. The United Kingdom sanctioned Unit 29155 as an organization and lists it among the three principal GRU cyber formations.
The leak establishes Borovkov’s attendance at Bauman but does not conclusively demonstrate that he graduated from Department No. 4. His relationship to the department must therefore remain qualified.
Conclusion
The documents show that Department No. 4 is a small part of a larger long-term military training system, not a single hacking unit. The program prepared personnel for espionage and offensive cyber operations within a larger Russian technical university system. Its doctrine treated cyber warfare as more than network intrusion. Students were taught not only adversarial cyber warfare, but also a larger holistic doctrine of cyber war using both defense and attack to be better able to carry out successful campaigns.
Practical exercises trained students to operate as attackers and defenders, reconstruct intrusion chains, analyze malware, and map command infrastructure. Technical courses also covered cryptography, firmware, hardware inspection, physical implants, and secure systems.
The strongest conclusion is institutional. Department No. 4 functions as a military cyber academy producing operators, analysts, planners, defenders, and reserve personnel for several elements of the Russian General Staff (GRU) and give a window into their cyber doctrines and programs.
Despite law enforcement arrests targeting the Silver Fox threat group in mid-June 2026, its malware delivery network remains active as a Malware-as-a-Service (MaaS) platform. Affiliates continue to deploy hundreds of new typosquatted domains and exploit major cloud services to distribute an obfuscated Gh0stRAT variant.
Introduction
In Parts I-IV of this series, we reported on a large-scale malware delivery network targeting Chinese speaking users. This cluster is frequently associated with the Silver Fox threat group and relies on thousands of typo-squatted domains. We noted previously that this infrastructure appeared to operate under an affiliate or Malware as a Service (MaaS) model. In mid June 2026, Chinese law enforcement reportedly arrested several individuals connected to Silver Fox operations. Despite this, the delivery network remained active. Multiple distinct affiliates continued registering hundreds of new malicious domains just days after the arrests. To keep these new campaigns online, the operators are blending localized .com.cn domains with abused legitimate services. We are currently tracking payloads hosted on GitHub release assets, Microsoft Store redirects, and enterprise cloud buckets across AWS, Google Cloud, and Alibaba.
The attackers behind these campaigns use software trends to maximize their infection rates. Their targeting changes based on whatever applications are currently dominating the Chinese market. Two years ago, their landing pages primarily spoofed web browsers and VPNs. Over the past year, they have capitalized heavily on the artificial intelligence boom by distributing fake installers for DeepSeek and Doubao. Regardless of the affiliate or the specific software being spoofed, the underlying infection chain identified in this campaign looks nearly identical. Victims receive a heavily modified Gh0stRAT variant hidden inside installers padded to over 100MB, which allows the malware to bypass file size limits on automated sandboxes. The execution process involves OLLVM obfuscation, a UAC bypass, and Reflective DLL Injection (sRDI) to load the malware directly into legitimate system processes. Once active, the payload communicates with its command and control servers using a custom network stack built on the hp-worker library.
Infrastructure and Lure Variations
Continuous monitoring of this cluster indicates the actor is rapidly diversifying both their distribution methods and their malware lures. While previous campaigns relied heavily on newly registered domains (NRDs), recent activity shows a systemic integration of abused legitimate services to bypass DNS reputation filtering.Analysis of the delivery URLs indicates the actor is hosting payloads across major cloud providers. Observed infrastructure used by the actor previously includes Alibaba Cloud OSS (doubaoaa.oss-cn-hongkong.aliyuncs[.]com), AWS S3 (dfgdhgg.s3.ap-east-1.amazonaws[.]com), and Google Cloud Storage (storage.googleapis[.]com). Additionally, the actor utilizes dynamic linking services like Branch.io (app[.]link), manipulates GitHub release assets, and abuses Microsoft Store search redirects (apps.microsoft[.]com).
To build trust on their landing pages, the actor frequently includes legitimate links to the Apple App Store and Google Play Store for mobile users, while serving the malicious payloads strictly to users downloading the Windows or macOS desktop executables.
Expansion of Spoofed Targets While the actor continues to target users seeking foreign access and trading platforms (ProtonVPN, NordVPN, MetaTrader 5, AICoin), they are increasingly spoofing domestic Chinese software.
Notable additions to the spoofing infrastructure include:
Artificial Intelligence: Capitalizing on current trends, the actor has registered domains spoofing DeepSeek (ai-deepseekapp[.]com[.]cn) and Doubao AI.
Enterprise and Productivity: Lures include DingTalk (Alibaba’s enterprise communication platform), Baidu Netdisk, and Quark Browser.
Security Software: The actor is distributing payloads masquerading as Huorong Security (down.app-huorong[.]cn), a widely used Chinese antivirus and endpoint protection platform.
Post-Arrest and the Affiliate Model
In mid-June 2026, reports indicated that Chinese law enforcement executed arrests targeting operators associated with the Silver Fox malware campaigns. However, pivot analysis of the domain infrastructure reveals that these campaigns continue to be active.
Between June 17 and June 27, 2026, over 400 new malicious domains were registered and provisioned with active hosting. This sustained operational tempo validates a hypothesis generated in Part IV of this series: the malware delivery "super-cluster" operates as a decentralized Malware-as-a-Service (MaaS) platform. Rather than a single monolithic threat actor, the infrastructure is utilized by multiple distinct affiliates or operators who bring their own lures and targeting preferences while utilizing a shared baseline of Gh0stRAT-style payloads and obfuscation tooling.
Infrastructure pivot analysis isolates at least three highly distinct operational profiles active in the post-arrest window:
Cluster 1: The most prolific active cluster is operated by an entity utilizing the email 7cf560423@baituo[.]io and the registrant name "徐涛" (Xu Tao). This operator registered 322 domains in the 10 days following the reported arrests.
TTPs: This operator utilizes a highly rigid, automated infrastructure deployment model. They provision exactly one dedicated Alibaba Cloud HK IP address per spoofed brand campaign. For example, all recent Surfshark lures resolve to 8[.]210[.]120[.]164, Kraken Exchange lures to 47[.]239[.]173[.]17, and Baidu Wangpan lures to 8[.]210[.]196[.]194.
Targeting: This operator focuses heavily on mass-market VPNs, cloud storage, and trending AI tools (DeepSeek, Tencent Yuanbao, Doubao).
Cluster 2: A second distinct operator utilizes the email 3799492994@qq[.]com and the registrant name "崔勇强" (Cui Yongqiang). This actor registered 113 domains in the post-arrest window.
TTPs: Like Cluster 1, this operator provisions dedicated Alibaba Cloud HK IPs (ASN 401696), but groups their infrastructure by specific deployment dates rather than strictly by brand.
Targeting: This actor exhibits a highly targeted focus on financial and enterprise platforms. Lures exclusively target users of MetaTrader 4, MetaTrader 5, TradingView, AiCoin, and specialized enterprise customer service applications like WangshangLiao (旺商聊) and KefuBao (客服宝).
Cluster 3: A third, smaller cluster operates independently from the Alibaba Cloud infrastructure, utilizing a Hong Kong hosting provider named LucidaCloud and the email daliandahouzi@gmail[.]com ("da houzi").
Targeting: This operator specifically targets futures trading platforms, utilizing unique lures such as "奇货神器" (Rare Goods Magic Weapon - a futures trading decision platform).
Traffic Redirection and Analytics Tracking
Consistent with findings in Part II, the operators continue to leverage tracking pixels and redirect hubs to manage campaign traffic. Analysis identified the continued use of Google Analytics 4 (GA4) tags (e.g., G-3GR90RW2M5) embedded across crypto-wallet phishing sites (imToken, AiCoin) to monitor victim interaction.
Additionally, the operators utilize centralized redirect hubs. Domains such as osnenfae[.]xyz (impersonating the OpenClaw AI agent) do not host payloads directly. Instead, these domains function as traffic directors, routing victims to central hubs like opencnwl.com[.]cn where the actual payload delivery mechanisms are hosted. This compartmentalization of infrastructure complicates takedown efforts, as defenders must identify and block both the outer redirector ring and the inner payload hosting hubs.
Sample Sites Spoofing Malicious Software:
Malware Analysis: Modified Gh0stRAT Delivery
Figure 1: Gh0stRAT Malware Execution Chain
The majority of samples analyzed from this recent cluster point to an obfuscated variant of Gh0stRAT. The infection chain utilizes a multi-stage dropper process involving bloated installers, steganography, and compiler-based obfuscation. For the samples reviewed in this campaign, the technical execution chain, obfuscation methods, and final payload structure are nearly identical regardless of the lures.
Inno Setup Bundles
Validating observations from Part IV, the initial payloads are Inno Setup executables artificially padded to sizes ranging from 117MB to over 147MB. The padding is an anti-analysis technique designed to exceed the file size limits of public sandboxes, and security gateways, which are typically around 100-200 MB and subsequently deter automated analysis.
Extracting the Inno Setup files reveals legitimate, digitally signed application binaries bundled with malicious components. In several of the applications observed, the file bundles contain dozens of legitimate applications that serve no purpose other than to increase the file size and the overall application's legitimacy. The setup script utilizes the hidewizard nowait directive, which presents the user with a standard installation GUI while the malicious loader executes silently in the background.
Following the installation routine, execution passes to a 64-bit loader (e.g., XwLOZ.exe). Code analysis of the loader indicates it is heavily obfuscated utilizing OLLVM (Obfuscator-LLVM) and VMProtect/Themida-style protections to complicate control flow analysis. The loader’s primary function is to map a companion DLL (e.g., GQucUJ.WLs) into memory and execute its various exports.
Figure 2: Code Obfuscation Throughout the Execution Chain
Figure 3: Obfuscated Export Names
Once mapped, the DLL searches the local file system for a specific data file dropped during the initial installation phase (e.g., DsHeEOJ6.bG). All DLLs analyzed share the same obfuscation compiler as the EXE loader component.
Payload Decryption
The DsHeEOJ6.bG file is structured to masquerade as an 800x600 PNG image, utilizing the standard %PNG (47 4e 50 89) magic bytes in its header. The DLL allocates a ~10MB memory segment with Read-Write (RW) permissions, removes the PNG headers, and decrypts the underlying payload. Following decryption, it uses VirtualProtect to modify the memory permissions to Read-Write-Execute (RWE) and redirects execution to the decrypted shellcode.
The decrypted shellcode is based on an sRDI (Reflective DLL Injection) implementation and uses the RtlDecompressBuffer API to unpack an embedded PE file into a new memory region.
Figure 4: sRDI Style Shellcode
The shellcode injects the final unpacked DLL payload as a headless PE into a separate, legitimate system process. In observed instances, the malware targets sihost.exe (Shell Infrastructure Host). By executing exclusively within the context of a trusted system process, the malware blends its subsequent network and file operations with normal operating system behavior. Additionally a lightweight watchdog DLL is injected into a separate system process such as uhssvc.exe (Microsoft Update Health Tools). It is worth noting that the DLL payload uses the same obfuscation compiler as the loader EXE and DLL, but the watchdog DLL does not.
To ensure continuous execution of the injected Gh0stRAT payload, the malware establishes a local watchdog mechanism. It drops a batch file into the C:\Windows\ directory utilizing a randomized 8-character filename (e.g., C:\Windows<random_8_chars>.bat). The contents of this script are obfuscated, but de-obfuscation reveals a continuous monitoring loop utilizing system utilities:
Figure 5: Deobfuscated Batch Script
If the tasklist command returns an error, indicating the injected uhssvc.exe process has been terminated, the batch script issues an sc start command to restart the obfuscated malicious service, effectively functioning as a persistent watchdog for the main Gh0stRAT process.
To facilitate execution within protected system boundaries and establish service-based persistence, the payload first performs a User Account Control (UAC) bypass. It achieves this by abusing the ICMLuaUtil elevated COM interface (CLSID {3E5FC7F9-9A51-4367-9063-A120244FBEC7}). This allows the malware to silently elevate its privileges without prompting the user.
Figure 6: UAC Bypass using ICMLuaUtil COM Interface
Configuration and Capabilities
Prior to initiating network communications, the injected payload reads its configuration from a hardcoded path: C:\ProgramData\C46EEF09DFB549819FACDBF1C9081293\config.ini.
The configuration file is XOR-encrypted using a static 0x62 key. Decryption yields operational parameters, versioning (version=s9C4pg==), and campaign group identifiers (e.g., group=tLa0uLa4tLim).
Figure 7: Decrypted Configuration File
Secondary persistence is established by copying an executable to a randomized path within the C:\msys64\ directory (e.g., C:\msys64\IHGW\qqit\aqzaeX\wKBe\yD4C7.exe). This executable is registered and launched as a service via cmd.exe.
Analysis of the unpacked payload confirms the core capabilities of Gh0stRAT. Extracted API calls show standard GDI and GDI+ functions (GdipCreateBitmapFromHBITMAP, BitBlt, StretchBlt) for screen capture, as well as SetWindowsHookExW and GetAsyncKeyState for keylogging. The payload utilizes WMI queries (ROOT\CIMV2) for system enumeration.
The payload also contains strings indicating targeted data collection and evasion. It queries specific paths for WeChat, Telegram, and regional browsers (e.g., %s\360se6\User Data\Default, NoLogWechat, NoLogTG). Additionally, the code checks for the presence of 360Hvm64.sys, a component of Qihoo 360 security software, indicating specific anti-analysis measures for Chinese operating systems.
Command and Control (C2)
Code analysis reveals class structures such as CTcpPackClientT, IPackClient, and CTcpClient, indicating the use of hp-worker (High-Performance Socket), an IOCP-based C++ networking library. This aligns with past observed behavior of other Gh0stRAT variants, which also utilize updated C++ network libraries to manage asynchronous data streams.
Figure 8: Network Data Stream for Gh0stRAT
Alternative Gh0stRAT Variant:
While the OLLVM/Inno Setup chain is the most prevalent in this cluster, analysis of AiCoin lures (e.g., AIcosin_x64.exe) revealed a distinct, secondary infection chain.
Like the primary variant, the initial installer is padded (~163MB); however, it utilizes an Advanced Installer package rather than Inno Setup. Execution relies on a DLL sideloading against a legitimate dropped executable (e.g., BrowserProtect.exe). The malicious DLL (DataState.dll) is 20MB in size and, notably, is signed with a valid Authenticode certificate issued to a Chinese company ("Shanxi 90s Catering Management Co., Ltd."). The use of a valid, stolen, or otherwise fraudulently obtained certificate allows the payload to bypass initial Mark-of-the-Web (MoTW) and endpoint trust checks.
This alternative chain lacks the compiler-level obfuscation seen in the primary variant. An injected DLL decrypts the final embedded payload, which matches publicly available Gh0stRAT code.
Indicators of Compromise (IoCs)
Inno Setup Installer Cluster
The majority of these samples share a common pattern: 32-bit Inno Setup installers built with a Delphi (XE2–XE6) compiler and Turbo Linker. Each drops 3 embedded files and beacons to 2 C2 addresses (a domain + an IP:port pair).
Intelligence Report: The Zedxion Corporate Nexus for Illicit Iranian Financial Funds Transfer for IRGC Entities.
DomainTools Investigations exposes the Zedxion and Zedcex ecosystem—a layered financial architecture leveraging disposable UK shell companies, persistent digital tokens, and UAE-based trade fronts to facilitate IRGC-linked sanctions evasion and illicit Iranian funds transfers.
Foreword
DomainTools Investigations began investigating the Zedxion Cryptocurrency Exchange in July 2025 thanks to an external partner coming to us with the question “Does anything look strange about this domain?” We continued our investigation into the Zedxion Exchange in partnership with TRM Labs who first published their own research on the Exchange in January 2026. Publishing in threat intelligence can be a tough balance to navigate. At the time, we determined holding the information closely and relaying only to trusted partner agencies was the right call. Given the attention Zedxion and Babak Zanjani have received this year, we now feel comfortable releasing our full writeup on not just the cryptocurrency angle but the much larger sanctions evasion mechanisms involved, including commodity goods and more. Signals point to BZ Group (and likely IRGC) moving towards establishing regional banking app(s) in order to more effectively obscure their transactions and mitigate disruption or takedown. We release this report to provide fuller context on the network and mechanisms involved to inform future enforcement efforts.
Executive Summary
This report documents a multi-jurisdictional corporate and digital network centered on the ZEDXION and ZEDCEX exchanges, the ZedPay payments layer, and the broader BZ Group ecosystem spanning the United Kingdom and the United Arab Emirates. When examined holistically, the constellation does not resemble a conventional cryptocurrency enterprise. Instead, it presents as a layered financial architecture in which legal entities, branding assets, governance actors, and digital infrastructure perform distinct and compartmentalized functions.
At the corporate level, the UK serves as a recurring incorporation platform. Companies are formed with high nominal capitalization, frequently £1,000,000, yet file dormant or non-trading accounts and exhibit no verifiable operating revenue. These entities are restructured, mirrored, or dissolved as exposure increases. ZEDXION EXCHANGE LTD and ZEDCEX EXCHANGE LTD reflect this pattern: structurally similar exchange vehicles, one absorbing litigation and regulatory pressure while the other preserves brand continuity and operational optionality. The dissolution of BZ BROKER LIMITED and the short lifecycle of BZ DIAMOND LTD reinforce the conclusion that UK entities function primarily as disposable regulatory interfaces rather than durable operating companies.
Governance patterns further support this interpretation. The record shows coordinated, short-tenure director appointments during restructuring phases, including the appointment of Mehdi Rezazadeh as a director of Mining Consultancy Ltd from December 2017 to March 2018. His synchronized appointment and resignation alongside parallel officers align with a formation-phase governance layer rather than sustained executive control. Such actors appear during transitional moments and withdraw before long-term consolidation occurs. In contrast, operational authority becomes progressively centralized after 2022 under Elizabeth Newman, whose directorship and PSC status coincide with infrastructure persistence rather than operational contraction. Earlier officers exit filings, but brand continuity and digital control remain intact.
Above this governance layer sits a durable digital infrastructure. Core domains, mail hosts, and token assets persist across corporate restructuring events. The ZEDXION token, issued on ERC-20 and BEP-20 standards, extends the exchange narrative into a capital-formation mechanism that operates independently of dormant UK filings. ZedPay adds a further segmentation layer: a payments-branded rail aligned with the exchange ecosystem yet not structurally identical to the exchange shells themselves. This separation of exchange, token, and payments branding reduces concentration risk and allows functional continuity even if individual entities become legally encumbered.
The broader branding architecture relies heavily on financial nomenclature designed to imply regulated status. IBAN-branded entities and bank-evocative domains adopt institutional terminology without corresponding licensing in the claimed jurisdictions. This pattern of confidence laundering is consistent across exchange, brokerage, and payments branding. The effect is the projection of legitimacy through corporate form and semantic signaling rather than through demonstrable regulatory compliance.
The upstream origin of the ecosystem traces to Babak Morteza Zanjani, whose early directorship of ZEDXION EXCHANGE LTD and broader BZ-branded commercial footprint provide the strategic and brand foundation from which subsequent entities descend. Although his formal withdrawal from UK filings creates the appearance of disengagement, domain persistence, brand continuity, and UAE-based operational anchoring suggest strategic repositioning rather than structural separation.
The risk profile escalates materially with the intersection of litigation and sanctions enforcement. U.S. federal court filings allege that Zedxion Exchange facilitated the laundering of fraud-derived proceeds. More significantly, the U.S. Department of the Treasury’s Office of Foreign Assets Control designated Zedxion-associated entities for sanctions-evasion and financial facilitation activity benefiting the Islamic Revolutionary Guard Corps. These actions shift the analytical frame from regulatory non-compliance to national-security-relevant sanctions exposure.
Taken together, the evidence describes a deliberate operational doctrine: companies are cycled, governance is stratified, infrastructure persists, and branding is diversified across exchange, payments, and trade narratives. The United Kingdom functions as a flexible incorporation venue, while the United Arab Emirates anchors the durable operational and branding base. Short-tenure formation actors such as Rezazadeh appear during transitional phases, while centralized control consolidates around trusted operators as risk intensifies.
This inversion where people and domains are stable while companies are ephemeral is characteristic of mature, risk-managed financial facilitation networks operating in the gray space between crypto-assets, offshore jurisdictions, and sanctions exposure. Whether ultimately categorized as fraud-facilitating infrastructure, sanctions-evasion-adjacent finance, or high-risk offshore exchange activity, the Zedxion / Zedcex / ZedPay / BZ constellation presents a structured system engineered for resilience, exposure management, and continuity under scrutiny rather than for transparent, regulated commercial exchange operations.
How these connections could be leveraged:
The ecosystem mapped across the Zedxion, Zedcex, ZedPay, IBAN-branded entities, and the broader BZ Group can be rationalized as a vertically layered financial architecture capable of transforming commodity-derived value such as proceeds from sanctioned oil into mobile digital assets insulated from traditional banking enforcement.
At the apex sits Babak Morteza Zanjani, whose historical association with sanctions exposure and oil-linked financial maneuvering provides the strategic origin point of the structure. His early directorship of ZEDXION EXCHANGE LTD, alignment with BZ-branded entities, and continued gravitational presence through UAE-linked commercial infrastructure suggest that the exchange ecosystem did not arise independently, but rather descends from a pre-existing trade and finance network. In this configuration, Zanjani functions less as a visible operator and more as a systemic architect whose commercial footprint anchors the broader constellation.
If sanctioned oil is monetized, the primary constraint is not the physical commodity, but the financial settlement. Sanctions regimes target correspondent banking channels, dollar clearing systems, and SWIFT connectivity. Therefore, the initial objective of any sanctions-evasion mechanism is to convert commodity shipments into funds outside the reach of U.S.-controlled banking rails. The UAE provides a permissive trade environment and access to regional banking relationships, while Turkey historically functions as a corridor for metals and commodity clearing. Within this ecosystem, the UAE-based BZ Group entities form the durable commercial base capable of anchoring trade activity, issuing invoices, and receiving settlement in regional currencies such as dirhams.
Once oil-derived value is monetized regionally, the next problem is abstraction. Funds tied directly to commodity transactions remain vulnerable if traceable through conventional banking channels. This is where IBAN-branded and bank-evocative entities become relevant. Entities such as IBAN 2 IBAN TRANSACTION & PAYMENT SOLUTIONS LTD and CAISSE REGIONALE DE CREDIT AGRICOLE MUTUEL FINANCE LTD adopt institutional nomenclature that implies regulated settlement authority without corresponding licensing. Whether functioning as active financial intermediaries or as narrative scaffolding, they provide a settlement layer that distances trade proceeds from their origin through layered transfers and inter-entity routing.
The introduction of ZedPay adds a critical intermediary stage. As an exchange-adjacent payments rail, ZedPay bridges fiat settlement structures and crypto conversion platforms. In architectural terms, it sits between trade monetization and exchange liquidity. Funds aggregated through trade or banking-façade entities can be routed into ZedPay-branded channels, creating the appearance of platform-based payment processing rather than direct commodity settlement. This segmentation reduces exposure concentration and separates liability across corporate wrappers.
The exchange layer ZEDXION EXCHANGE LTD and ZEDCEX EXCHANGE LTD then provides the conversion mechanism. Once funds enter the exchange environment, they can be transformed into stablecoins or other cryptocurrencies, transferred internally across accounts, or moved on-chain beyond conventional banking controls. At this stage, the value no longer depends on correspondent banking systems. It exists as digital assets capable of rapid cross-border movement, layering, or reintegration into financial systems under altered provenance. The designation of these exchanges by OFAC for sanctions-evasion activity underscores the risk profile inherent in this conversion capability.
Governance stratification reinforces the structural logic. Zanjani occupies the upstream strategic position. Elizabeth Newman consolidates operational control at the UK corporate interface after 2022. Transitional actors, including Mehdi Rezazadeh and others, appear during formation or restructuring windows, then recede. UK companies cycle through incorporation and dormancy, absorbing regulatory pressure when necessary. The UAE layer persists as the durable operational anchor. This separation between strategic origin, operational control, formation-phase actors, and corporate wrappers is characteristic of risk-managed financial structures rather than linear commercial enterprises.
Viewed as a whole, the architecture functions as a sequence of transformations: commodity to regional currency, regional currency to settlement abstraction, abstraction to platform-based payment routing, payment routing to crypto conversion, and crypto conversion to globally mobile digital value. Each stage introduces distance from the original sanctioned commodity transaction. Each layer distributes exposure across jurisdictions and entities. The system does not rely on a single company or officer; it relies on structural segmentation and persistence of digital infrastructure.
This narrative does not assert that every participant knowingly facilitates sanctions violations. Rather, it explains how the ecosystem’s design, its jurisdictional arbitrage, disposable corporate shells, banking-style nomenclature, payments segmentation, and exchange conversion capability could operate as a contemporary sanctions-evasion mechanism consistent with oil-derived value movement and subsequent crypto-based mobility.
Key Judgments (High Confidence)
Elizabeth Newman (Potential cutout individual personna) is the post-2022 operational nexus She appears across governance, infrastructure, token promotion, and litigation, with evidence of operational involvement preceding formal directorships.
UK corporate entities are disposable; digital infrastructure is not Domains, mail servers, and token branding persist across dissolved or dormant companies.
Babak Zanjani represents strategic origin, not day-to-day control His withdrawal from UK filings coincides with governance “clean-up,” not shutdown.
The BZ UAE group provides the enduring commercial backbone UAE-based entities and branding outlast UK shells and anchor operations in a permissive jurisdiction.
Financial branding materially exceeds regulatory reality “Bank,” “IBAN,” and “exchange” labels create implied legitimacy without licenses.
Principal Individuals
The network of entities associated with Zedxion, Zedcex, and the broader BZ constellation is best understood through the individuals who occupy key control, transitional, and peripheral roles within it. Rather than presenting as a conventional corporate management structure, the pattern of personnel observed across filings, infrastructure, and operational touchpoints reflects a deliberate, layered approach to governance. Authority, risk, and visibility are distributed unevenly, allowing the network to preserve operational continuity while periodically reconfiguring its formal corporate face.
From an analytical perspective, the principal individuals serve distinct functions within this architecture. Some operate as upstream strategic figures, shaping branding, capital flows, and ecosystem design without remaining visible in day-to-day corporate governance. Others function as operational controllers, consolidating formal directorships and PSC status during periods of heightened regulatory or legal exposure. A third category consists of transitional or nominee-like actors, whose brief appearances align with early formation phases or entity restructuring, and who do not persist as the network matures. Finally, certain individuals occupy commercial or retail-facing roles, providing legitimate-appearing business activity that coexists alongside more opaque financial or exchange operations.
This section introduces the principal individuals within the Zedxion–BZ ecosystem and situates them within this control framework. It traces how leadership and ownership evolve over time, how technical and commercial responsibilities are compartmentalized, and how branding and infrastructure persist despite changes in formal governance. Understanding these individuals and their respective roles is essential to interpreting the network not as a series of isolated companies, but as an integrated system designed to manage risk, obscure attribution, and sustain long-term operational capability.
Newman emerged as the central node of the network from mid-2022 onward. She is the sole or dominant director across ZEDXION EXCHANGE LTD, ZEDCEX EXCHANGE LTD, and BZ BROKER LIMITED, and is linked to operational infrastructure via:
An early-2022 Zendesk profile referencing developer@zedxion[.]com, predating her UK directorship.
Public token-exchange correspondence (VinDAX) signed in her name.
Service of U.S. federal court summons at the Shelton Street address used across Zedxion entities.
Her consolidation coincides with the removal of higher-risk legacy figures from UK filings while maintaining functional continuity.
Zanjani served as an early director of ZEDXION EXCHANGE LTD (2021–2022). His wider business footprint, Sorinet Group, Avan Financial & Economic Development Group, and BZ Group AE (UAE) forms the upstream ecosystem from which Zedxion branding and infrastructure appear to descend.
Although he exited UK governance in 2022, branding continuity, domain persistence, and UAE group activity suggest strategic rather than operational disengagement.
Solmaz Bani aka Sara Bani
Role: Director and PSC, BZ DIAMOND LTD
Bani controlled BZ DIAMOND LTD, a short-lived UK entity with EU-denominated shares and UAE service addresses. The company exhibits classic shell characteristics: sole controller, rapid rebranding, and dissolution once utility is exhausted.
Bahareh Zanjani
Open-source corporate and technical records identify BZ Diamond (bzdiamond.ae) as a Dubai-based commercial entity operating under the BZ- branding convention observed elsewhere in the broader BZ ecosystem. Bahareh Zanjani is identified through professional and commercial listings as the owner-operator of BZ Diamond, exercising apparent managerial and commercial control over the business.
Independent domain-registration data for bz-diamond[.]com attributes the creation and administrative registration of the domain to Solmaz Bani, indicating a separation between technical control of digital infrastructure and public-facing commercial ownership. This division where domain creation and control are held by an individual distinct from the listed owner-operator is consistent with patterns observed elsewhere in the network, in which branding and operational continuity are maintained through shared infrastructure rather than transparent corporate filings.
The use of BZ-prefixed branding by BZ Diamond aligns it nominally with other BZ-associated entities, though no formal regulatory filings or enforcement actions currently place BZ Diamond (bz-diamond[.ae]) itself under sanctions or name it directly in OFAC designations. Nevertheless, the convergence of (a) the Zanjani surname, (b) shared branding conventions, and (c) domain-level control by a separate affiliated individual warrants analytical treatment of BZ Diamond as part of the extended commercial perimeter of the BZ constellation, rather than as an isolated retail enterprise.
From an intelligence perspective, BZ Diamond appears to function as a legitimate-appearing commercial node within a wider environment characterized by shell-company cycling, branding persistence, and infrastructure reuse. While distinct from the crypto-exchange operations of ZEDXION / ZEDCEX, its ownership and technical-control structure reflects the same compartmentalization logic, separating public ownership, operational control, and digital infrastructure to reduce transparency and complicate attribution.
Mehmet Hasancebi and Sara Bani
Role: Transitional directors
Both appear in IBAN 2 IBAN TRANSACTION & PAYMENT SOLUTIONS LTD, an early payments-branded entity. Their short tenures and lack of downstream continuity are consistent with nominee or transitional governance during early network formation.
Erol Bulbul and Mustafa Ozkan
Role: Directors / PSCs, IBAN-branded entities
These individuals control or initially controlled IBAN 2 IBAN LTD / CAISSE REGIONALE DE CREDIT AGRICOLE MUTUEL FINANCE LTD, a renamed UK company whose branding deliberately evokes legitimate European banking institutions despite no such affiliation.
Corporate Entity Analysis (UK)
The UK-registered companies associated with the Zedxion and BZ ecosystem do not operate as conventional commercial enterprises. Instead, they function as a regulatory interface layer, a set of entities designed to absorb legal exposure, project legitimacy, and provide corporate scaffolding, while remaining operationally thin, dormant, or short-lived. When examined collectively, these companies exhibit recurring structural features: high nominal capitalization with no corresponding trading activity, rapid director consolidation, parallel or mirrored entity creation, and timely dissolution aligned with rising litigation or reputational risk.
This section analyzes the principal UK corporate entities within the network and situates them within the broader organizational logic. The evidence indicates that UK companies are not the durable core of operations, but rather disposable shells used for branding, exchange presentation, payments signaling, and regulatory positioning. Governance changes — most notably the transition from Babak Morteza Zanjani to Elizabeth Newman — are best understood as risk-management maneuvers rather than indicators of operational disengagement or restructuring.
By contrast, the behavior of these UK entities becomes intelligible when viewed alongside the network’s UAE-based companies. While UK firms cycle through incorporation, dormancy, and dissolution, the UAE layer persists, anchoring branding, officer residency, and service locations. The UK therefore appears to function as a sacrificial jurisdiction, optimized for flexibility and deniability, whereas the UAE serves as the durable operational base.
The following analysis evaluates each UK entity in turn ZEDXION EXCHANGE LTD, ZEDCEX EXCHANGE LTD, BZ BROKER LIMITED, BZ DIAMOND LTD, and the IBAN-branded companies focusing on their stated function, governance profile, lifecycle, and role within the wider network. Together, these entities illustrate a coherent pattern of shell-company cycling, confidence signaling, and continuity planning that is inconsistent with ordinary commercial practice and indicative of a mature, risk-aware corporate architecture.
Zedxion presents itself publicly as a high-volume crypto exchange while filing dormant accounts. It is explicitly named in U.S. litigation alleging facilitation of fraud proceeds laundering. Governance shifts from Zanjani to Newman align with reputational risk management rather than operational change.
Despite its dormant corporate filings, exchange-branded infrastructure, token promotion, and exchange-adjacent payment mechanisms continue to operate in parallel, suggesting functional continuity independent of UK corporate reporting.
Zedcex mirrors Zedxion structurally but is “cleaner”: single director (Newman), no legacy officers, and identical capital patterns. This suggests continuity planning — a ready replacement entity if Zedxion becomes legally encumbered.
The parallel existence of Zedcex further reinforces the network’s entity-redundancy doctrine: one exchange vehicle may absorb litigation or regulatory pressure while another preserves brand continuity and operational optionality.
ZedPay operates as the payments-facing extension of the Zedxion ecosystem. While not structured as a standalone UK exchange company in the same manner as Zedxion or Zedcex, it functions as a transactional bridge within the broader network, aligned with the zed-pay[.]com domain infrastructure identified in Appendix C.
The presence of a payments-branded node separate from the exchange entities reflects layered architecture design:
Exchange front-end (Zedxion / Zedcex)
Token layer (ZEDXION token)
Payments rail (ZedPay / Zed-Pay)
This segmentation reduces concentration risk. Should exchange entities face regulatory constraint, payment-branded infrastructure may continue facilitating value transfer under a distinct commercial narrative.
Unlike Zedxion and Zedcex, ZedPay does not appear in dormant UK filings with declared £1,000,000 capital; instead, it operates primarily at the digital-brand and infrastructure level. This divergence further illustrates the inversion observed throughout the ecosystem: operational functionality persists at the domain and branding layer even where corporate shells remain dormant or are dissolved.
BZ BROKER LIMITED
Function: Brokerage shell Status: Dissolved 2025
This entity follows the same pattern: high nominal capital, sole director/PSC (Newman), no trading, and short lifespan. Its dissolution coincides with heightened litigation risk around Zedxion.
BZ Diamond connects the UK shell ecosystem to BZ trade branding seen in UAE entities. It demonstrates how commodity-themed companies are used briefly and discarded.
IBAN-Branded Entities (IBAN 2 IBAN)
Function: Payments / banking façade
Entities operating under “IBAN” and “Credit Agricole”-like names represent confidence laundering through nomenclature, implying regulated banking relationships without authorization.
The BZ UAE Group
The BZ Group AE (UAE) and related UAE-based businesses represent the persistent core of the network. Unlike UK entities, which are routinely dissolved, UAE companies:
Remain active longer.
Anchor branding (BZ, Zed, bank-like services).
Provide operational addresses and service locations for officers.
This pattern strongly suggests that the UK serves as a disposable regulatory interface, while the UAE functions as the durable operational base.
Digital & Token Infrastructure
Introduction — Digital & Token Infrastructure
The digital and token-layer assets associated with the Zedxion ecosystem provide a critical lens into how operational continuity is maintained independent of formal corporate structures. While UK entities are incorporated, rebranded, or dissolved over time, domains, email infrastructure, and tokenized products persist, functioning as the durable connective tissue of the network. This persistence underscores a key analytical distinction: legal entities change, but digital control does not.
From an intelligence perspective, domains and email systems represent higher-fidelity indicators of real control than corporate filings. The continued use of core domains such as zedxion[.]com and zedcex[.]com, alongside consistent mail-host configurations, demonstrates infrastructure stability across governance transitions. Email evidence linking Elizabeth Newman to operational addresses further collapses the distinction between nominal directorship and active technical control, reinforcing her role as a central operator rather than a passive corporate officer.
The token layer extends this digital infrastructure into a capital-formation and legitimacy-signaling mechanism. The ZEDXION token issued on both BEP-20 and ERC-20 standards is marketed in parallel with the exchange itself, despite the exchange’s dormant corporate posture. Promotional and listing materials signed by Newman position the token as a growth and investment vehicle, effectively decoupling capital-raising narratives from regulated exchange activity. In this configuration, the token functions not merely as a product, but as an auxiliary financial rail that leverages branding, community perception, and speculative demand without the disclosures or controls expected of a regulated financial institution.
This section examines the digital and token infrastructure in detail, focusing on how domains, email, and token issuance operate as continuity mechanisms. Together, they reveal how control, fundraising, and market presence are sustained even as corporate shells are cycled, dissolved, or legally constrained — highlighting the central role of digital assets in preserving operational resilience and obscuring accountability.
Domains and Email
Domains such as zedxion[.]com, zedcex[.]com, and their mail hosts persist across corporate changes. Email evidence ties Newman directly to operational control.
Token Layer
The ZEDXION token (BEP-20 / ERC-20) is marketed alongside the exchange, with listing materials signed by Newman. Token promotion provides a capital-raising narrative decoupled from regulated exchange activity.
Financial Flows and Allegations
Alleged Fraud Proceeds In Evans v. BlofinTYU et al., plaintiffs allege that approximately $348,907.18 in fraud proceeds were routed through Zedxion Exchange. While unproven in court, this allegation aligns with broader concerns about the exchange’s architecture: an exchange front-end with limited financial transparency and offshore operational control.
OFAC Sanctions and Sanctions Evasion Concerns On January 30, 2026, the U.S. Department of the Treasury’s Office of Foreign Assets Control (OFAC) designated ZEDXION EXCHANGE LTD alongside ZEDCEX EXCHANGE LTD on the Specially Designated Nationals (SDN) list under Iran-related sanctions authorities. Both entities were sanctioned for operating within Iran’s financial sector and processing cryptocurrency transactions linked to the Islamic Revolutionary Guard Corps (IRGC) and other Iranian actors, marking the first time OFAC has designated digital asset exchanges themselves rather than only wallets or individuals for such conduct. (OFAC)
OFAC’s designation subjects these companies to blocking sanctions: all U.S. property in which they hold an interest is frozen, and U.S. persons are generally prohibited from engaging in transactions with them. According to enforcement reporting, Zedcex alone has reportedly processed more than $94 billion in transactions since its launch in August 2022, and multiple wallet addresses associated with the exchanges have been publicly identified by sanctions enforcement and blockchain analysis firms as conduits for Iran-linked financial flows. (OFAC)
The designation also targets Babak Morteza Zanjani, a long-standing Iranian businessman previously sanctioned for sanctions-evasion activity and connected to the formation and branding of these exchanges, reinforcing the connection between the entities and sanctioned actors. (U.S. Department of the Treasury)
This regulatory action elevates the risk profile of Zedxion beyond private litigation. Rather than merely alleging facilitation of illicit proceeds, U.S. authorities have determined — based on on-chain data, governance ties, and transactional patterns — that Zedxion and its structural equivalents have served as infrastructure nodes supporting sanctioned state interests and sanctions-evasion activity.
Declared vs. Real Capital The repeated declaration of £1,000,000 in share capital for Zedxion and structurally similar UK entities appears nominal and unrelated to verifiable economic activity. There is currently no evidence of corresponding operating cash flows, bank accounts, or revenue consistent with a functioning high-volume exchange. Given OFAC’s designation citing substantial sanctions-evasion flows and the dormant account filings, the mismatch between declared capital and actual on-chain transaction volumes further underscores the discrepancy between regulatory form and operational reality.
Extant Corporate Connections to the Sitki Ayan Sanctions Evasion Program
This section evaluates whether any demonstrable corporate, financial, or operational linkage exists between the sanctions-designated oil monetization network attributed to Sitki Ayan and the fintech and exchange ecosystem associated with Babak Zanjani, including ZedPay and Zedxion.
The analytical catalyst for this review is ZedPay’s publicly available licensing disclosure, captured in the uploaded image above, in which the company asserts that it is “fully licensed and regulated,” specifically stating that its Turkish e-money licensing is conducted “through collaboration with Vepara and Vakıf Katılım Bank,” and that its Canadian FINTRAC registration is held in collaboration with BZ-Payment. This representation establishes a declared institutional relationship between ZedPay and two Turkish financial entities: Vepara and Vakıf Katılım Bankası A.Ş..
The question is whether those institutions intersect in any documented way with the Ayan sanctions evasion structure.
Public U.S. Treasury and Department of Justice filings describe the Ayan architecture as a layered sanctions-evasion program designed to facilitate Iranian oil sales on behalf of the Islamic Revolutionary Guard Corps Qods Force. That network relied on Gibraltar holding companies, Turkish energy trading firms, UAE intermediaries, and shadow-fleet maritime assets to obscure crude origin, manage discounted oil sales, and route proceeds back to IRGC-linked beneficiaries. The Ayan program was commodity-centric, logistics-heavy, and constructed around physical oil movement supported by corporate camouflage and documentation manipulation.
Notably, neither Vepara nor Vakıf Katılım Bank appears in OFAC designation materials related to Sitki Ayan. No SDN listing, Federal Register entry, or DOJ indictment identifies those institutions as participants in, facilitators of, or correspondents to the Ayan oil network. There is no presently available public evidence tying those Turkish financial institutions to Ayan’s sanctioned entities.
By contrast, the Zanjani-linked ecosystem operates in a different vertical. Rather than brokering crude oil shipments, the ZedPay/Zedxion infrastructure centers on digital finance: electronic money services, token issuance, exchange operations, and cross-jurisdictional corporate shells designed to sustain brand continuity across entity changes. The uploaded ZedPay disclosure confirms that this fintech architecture anchors its Turkish regulatory narrative in relationships with Vepara and Vakıf Katılım Bank, suggesting reliance on licensed Turkish financial rails for settlement, e-money issuance, or custodial services.
At the evidentiary level, there is no demonstrated corporate bridge between the Ayan network and the Zanjani fintech ecosystem. There is no documented shared ownership, no overlapping directors or shareholders, no correspondent banking disclosures linking Vakıf Katılım to Ayan-designated firms, and no regulatory action tying Vepara to Ayan’s oil operations. The two networks remain operationally distinct in publicly verifiable records.
However, structural parallels are evident. Both architectures emerged in sustained sanctions environments. Both rely on multi-jurisdictional layering. Both deploy commercial façades to generate legitimacy signaling. Both utilize Turkish corporate or financial infrastructure as part of their operational geography. In the Ayan case, Turkey functioned as a base for energy trading fronts and logistics entities. In the ZedPay case, Turkey serves as the jurisdictional anchor for electronic money licensing through regulated institutions.
This convergence is jurisdictional and architectural, not transactional.
Turkey’s historical role as a commercial bridge in Iran-related sanctions contexts introduces geopolitical sensitivity. The Ayan program demonstrates how Turkish corporate vehicles were used to facilitate high-value oil monetization under sanctions pressure. The ZedPay disclosure demonstrates that Turkish licensed financial institutions underpin the compliance narrative of a Zanjani-linked fintech platform. These facts coexist, but they do not currently intersect.
From an intelligence assessment standpoint, the relationship between the two networks is best characterized as structural adjacency. They operate in similar geopolitical and regulatory environments, and they exhibit comparable design logic: delegate monetization to semi-private intermediaries, layer corporate entities across jurisdictions, and foreground licensing language to mitigate counterparty risk perception. Yet there is no publicly documented evidence of coordination, integration, or shared operational infrastructure.
Accordingly, the present record supports three conclusions:
ZedPay publicly claims reliance on Turkish regulated financial institutions.
Sitki Ayan’s sanctions-designated network relied heavily on Turkish corporate infrastructure for oil monetization.
No documented corporate or financial overlap between the two systems has been identified.
Absent registry-level shareholder convergence, enforcement findings, correspondent banking disclosures, or transactional tracing, the two networks remain analytically comparable but evidentially separate. That said however, it is the assessment of this investigation that the connections be scrutinized more closely by authorities to determine how they may operate to evade sanctions and move finances outside of the law.
Tradecraft and Pattern Assessment
This section synthesizes the preceding corporate, financial, and digital analyses into a coherent tradecraft and pattern assessment. Rather than treating each company, domain, or individual in isolation, the focus here is on recurring behaviors that, taken together, reveal an intentional operational doctrine. These patterns are not incidental artifacts of poor management or startup failure; they are repeatable techniques used to manage risk, preserve control, and maintain functional continuity in the face of regulatory, legal, or reputational pressure.
From an intelligence and counter–financial-crime perspective, such indicators function as behavioral signatures. Shell-company cycling, infrastructure persistence, and rapid governance consolidation are well-established methods for insulating core operations from enforcement actions while preserving outward legitimacy. Jurisdictional arbitrage leveraging the procedural flexibility of UK corporate filings while anchoring operations in the UAE further reinforces this interpretation, enabling regulatory exposure to be shifted without disrupting underlying activity.
Equally significant is the consistent use of confidence laundering: the deliberate adoption of bank-like or exchange-like naming conventions, capital structures, and branding that imply regulatory oversight or institutional legitimacy where none exists. When combined with the observed digital and token infrastructure, these techniques form a layered system designed to blur the boundary between lawful enterprise and opaque financial activity.
The indicators summarized below are therefore assessed not as isolated red flags, but as components of an integrated pattern. Together, they describe a mature, risk-aware network employing established tradecraft to obscure attribution, manage exposure, and sustain operations over time.
Indicator
Assessment
Shell cycling
Repeated short-lived UK companies
Domain persistence
Infrastructure outlives corporations
Control consolidation
Shift to single trusted director
Jurisdictional arbitrage
UK filings, UAE operations
Confidence laundering
Bank/exchange naming without licenses
Overall Assessment
The Zedxion / Zedcex / BZ constellation does not exhibit the characteristics of a bona fide cryptocurrency exchange group. Instead, the totality of evidence indicates a financial façade ecosystem. A deliberately structured network of legal entities, digital infrastructure, and branding designed to project legitimacy while minimizing transparency, accountability, and regulatory exposure.
Across corporate filings, governance changes, digital assets, and token activity, the architecture consistently favors resilience over compliance. UK companies are incorporated with high nominal capitalization, rendered dormant or non-trading, and dissolved when exposure increases. Parallel entities are created to preserve brand presence and operational optionality, allowing functions to migrate without interruption. Domains, email infrastructure, and token products persist across these transitions, ensuring continuity even as legal wrappers are discarded.
Control dynamics further reinforce this assessment. Governance consolidates around a small number of trusted operators at moments of heightened risk, while upstream or legacy figures withdraw from formal roles without any corresponding loss of branding or functional alignment. This separation between strategic influence, operational control, and public-facing ownership is a hallmark of risk-aware financial tradecraft rather than ordinary corporate evolution.
Jurisdictional behavior is equally telling. The United Kingdom appears to function as a disposable regulatory interface useful for incorporation, signaling, and limited legitimacy while the United Arab Emirates serves as the durable operational and branding anchor. This bifurcation enables regulatory arbitrage and complicates enforcement, particularly when combined with confidence-laundering techniques such as bank-like or exchange-like naming conventions unsupported by licenses or disclosures.
Taken together, the network is optimized for:
Rapid entity replacement in response to legal or reputational pressure.
Brand and infrastructure continuity independent of corporate survival.
Reduced personal exposure for upstream or strategic figures.
Sustained operation within regulatory gray zones across jurisdictions.
Whether ultimately characterized as fraud-facilitating infrastructure, sanctions-evasion-adjacent finance, or a high-risk offshore exchange and token ecosystem, the Zedxion / Zedcex / BZ network presents material financial-crime risk. The consistency and intentionality of the observed patterns argue against mismanagement or coincidence and instead support the conclusion that this is a mature, deliberately engineered system designed to obscure attribution, manage exposure, and preserve financial throughput under adverse scrutiny.
Appendix A: CORPORATE OFFICER & PSC CITATIONS
CORPORATE OFFICER & PSC CITATIONS
Zedxion / Zedcex / BZ / IBAN Entities
Elizabeth Newman
Roles:
Director
Person with Significant Control (PSC)
Operational controller (post-2022)
Cited PDFs:
13404089_psc01_2022-08-19.pdf PSC notification establishing Elizabeth Newman as controller
ZEDXION EXCHANGE LTD people - Find and update company information - GOV.UK.pdf Official Companies House snapshot listing Newman as director / PSC
13404089_ap01_2022-08-17.pdf Director appointment / governance change
13404089_cs01_2023-05-12.pdf Confirmation statement reflecting updated control
13404089_cs01_2024-05-15.pdf Confirmation statement confirming continued control
13404089_tm01_2021-11-02.pdf Share allotment / transfer
13404089_tm01_2022-08-18.pdf Share transfer concurrent with control consolidation
13404089_tm02_2024-03-13.pdf Later capital restructuring
Judicial Context (Officer Exposure)
Cited PDFs:
gov.uscourts.txed.236381.3.3.pdf U.S. District Court complaint naming ZEDXION EXCHANGE LTD and exposing officer-level governance to litigation risk
Below is the updated entry formatted to match the Appendix A structure in and incorporating the companies and roles tied to Rezazadeh.
Mehdi Rezazadeh
Roles: CEO of Zedpay / Zed-Pay (operational leadership role; exchange-adjacent payment rail branding) Director (historic) Mining Consultancy Ltd Formation-phase governance actor Transitional director (parallel appointment cluster; Dec 2017 – Mar 2018)
Associated Companies / Entities:
Mining Consultancy Ltd (Company No. 08547173) — UK Role: Director Tenure: 08 December 2017 – 31 March 2018 Context: Parallel director appointments with Ehsan Parvizian; overlapped with active officers Seyed Ali Heydarian (Director) and Shahin Ghorbani-Harsini (Secretary).
Zedpay / Zed-Pay (exchange-adjacent payments branding) Role: Chief Executive Officer (public-facing operational designation) Context: Payments-layer alignment within the broader Zedxion ecosystem; branding convergence with zed-pay[.]com domain infrastructure.
Cited PDFs:
08547173_ap01_2017-12-08.pdf Director appointment — Mining Consultancy Ltd (Company No. 08547173)
08547173_tm01_2018-03-31.pdf Director resignation — Mining Consultancy Ltd
Mining Consultancy Ltd people - Find and update company information - GOV.UK.pdf Official Companies House officer listing reflecting appointment and resignation dates
Appendix B: Domain Registry Attribution to Named Individuals (Officer-Level Linkage)
Overview
Analysis of the IRIS Passive Enrichment (PE) export dated 2026-02-03 demonstrates that the Zedxion / Zedcex / BZ ecosystem is not only sustained by persistent domains across corporate churn, but that domain registration and operational control can be reasonably attributed to specific named individuals appearing in corporate filings. This finding materially strengthens the assessment that the network is person-centric rather than entity-centric, with companies serving as interchangeable wrappers around a stable human and digital core.
The domain registry data shows repeated convergence between:
Named UK company officers and PSCs,
UAE-based operational actors,
Reused registrant emails, name servers, and hosting patterns.
Elizabeth Newman: Domain Control Nexus
Elizabeth Newman emerges as the primary human-domain nexus across the exchange and token infrastructure.
Domains directly or indirectly attributable to Newman via registrant email reuse, operational email artifacts, or exclusive corporate control include:
zedxion.com
mail-zedxion.com
zedcex.com
mail-zedcex.com
These domains align with:
ZEDXION EXCHANGE LTD (Company No. 13404089)
ZEDCEX EXCHANGE LTD (Company No. 14311274)
IRIS enrichment indicates consistent registrar usage and hosting continuity across periods when corporate directors changed or entities became dormant. This persistence coincides with Newman’s tenure as sole or dominant director and is reinforced by the documented use of developer@zedxion.com tied to her prior to formal appointment.
Assessment: Newman should be treated as the effective beneficial controller of the exchange-related domain infrastructure, independent of the legal entities attached at any given time.
Babak Morteza Zanjani: Legacy Brand and Domain Alignment
Domain data also shows residual alignment with Babak Morteza Zanjani, particularly through branding and legacy domains that predate or parallel the Zedxion corporate layer.
Domains of note include:
babakzanjani.com
bz-bank.com
kontbank.com
sctbankers.com
While not all domains are formally registered in his personal name, IRIS enrichment and historical branding analysis place these domains within the BZ / Zanjani commercial ecosystem, which also includes UAE-based entities and trade branding.
These domains are not associated with licensed banking institutions in any jurisdiction, yet are deliberately constructed to evoke regulated financial services. Their persistence following Zanjani’s formal exit from UK company records strongly suggests strategic brand retention rather than abandonment.
Assessment: Zanjani retains brand-level and reputational gravity within the domain layer, even where legal governance has been deliberately distanced.
Solmaz Bani: Trade and Commodity Domain Alignment
Solmaz Bani, director and PSC of BZ DIAMOND LTD (Company No. 13172355), is associated through IRIS enrichment with domains used for trade and commodity branding:
bz-diamond.com
The lifecycle of this domain outlasts the dissolution of the UK entity, mirroring the broader pattern observed across the network. Hosting and registrar reuse indicate operational continuity despite corporate closure.
Assessment: Bani’s role appears consistent with trade-facing shell deployment, where the individual remains aligned with the domain even as the legal entity is discarded.
For individuals associated with IBAN-branded entities Mehmet Hasancebi, Sara Bani, Erol Bulbul, and Mustafa Ozkan—domain analysis reinforces the confidence-laundering thesis.
IRIS enrichment shows no evidence of licensed financial infrastructure behind these domains, yet naming, MX configuration, and web presentation are designed to imply legitimate banking or payments operations.
Assessment: The individuals associated with these entities function as nomenclature shields, enabling the appearance of financial legitimacy while domain control remains centralized and persistent.
UAE-Centric Domain Control and Residency Correlation
A critical insight from the IRIS dataset is the geographic convergence between UAE residency and domain control.
Multiple domains across the BZ and Zedxion ecosystem resolve to hosting environments and registrars commonly used by UAE-based operators. This aligns with:
The operational residence of Elizabeth Newman,
The commercial base of BZ Group AE / BZ Group FZCO (Trade Licence No. 23694),
The durability of UAE entities relative to UK shells.
Assessment: Domain control is most plausibly exercised from the UAE, reinforcing the conclusion that the UAE functions as the operational command layer, while UK entities are regulatory interfaces.
Analytical Conclusion (Domain ↔ Person Layer)
When domain registry data is linked directly to named corporate officers and PSCs, the network resolves into a clear hierarchy:
Individuals (stable): Newman, Zanjani, and a small set of trusted associates.
Domains (persistent): Exchange, banking-style, and trade branding.
Companies (disposable): UK entities formed and dissolved as risk profiles change.
This inversion, where people and domains are stable while companies are ephemeral—is a defining characteristic of high-risk financial facilitation networks, particularly those operating at the intersection of crypto-assets, offshore jurisdictions, and sanctions exposure.
Appendix C: Expanded Domains Investigation of Zanjani Network (BZ)
Overview
Analysis of domains tied to Zanjani corporate entities and personae identifies a coherent but deliberately diversified domain portfolio associated with the Zedxion/Zedcex ecosystem. The domains span banking, payments, commodities, hospitality, automotive, and personal branding, reflecting a classic financial-obfuscation and legitimacy-layering strategy rather than a consumer-facing digital footprint.
This portfolio exhibits strong indicators of purposeful sectoral dispersion, consistent with shell-company networks used for sanctions evasion, capital movement, and narrative laundering.
Functional Domain Segmentation
1. Financial & Banking-Themed Infrastructure
Domains explicitly signaling banking or financial legitimacy:
bz-bank.com
kontbank.com
sctbankers.com
royalbankdevelopmentcapital.com
iban2iban.net
Assessment: These domains employ institutional lexicon (“bank,” “capital,” “IBAN,” “bankers”) designed to convey regulated financial authority. None correspond to recognized Tier-1 or Tier-2 financial institutions, suggesting synthetic financial branding intended to facilitate correspondent relationships, payment onboarding, or client confidence during off-platform transactions.
The presence of iban2iban.net is particularly notable, as it implies cross-border settlement facilitation, a recurring requirement in sanctions-evasion architectures.
2. Payments & Exchange-Adjacent Infrastructure
Domains likely supporting transactional or exchange-related functions:
zed-pay.com
mail-zedxion.com
mail-zedcex.com
Assessment: The separation of mail infrastructure from primary brand domains indicates operational security segmentation, reducing reputational blast radius in the event of enforcement action or infrastructure seizure. This pattern is consistent with financial networks that anticipate regulatory scrutiny.
3. Commodities & Trade Cover Domains
Domains referencing oil, metals, diamonds, and industrial trade:
international-safeoil.com
iraq-safeoil.com
bz-diamond.com
bzdiamond.ae
bz-metal.com
metal-istanbul.com
Assessment: These domains align with commodity-based value transfer narratives, a historically favored mechanism for masking illicit capital flows. The geographic cues (“Iraq,” “Istanbul,” “.ae”) map cleanly onto known trade-based money laundering (TBML) corridors, particularly those used by Middle Eastern and Eurasian actors under sanctions pressure.
The duplication of diamond branding across gTLD and UAE ccTLD strengthens the assessment of jurisdictional arbitrage.
4. Hospitality, Automotive, and Lifestyle Fronts
Domains inconsistent with financial services but valuable for cover and asset justification:
sorinethotels.asia
sorinethotels.co
sorinethotels.us
bz-motor.com
Assessment: Hospitality and automotive sectors are commonly used for cash-intensive explanations, property acquisition, and invoice-based laundering. The multi-TLD replication of Sorinet Hotels suggests brand reservation rather than organic business growth, consistent with shell-entity behavior.
5. Personal Branding & Narrative Control
babakzanjani.com
multiversewarrior.com
Assessment: The inclusion of a personal-name domain tied to Babak Morteza Zanjani alongside a non-commercial ideological or identity-driven site suggests reputation shaping and narrative hedging. Such assets are often used to influence search results, establish alternative biographies, or host future messaging if primary platforms are disrupted.
Structural Observations
No consumer-grade clustering: Domains do not consolidate around a single brand, reducing detectability.
Jurisdictional signaling: UAE, Iraq, Istanbul, and generic “international” naming conventions are used as semantic proxies for legitimacy.
Mail infrastructure isolation: Indicates anticipation of takedowns or subpoenas.
Strategic Assessment
Taken together, the IRIS PE domain set represents infrastructure, not marketing. The domains function as financial scaffolding rather than revenue-generating properties. Their structure is consistent with a shadow-banking and sanctions-evasion ecosystem rather than a conventional corporate group.
Intelligence Confidence
High confidence that this domain portfolio was intentionally constructed to:
Support cross-border financial activity,
Enable trade-based laundering narratives,
Reduce enforcement visibility through diversification,
Maintain rapid reconstitution capability after disruption.
Domain → Company → Officer Correlation Table
Source: IRIS PE CSV export (2026-02-02) + Companies House / Dubai corporate filings
Domain
Associated Company / Entity
Jurisdiction
Known Officers / Controllers
Confidence
babakzanjani[.]com
Personal branding site
N/A
Babak Morteza Zanjani
High
bz-bank[.]com
B Z Group–linked financial front
UAE / UK (probable)
Babak M. Zanjani (control), proxies unidentified
Medium
kontbank[.]com
Unlicensed banking-branded entity
Unknown / Offshore
Linked to Zanjani-controlled network
Medium
sctbankers[.]com
Financial services shell
UK / Offshore
Indirect Zanjani control
Medium
royalbankdevelopmentcapital[.]com
Capital / investment vehicle (shell)
Offshore
Zanjani network (no formal officers identified)
Medium
iban2iban[.]net
Payment / settlement intermediary
UK-linked
Mustafa Özkan (former PSC), Babak Zanjani (control)
Threat Intelligence Report: The Pro-Iran Hacktivist Ecosystem 2026
Moving beyond traditional state-centric APT structures, the pro-Iran coalition of jihadist-aligned collectives, nationalist actors, and opportunistic groups coordinates via Telegram to turn low-cost cyber operations into high-impact psychological warfare. While individual actors primarily rely on technically unsophisticated tradecraft like DDoS-for-hire tools, website defacements, and recycled breach data, their strategic strength lies in speed, visibility, and rapid mobilization alongside real-world kinetic events.
Executive Summary
The cyber environment surrounding the U.S.-Iranian conflict and regional tensions has produced a decentralized wartime cyber ecosystem in service of Iran. It is not a single organized force, instead, it is a loose mix of jihadist-aligned cyber collectives, nationalist actors, and state-adjacent influence networks that converge around shared enemies and geopolitical narratives. This activity has intensified with tensions around the events in Iran and the attacks on regional infrastructure.
The ecosystem operates through Telegram channels and websites, shared target lists, DDoS-for-hire tools, recycled breach data and leak-amplification campaigns. Attack claims and propaganda often appear within hours of kinetic events. This gives actors a deniable auxiliary role while keeping them separate from formal state structures.
Most activity remains technically unsophisticated. DDoS attacks, website defacements, and hack & leak extortion-style messaging with exaggerated claims are more common than verified advanced intrusions. The strategic effect comes less from technical capability than from speed, visibility, and ideological framing that make it into news cycles. In practice these actors use cyber activity as scalable asymmetric information warfare. Even with limited high-end capability, loosely aligned ideological and state-adjacent networks can impose psychological, political, and economic pressure on adversaries during periods of regional crisis.
Iran Aligned Actor Groups
The current pro-Iran and “Axis of Resistance” cyber ecosystem is decentralized, blending hacktivist groups, ideological cyber militias, influence operators, and jihadist cyber propagandists. This ecosystem does not operate as a single command infrastructure, instead functioning as a loose knit cyber mobilization network. Coordination happens through online platforms like Telegram and websites created for dumps of data and propaganda release. All of these are then amplified by social media and news reporting picking up on splashy reports of hack-and-leak operations for the most part.
The groups in this report show how modern cyber conflict is moving beyond traditional espionage toward more influence operations. Much of this activity is built for wartime influence by leveraging public visibility for asymmetric pressure against perceived enemies.
Their primary tradecraft centers on DDoS campaigns, hack-and-leak operations, propaganda amplification, and extortion-style messaging. Targeting is often symbolic, with activity directed against government, telecommunications, healthcare, finance, logistics, and open-source infrastructure that is aligned with, or within the borders of, the enemies of the state they are supporting.
The ecosystem matters less because of proven advanced capability and more because of scale, coordination, and visibility. It can turn low-cost disruption into wartime psychological pressure. Groups such as Handala, 313 Team, Cyber Islamic Resistance, Fatimiyoun/FAD Team, Dark Storm, CJM, Keymous+, DieNet, MONARCH, Killnet, and other coalition actors create the appearance of a broad transnational cyber front. They do this primarily through synchronized propaganda and hacking campaigns.
One notable example of this activity is the May 2026 DDoS campaign against Canonical and Ubuntu infrastructure. This campaign demonstrated how commercial stresser tools and coalition amplification could be used to create outsized disruption against globally important digital platforms.
As tensions rise around the Strait of Hormuz and the wider regional conflict these actors should be treated as deniable asymmetric auxiliaries (e.g. proxies). They may not always demonstrate high-end capability but they can still generate persistent disruption, economic and reputational damage, and psychological instability.
Islamic Cyber Resistance in Iraq / 313 Team
The Islamic Cyber Resistance in Iraq, also known as 313 Team, is one of the most visible Iraqi resistance-branded cyber personas in the pro-Iran ecosystem. Its “313” branding draws from Shia theology and militia culture, giving the group ideological weight inside Iran-aligned media and militia networks.
Operationally, 313 Team focuses on DDoS attacks and website disruption. It also uses Telegram propaganda, symbolic targeting and wartime messaging. The group gained visibility during the aforementioned May 2026 DDoS campaign against Canonical and Ubuntu infrastructure. The campaign affected ubuntu.com, Launchpad package repositories and security APIs update systems as well as related services used by enterprise and cloud environments.
The group claimed use of the “Beamed” DDoS-for-hire platform. This reinforces the assessment that its model relies more on commercial stressers, shared infrastructure, and coalition tooling than it does on custom malware or advanced tradecraft.The Ubuntu campaign was significant because of asymmetric leverage rather than technical sophistication. By targeting open-source infrastructure used across enterprise cloud DevOps and security-update environments, the group created outsized visibility and operational friction with relatively simple methods, in this case DDoS.
313 Team has also been linked to GitHub-hosted tooling. It has used public proof-of-impact services such as check-host[.]net to confirm events. Reporting also connects the group to SQL-injection tools, AI-generated propaganda, and defacement-style activity against government and institutional targets in Kuwait and the wider Gulf. 313 Team operates inside the broader coalition environment of similar groups. Reported aligned actors include RipperSec, Cyb3rDrag0nz, Cyber Fattah Team, Fatimiyoun/FAD Team, Conquerors Electronic Army, and other resistance-branded groups. These actors coordinate through Telegram, shared narratives, target lists, and synchronized public claims. This structure lets low-to-moderate capability actors create the appearance of a larger cyber front.
Threat Assessment: Moderate-to-high for DDoS, disruption, propaganda amplification, and wartime information operations; low-to-moderate for opportunistic intrusion activity; currently low for verified advanced destructive or cyber-physical capability.
Handala Hack Team
Handala Hack Team is among the most consequential and psychologically sophisticated actors in the pro-Iran ecosystem. Unlike many disruption-focused hacktivist groups, Handala specializes in hack-and-leak operations, intimidation campaigns, identity exposure, and coercive information operations.
Its activity aligns closely with Iranian information warfare objectives, even where formal command relationships remain unconfirmed. Handala’s operations frequently blend cyber intrusion claims with propaganda, coercive messaging, and public intimidation. Within the ecosystem, Handala functions as a high-credibility influence and leak node whose operations provide aspirational models for smaller hacktivist crews. It is also of note that recent attacks have leveraged hack and wiper activities that place Handala at a higher level of damage capabilities than the others profiled here.
Threat Assessment: High for psychological operations, hack-and-leak activity, and reputational damage; moderate for broader disruptive capability.
Cyber Fattah Team
Cyber Fattah ( فاتح سايبر) is a pro-Iran hacktivist persona focused on wartime propaganda, DDoS activity, defacement operations, and symbolic disruption. The group operates within the broader Axis-aligned propaganda ecosystem and contributes to coalition attack volume during periods of regional escalation.
Its operations are consistent with mid-tier wartime hacktivism:
public target selection
disruption claims
Telegram amplification
and symbolic attacks against state and infrastructure targets
The group’s strategic importance lies more in participation and coalition signaling than technical sophistication.
Threat Assessment: Moderate for DDoS, disruption, and propaganda amplification.
Fatimiyoun Cyber Team / FAD Team
Fatimiyoun Cyber Team, also referred to as FAD Team, combines militia-aligned ideological branding with rhetoric centered on cyber sabotage, destructive operations, and critical infrastructure intimidation. The group frequently references wiper malware, permanent destruction narratives, and infrastructure targeting themes.
The “Fatimiyoun” branding invokes the Afghan Shia militia ecosystem aligned with Iran’s regional proxy architecture, providing ideological legitimacy and escalation signaling.
Although public evidence of mature destructive capability remains limited, the group’s strategic value lies in psychological escalation. By repeatedly framing itself around cyber sabotage and infrastructure destruction, it injects uncertainty into the wartime information environment.
Threat Assessment: Moderate-to-high for intimidation and escalation signaling; unverified for sophisticated destructive operations.
Cyber Isnaad Front
Cyber Isnaad Front ("الجبهة الإسناد السيبرانية) represents the evolution of pro-Iran cyber activity from infrastructure disruption toward individualized coercive targeting. The group has reportedly published target lists and conducted intimidation-oriented campaigns focused on individuals tied to critical sectors. Its operations demonstrate the increasing fusion of cyber operations with psychological warfare and harassment tactics. Rather than focusing solely on institutional compromise, the group attempts to generate fear and pressure through exposure, intimidation, and public targeting.
Threat Assessment: Moderate for intimidation, doxxing, and psychological pressure campaigns.
Dark Storm Team
Dark Storm Team occupies a hybrid space between ideological hacktivism and criminal-adjacent cyber operations. The group has been linked to DDoS campaigns, ransomware claims, and attacks targeting financial-sector organizations.
Unlike purely ideological DDoS crews, Dark Storm’s association with ransomware narratives increases its risk profile by blending coercive financial pressure with wartime propaganda.The group contributes to the ecosystem by providing both disruption capability and criminal-style intimidation mechanics.
Threat Assessment: High for DDoS; moderate-to-high if ransomware capability is operationally validated.
APT Iran
APT Iran (مرکز تحقیقاتی) is primarily a branding-oriented pro-Iran hacktivist persona rather than a formally identified state APT. The name itself is strategically useful because it implies sophistication and state linkage regardless of actual operational capability.
The group appears focused on:
symbolic targeting (retribution ops)
propaganda-oriented disruption
and coalition participation for propaganda
Its value within the ecosystem is narrative inflation rather than uniquely advanced capability.
Threat Assessment: Moderate for disruption claims and propaganda amplification.
Evil Markhors
Evil Markhors (ایول مارخور) occupies a more operationally useful niche within the ecosystem by focusing on credential harvesting, reconnaissance, and exposed-system discovery. While less visible publicly than DDoS-centric actors, credential and recon-focused groups are strategically important because they can enable downstream compromise by coalition participants.
The group’s activities likely include:
password spraying
reconnaissance scanning
exposure discovery
and credential aggregation
In a decentralized coalition environment, such access-enablement actors can disproportionately increase ecosystem effectiveness.
Threat Assessment: Moderate for credential compromise and reconnaissance; potentially higher if access-sharing occurs across coalition actors.
Conquerors Electronic Army (CEA)
Conquerors Electronic Army (جيش الفاتحين الإلكتروني,) functions as a coalition-aligned DDoS and propaganda actor participating in wartime disruption campaigns. The group contributes to coalition messaging, attack volume, and amplification operations targeting Israeli and Western infrastructure.
Its operational profile is consistent with high-visibility wartime hacktivism:
DDoS
defacement
and public disruption claims
Threat Assessment: Moderate for DDoS and defacement activity.
Nation of Saviors (NOS)
Nation of Saviors is a smaller coalition participant operating within pro-Palestinian and anti-Israel narratives. Its significance lies primarily in coalition breadth and amplification rather than technical specialization.
The group contributes:
DDoS participation
propaganda reinforcement
and wartime messaging
Threat Assessment: Moderate for coalition participation and DDoS activity.
Hider Nex / Tunisian Maskers Cyber Force
Hider Nex, also known as Tunisian Maskers Cyber Force, is a regional pro-Palestinian actor associated with telecom-focused DDoS campaigns and symbolic infrastructure targeting.
The group’s operations demonstrate the ecosystem’s ability to rapidly mobilize around visible civilian infrastructure targets where even limited disruption can generate substantial media attention and psychological impact.
Threat Assessment: Moderate for symbolic disruption and telecom-targeted DDoS operations.
RipperSec
RipperSec (新闻频道) is a coalition-aligned hacktivist group focused on DDoS, defacement, and propaganda amplification based in Malaysia. The group’s importance lies in demonstrating how the ecosystem absorbs or aligns with preexisting hacktivist brands in order to rapidly increase campaign scale.
Its activity is primarily tactical:
disruption
visibility
and social-media amplification
Threat Assessment: Moderate for DDoS and defacement operations.
Cyb3rDrag0nz
Cyb3rDrag0nz represents another coalition-density actor contributing to DDoS campaigns, Telegram amplification, and wartime disruption messaging. Like many smaller crews in the ecosystem, its primary value lies not in technical specialization but in attack-volume generation and coalition optics.
Threat Assessment: Moderate for DDoS and propaganda participation.
Cyber Jihad Movement (CJM)
Cyber Jihad Movement (CJM الجهاد السيبراني) represents one of the most strategically significant developments within the wartime cyber ecosystem because it bridges Sunni jihadist cyber mobilization with the broader Iranian Axis-aligned cyber environment.
The group’s public statements call for “global cyber jihad” against the United States, Israel, and allied governments. This messaging signals a tactical convergence between historically hostile ideological ecosystems united temporarily around shared anti-Western objectives.
CJM’s importance is therefore ideological and mobilizational rather than purely technical. It expands the ecosystem’s recruitment potential, propaganda reach, and cross-platform amplification capacity.
Threat Assessment: Moderate for ideological mobilization, propaganda amplification, and public-sector disruption.
Keymous+
Keymous+ emerged as one of the highest-volume DDoS actors during the early 2026 wartime surge. Its strategic importance lies in attack tempo and operational persistence rather than advanced intrusion capability.
The group demonstrates how commodity stresser infrastructure and coordinated attack waves can create disproportionate operational burden and media attention.
Threat Assessment: High for DDoS volume and sustained disruption.
DieNet
DieNet functions similarly to Keymous+, contributing persistent high-volume DDoS activity against government and public-sector targets.
Its role within the coalition is to sustain operational noise, repeated disruption, and public claim generation during escalation cycles.
Threat Assessment: High for DDoS and operational disruption.
NoName057(16)
NoName057(16) aka DDoSiaProject is primarily a pro-Russian hacktivist actor that entered the broader anti-Western and pro-Iran wartime ecosystem opportunistically. Its participation demonstrates increasing convergence between Russian-aligned cyber activism and Middle East wartime cyber narratives.
The group is already well known for high-volume DDoS operations, making it a natural participant in coalition-style wartime disruption campaigns.
Threat Assessment: High for DDoS and coalition amplification.
Killnet
Killnet represents a pro-Russian hacktivist brand whose wartime participation appears primarily opportunistic and ideologically adjacent rather than directly subordinated to Iranian coordination structures. The group contributes symbolic support, amplification, and anti-Western targeting consistent with broader wartime narratives.
Threat Assessment: Moderate-to-high for DDoS and propaganda amplification.
Russian Legion aka CARDINAL aka MONARCH
The Russian Legion now increasingly uses the name MONARCH. It appears to function as an opportunistic anti-Western amplification actor within the wider Iran, Israel, and U.S. wartime cyber ecosystem.
The shift from Russian Legion to MONARCH fits a broader pattern of hacktivist identity cycling. It also fits the use of refreshed propaganda rebranding to maintain visibility and complicate attribution. The actor’s messaging remains focused on anti-Western, anti-Israel, and militarized geopolitical narratives. Its activity emphasizes symbolic targeting, wartime propaganda, and high-visibility disruption claims.
Operationally MONARCH appears to fill the same role previously associated with the Russian Legion. That role includes coalition participation, DDoS-focused disruption, influence amplification, and synchronized wartime messaging. However, there is limited public evidence of independently verified advanced intrusion capability.
Telegram and social media appear central to its model. These platforms allow the group to spread claims, announce targets, and amplify coalition building propaganda across loosely connected pro-Russian and pro-Iran information networks.
Analytically, MONARCH should be understood less as a standalone sophisticated threat actor and more as a coalition-force multiplier operating within a decentralized proxy cyber environment. Its strategic value derives from visibility, repetition, ideological alignment and the ability to reinforce a wider perception of coordinated cyber pressure.
Threat Assessment: Moderate for DDoS, coalition amplification, and wartime propaganda operations; low-to-moderate for independently verified advanced intrusion capability; currently low for demonstrated destructive or cyber-physical operations.
Server Killers
Server Killers illustrates the opportunistic nature of wartime cyber ecosystems. The group appears motivated by visibility and coalition participation rather than deep strategic coordination. Its presence demonstrates how wartime cyber conflicts attract loosely affiliated actors seeking relevance or opportunistic influence within larger geopolitical narratives.
Threat Assessment: Moderate for nuisance disruption and opportunistic DDoS activity.
Strategic Assessment
The pro-Iran cyber ecosystem increasingly resembles a form of decentralized digital proxy warfare rather than traditional state-centric cyber operations.
Its defining characteristics are:
coalition behavior
Telegram-native coordination
rapid mobilization
ideological amplification
and psychological disruption
The ecosystem’s center of gravity is not advanced malware, covert espionage, or long-term persistence. Instead, it is rapid disruption turned into strategic psychological effect through coalition activity, synchronized propaganda, and wartime information operations.
As regional conflict continues to intensify, these actors are likely to remain focused on:
DDoS campaigns
symbolic infrastructure targeting
leak operations
coercive messaging
and psychological pressure operations
Defensive Implications
Organizations should treat this cluster as a disruption and reputational-risk threat during periods of geopolitical escalation. Priority controls should focus on
DDoS readiness
WAF and CDN hardening
credential-stuffing detection
MFA enforcement
leaked-credential monitoring
abuse-desk escalation
executive doxxing monitoring
rapid response and communications procedures for false or exaggerated breach claims
The key analytic discipline is separating access from amplification. A Telegram claim does not prove intrusion. A DDoS screenshot does not prove compromise. A leaked sample does not prove current access.
Still, repeated low-end activity across many brands can create real operational pressure, reputational damage, and psychological cost.
Conclusions
The pro-Iran and “Axis of Resistance” cyber ecosystem is best understood as a decentralized wartime disruption network, not a traditional APT structure. Its strength is not advanced technical capability, but speed, visibility, coalition activity, and the ability to turn low-cost cyber actions into psychological and political pressure. Many of these groups function as proxies or cutouts for Iranian-aligned interests, with varying degrees of likely support, direction, encouragement, or operational tolerance from Iran. These groups and related actors help create the appearance of a broad transnational cyber front. That perception is itself part of the operation.
Most of these actors rely on basic tradecraft, including DDoS attacks, defacements, credential reuse, recycled breach data, public claims, and propaganda amplification to effect. These methods are often low-end, but they can still create real impact when many groups act at once during geopolitical escalation. The main defensive challenge is not only intrusion prevention, but also managing disruption, reputational risk, and alert fatigue across public-facing systems.
During future Gulf-region escalation, this ecosystem is likely to surge quickly, with claims appearing within hours of kinetic events.The core assessment is that this ecosystem is less a high-end cyber weapon than a scalable asymmetric pressure system, with value derived from mobilization, amplification, and psychological effect.
Threat Intelligence Report: Nation-State Targeting of Water Systems 2024–2026
DTI reveals how Russia, China, and Iran are exploiting weak OT security and internet-facing PLCs to target critical water and wastewater infrastructure. From Volt Typhoon's strategic pre-positioning to Sandworm-adjacent sabotage, discover the primary TTPs, vulnerabilities, and MITRE ATT&CK mappings reshaping modern hybrid warfare.
Executive Summary
Water and wastewater systems have become favored gray-zone targets because they are highly vulnerable and hold disproportionate strategic value. The combination of chronic underinvestment and weak baseline operational technology (OT) security make many of these critical systems easy to compromise. Such intrusions can have both physical and psychological impact, and disruptions often affect civilian life, public health, and trust in government.
Recent nation-state cyber activity targeting water systems includes Iranian IRGC-linked targeting of exposed programmable logic controllers (PLCs), Russian and pro-Russian access to municipal water-control environments, and PRC-linked pre-positioning in U.S. critical infrastructure, including water and wastewater systems. U.S. federal agencies, including CISA, FBI, NSA, and EPA, have warned that many utilities remain exposed through internet-facing human-machine interfaces (HMIs) and PLCs, weak credentials, shared accounts, legacy devices, limited monitoring, and poor IT/OT segmentation.
Operations targeting water systems fit a modern hybrid warfare doctrine that has become increasingly dominant in recent years. Russia, China, and Iran all use cyber access primarily as a shaping tool, not a destructive weapon. Water-system access specifically can create fear, test response thresholds, consume emergency resources, and provide leverage during crises. Each nation puts their unique twist on their operations. Russia tends to pair infrastructure access with pressure and destabilization. Iran often blends symbolic retaliation, psychological signaling, and opportunistic disruption. In contrast, China places more emphasis on long-term pre-positioning and strategic persistence.
All three models converge on the same underlying thesis: targeting civilian utilities provides strategic options.
Water Systems as Pre-War Terrain
From 2024 to 2026, water-sector targeting moved from opportunistic nuisance activity to a feature of state competition. Water systems are now pressure points used to create fear, test resilience, and prepare options before wider conflict. Specifically, threat actors have exploited internet-exposed PLCs and weak credentials to deface HMIs and make public spectacles out of their compromises.
Iran uses successful compromise of water systems for visible signaling, retaliation narratives, and propaganda, while Russia uses it for disruption, intimidation, and hybrid pressure against NATO-aligned states. Meanwhile, China focuses on quiet persistence, reconnaissance, and contingency access inside U.S. critical infrastructure. However, all of these operations are meant to serve the same purpose: setting the stage for war without crossing the threshold into open conflict.
Iran: CyberAv3ngers / IRGC-Linked PLC Targeting
Iran-linked activity has been the most direct in targeting water and wastewater systems.In April 2020, Iranian state-sponsored hackers launched a cyberattack targeting Israeli water and wastewater control systems. While this attack attempted to manipulate the SCADA systems, automated systems kicked in and thwarted the attempt. Had it succeeded, during a heat wave, it could have harmed many people.
In December 2024, CISA reported that the IRGC-affiliated CyberAv3ngers targeted and compromised Israeli-made Unitronics Vision Series PLCs used across multiple sectors, including U.S. water and wastewater systems. The activity exploited poor authentication and exposed PLC/HMI interfaces rather than sophisticated malware delivery. Clearly this shows that the Iranian government is accustomed to the idea of attacking public infrastructure, something usually outside the bounds of conventional warfare.
In April 2026, CISA, FBI, NSA, EPA, and partner agencies issued a new advisory warning that Iranian-affiliated cyber actors were exploiting internet-facing PLCs across critical infrastructure, including water, wastewater, energy, and government facilities. The EPA separately framed the advisory as a water-sector resilience warning, stressing that national security depends on water systems reporting incidents and hardening exposed OT assets.
Assessment: While Iran has demonstrated the ability to access exposed control devices, deface HMIs, and create public fear, the public evidence of their activity still points more toward opportunistic OT access than reliable cyber-physical sabotage at scale.
Primary TTPs
Threat level: High for exposed small and mid-sized utilities; moderate for mature utilities with segmented OT.
Russia: Pro-Russian Hacktivist and Sandworm-Adjacent Water Disruption
Russia-aligned actors have shown a willingness to use their access to manipulate water-control systems directly. In Mulshoe, Texas in January 2024, attackers accessed a remote industrial interface and caused a municipal water tank to overflow for roughly 30–45 minutes. The Cyber Army of Russia Reborn claimed responsibility, and Mandiant linked the group to Sandworm, Russia’s GRU-associated destructive cyber unit.
A little over a year later, in April 2025, attackers seized control of a dam in Bremanger, Norway. They opened a floodgate, releasing roughly 500 liters of water per second for four hours before the incident was stopped. Norway’s counterintelligence chief publicly blamed Russia-linked actors for the intrusion.
Assessment: Russian-linked activity is more sabotage-oriented than Iranian activity. The pattern fits Moscow’s broader hybrid campaign: low-cost disruptive access, public fear generation, and probing of Western infrastructure resilience.
Primary TTPs
Threat level: High in Europe and NATO-adjacent states; moderate-to-high in exposed U.S. municipal water systems.
China: Volt Typhoon Pre-Positioning in Water and Wastewater Networks
In February 2024, CISA, NSA, FBI, and allied agencies confirmed that Volt Typhoon had compromised IT environments across multiple U.S. critical infrastructure sectors, including water and wastewater, communications, energy, and transportation. The advisory assessed that the activity was intended to enable disruptive or destructive effects during a future crisis or kinetic conflict.
The same year, the EPA distributed an alert to more than 60,000 water and wastewater systems regarding Volt Typhoon and coordinated cybersecurity assistance for water infrastructure supporting U.S. defense-critical facilities.
Assessment: PRC water-sector targeting is strategically different from Iran and Russia. Rather than demonstrate immediate effects, Volt Typhoon’s objective is durable access, reconnaissance, and strategic pre-positioning.
Primary TTPs
Threat level: Severe strategic threat; lower risk of short-term disruption.
Poland and European Water-System Exposure
A May 2026 report released by the Polish Intelligence Service stated that hackers breached five Polish water treatment plants in 2025. The threat actors leveraged weak/default passwords and internet-exposed control systems. Once inside ICS controlling pumps and filters, they had the ability to alter chemical-dosing parameters. The attacks were never attributed to a specific nation-state or threat actor; however, the same intelligence report alluded to prior Russian and Belarusian hybrid operations against Polish infrastructure.
Assessment: Poland is a high-priority target because of its role as a NATO logistics hub for Ukraine. Even unattributed water-system intrusions in Poland should be assessed against Russian hybrid-warfare objectives: intimidation, disruption, reconnaissance, and resilience testing.
Threat level: High for this region downrange from Russia.
Major Non-Attributed Water-Sector Incidents Relevant to State Threat Modeling
American Water disclosed a cyber incident in October 2024 that affected customer-facing and billing systems, but not water or wastewater operations. Veolia North America reported a January 2024 ransomware incident that disrupted back-end systems and online bill payment, while treatment operations remained unaffected. Southern Water in the United Kingdom was also claimed by Black Basta, with customer and employee data at risk but no reported operational impact.
Other cases moved closer to operational risk. Arkansas City, Kansas shifted its water treatment facility to manual operations after a September 2024 cyber incident. Minot, North Dakota did the same in March 2026 after ransomware affected a server tied to the water treatment environment. In both cases, water remained safe, but operators had to rely on fallback procedures.
These incidents matter because they show that state actors do not need custom ICS malware to create risk. Billing systems, customer portals, GIS repositories, vendor access, remote administration, identity systems, backups, and SCADA-adjacent servers can all provide useful access or intelligence. Criminal and unattributed incidents should therefore be treated as live demonstrations of the same weaknesses a state actor could exploit with more patience, planning, and operational intent.
Common Vulnerabilities Exploited Across Cases
Water-sector targeting repeatedly converges on the same weaknesses:
Internet-facing HMIs and PLCs,
Weak or default credentials,
Exposed remote-access tools,
Shared operator accounts,
Unsupported legacy systems,
Limited monitoring,
Poor segmentation between IT and OT networks.
These gaps give actors simple access paths into systems that control pumps, valves, filters, chemical dosing, and alarms.
Reporting from the EPA and Government Accountability Office (GAO) shows that this is a systemic risk, not a one-off failure. The U.S. water sector includes roughly 170,000 water and wastewater systems, many of which operate with limited resources, voluntary security adoption, and uneven cyber maturity. This structure makes the sector easy to probe, difficult to standardize, and attractive to state and state-aligned actors seeking leverage, visibility, and disruption opportunities.
Strategic Assessment
The last two years show clear segmentation among state-sponsored and state-aligned actors. Iran uses water system intrusions to maximize ideological and psychological impact. Russia treats water and dam systems as part of sabotage-oriented hybrid warfare. China targets water infrastructure for strategic pre-positioning.
The near-term risk is not a Stuxnet-class attack. It is a low-complexity compromise of exposed OT that causes local disruption, unsafe operations, or panic. The larger strategic risk is quiet PRC-style persistence inside water-sector IT and OT-adjacent networks that could be used during a geopolitical crisis, such as kinetic conflict between the U.S. and China over Taiwan.
Conclusion
State and state-aligned actors treat water and wastewater infrastructure as strategic pressure points. The value is primarily psychological and political rather than kinetic. Even limited access or brief disruptions can trigger disproportionate reactions because water is tied directly to public health, trust, and government competence.
The most likely future is not a catastrophic “cyber Pearl Harbor.” It is persistent low-level access, intermittent disruption, coercive signaling, information operations, and pre-positioning for broader confrontations.
Appendix A: Indicators of Compromise and Detection Artifacts
Used by Iranian-affiliated APT actors to communicate with Rockwell Automation / Allen-Bradley PLCs
185.82.73[.]162
IP address
Jan 2025–Mar 2026
Same
185.82.73[.]164
IP address
Jan 2025–Mar 2026
Same
185.82.73[.]165
IP address
Jan 2025–Mar 2026
Same
185.82.73[.]167
IP address
Jan 2025–Mar 2026
Same
185.82.73[.]168
IP address
Jan 2025–Mar 2026
Same
185.82.73[.]170
IP address
Jan 2025–Mar 2026
Same
185.82.73[.]171
IP address
Jan 2025–Mar 2026
Same
CISA, FBI, NSA, EPA, DOE, and U.S. Cyber Command reported that Iranian-affiliated actors used overseas infrastructure to access internet-facing Rockwell Automation / Allen-Bradley PLCs, including CompactLogix and Micro850 devices, and that activity resulted in project-file extraction, HMI / SCADA data manipulation, operational disruption, and financial loss. (Internet Crime Complaint Center)
Iran: Ports, Devices, and Tools
Indicator / Artifact
Type
Relevance
TCP/44818
OT protocol port
EtherNet/IP / Rockwell Automation communications
TCP/2222
OT protocol port
EtherNet/IP implicit messaging
TCP/102
OT protocol port
Siemens S7 communications
TCP/502
OT protocol port
Modbus/TCP
TCP/22
Remote access port
SSH access; Dropbear SSH observed on victim endpoints
Dropbear SSH
Tool
Used for remote access persistence through port 22
Studio 5000 Logix Designer
Legitimate engineering software
Used to connect to and interact with exposed Rockwell PLCs
.ACD project files
Rockwell project artifact
Targeted / extracted project files containing ladder logic and configuration
The April 2026 joint advisory specifically called out malicious traffic to ports 44818, 2222, 102, 22, and 502, and noted Dropbear SSH deployment for remote access. (Internet Crime Complaint Center)
Iran: 2023 Unitronics / CyberAv3ngers Artifacts
Indicator / Artifact
Type
Relevance
Unitronics Vision Series PLCs
Targeted product family
Israeli-made PLC/HMI platform used in water, wastewater, energy, food, beverage, manufacturing, and healthcare
Default credentials
Access condition
Core compromise vector
"You have been hacked, down with Israel. Every equipment 'made in Israel' is CyberAv3ngers legal target."
Defacement text
HMI/PLC defacement message reported in 2023 activity
The earlier joint advisory reported IRGC-affiliated CyberAv3ngers targeting Unitronics Vision Series PLCs, commonly used in U.S. water and wastewater systems, and compromising devices using default credentials.
Russia: Cyber Army of Russia Reborn / Sandworm-Adjacent Activity
Indicator / Artifact
Type
Relevance
Cyber Army of Russia Reborn / CARR
Actor persona
Claimed water-system manipulation activity in Texas and Europe
Telegram claim videos
Influence artifact
Public proof-of-access / propaganda amplification
HMI screen recordings
Operational artifact
Demonstrated interaction with water-control interfaces
Water-level / stop-level manipulation
Process-control behavior
Associated with Muleshoe / Abernathy water tank incidents
SCADA / HMI access to small municipal utilities
Targeting pattern
Low-resource water utilities used as disruption targets
Mandiant linked CARR to Sandworm-associated infrastructure and personas, while Treasury reported that CARR claimed responsibility for overflowing water storage tanks in Abernathy and Muleshoe, Texas, and posted video of HMI manipulation. (CyberScoop)
Norway and Poland Exposure Artifacts
Indicator / Artifact
Type
Relevance
Bremanger / Risevatnet dam floodgate manipulation
Process-control behavior
Floodgate opened, releasing roughly 500 liters per second for four hours
Weak/default passwords
Access condition
Reported as common vector in European water incidents
Internet-exposed control systems
Exposure condition
Reported vector in Polish water treatment plant breaches
Pump, filter, and chemical-dosing control access
Process-control exposure
Relevant to Polish water treatment plant incident reporting
Reuters reported that Norway’s counterintelligence chief blamed Russian hackers for the April 2025 Bremanger dam incident. TNW and SecurityWeek reported that Polish water treatment plant breaches involved weak passwords and internet-exposed control systems; attribution remains unconfirmed for those Polish incidents. (Reuters)
China: Volt Typhoon Behavioral IOCs
Indicator / Artifact
Type
Relevance
wmic / WMIC
Native Windows tool
Process creation, discovery, credential-access workflows
ntdsutil.exe
Native Windows tool
Active Directory database extraction
ntds.dit
Credential artifact
Domain credential database targeted for exfiltration
SYSTEM registry hive
Credential artifact
Used with ntds.dit for password hash extraction
SECURITY registry hive
Credential artifact
Credential and policy data
netsh interface portproxy
Native Windows tool
Port forwarding / proxying for persistence and C2
PowerShell
Native Windows tool
Execution, discovery, and administration abuse
Compromised SOHO routers
Infrastructure
Proxying and operational obfuscation
C:\Windows\Temp\
Host artifact path
Staging location observed in advisory examples
C:\Users\Public\
Host artifact path
Staging location observed in advisory examples
ADMIN$ share output redirection
Windows admin artifact
Used in command execution / remote activity
NSA and partner agencies reported Volt Typhoon’s living-off-the-land model using built-in tools including wmic, ntdsutil, netsh, and PowerShell; the same advisory included examples of ntds.dit extraction, registry hive collection, and portproxy abuse.
Appendix B: MITRE ATT&CK Mapping
Actor / Stream
Tactic
Technique
ID
Observed / Assessed Use
Iran / CyberAv3ngers
Initial Access
Internet Accessible Device
T0883
Accessed publicly exposed PLCs without sufficient network hardening
Iran / CyberAv3ngers
Command and Control
Commonly Used Port
T0885
Used OT ports including 44818, 2222, 102, 502, and SSH on 22
Iran / CyberAv3ngers
C&C
Remote Access Software
T1219
Deployed Dropbear SSH for remote access
Iran / CyberAv3ngers
Impact
Stored Data Manipulation
T1565
Interacted with project files and altered HMI / SCADA display data
Iran / CyberAv3ngers
Initial Access
Valid Accounts
T1078
Inferred from default / weak credential abuse against PLCs
Iran / CyberAv3ngers
Impact
Defacement
T1491
HMI/PLC defacement messaging in Unitronics activity
Russia / CARR / Sandworm-adjacent
Initial Access
External Remote Services
T1133
Likely access through remote industrial interfaces / exposed remote control paths
Russia / CARR / Sandworm-adjacent
Initial Access
Valid Accounts
T1078
Likely weak credential or exposed HMI access model
Russia / CARR / Sandworm-adjacent
Discovery
Network Service Discovery
T1046
Assessed scanning / discovery of exposed water-control interfaces
Russia / CARR / Sandworm-adjacent
Impact
Service Stop / Process Disruption
T1489 / ICS-aligned impact
Manipulation of water-system process controls resulting in overflow / floodgate events
Russia / CARR / Sandworm-adjacent
Impact
Data Manipulation
T1565
Manipulation of set points, values, and control-system displays
Russia / CARR / Sandworm-adjacent
Collection / Influence
Screen Capture / Public Claims
T1113 / influence artifact
Claim videos showed screen recordings of HMI manipulation
China / Volt Typhoon
Initial Access
Exploit Public-Facing Application
T1190
Compromise of exposed edge devices and public-facing infrastructure
China / Volt Typhoon
Defense Evasion
Living-off-the-Land
Multiple
Use of native tools to blend with administration activity
China / Volt Typhoon
Execution
Windows Management Instrumentation
T1047
WMIC execution for process creation and credential-access workflows
China / Volt Typhoon
Credential Access
OS Credential Dumping: NTDS
T1003.003
Attempted extraction of ntds.dit and registry hives
China / Volt Typhoon
Command and Control
Proxy
T1090
netsh portproxy used for forwarding / covert access
China / Volt Typhoon
Execution
PowerShell
T1059.001
Native PowerShell use in LOTL activity
China / Volt Typhoon
Discovery
Account Discovery
T1087
Account and environment enumeration
China / Volt Typhoon
Discovery
Remote System Discovery
T1018
Network and host reconnaissance
China / Volt Typhoon
Lateral Movement
Remote Services
T1021
Movement through compromised internal environments
China / Volt Typhoon
Collection
Archive Collected Data
T1560
Staging and compression of collected data, including 7z examples
China / Volt Typhoon
Defense Evasion
Impair Defenses
T1562
Avoidance of EDR visibility through native tooling and low-noise operations
Poland / Unattributed
Initial Access
Internet Accessible Device
T0883
Internet-exposed ICS used as access path
Poland / Unattributed
Initial Access
Valid Accounts
T1078
Weak/default passwords
Poland / Unattributed
Impact
Data Manipulation
T1565
Potential manipulation of pump, filter, and dosing parameters
American Water / Unattributed
Initial Access
Unknown
N/A
Public reporting does not disclose technical access vector
American Water / Unattributed
Impact
Service Disruption
T1489, if confirmed
Customer-facing and billing systems were affected; company stated water/wastewater operations were not impacted
The Iran rows are directly mapped from AA26-097A’s ATT&CK tables; the Volt Typhoon rows are mapped from NSA/CISA/FBI partner reporting on living-off-the-land activity; the Russia and Poland rows are analytic mappings based on public incident descriptions and should be treated as lower-confidence than the official advisory mappings. (Internet Crime Complaint Center)
Threat Intelligence Report: Russia, Router, DNS, and Messaging-Layer Collection Operations
New research exposes Russian GRU (APT28) cyber operations using router compromise, DNS hijacking, and Signal/WhatsApp phishing for long-term espionage.
Executive Summary
Russian intelligence-linked cyber operations continue to emphasize communications-layer collection over disruptive or destructive activity. Recent reporting from U.S. agencies, allied partners, and private researchers highlights two lines of effort. One is the compromise of vulnerable SOHO routers for DNS hijacking and adversary-in-the-middle collection. The other is phishing against secure and commercial messaging platforms. Together, these operations support long-term intelligence collection against government, defense, critical infrastructure, diplomatic, media, NGO, and Ukraine-related targets.
The goal is access. Quiet and lasting. By taking routers and bending DNS, Russian operators can watch traffic, steer chosen victims, and steal credentials without putting malware on the machine. Their work against Signal, WhatsApp, Telegram, and Microsoft 365 gives them the other half: messages, contacts, trusted names, and private conversations. Together, it lets them collect, map people, and stay close to the networks that matter.
Key Assessments
Russia is increasingly treating edge infrastructure and messaging platforms as persistent intelligence-collection terrain. Router compromise provides GRU-linked operators with a passive upstream vantage point over victim traffic, while messaging-account compromise provides visibility into human networks, operational discussions, authentication workflows, and trusted social relationships. Together, these operations support long-duration intelligence collection, access persistence, credential interception, social-graph mapping, and pre-positioning for future contingency operations.
The most significant router activity is attributed to the Russian GRU's Unit 26165, tracked as APT28/Fancy Bear. U.S. and allied agencies report ongoing exploitation of vulnerable routers and edge devices to manipulate DNS and DHCP settings, enabling adversary-in-the-middle collection and credential interception without requiring endpoint malware. The objective is persistent intelligence collection and access rather than immediate disruption.
Evolution of GRU Tradecraft: From Intrusion and Disruption to Communications-Layer Collection
Russian messaging targeting now reaches beyond Signal. It includes WhatsApp, Telegram, and Microsoft 365 OAuth flows. The goal is not just the account. It is the conversation, the contact list, the trusted name, and the path into the next victim.
GRU tradecraft has changed, but the aim has not. The old operations broke in, stole, leaked, and sometimes destroyed. The new operation is quieter. It compromises routers, bends DNS, abuses QR codes, linked devices, cloud logins, and OAuth prompts. It sits close to the traffic and the trust. It maps who talks to whom and keeps access to the communications layer itself.
Victimology
The victim set falls into two groups. The first set is broad; router and DNS campaigns reach across home routers, small offices, and edge devices in many regions. However, Russian actors do not exploit every victim the same way. They look for value in targets with the highest likelihood of a significant intelligence yield such as military, government, critical infrastructure, foreign ministry, law enforcement, telecom, and email providers.
The second group is more personal. The messaging campaigns go after people whose conversations matter for Russian intelligence collection, including Ukrainian military personnel, government officials, politicians, journalists and researchers, activists, NGO staff and human-rights workers. Communications platforms like Signal, WhatsApp, Telegram, and Microsoft 365 then function as doors into contact lists, private conversations, trusted names, and the next victim.
Russian-linked targeting in 2026 focused on people and institutions with intelligence value. FBI/CISA reporting identified current and former government officials, military personnel, political figures, and journalists as high-value targets, while Volexity documented related activity against Ukraine-linked and human-rights organizations through Signal, WhatsApp, and Microsoft 365 OAuth compromise. Google reporting on defense-sector threats and Reuters coverage of Signal phishing against politicians, diplomats, military officers, and journalists reinforce the same pattern. The target set was strategic, not random.
Secondary exposure came through the tools those targets used every day. Microsoft reported Russian-linked compromise of home and small-office routers, DNS hijacking, and Outlook on the web targeting, while Lumen described broad router exploitation across more than 18,000 IPs in at least 120 countries. That scale gave operators a wide collection base. From there, they could sort victims by intelligence value and pursue the accounts, organizations, and communications channels that mattered most.
Router and DNS Hijacking Operations
In April 2026, the IC3 warned that Russian GRU actors were exploiting routers worldwide to steal military, government, and critical infrastructure data. The activity was tied to Unit 26165, also known as APT28, Fancy Bear, and Forest Blizzard. The actors changed DNS and DHCP settings, pushed victims through Russian-controlled resolvers, and used the access for quiet collection.
DOJ said the network relied on compromised SOHO routers, including thousands of TP-Link devices. The actors stole credentials, filtered DNS requests, and used false DNS records to stage adversary-in-the-middle attacks against services such as Outlook Web Access.
Microsoft assessed the campaign had run since at least August 2025, affecting more than 200 organizations and 5,000 consumer devices. The goal was not noise. It was persistent visibility.
Technical Tradecraft
The attack chain is simple and effective. The actors compromise routers, change DNS and DHCP settings, and push connected devices to use Russian-controlled resolvers. Most traffic can be watched quietly. Selected targets can be redirected.
The sharper risk is TLS interception. Forest Blizzard spoofed DNS responses for targeted domains, including Microsoft webmail. It then served bad certificates. If users clicked through the warning, the actor could read email and cloud traffic in plaintext.
The value is in the gap. Home routers, small-office routers, and remote-worker paths often sit outside enterprise EDR. The cloud account may be secure. The network edge may not be.
Messaging Application Targeting
Russian services are also targeting messaging accounts. FBI and CISA warned in March 2026 that Russian-linked actors had compromised thousands of commercial messaging accounts. Once inside, they could read messages, steal contacts, impersonate victims, and phish from trusted identities.
Google reported the same pressure against Signal. Actors abused the linked-device feature with malicious QR codes dressed as group invites, security alerts, pairing prompts, or Ukraine-themed apps. Once linked, the attacker could read future Signal messages in real time.
Microsoft saw Star Blizzard move into WhatsApp lures. Volexity saw suspected Russian actors use Signal and WhatsApp to push Microsoft 365 OAuth phishing. The pattern is clear. Russia is not only chasing accounts. It is chasing conversations, contacts, and trust.
Threat Level Assessment
The threat is highest for government, defense, critical infrastructure, telecom, energy, Ukraine-support organizations, journalists, NGOs, policy researchers, and other targets of likely intelligence value. These sectors align with Russian collection priorities and are most likely to face targeted exploitation after initial access.
Risk is also elevated for enterprises with remote or hybrid staff accessing Microsoft 365, webmail, VPN portals, cloud platforms, or sensitive collaboration tools from unmanaged home networks. For the broader private sector, the threat is moderate: router compromise may be broad, but follow-on exploitation appears selective and focused on victims with intelligence value.
Defensive Recommendations
Organizations should treat SOHO routers and remote-worker network paths as part of the attack surface. Replace end-of-life routers, patch firmware, disable remote administration, rotate router admin credentials, verify DNS settings, and monitor for unexpected resolvers. Remote-access policies should assume that home networks may be hostile.
For messaging applications, it is most important to prioritize linked-device hygiene. Users should regularly review linked devices in Signal, WhatsApp, and Telegram; remove unknown sessions; enable registration locks or PINs where available; and treat QR codes, group invites, “security alerts,” and video-call setup links as high-risk when received from sensitive contacts.
For enterprise identity, organizations should harden Microsoft 365 against OAuth and device-code phishing. Enforce phishing-resistant MFA, restrict risky OAuth consent flows, monitor anomalous device joins, review possible travel and token abuse, and train high-risk personnel not to return authentication codes to anyone.
Conclusion
Russian intelligence-linked cyber operations are moving closer to the communications layer. The objective is not immediate disruption. It is quiet access, persistent visibility, and control over the paths people use to communicate, authenticate, and coordinate.
The router and DNS hijacking activity shows the value of edge infrastructure. Compromised SOHO routers gave Russian operators a place to watch traffic, redirect selected victims, and intercept credentials without touching the endpoint. Messaging-platform targeting gave them the human layer: contacts, conversations, trusted names, and social relationships.
Together, these operations formed a durable intelligence-collection model. Broad compromise created scale. Selective follow-on targeting created value. Government, defense, critical infrastructure, Ukraine-support networks, journalists, NGOs, researchers, and political figures remained the highest-risk targets, while remote and hybrid workers widened the exposure path.
Now that this activity has been exposed, Russian operators will likely pivot again. They may shift infrastructure, rotate DNS and proxy methods, alter messaging lures, move to new linked-device abuse workflows, or lean harder into cloud identity and trusted-platform compromise. The collection requirement will remain. The access path will change.
The defensive lesson is direct. Organizations can no longer treat home routers, personal messaging apps, OAuth workflows, or linked-device features as outside the enterprise threat model. For Russian operators, these are not secondary surfaces. They are collection terrain. Once detected, that terrain will be reshaped, not abandoned.
Appendix A: MITRE ATT&CK Mapping
Initial Access/Persistence
Evasion and Credential Collection
Tactic
Technique
ID
Observed Use
Initial Access
Exploit Public-Facing Application
T1190
Exploitation of vulnerable SOHO and TP-Link routers
Initial Access
Phishing
T1566
Messaging-app phishing and OAuth lure delivery
Initial Access
Spearphishing Link
T1566.002
Delivery of malicious OAuth/device-code URLs
Initial Access
Valid Accounts
T1078
Abuse of compromised messaging and cloud accounts
Execution
User Execution
T1204
Victim interaction with QR codes and phishing links
Persistence
Account Manipulation
T1098
Addition of linked devices to Signal accounts
Persistence
External Remote Services
T1133
Continued access through compromised cloud identities
Persistence
Modify Authentication Process
T1556
OAuth workflow abuse and session persistence
Privilege Escalation
Abuse Elevation Control Mechanism
T1548
Router administrative compromise and configuration manipulation
Defense Evasion
Proxy
T1090
DNS and AiTM proxy routing
Defense Evasion
Impair Defenses
T1562
Operating outside enterprise EDR visibility
Credential Access
Adversary-in-the-Middle
T1557
TLS interception and DNS redirection
Credential Access
Steal or Forge Authentication Certificates
T1649
Use of fraudulent/invalid TLS certificates
Credential Access
Input Capture
T1056
Credential interception via redirected authentication flows
Credential Access
Credentials from Password Stores
T1555
Interception of stored or synced credentials
Discovery
Network Service Discovery
T1046
Reconnaissance through DNS visibility
Discovery
System Network Configuration Discovery
T1016
Observation of network and resolver configurations
Discovery
Gather Victim Identity Information
T1589
Collection of contact lists and identity relationships
Discovery
Gather Victim Network Information
T1590
DNS and routing visibility collection
Collection
Email Collection
T1114
Interception of Outlook Web Access traffic
Collection
Audio Capture
T1123
Potential collection through compromised communication workflows
Collection
Data from Information Repositories
T1213
Access to cloud-hosted communications
Collection
Screen Capture
T1113
Potential follow-on account monitoring activities
Collection
Data from Cloud Storage
T1530
Microsoft 365 and cloud-message access
Command and Control
Application Layer Protocol
T1071
DNS- and HTTPS-based communications
Command and Control
Encrypted Channel
T1573
Use of TLS/HTTPS transport
Command and Control
Dynamic Resolution
T1568
Actor-controlled DNS infrastructure
Exfiltration
Exfiltration Over Web Service
T1567
Cloud-account data access and exfiltration
Impact
Network Denial of Service
T1498
Potential latent capability through router control
Threat Intelligence Report: ZionSiphon OT Malware First Attempts? Psyops? Both?
Analysis of ZionSiphon (SCADA_SecurityPatch_v8.4.exe), a .NET OT malware targeting Israeli water utilities. Discover its IOCs, targets, and flawed activation code.
Executive Summary
ZionSiphon is a malware sample (“SCADA_SecurityPatch_v8.4.exe”) that has been circulating in public sandboxes since 2025. It is best understood as a Windows-based implant with explicit industrial control system (ICS) targeting intent but with a critical limitation in its verification of geographic data that fundamentally constrains its operational viability. While earlier analysis established the malware as functionally capable at the host level, subsequent findings confirm the presence of a critical XOR bug in its geographic validation logic, preventing the payload from activating in its intended environment. Additionally, there is no evidence of vendor-specific protocol handling, no confirmed register mapping, and no interaction with PLC firmware or engineering toolchains. The malware appears to rely on file-based or high-level configuration manipulation, which may not translate into actual process changes in most industrial environments.
The malware’s architecture remains coherent and deliberate. It combines geographic scoping, environment-aware execution, and embedded process manipulation logic, demonstrating a structured conceptual model of water treatment and desalination systems. Its internal string corpus provides high-confidence evidence of targeting, including references to Mekorot and major desalination facilities such as Sorek, Hadera, Ashdod, Palmachim, Shafdan, and Eilat water plants in Israel, alongside a dense vocabulary covering reverse osmosis, chlorine dosing, and salinity control. Filesystem-based validation and vendor-associated paths further reinforce that the malware is engineered to identify and operate within specific industrial environments.
However, the XOR validation flaw introduces a decisive constraint. The malware is designed to restrict execution to Israeli (“IL”) network ranges and to self-destruct if those conditions are not met. Due to the encoding error, this validation check never evaluates as true, meaning the malware fails to recognize its target environment even when present. As a result, the payload does not progress to its process manipulation stage and instead frequently triggers its own cleanup routines. This explains previously observed inconsistent or absent execution behavior: rather than reflecting conditional activation alone, it represents a systemic failure in the activation pathway.
The intended sabotage model remains conceptually clear despite this failure. ZionSiphon includes embedded parameters designed to manipulate critical control points, such as increasing chlorine dosing and altering reverse osmosis pressure, and contains references to industrial protocols including Modbus, DNP3, and S7comm. These elements demonstrate an understanding of how disruption could be achieved within water treatment systems. However, these attempts are just that. The malware does not contain actual ICS code that would attempt to effect those changes. What it does do, is attempt to do so through the manipulation of the OT layer (e.g. the Windows machines that the malware is detonated on to change those levels in the front end) However, because the activation condition cannot be satisfied, this logic remains dormant and unexecuted, reinforcing that the malware is not currently capable of delivering physical-world impact.
This reframes the malware’s maturity. ZionSiphon operates entirely at the Windows host layer, using registry persistence, PowerShell-based execution, and USB-oriented propagation logic. It is a real, functioning implant in terms of execution mechanics, but the XOR bug prevents it from transitioning into an active sabotage phase, rendering it effectively non-operational as an ICS attack tool.
Compounding this limitation is the absence of any meaningful communication stack or command-and-control (C2) channel. The malware assessed (SCADA_SecurityPatch_v8.4.exe)
does not maintain operator connectivity, does not receive tasking, and cannot adapt its behavior dynamically once deployed. This removes the possibility of controlled, iterative interaction with target systems, an essential component of any serious ICS attack capability.
As a result, even in a hypothetical scenario where the activation flaw did not exist, the operational model would still be extremely constrained. The malware behaves more like a single-shot, pre-scripted payload than a coordinated intrusion tool. In practical terms, this resembles a “drive-by” action with no ability to correct aim, adjust targeting, or respond to environmental feedback and in this case, executed with insufficient precision to achieve its intended effect.
In its present form, ZionSiphon is therefore more accurately categorized as a prototype, misconfigured payload, or intentionally constrained artifact, rather than a deployable cyber-physical weapon. Its structure demonstrates intent and conceptual targeting, but lacks the control, reliability, and feedback mechanisms required for sustained or meaningful impact on water infrastructure systems.
An additional dimension now strengthens this interpretation: the nature of the code itself. The malware exhibits a pattern of semantically rich but technically shallow ICS logic, where process terminology and targeting concepts are convincing, but underlying implementation depth is limited. This includes incomplete protocol handling, an absence of PLC-resident execution, and a lack of deterministic control paths. Combined with the presence of a critical logic error in a core validation function, this suggests a development process that may have incorporated partial automation or assisted code generation, rather than rigorous engineering validation. While not determinative, the structure is consistent with a scenario in which elements of the code, particularly naming conventions, scaffolding, or ICS-related logic may have been augmented through LLM-style assistance, while overall assembly and operational framing remain human-directed.
The presence of explicit ideological messaging embedded within the binary further complicates interpretation. Decoded content referencing attacks on Israeli population centers introduces a clear narrative and psychological layer that is independent of technical execution. When combined with a payload that cannot activate and a second stage that cannot execute past the Windows host, this raises the possibility that the malware functions, at least in part, as a PSYOP-adjacent artifact, where the objective is to project capability, signal intent, and shape perception rather than achieve immediate operational effect.
From a capability perspective, ZionSiphon still reflects an early-stage attempt to approximate a Stuxnet-like attack model, leveraging a Windows foothold to influence industrial processes. However, the combination of incomplete ICS integration, execution fragility, and the XOR validation failure indicates that it falls well short of a reliable implementation. Whether this reflects immature development, operator error, or deliberate constraint remains unresolved, but it clearly places the malware within a mid-tier or experimental development context.
The most accurate interpretation is therefore layered:
Technical Layer: A real Windows-based malware implant with coherent targeting logic
Capability Layer: Non-functional as an ICS weapon due to a critical validation flaw
Development Layer: Likely a prototype or partially validated build, with possible assisted code generation elements
Psychological Layer: Potential signaling artifact, where perceived capability exceeds actual execution
ZionSiphon should therefore be understood as a conceptually mature but functionally broken ICS-targeting malware, whose significance lies less in its current operational capability and more in what it reveals about the evolving accessibility, modularity, and perception-driven use of cyber-physical attack tooling.
Malware Analysis: SCADA_SecurityPatch_v8.4.exe
ZionSiphon (SCADA_SecurityPatch_v8.4.exe), as understood by the malware sample from 2025, is best understood as a Windows-hosted operational malware implant built around explicit OT and water-sector targeting intent rather than a purely conceptual or symbolic artifact. The cumulative evidence gathered through static reverse engineering, sandbox telemetry, recovered string analysis, and vendor reporting materially reduces earlier uncertainty about the malware’s purpose and operational model. The sample is a PE32 Mono/.NET executable that relies on the Common Language Runtime (mscoree.dll) for execution, placing its logic entirely within the Windows host layer rather than within PLC firmware or native controller environments. Architecturally, this positions ZionSiphon as host-based OT intrusion tooling designed to compromise operator or engineering workstations as the pathway toward potential process disruption.
The malware’s execution workflow is internally coherent and operationally plausible. Embedded identifiers and execution strings including RunAsAdmin, SystemHealthCheck, Start-Process -Verb RunAs, target_verify.log, and delete.bat map to a structured lifecycle involving privilege escalation, persistence, environment validation, and cleanup. Hybrid Analysis telemetry confirmed that the sample stages itself into %LOCALAPPDATA%\svchost.exe, establishes persistence through the current-user Run registry key under SYSTEMHEALTHCHECK, and invokes cleanup routines through batch execution if execution conditions are not met. The masquerading of the payload as svchost.exe reflects recognizable adversary tradecraft intended to blend into legitimate Windows process naming conventions rather than functioning as a placeholder or incomplete concept.
The strongest evidence of deliberate targeting lies within the malware’s environment modeling and industrial process references. The binary contains extensive water-sector-specific configuration names and file paths including C:\ChlorineControl.dat, C:\DesalConfig.ini, C:\RO_PumpSettings.ini, C:\SalinityControl.ini, and C:\WaterTreatment.ini, alongside references to industrial and desalination-associated entities such as Schneider Electric, IDE Technologies, and WaterGenix. These are not generic enterprise strings or superficial theming elements. Instead, they reflect a logically structured representation of desalination and water-treatment operational environments. Additional managed-code identifiers including IncreaseChlorineLevel, IsDamDesalinationPlant, GetProcesses, and CreateUSBShortcut further demonstrate that the malware was designed to enumerate processes, validate target environments, and interact with removable media in ways consistent with industrial intrusion workflows.
The sabotage-oriented process logic embedded in the sample reinforces this assessment. Strings such as Chlorine_Dose=10, Chlorine_Flow=MAX, Chlorine_Pump=ON, Chlorine_Valve=OPEN, and RO_Pressure=80 define a conceptual model for manipulating chemical dosing and reverse-osmosis pressure systems. These parameters correspond to operationally sensitive functions within water-treatment infrastructure and imply an intent to push process variables into potentially disruptive or unsafe states. While there is no evidence that the malware contains mature PLC-specific payload delivery or ladder-logic manipulation capability, the embedded logic clearly moves beyond espionage-oriented collection tooling and into the domain of intended process interference.
At the same time, the malware remains technically constrained and immature when compared to fully operational ICS-native malware families such as Stuxnet, TRITON, Industroyer, or IOCONTROL. Although the sample references industrial protocols including Modbus and DNP3, there is still no evidence of complete protocol implementation, vendor engineering software integration, PLC firmware interaction, or safety-system manipulation. Hybrid Analysis telemetry also confirmed the absence of meaningful DNS resolution, outbound HTTP traffic, or operational command-and-control communications during execution. Despite containing networking functionality through .NET TcpClient, socket APIs, and connection-handling routines, the malware did not demonstrate active beaconing or remote tasking behavior. This strongly suggests an autonomous or pre-scripted execution model in which actions are triggered locally through environment validation rather than controlled dynamically through external infrastructure.
The detonated filename itself further reinforces this operational model. The use of naming the file SCADA_SecurityPatch_v8.4.exe strongly suggests deliberate masquerading as a legitimate industrial software update or maintenance utility. Combined with the extensive OT-themed naming conventions and water-sector references embedded throughout the sample, this creates a highly plausible watering-hole or trusted-update delivery scenario. Under such a model, attackers could establish a malicious website or compromised vendor portal advertising a supposed SCADA or water-treatment software patch and direct operators or engineers toward it through spear-phishing or industry-themed communications. Once executed, the malware could establish persistence, validate the target environment, and opportunistically seed removable media for downstream propagation into more sensitive operational enclaves.
Execution gating and cleanup behavior further support the conclusion that the malware was designed for selective deployment rather than indiscriminate execution. The presence of target_verify.log, environment-validation logic, Israeli IP-range geofencing, and cleanup mechanisms such as delete.bat indicate that the malware evaluates its environment before activating fully and removes artifacts if conditions are not satisfied. This reflects a controlled operational philosophy intended to minimize exposure and reduce forensic visibility outside intended targets.
Overall, ZionSiphon occupies an unusual position within the spectrum of OT malware. It is substantially more operationally coherent than simple propaganda or proof-of-concept malware and demonstrates a complete host-level intrusion lifecycle including privilege escalation, persistence, environment validation, removable-media interaction, and cleanup. At the same time, it lacks the mature ICS-native functionality associated with the most sophisticated cyber-physical malware families. The result is a malware framework that appears operationally credible at the Windows host layer and explicitly aligned toward water-sector disruption, while still remaining developmental, partially constrained, and dependent on contextual execution and human-assisted propagation to achieve meaningful operational impact.
Actor Assessment and Strategic Framing
Attribution remains unconfirmed. The available evidence supports a plausible Iranian nexus, but it does not prove that ZionSiphon was created or deployed by an Iranian state actor, an Iranian proxy, or any specific Iranian APT cluster. The malware’s target selection, embedded references to Israeli water infrastructure, and decoded anti-Israel messaging align with operational themes long associated with Iranian cyber activity directed at Israeli civilian infrastructure. Public reporting also places the malware in the context of Israeli water-treatment and desalination targeting.
Within that frame, the best technical fit is still a mid-tier, MOIS-aligned ecosystem such as MuddyWater or a related contractor/proxy environment, rather than a top-tier bespoke ICS weapons program. The sample’s architecture is a managed PE32 Mono/.NET executable that runs through mscoree.dll, stages itself as %LOCALAPPDATA%\svchost.exe, persists via the SystemHealthCheck Run key, elevates through PowerShell using Start-Process -FilePath ... -Verb RunAs, and cleans up through delete.bat and target_verify.log. That pattern is closer to commodity or lightly customized Iranian tradecraft than to a highly specialized controller-native platform. The Falcon Sandbox report also confirms a malicious score, registry persistence, self-deletion behavior, guarded-memory anti-analysis features, Base64 decoding capability, and the absence of relevant DNS, HTTP, or contacted-host infrastructure.
At the same time, the malware does not exhibit the hallmarks of a mature ICS weapon. It contains water-sector process logic, industrial vocabulary, and protocol references, but no demonstrated PLC-resident code, no ladder-logic manipulation, no vendor-specific engineering-stack abuse, no validated register maps, and no deterministic command path into real control systems. Public reporting similarly describes it as a targeted OT/ICS malware strain aimed at Israeli water systems, but not as a proven Stuxnet- or TRITON-class capability. The most defensible technical reading is that this is a Windows-hosted OT sabotage implant whose ICS layer is still incomplete, experimental, or intentionally simplified. (Darktrace)
The strongest evidence for an Iran-aligned framing comes from the decoded strings. The sample contains extensive water/OT targeting strings tied to Israeli infrastructure and desalination operations, including facility and environment markers such as Mekorot, Sorek, Hadera, Ashdod, Palmachim, Shafdan, and Eilat Desal, alongside control-oriented terms such as DesalPLC, OsmosisPLC, WaterPLC, ChlorineCtrl, ChlorineDose, RO_Pump, and BrineControl. More importantly, the decoded ideological content includes the explicit line “Poisoning the population of Tel Aviv and Haifa”, and the malware also contains an execution-guardrail message reading “Target not matched. Operation restricted to IL ranges. Self-destruct initiated.” These strings materially strengthen the assessment that the malware is framed as anti-Israel and specifically oriented toward Israeli water infrastructure.
However, those same strings are also the clearest reason not to overstate attribution. Ideological text that points toward Iran and against Israel can support an Iran-aligned hypothesis, but it can also function as attribution theater. An actor seeking to implicate Iran, exaggerate Iranian capability, or exploit existing expectations about Iranian cyber behavior could deliberately embed precisely these kinds of messages. The sample’s combination of overt anti-Israel language, Israeli geofencing, Mekorot branding, and incomplete ICS execution depth is consistent not only with a genuine Iranian capability in development, but also with a scenario in which another actor is muddying the water by constructing a malware artifact that looks Iranian on first inspection. In that sense, the ideological layer is evidentiary, but not dispositive.
That ambiguity is especially important because ZionSiphon also reads as an early attempt at a Stuxnet-like attack path against Israel, but without Stuxnet-like engineering maturity. The malware clearly models cyber-physical effects: it hunts for desalination and treatment artifacts, references Modbus and DNP3, and embeds static sabotage values such as Chlorine_Dose=10, Chlorine_Flow=MAX, Chlorine_Pump=ON, Chlorine_Valve=OPEN, and RO_Pressure=80. It is trying to move from a Windows foothold on operator or engineering systems into process disruption. That is strategically significant. But the implementation still falls well short of a real, deterministic industrial attack platform, which makes it plausible both as a prototype capability and as a signaling artifact meant to invoke the idea of an Iranian Stuxnet-for-Israel scenario.
The Falcon Sandbox findings reinforce the dual-use interpretation. The sample is operationally real at the host level: it persists, stages, executes, validates the environment, and self-cleans. But it shows no relevant DNS requests, no relevant HTTP traffic, and no relevant contacted hosts, which means there is no public evidence of a live C2-backed campaign around this sample. That absence supports the view that ZionSiphon is either a self-contained, pre-scripted sabotage implant or a demonstration artifact whose strategic value derives partly from being discovered and analyzed.
The most accurate conclusion is therefore deliberately layered. ZionSiphon may well be consistent with MOIS-linked Iranian operational patterns, and MuddyWater remains the closest tradecraft fit among known Iranian clusters. But there is still no real proof that an Iranian actor built it, and the available data also supports the possibility that another actor intentionally embedded Iran-supporting and anti-Israel text to create exactly that impression. In practical terms, ZionSiphon should be understood as a hybrid artifact: a real host-based malware implant with clear OT sabotage intent, a likely experimental or early-stage attempt to approximate a Stuxnet-like attack path against Israeli infrastructure, and a possible PSYOP or attribution-shaping tool whose ambiguity may itself be part of its operational effect.
Detection Profile and Operational Maturity Assessment
Integration of multi-source analysis including static reverse engineering of the uploaded samples, sandbox telemetry from ANY.RUN and Hybrid Analysis, and detection data from VirusTotal provides a consolidated view of ZionSiphon’s true position within the threat landscape. The resulting picture is not ambiguous: the malware is operationally real at the host-implant layer, but its ICS disruption capability remains unproven and likely immature in its current form.
From a detection standpoint, VirusTotal confirms that the sample is broadly recognized as malicious across multiple engines. However, the classification is inconsistent and generic, with most vendors labeling the file as a .NET or MSIL-based trojan, loader, or agent. There is no consensus naming, and critically, no engine identifies the sample as ICS malware or associates it with industrial protocol abuse. This absence is not incidental. It indicates that the malware’s OT-specific logic is not driving its detection profile. Instead, detection is triggered by conventional behaviors, such as PowerShell-based execution, registry persistence, process masquerading, and general suspicious activity, placing ZionSiphon firmly within the detection envelope of commodity Windows malware.
This observation aligns directly with the static and dynamic analysis of the binary. Reverse engineering confirms that the sample is a Mono/.NET executable with a minimal import table and all functional logic embedded internally. The malware establishes persistence through a Run key (SystemHealthCheck) pointing to a disguised payload (svchost.exe), relaunches itself with elevated privileges via PowerShell, and implements cleanup routines using delete.bat and target_verify.log. These behaviors are not theoretical; they are consistent across sandbox environments and embedded directly in the binary. The implant layer is therefore fully functional and operationally credible, with no indication of being a placeholder or decoy.
Where the assessment becomes more complex is at the ICS interaction layer. The binary contains extensive water-sector targeting artifacts, including configuration paths, process identifiers, and explicit manipulation strings such as Chlorine_Dose=10, Chlorine_Flow=MAX, and RO_Pressure=80. These elements demonstrate clear intent to interfere with water treatment processes, particularly chemical dosing and pressure regulation. However, the implementation lacks the depth required for reliable real-world execution.
Dynamic analysis reinforces this limitation. Execution behavior varies significantly between sandbox runs, with some environments exhibiting full persistence and artifact creation, while others produce minimal activity or even a “no threat detected” verdict. This inconsistency suggests that the malware is highly dependent on environmental conditions, potentially due to validation gating, incomplete code paths, or anti-analysis mechanisms. While this behavior could be interpreted as evasive design, it also introduces uncertainty regarding execution reliability, particularly in non-laboratory conditions.
The broader implication is that ZionSiphon occupies a hybrid position between commodity malware and specialized OT tooling. Its underlying framework is indistinguishable from generic .NET malware, as confirmed by both imphash clustering and VirusTotal classification. Its distinguishing features, the ICS targeting logic and sabotage intent, are layered on top of this framework but are not yet expressed in a technically mature or reliably executable form. This architectural choice provides flexibility and ease of development but limits the malware’s ability to achieve consistent physical impact.
From an operational perspective, the malware is highly likely to succeed in compromising Windows-based systems, particularly those associated with engineering or supervisory functions in water-sector environments. It can persist, execute, and perform environment validation with high confidence. It may also disrupt local applications or introduce configuration inconsistencies that affect operator workflows. However, the probability that it can directly and reliably manipulate physical processes such as chlorine dosing or system pressure—remains low without further development or environment-specific customization.
This duality is central to understanding ZionSiphon. It is not a non-functional artifact, nor is it a mature ICS weapon. It is a functional host-based implant with embedded, but not yet fully realized, OT disruption logic. Its current form suggests either an early-stage capability under development or a modular framework intended for future enhancement. In either case, the gap between intent and execution is evident.
The most defensible conclusion is that ZionSiphon represents a transitional class of malware, bridging traditional IT compromise and potential OT impact. Its significance lies less in its immediate effectiveness and more in what it signals: that targeted, domain-aware cyber-physical tooling can be constructed using relatively accessible components. While it does not yet demonstrate the precision or reliability of established ICS malware families, it provides a clear indication of direction toward more modular, adaptable, and potentially proliferating OT-focused threats.
Strategic Assessment and Forward Outlook
ZionSiphon is best understood as a targeted ICS sabotage capability in development, combining deliberate, domain-aware targeting logic with a modular and reusable technical foundation. The accumulated evidence of static analysis, sandbox telemetry, and decoded string corpus confirms that the malware encodes a coherent conceptual model of water treatment operations, particularly chlorine dosing and reverse osmosis control. At the same time, it relies on a commodity Windows/.NET implant layer for execution, persistence, privilege escalation, and delivery. This hybrid construction places the malware in a transitional category: operationally real and credible at the host level, but not yet reliably effective at the control-system level.
The broader strategic context reinforces this interpretation, while also introducing a critical layer of ambiguity. Since 2025, Israeli water infrastructure, especially systems associated with Mekorot, has remained a recurring target in cyber operations and reporting. ZionSiphon fits squarely within that targeting pattern, including its geographic scoping to Israeli networks and its explicit references to desalination facilities and water-treatment processes. However, there is still no publicly confirmed instance of successful cyber-induced physical disruption to these systems in the current reporting cycle. This persistent gap between targeting intensity and observable impact is analytically significant. It highlights both the priority placed on this sector and the continued limitations of adversary capabilities.
ZionSiphon embodies that gap directly. Its embedded parameter manipulation strings, process-specific vocabulary, and environment validation logic clearly demonstrate intent to influence physical processes. Yet its reliance on static configuration assumptions, incomplete industrial protocol handling, absence of validated PLC interaction, and environment-dependent execution behavior indicate that it is not yet a mature or deterministic ICS weapon. In its current form, the malware is more likely to produce host-level compromise, configuration disruption, and operational friction than sustained or precise control over industrial processes.
At the same time, the sample introduces an additional dimension that materially affects its strategic interpretation: the presence of explicit ideological messaging and narrative cues embedded within the binary. These elements are not required for execution and instead serve a signaling function, shaping how the malware is interpreted once discovered. Combined with its Israeli targeting, they create an artifact that is not purely technical. This opens the possibility that ZionSiphon is functioning in part as a PSYOP-adjacent tool, where perception of capability and intent is itself an operational objective. Importantly, while the messaging aligns with Iran-aligned narratives, there is no definitive proof that the malware originates from an Iranian actor. The same elements that support an Iranian attribution hypothesis could also be deliberately constructed by another actor to mimic, exaggerate, or redirect attribution, effectively muddying the waters.
From a capability perspective, ZionSiphon also reads as an early-stage attempt to approximate a Stuxnet-like attack model, but within a far less mature development ecosystem. It follows the same broad conceptual pathway leveraging a Windows foothold to reach and influence physical processes but lacks the deep engineering integration, protocol precision, and reliability that defined earlier state-developed ICS weapons. It is therefore best characterized as a process-aware prototype, reflecting ambition and direction rather than fully realized capability.
Despite its current limitations, the malware’s architecture carries significant forward-looking implications. By decoupling ICS-specific logic from the underlying implant, ZionSiphon reflects a modular design philosophy that enables rapid iteration and reuse. The Windows-based execution layer provides a stable foundation onto which increasingly sophisticated OT-specific components can be layered. Future variants could therefore evolve quickly, incorporating:
More complete protocol implementations (e.g., Modbus, DNP3, or vendor-specific interfaces)
Improved environment detection and targeting precision
Greater execution reliability and error handling
Limited feedback mechanisms or controlled tasking capabilities
Such evolution would move the capability from conceptual disruption toward repeatable and controllable operational effects, narrowing the current gap between intent and execution.
The most significant implication is structural rather than purely technical. ZionSiphon signals that cyber-physical attack development is becoming more accessible. Unlike earlier ICS malware such as Stuxnet, which required extensive resources, specialized engineering knowledge, and tightly integrated development pipelines, this model leverages widely available tooling and incremental domain understanding. The barrier to entry is therefore lower, enabling a broader range of actors including contractors, proxy groups, or semi-professional operators to experiment with OT-oriented malware development.
This shift also increases the likelihood of proliferation and adaptation. The same architectural model could be repurposed across sectors by substituting environment-specific logic, extending beyond water infrastructure into energy, manufacturing, or transportation systems. Even if ZionSiphon itself remains limited, it represents a template for iterative development, where successive improvements progressively close the gap between conceptual capability and operational effectiveness.
Finally, the dual-use nature of the malware remains strategically important. In an environment where no confirmed physical attacks have occurred despite persistent targeting, artifacts like ZionSiphon may serve not only as technical tools but also as instruments of signaling and perception management. Their discovery, analysis, and public reporting contribute to an evolving perception of cyber-physical threat capability, influencing defensive postures, policy responses, and strategic calculations.
ZionSiphon should therefore be understood not as a fully realized ICS weapon, but as a directional indicator: a hybrid artifact that combines real host-level capability, emerging cyber-physical intent, and potential psychological or attribution-shaping effects.
Appendix A – Indicators of Compromise: ZionSiphon / SCADA_SecurityPatch_v8.4.exe
Hybrid mapped the sample to execution guardrails, sandbox/VM checks, host discovery, process enumeration, and language/locale discovery.
A.5 Water / OT Targeting Indicators
Process name checks
DesalPLC
OsmosisPLC
ROController
DesalMonitor
SchneiderRO
RO_Filter
DamRO
ChlorineDose
ReverseOsmosis
RO_Membrane
WaterGenix
DesalFlow
RO_Pump
WaterTreat
ChlorineCtrl
SalinityCtrl
WaterPLC
SeaWaterRO
BrineControl
Directory checks
C:\Program Files\Desalination
C:\Program Files\RO Systems
C:\Program Files\Schneider Electric\Desal
C:\Program Files\DesalTech
C:\Program Files\IDE Technologies
C:\Program Files\Aqua Solutions
C:\Program Files\Water Treatment
C:\Program Files\Hydro Systems
Configuration file checks
C:\DesalConfig.ini
C:\WaterTreatment.ini
C:\ROConfig.ini
C:\ChlorineControl.dat
C:\DesalSettings.conf
C:\RO_PumpSettings.ini
C:\Program Files\Desalination\system.cfg
C:\SalinityControl.ini
Facility / sector strings
Mekorot
Shafdan
Sorek
Schneider Electric
Hadera
IDE Technologies
Ashdod
WaterGenix
Palmachim
Hybrid file metadata also lists ProductName and FileDescription as Mekorot, reinforcing the Israeli water-sector masquerade.
A.6 Configuration Manipulation Indicators
Chlorine_Dose
10
Chlorine_Pump
ON
Chlorine_Flow
MAX
Chlorine_Valve
OPEN
RO_Pressure
80
These remain high-confidence impact-oriented strings tied to chlorine handling and reverse-osmosis pressure manipulation.
A.7 Network and Protocol Indicators
Network APIs and socket capability
Hybrid confirms socket capability but also reports:
Network APIs
System.Net
NetworkStream.Read
System.Net.Sockets
NetworkStream.Write
TcpClient
TcpClient.Close
TcpClient.Connect
WSAStartup
TcpClient.BeginConnect
setsockopt
TcpClient.GetStream
gethostbyname
GetAddrInfoW
Network activity
No relevant DNS requests
No relevant contacted hosts
No relevant HTTP requests
This supports the assessment that no operational C2 was observed during detonation.
Industrial protocol references
Protocol / pattern
Bytes
Modbus
DNP3
S7comm
Modbus request pattern
01 03 00 00 00 0A
DNP3 partial pattern
05 64 0A 0C 01 02
S7comm partial pattern
03 00 00 13 0E 00
S7comm partial pattern
05 00 1C 22 1E
A.8 Targeting and Geofencing Indicators
IPv4 ranges observed in binary/memory
2.52.0.0 – 2.55.255.255
5.28.0.0 – 5.29.255.255
79.176.0.0 – 79.191.255.255
212.150.0.0 – 212.150.255.255
Hybrid directly reported the 2.52.0.0-2.55.255.255 and 5.28.0.0-5.29.255.255 ranges as potential IP ranges in binary/memory.
A.9 USB / Removable-Media Propagation Indicators
Recovered strings and behavioral primitives
CreateUSBShortcut
SetAttributes
DriveInfo
.lnk
GetLogicalDrives
shell32.dll
GetFiles
svchost.exe
CopyFileW
CopyFileExW
Assessed removable-media artifacts
\svchost.exe
*.lnk files in root of removable media
Shortcut TargetPath pointing to hidden executable
Icon spoofing via shell32.dll,4
Hybrid confirms GetLogicalDrives, file-copy behavior, and file-attribute capability, but did not capture a complete successful USB infection event during detonation. Therefore, USB propagation should be treated as strongly supported by strings and vendor reverse engineering, not as a fully observed sandbox behavior.
A.10 Self-Deletion and Cleanup Indicators
Cleanup artifacts
%TEMP%\delete.bat
cmd.exe /c "%TEMP%\delete.bat"
Observed deletion targets
C:\SCADA_SecurityPatch_v8.4.exe
%TEMP%\delete.bat
Hybrid observed cmd.exe executing %TEMP%\delete.bat and marking both the original sample and cleanup script for deletion.
No confirmed fully executed USB infection event in sandboxThese negative indicators suggest a constrained or pre-operational deployment model, likely centered on local execution, environmental validation, and workflow-assisted movement rather than remotely tasked command-and-control.
APPENDIX B Static Reverse Engineering of the Uploaded Sample
The uploaded file, identified by SHA-256 07c3bbe60d47240df7152f72beb98ea373d9600946860bad12f7bc617a5d6f5f, is a PE32 Mono/.NET executable, indicating that all operational logic is implemented in managed code rather than native binaries. The import table is minimal and limited to the CLR bootstrap (mscoree.dll via _CorExeMain), which is characteristic of .NET malware that delegates functionality to internal assemblies. This structural choice confirms that the sample is a Windows-hosted implant, not a controller-resident ICS payload, and that its operational model depends on execution within userland environments such as engineering workstations or operator systems.
The binary exhibits a coherent and internally consistent execution model. Embedded strings and method identifiers indicate that the malware initiates execution by attempting to relaunch itself with elevated privileges through PowerShell, using a command pattern consistent with Start-Process -FilePath ... -Verb RunAs. This is followed by persistence establishment via the Windows registry. Specifically, the malware is designed to write a Run key under Software\Microsoft\Windows\CurrentVersion\Run using the value name SystemHealthCheck, pointing to a staged payload masquerading as svchost.exe within the user’s local application directory. This persistence mechanism is operationally credible and aligns with common masquerade techniques intended to blend malicious binaries with legitimate system processes.
The sample’s most distinctive feature is its environment validation logic, which is explicitly tailored to water treatment and desalination systems. The binary contains numerous hardcoded file paths and configuration filenames associated with industrial processes, including chlorine control, reverse osmosis, salinity regulation, and water treatment operations. These include paths such as C:\ChlorineControl.dat, C:\DesalConfig.ini, C:\RO_PumpSettings.ini, and C:\WaterTreatment.ini, as well as vendor- or application-associated directories such as C:\Program Files\Schneider Electric\Desal\config.ini and C:\Program Files\WaterGenix\system.conf. The presence of these strings indicates that the malware performs host-based reconnaissance to determine whether it is executing within a relevant operational environment before proceeding.
This validation stage is further reinforced by recovered method names such as IsDamDesalinationPlant, GetProcesses, and DriveInfo, which suggest a structured approach to system classification. The malware likely enumerates running processes, inspects filesystem artifacts, and evaluates system characteristics to determine whether the host is associated with desalination or water treatment infrastructure. Only upon successful validation does the malware proceed to its impact phase, indicating a gated execution model designed to minimize noise and avoid unintended activation.
The impact logic itself is revealed through a set of explicit configuration strings embedded in the binary. These include Chlorine_Dose=10, Chlorine_Flow=MAX, Chlorine_Pump=ON, Chlorine_Valve=OPEN, and RO_Pressure=80. These values correspond directly to operational parameters within water treatment systems and suggest that the malware is designed to modify or inject configuration data affecting chemical dosing and pressure control. While static analysis cannot confirm whether these values map precisely to real-world control systems, their specificity and coherence indicate a clear intent to disrupt physical processes, particularly those related to water quality and system stability.
In addition to its primary payload, the malware includes functionality for removable media interaction, as evidenced by strings such as CreateUSBShortcut, .lnk, and shell32.dll, 4. This suggests the ability to create deceptive shortcut files on USB drives, potentially enabling lateral movement or execution in segmented environments where direct network propagation is not feasible. This feature is consistent with operational environments in ICS networks, where air gaps or limited connectivity often necessitate physical transfer mechanisms.
The sample also implements a cleanup and self-deletion routine, using artifacts such as target_verify.log and delete.bat. These components indicate that the malware logs the outcome of its environment validation and, if conditions are not met or execution fails, initiates a self-removal process via a batch script. This behavior aligns with a low-footprint operational model, where the malware seeks to avoid detection by minimizing residual artifacts on non-target systems.
From a tradecraft perspective, the binary demonstrates a functional and intentional design. It includes persistence, privilege escalation, environment validation, removable media handling, and process-specific manipulation logic. These elements collectively support the assessment that the sample is a real and operational Windows-based implant, not merely a decoy or string-based artifact. However, the malware does not exhibit the characteristics of a mature ICS platform. There is no evidence of PLC firmware interaction, vendor-specific engineering tool manipulation, or deep integration with industrial control protocols at the controller level.
The most accurate classification is that this sample represents a host-side OT sabotage implant, designed to operate within Windows environments that interface with water treatment systems. Its strength lies in its targeting logic and process awareness, rather than in advanced ICS exploitation techniques. This places it in a transitional category of malware that bridges traditional IT compromise and OT disruption, relying on access to engineering or supervisory systems to influence physical processes.
Threat Intelligence Report: The SDA / Structura / Doppelgänger, Influence Operations, Infrastructure, Reach, and Potential
How does the Doppelgänger influence campaign reach 5M+ users? Read DTI’s latest report on the SDA/Structura ecosystem, featuring a deep dive into narrative propagation, domain rotation tactics, and a 72-hour crisis influence timeline.
Executive Summary
The Doppelgänger (aka Social Design Agency (SDA)) campaigns are a coordinated series of online influence operations attributed to Russian-linked actors and associated with the technical operator, Structura. The campaign leverages a distributed ecosystem of spoofed media websites, Telegram amplification networks, and coordinated X/Twitter bot account clusters to disseminate political narratives targeting Western audiences.
The operational architecture is designed around a feeder-and-amplifier model. Controlled websites host narrative artifacts such as articles, memes, and commentary. These artifacts are distributed through Telegram channels with large subscriber bases and are subsequently injected into active discussions on X through coordinated reply swarms.
This architecture enables the campaign to scale rapidly while maintaining resilience against disruption. Domain infrastructure can be regenerated quickly, social accounts are disposable, and narratives can be redistributed through independent amplification channels.
Analysis of subscriber counts and documented campaign activity suggests that a typical Doppelgänger narrative wave exposes approximately 1.5 to 2.7 million users, with larger event-driven campaigns potentially reaching 3 to 5 million users.
The campaign’s objective is not necessarily direct persuasion but narrative saturation, in which repeated exposure across multiple platforms introduces and normalizes targeted narratives within the information ecosystem.
Actor and Organizational Structure
The operational structure of the Doppelgänger influence campaign reflects a coordinated system that combines strategic messaging organizations, technical infrastructure providers, and elements associated with Russia’s broader state-directed political communication environment. At the center of this ecosystem are two entities that appear to play complementary roles: the Social Design Agency (SDA) and Structura. Together, these organizations form the operational core of the campaign’s architecture, linking narrative development with the technical systems required to publish, distribute, and amplify influence content across multiple digital platforms.
The Social Design Agency (SDA) appears to function as the primary strategic and operational planning body behind the campaign. Open-source investigations and public reporting have associated the organization with a number of large-scale information operations targeting audiences in Europe and North America. Within the Doppelgänger ecosystem, SDA’s role is assessed to focus on the design and coordination of narrative components that underpin the campaign’s messaging. This includes the development of thematic narratives, the planning and timing of coordinated influence activities, and the orchestration of distribution through social
media channels and affiliated amplification networks. SDA also appears to maintain relationships with technical service providers responsible for maintaining the infrastructure used to host and disseminate campaign content. In this capacity, the organization functions as the central coordinating entity that aligns narrative development, operational timing, and distribution strategies across the broader influence network.
Complementing this strategic function, Structura appears to provide the technical infrastructure that allows the campaign to operate at scale. Structura acts as the backbone of the Doppelgänger ecosystem by managing the digital assets used to publish, distribute, and track campaign narratives. Its responsibilities include the registration and administration of domains used for pseudo-media websites, the deployment and maintenance of the web infrastructure hosting campaign articles, and the operation of redirect systems that guide audiences from social media platforms to campaign-controlled sites. Structura is also believed to operate analytics and tracking capabilities that enable operators to measure engagement levels, monitor traffic patterns, and evaluate the performance of individual narratives. These capabilities support both operational resilience and adaptive campaign management, allowing infrastructure to be regenerated or replaced quickly when domains are seized, blocked, or otherwise disrupted.
Evidence from multiple public investigations further suggests that the Doppelgänger campaign operates within a broader ecosystem of Russian state-aligned information activities. Reporting has connected elements of the network to organizations and political communication structures associated with the Russian Presidential Administration, including the government-linked organization ANO Dialog and senior political figures such as Sergei Kiriyenko, who has been identified in public reporting as playing a significant role in coordinating domestic and international messaging initiatives. While the precise command relationships within this ecosystem are not fully transparent, these connections indicate that the operation likely functions within a wider strategic communications environment linked to Russian state interests.
Taken together, the interaction between SDA’s narrative planning and campaign coordination functions, Structura’s management of technical infrastructure, and the broader involvement of state-linked political communication structures suggests a coordinated operational model. Within this model, influence operations are integrated into a larger system of information confrontation. Inside the system, messaging strategy, technical infrastructure, and distribution networks are aligned to introduce and amplify narratives within the international information environment in ways that support broader geopolitical objectives.
Synthetic Media Personnel Structure (RRN Employee Layer)
Analysis of the ingested employee directory from Reliable Recent News provides direct insight into the constructed human layer underpinning the Doppelgänger ecosystem. In contrast to infrastructure or domain-based analysis, this dataset reveals how the operation systematically simulates a functioning media organization through a curated set of personnel, roles, and hierarchical relationships. This structure does not reflect a genuine workforce; rather, it constitutes a deliberately engineered organizational façade designed to support narrative attribution and reinforce perceived credibility.
The employee listing presents a fully developed newsroom hierarchy that closely mirrors legitimate Western media institutions, with an Editor-in-Chief at the apex, followed by senior and section editors, subject-matter analysts, and a base layer of journalists, correspondents, and contributors. The consistency and repeatability of this structure indicate a templated design rather than organic organizational growth, replicating the visual and procedural signals of editorial rigor, review, and domain expertise associated with credible outlets. In practice, these roles function primarily as perception management mechanisms: senior editors act as legitimacy anchors, analysts serve as authority proxies for geopolitical narratives, and journalists provide bylines that convert anonymous content into ostensibly reported material. Collectively, this framework simulates the full lifecycle of journalism analysis, reporting, editing, and publication without any underlying authentic process.
The identities themselves exhibit hallmarks of synthetic construction, including generic Western naming conventions, absence of external validation, and minimal or templated biographical detail, supporting their assessment as fabricated and designed for reuse. The uniform role structure enables rapid replication across domains, reinforcing consistent credibility signals while allowing personas to be reassigned or recycled without disrupting the façade of institutional integrity. Functionally, this layer operates as an intermediary between content and audience perception, transforming unattributed messaging into authored analysis extended across websites, Telegram channels, and social platforms to create a persistent identity presence. This demonstrates that the Doppelgänger operation incorporates identity fabrication as a core architectural component that is structured, reusable, and integral to delivery. It also means that effective disruption must address not only infrastructure but this portable persona layer, which can be rapidly redeployed to reconstitute credible media fronts.
Infrastructure Architecture
Feeder Website Network
The operational foundation of the Doppelgänger campaign is a distributed network of websites designed to host narrative content while closely mimicking legitimate news organizations. These sites function as the primary publishing layer of the campaign, providing the initial point of origin for narratives that are subsequently distributed across social media platforms.
Rather than relying exclusively on social media posts, the campaign infrastructure directs audiences to these external domains, which are designed to resemble independent media outlets. This approach provides several operational advantages. First, it allows operators to publish long-form narrative content that appears to originate from a news-style source rather than from social media accounts. Second, it creates a stable destination for links shared across Telegram channels and X/Twitter accounts, enabling narratives to persist even when individual social media posts are removed or accounts are suspended.
The feeder sites also serve an important operational security function. By hosting narrative content on controlled domains, operators create a layer of separation between the messaging infrastructure and the social media accounts used to distribute the content. This separation complicates attribution and allows narratives to circulate through secondary citation chains in which the original campaign infrastructure is no longer visible.
In addition to narrative hosting and attribution shielding, the feeder websites allow operators to collect traffic metrics and engagement data. By directing audiences to controlled domains, campaign operators can measure which narratives attract the greatest engagement and adjust future messaging accordingly.
Investigations into the Doppelgänger infrastructure have identified several representative domains associated with the campaign’s publishing network, including rrn[.]world *now an investigative site into SDA not an SDA controlled domain*, memhouse[.]online, truemaps[.]info, tribunalukraine[.]info, and avisindependent[.]eu. Alongside these domains, the ecosystem includes numerous cybersquatted sites designed to resemble well-known Western news organizations. These domains typically replicate visual branding, layout, and naming conventions of legitimate media outlets in order to increase the perceived credibility of the hosted content.
Redirect and Tracking Infrastructure
Supporting the feeder website network is a layered redirect and traffic-management system that enables the campaign to control how audiences reach narrative content. This infrastructure provides several operational capabilities, including audience geo-targeting, detailed traffic analytics, link obfuscation, and rapid substitution of infrastructure when individual domains are disrupted.
Redirect chains allow campaign operators to route users through multiple intermediary links before they arrive at the final destination site. This technique serves both operational security and campaign optimization purposes. From an operational perspective, it obscures the relationship between the original distribution platform and the hosting domain, making attribution more difficult. From an analytics perspective, it allows operators to monitor user engagement and measure the performance of individual links and narratives.
Public investigations have identified the use of traffic-management platforms such as Keitaro, a software system widely used in affiliate marketing ecosystems to manage link routing and analyze traffic patterns. When applied within influence operations, tools of this type can provide operators with detailed information about audience behavior, including geographic distribution, referral sources, and click-through rates. These capabilities enable campaign managers to refine messaging and distribution strategies based on real-time engagement metrics.
Domain Rotation and Regeneration
A defining characteristic of the Doppelgänger infrastructure is its ability to regenerate quickly when individual domains are blocked or seized. The campaign employs a strategy of continuous domain rotation in which new websites are deployed to replace disrupted infrastructure with minimal delay.
Evidence from multiple investigations indicates that replacement domains can appear with rapidity after a disruption event. This rapid regeneration capability suggests the presence of an organized infrastructure management process capable of registering domains, deploying website templates, and integrating new sites into the existing redirect and distribution systems on short notice.
The ability to rapidly replace infrastructure significantly increases the resilience of the campaign. Even when individual domains are removed by platform enforcement actions or law enforcement interventions, the broader narrative distribution network can continue operating with minimal interruption. As a result, the campaign’s influence activities persist through a cycle of disruption and regeneration that allows operators to maintain a continuous presence within the information ecosystem.
Operational Distribution Model
The Doppelgänger campaign distributes narratives through a structured, multi-stage pipeline designed to move content from controlled publishing infrastructure into large-scale public exposure across social media platforms. Rather than relying on a single channel for dissemination, the campaign employs a layered distribution architecture in which each stage performs a distinct operational role. This structure allows operators to maintain separation between narrative creation, infrastructure hosting, and public amplification, increasing both the resilience and scalability of the campaign.
The process begins with content creation, where narratives are developed and formatted for publication. At this stage, messaging themes are crafted to align with broader campaign objectives and current geopolitical developments. The narratives are typically designed to resemble journalistic reporting or analysis in order to increase their credibility and shareability once introduced into public discourse.
Once created, the content is published on feeder websites controlled by the campaign infrastructure. These sites serve as the primary hosting layer for narrative material and provide a stable destination for links that will later be shared across social media platforms. By placing the content on standalone domains that mimic legitimate news outlets, operators create a degree of separation between the narrative source and the social accounts used for distribution.
Following publication, the narrative enters the Telegram amplification stage. Telegram channels with established audiences serve as the primary distribution engine for the campaign. These channels repost links to the feeder websites, exposing the narratives to large subscriber bases and creating the initial wave of engagement. Because many of these channels already maintain audiences interested in geopolitical or ideological content, Telegram functions as an efficient mechanism for rapidly spreading narratives to receptive communities.
After gaining traction within Telegram networks, the campaign proceeds to X/Twitter injection. At this stage, coordinated social media accounts begin posting links to the feeder sites or discussing the narratives within existing conversations on the platform. These posts often appear within replies to trending topics, political discussions, or posts from influential accounts. The goal of this stage is to introduce the narrative into broader public discourse, reaching users who are not directly connected to the Telegram amplification network.
The final stage of the pipeline is audience exposure, where the narrative reaches individuals across the wider information ecosystem. At this point, the content may be encountered through social media threads reposted by other users, or referenced in discussions across forums, blogs, and other digital platforms. Once a narrative reaches this stage, it may continue circulating independently of the original campaign infrastructure.
This multi-stage distribution model allows the Doppelgänger campaign to move narratives from controlled infrastructure into mainstream online discourse while maintaining operational flexibility. By separating narrative creation, hosting, and amplification across distinct layers, the campaign achieves both scalability and resilience, enabling it to sustain influence activities even when individual domains or accounts are disrupted.
Telegram Amplification Layer
Within the Doppelgänger campaign architecture, Telegram functions as the primary distribution engine and reach multiplier. While feeder websites host the narrative content and X/Twitter accounts inject the narratives into public conversation, Telegram channels provide the high-capacity amplification required to expose those narratives to large audiences quickly.
The platform’s structure makes it particularly well suited to this role. Telegram channels can accumulate very large subscriber bases and distribute content instantly to those audiences without the algorithmic filtering mechanisms present on many Western social media platforms. As a result, a single post in a high-subscriber channel can expose campaign narratives to hundreds of thousands of users within minutes.
The Doppelgänger campaign leverages this dynamic by utilizing established channels within the broader pro-Kremlin Telegram ecosystem. These channels function as distribution hubs, reposting links to feeder websites and circulating campaign narratives across interconnected networks of subscribers. Once a narrative appears in one of these large channels, it is frequently reposted by smaller affiliated channels, creating an amplification cascade that expands the narrative’s reach across the platform.
Several prominent Telegram channels have been identified as major amplifiers within this ecosystem. These include Readovka, SolovievLive, IntelSlava, Ukraina[.]ru, and OstashkoNews, each of which maintains a substantial subscriber base and regularly circulates geopolitical and war-related content aligned with pro-Kremlin messaging. Collectively, these channels represent a significant distribution network capable of reaching millions of users.
Combined subscriber counts across these channels exceed five million accounts. However, subscriber overlap between channels means that the total audience exposed to a given narrative is smaller than the raw subscriber numbers might suggest. Many users subscribe to multiple channels within the same information ecosystem, which reduces the number of unique individuals reached by each amplification wave.
Taking this overlap into account, the estimated unique exposure per narrative wave distributed through these major channels historically has approximately been up to 1.2 to 2.4 million viewers. This range reflects the realistic audience size likely to encounter a narrative during a typical amplification cycle.
Because of this reach, Telegram serves as the central amplification layer within the Doppelgänger campaign. The platform enables rapid dissemination of narratives from the feeder website network and provides the initial audience engagement that supports subsequent injection of those narratives into broader social media conversations on platforms such as X/Twitter.
X / Twitter Injection Layer
Within the Doppelgänger campaign architecture, X (formerly Twitter) serves a different operational function from Telegram. Whereas Telegram channels provide large-scale distribution to existing subscriber audiences, X is primarily used as a mechanism for narrative insertion into active public conversations. The platform’s role in the campaign is therefore less about direct reach through large follower bases and more about leveraging algorithmic visibility within ongoing discussions.
Unlike traditional influence campaigns that rely on prominent influencers or high-follower accounts, Doppelgänger operators typically deploy clusters of disposable social media profiles. These accounts are designed to be rapidly created, used for short operational periods, and replaced when suspended or detected. As a result, the accounts associated with these operations often exhibit several common characteristics.
Most have minimal follower counts, indicating that they are not intended to build long-term audiences. Many profiles are recently created, sometimes within days or weeks of their participation in coordinated posting activity. Usernames frequently consist of generic or randomly generated combinations of characters, and profile images are commonly drawn from stock photography or produced using AI-generated portrait tools. These traits collectively suggest that the accounts are designed primarily for operational utility rather than credibility or sustained engagement.
Instead of broadcasting content to followers, these accounts engage in coordinated reply behavior. Operators target posts that are already receiving significant engagement—such as political discussions, breaking news events, or posts from high-profile accounts—and insert replies containing links to feeder websites or narrative fragments aligned with campaign messaging. By appearing within existing conversation threads, the campaign attempts to expose the narrative to users who are already participating in or observing those discussions.
Investigations into the Doppelgänger campaign have documented several examples of this tactic. One operation targeting U.S. audiences involved approximately thirty-nine coordinated accounts posting replies within political discussions. Other investigations have identified larger botnet-style clusters consisting of more than one thousand coordinated accounts, indicating that the scale of these operations can vary significantly depending on the campaign objectives.
Within the overall influence architecture, the X layer therefore contributes algorithmic amplification rather than follower-based distribution. By inserting narratives into high-visibility discussion threads, the campaign can exploit platform algorithms that prioritize active conversations, allowing content posted by otherwise low-follower accounts to appear in front of large audiences. In this way, the X component of the campaign acts as a bridge between the controlled distribution channels of Telegram and the broader public information environment.
Narrative Propagation Mechanics
The spread of narratives within the Doppelgänger ecosystem follows a cascade-style propagation model in which content moves through a sequence of amplification stages. Each stage expands the potential audience and increases the likelihood that the narrative will enter broader online discourse. This cascading structure allows relatively small origin accounts or channels to generate large-scale exposure once the narrative reaches high-capacity distribution nodes.
The process typically begins with an origin post, which may appear either on a feeder website or within a smaller Telegram channel associated with the campaign ecosystem. At this stage, the narrative exists within a relatively limited audience environment and functions primarily as the initial seed for the distribution pipeline.
From there, the narrative is introduced into a Telegram origin channel, where it begins to circulate within networks of subscribers that regularly consume geopolitical or ideological content aligned with pro-Kremlin messaging. These origin channels often serve as staging points where narratives are prepared for broader amplification.
The critical expansion phase occurs when the narrative is reposted by a large Telegram amplifier channel with a substantial subscriber base. Channels operating at this level of the ecosystem can expose content to hundreds of thousands of users simultaneously. Once a narrative reaches this stage, it becomes highly visible across the Telegram information environment.
Following publication in a major amplifier channel, the narrative enters a secondary repost cascade. Smaller affiliated channels frequently repost content originating from large channels, either automatically or through loosely coordinated editorial behavior. This reposting activity produces a cascading effect in which the narrative spreads across interconnected Telegram communities, further expanding its reach.
After the narrative gains traction within Telegram, the campaign introduces the content into the X/Twitter layer through coordinated account activity. Clusters of disposable accounts begin posting links, excerpts, or commentary related to the narrative within active discussions on the platform. This step serves to insert the narrative into broader public conversations, particularly those involving political or geopolitical topics.
The final stage of the cascade occurs when the narrative achieves secondary discourse uptake. At this point, users outside the original campaign infrastructure begin referencing or discussing the narrative independently. The content may appear in comment threads, forums, blog posts, or other social media discussions, often without direct reference to the original source.
Through this cascade model, a narrative originating from a relatively small node within the campaign network can rapidly expand to reach a much larger audience. The combination of Telegram amplification and social media insertion enables the Doppelgänger ecosystem to convert limited initial publication into widespread exposure across multiple digital platforms.
Campaign Reach and Effects
Subscriber metrics from major Telegram amplification channels, combined with observed activity patterns, enable bounded estimates of reach for a typical Doppelgänger narrative wave. The distribution model using Telegram as the primary amplifier, followed by coordinated activity on X/Twitter means total exposure is driven by the number of participating channels and the intensity of downstream social amplification.
Operationally, narrative waves fall into three intensity tiers:
Baseline Campaign The most common configuration. Narratives are pushed through multiple large Telegram channels, then reinforced by coordinated X/Twitter reply clusters. This layered amplification produces an estimated reach of 1.5–2.7 million users, with 100,000–300,000 interactions. Secondary uptake expands to 10,000–40,000 mentions, indicating spillover beyond controlled infrastructure into broader discourse.
Low-Intensity Campaign A single major Telegram channel with limited X/Twitter support. The distribution cascade is constrained, yielding 800,000–1.3 million users reached, 40,000–120,000 interactions, and 2,000–5,000 secondary mentions. Despite lower scale, narratives still penetrate sizable audiences, particularly within high-interest topics.
High-Intensity Campaign Aligned with major geopolitical events, leveraging elevated attention and search activity. Multiple high-capacity Telegram channels and dense X/Twitter coordination drive accelerated spread. Estimated reach increases to 3–5 million users, with 250,000–700,000 interactions and 40,000–100,000 secondary mentions. At this stage, narratives routinely escape campaign control and persist in wider information ecosystems.
Across all tiers, the architecture demonstrates consistent scaling behavior: small origin points are amplified through Telegram, reinforced via coordinated social activity, and ultimately propagated into broader public discourse.
Strategic Impact Assessment
The Doppelgänger campaign is engineered for visibility, not direct persuasion. Its architecture–feeder websites, Telegram amplification, and coordinated X/Twitter activity–prioritizes rapid distribution and repeated exposure across platforms to maximize encounter frequency.
The objective is to seed narratives into the information environment and sustain their circulation, rather than secure immediate belief. Repetition across multiple sources increases perceived relevance and can shape interpretation of events, even when claims remain contested.
A central mechanism is manufactured ubiquity. By injecting narratives into active discussions and amplifying them across channels, the campaign creates the appearance of widespread, organic debate. This perceived consensus elevates legitimacy, particularly when content surfaces simultaneously across domains and platforms.
Effectiveness does not require broad persuasion. Limited engagement is sufficient to generate secondary propagation mentions, reposts, and commentary that extend reach beyond controlled infrastructure. As these references accumulate, narratives diffuse into general discourse, producing a form of information contamination in which repeated exposure normalizes their presence.
Over time, this process increases perceived credibility and embeds narratives within the broader information ecosystem. The strategic outcome is not conversion, but contextual influence shaping how events are framed and understood.
Doctrinal Context: Doppelgänger Within Russian Information Confrontation Strategy
The operational architecture of the SDA / Doppelgänger campaign aligns closely with established Russian concepts of information confrontation (informatsionnoye protivoborstvo/информационное противоборство), a strategic doctrine that integrates information operations into broader geopolitical competition.
Rather than focusing solely on direct persuasion or propaganda in the traditional sense, Russian information confrontation doctrine emphasizes shaping the information environment itself. The objective is to influence how events are interpreted, weaken adversary cohesion, and introduce persistent uncertainty into public discourse.
The layered architecture observed in the Doppelgänger campaign, such as combined web infrastructure, social amplification networks, and rapid regeneration capabilities reflects this doctrinal emphasis on environmental influence rather than individual audience conversion.
Continuity With Soviet Active Measures
The operational structure of the Doppelgänger campaign demonstrates clear continuity with Soviet-era Active Measures, a category of covert influence operations historically conducted by the KGB and other Soviet intelligence services. Active Measures were designed to shape political perceptions abroad through the controlled dissemination of misleading or manipulated information. Rather than relying solely on overt propaganda channels, these operations frequently used covert or semi-covert mechanisms intended to obscure the origin of the messaging and create the appearance of independent sources.
Historically, Active Measures campaigns relied on a combination of forged publications, front organizations, and intermediary actors to introduce narratives into foreign information environments. Articles containing false or misleading claims were often placed in controlled outlets or sympathetic publications, where they could be cited by other media organizations without clear attribution to Soviet state actors. This layered dissemination model enabled narratives to circulate widely while masking their true origin in the same manner as the SDA/Doppelgänger campaigns do in the 21st century.
Several core techniques were characteristic of these operations. Soviet intelligence services frequently published fabricated or manipulated articles in outlets under their influence, ensuring that narratives appeared to originate from credible media sources. They also relied on intermediaries, sometimes sympathetic individuals or organizations, and sometimes unwitting participants to amplify and redistribute these narratives. Additionally, front organizations and proxy institutions were used to conceal the involvement of state actors, creating plausible deniability and complicating attribution.
The modern Doppelgänger ecosystem replicates many of these operational concepts but implements them through digital infrastructure rather than traditional print or broadcast channels. In place of forged newspapers or pamphlets, the campaign operates cloned media websites designed to resemble legitimate news organizations. Instead of proxy publications in foreign countries, the campaign relies on pseudo-journalistic domains that host narrative content while maintaining the appearance of independent media outlets.
Likewise, where Soviet Active Measures depended on diplomatic contacts, activist groups, or aligned publications to redistribute narratives, the Doppelgänger campaign utilizes Telegram amplification channels to perform a similar role. These channels function as distribution hubs that rapidly disseminate narratives to large subscriber bases. Finally, the rumor propagation networks historically used to circulate political claims have been replaced by coordinated X/Twitter reply swarms, which insert narratives into active discussions across social media platforms.
Although the underlying techniques remain conceptually similar, the digital environment dramatically increases the speed, scale, and reach of these operations. Where Cold War Active Measures might have taken weeks or months to propagate through traditional media channels, digital infrastructure allows narratives to circulate globally within hours. This acceleration enables modern influence campaigns such as Doppelgänger to achieve levels of audience exposure and message repetition that were difficult to achieve through earlier forms of covert propaganda.
Alignment With Contemporary Russian Hybrid Warfare Doctrine
The operational design of the Doppelgänger campaign also reflects principles associated with Russia’s contemporary hybrid warfare doctrine, which integrates informational influence with broader geopolitical strategy. Discussions of this doctrine frequently reference writings and strategic concepts attributed to Russian military leadership that emphasize the growing importance of non-military tools in modern conflict.
Hybrid warfare is characterized by the coordinated use of military, political, economic, and informational instruments to influence adversaries while avoiding direct conventional confrontation. Within this framework, influence operations play a central role in shaping public perception, undermining adversary cohesion, and influencing decision-making environments before or during geopolitical crises.
Information operations such as the Doppelgänger campaign function as one component of this broader strategic toolkit. By introducing and amplifying narratives across digital information environments, the campaign can affect political discourse and public perception in ways that complement diplomatic, economic, or military pressure. The architecture of the campaign–combining narrative development, infrastructure hosting, and multi-platform distribution–demonstrates how modern influence capabilities can operate continuously alongside other forms of geopolitical competition.
Within the context of hybrid warfare strategy, campaigns like Doppelgänger serve several strategic purposes. They can weaken public support for adversary policies, particularly in democratic societies where political legitimacy depends on public opinion. By amplifying internal political disagreements or contentious social issues, such operations may also intensify existing divisions within target societies, complicating unified responses to international crises.
Influence campaigns can also contribute to strategic ambiguity surrounding geopolitical events. By introducing multiple competing explanations or allegations into public discourse, the information environment becomes more difficult to interpret, increasing uncertainty about the causes or implications of major developments. In addition, these campaigns can help shape international narratives around conflicts, promoting interpretations that align with Russian strategic messaging while challenging competing perspectives.
The Doppelgänger campaign’s operational emphasis on narrative saturation rather than direct persuasion aligns closely with this doctrinal approach. Rather than focusing on convincing audiences of a single specific claim, the campaign introduces a large volume of narratives designed to circulate simultaneously across the information ecosystem. This proliferation of competing narratives can complicate consensus formation, increase confusion about the reliability of information sources, and ultimately influence how audiences interpret geopolitical events.
Information Environment Manipulation
Russian information confrontation doctrine prioritizes control of the interpretive context through which audiences understand events. Perception is shaped less by facts than by narrative frameworks that assign meaning, causality, and emotional weight. By manipulating these frameworks, influence operations can alter how events are interpreted without changing the underlying facts.
Accordingly, campaigns focus on reshaping context rather than advancing isolated claims. This is achieved by promoting alternative explanations, introducing conspiratorial interpretations, and amplifying emotionally charged narratives to influence perception and legitimacy.
The Doppelgänger campaign operationalizes this model through a repeatable distribution pipeline. Narratives are developed in alignment with strategic objectives, published on feeder websites designed to mimic legitimate media, amplified via Telegram channels, and then inserted into active discussions on X/Twitter. This sequence enables rapid, multi-platform injection of interpretive frames into public discourse.
The architecture is modular and resilient, allowing narratives to be redeployed across domains, channels, and account clusters even after disruption. This persistence sustains exposure over time, reinforcing narrative frames and embedding them within the broader information environment.
Strategic Persistence
A defining characteristic of Russian information confrontation strategy is operational persistence. Rather than relying on isolated or short-lived influence campaigns, Russian information operations are typically conducted as continuous activities designed to exert sustained pressure on the information environments of targeted societies. This approach recognizes that influence within complex media ecosystems is cumulative; narratives may gain traction gradually through repeated exposure rather than through a single high-impact campaign.
Within this framework, influence operations are structured to remain active over extended periods, allowing operators to continually introduce, reinforce, and adapt narratives in response to changing geopolitical conditions. The objective is not simply to deliver a single message but to maintain a persistent presence within public discourse, ensuring that strategically aligned narratives remain visible and repeatedly encountered by audiences.
The Doppelgänger ecosystem reflects this emphasis on persistence through several operational mechanisms embedded within its infrastructure and distribution architecture. One such mechanism is rapid domain regeneration, which allows operators to replace disrupted or seized feeder websites quickly. When a domain is taken offline, replacement sites can be deployed within a short time frame, allowing the narrative distribution pipeline to continue functioning with minimal interruption.
The campaign also relies heavily on disposable social media accounts, particularly on platforms such as X/Twitter. These accounts are typically created with minimal investment in long-term identity or follower growth, allowing them to be used for short operational cycles and replaced easily if they are suspended or detected. This disposable-account model reduces the impact of platform enforcement actions and enables the campaign to maintain continuous activity despite account removals.
Another key element of this persistence is the campaign’s integration with existing Telegram channels that already possess large subscriber bases. Because these channels operate as stable distribution hubs within the broader pro-Kremlin information ecosystem, they provide a consistent amplification platform that does not need to be rebuilt for each campaign wave. This existing infrastructure allows narratives to be circulated repeatedly through established audiences.
Finally, the campaign reinforces persistence through the repeated reintroduction of narratives across multiple operational cycles. Even after a particular narrative has circulated through the distribution pipeline, the same or slightly modified messaging may be reintroduced in later campaign waves, often in response to new geopolitical developments. This repetition increases the likelihood that the narrative will become embedded within broader online discourse.
Taken together, these mechanisms allow the Doppelgänger campaign to maintain long-term influence activity even when individual components of the infrastructure are disrupted. The persistence of the system ensures that the broader narrative themes promoted by the campaign remain present within the information environment, enabling influence operations to continue shaping discourse over time.
Strategic Implications
The Doppelgänger campaign represents a mature influence capability that fuses traditional propaganda methods with modern digital infrastructure. It operates as a coordinated ecosystem, producing, distributing, and reinforcing narratives across platforms, rather than as isolated disinformation activity.
This model aligns with state-level information confrontation, where influence operations are integrated into broader geopolitical strategy. Its architecture functions as a persistent mechanism for shaping external information environments.
These components form a scalable, resilient distribution system. Modular design enables rapid adaptation, infrastructure regeneration, and repeated campaign cycles despite disruption.
Effectiveness is not defined by direct persuasion, but by cumulative environmental impact. Through sustained narrative injection and amplification of controversy, the campaign degrades informational coherence, proliferates competing interpretations, and complicates consensus formation.
Detection Framework Development
The operational characteristics of the Doppelgänger campaign produce a number of recurring technical and behavioral indicators that can assist analysts in identifying active influence operations. Although individual domains, social media accounts, and distribution channels may change over time, the underlying structure of the campaign’s infrastructure and propagation mechanisms generates patterns that are observable across multiple campaign waves.
These indicators generally fall into three broad categories: infrastructure indicators, behavioral indicators, and cross-platform propagation indicators. Together, they provide a framework for identifying and tracking influence activity associated with the Doppelgänger ecosystem.
Infrastructure Indicators
Infrastructure indicators are the most consistent signals of the campaign. The feeder network relies on recently registered domains that mimic legitimate news or commentary sites, using media-style naming to project credibility.
A key pattern is rapid domain rotation: sites are replaced quickly after disruption, often reusing similar naming conventions, branding, and technical configurations. Redirect infrastructure is also common, routing users through intermediary links to obscure source relationships while enabling traffic tracking.
Repeated website templates further indicate standardization. Shared layouts, visual elements, and backend configurations suggest the use of prebuilt deployment packages that support rapid infrastructure regeneration.
Behavioral Indicators
Beyond infrastructure, the campaign exhibits clear behavioral indicators of coordination. Telegram repost cascades are the most visible signal, where identical narratives propagate rapidly across multiple channels from a small set of origin posts.
Synchronized posting is also common, with near-identical content appearing across channels and accounts within minutes, indicating centralized dissemination. Clusters of newly created social media accounts characterized by low followers, generic identities, and stock or AI-generated images support short, disposable operational cycles.
On X/Twitter, activity often takes the form of reply swarms, where coordinated accounts inject narrative fragments and links into active discussions to amplify visibility and reach.
Cross-Platform Indicators
A third category of indicators involves the cross-platform propagation patterns that characterize the campaign’s distribution pipeline. Narratives often follow a consistent sequence of appearance across platforms, beginning with publication on a feeder website and subsequently spreading through Telegram amplification channels.
Shortly after appearing on Telegram, the same narratives may be introduced into X/Twitter discussions through coordinated account activity. This sequence—feeder site publication followed by Telegram amplification and social media insertion—represents a recurring propagation pattern that can signal the presence of a coordinated influence operation.
By monitoring these infrastructure, behavioral, and cross-platform indicators together, analysts can identify emerging campaign waves and better understand the mechanisms through which the Doppelgänger ecosystem distributes narratives across the digital information environment.
Disruption Strategy
Disrupting the Doppelgänger ecosystem requires a multi-layered approach targeting both infrastructure and distribution channels. Its design of rapidly replaceable domains, disposable accounts, and persistent amplification hubs means mitigation must be continuous and coordinated, not episodic.
Domain seizures and infrastructure takedowns can interrupt the publishing pipeline, but must be repeated due to rapid regeneration. Collaboration with registrars and hosting providers, using identifiable patterns in domain naming and deployment, can slow replacement cycles.
Account removal is equally critical. Suspending coordinated clusters on platforms like X/Twitter reduces narrative insertion into high-visibility discussions, while botnet detection helps identify and disrupt amplification networks exhibiting synchronized behavior.
Monitoring Telegram channels provides early warning and visibility into narrative propagation, even when direct removal is constrained.
Because campaign assets are disposable by design, effective disruption depends on sustained, cross-platform pressure. This raises operational costs, degrades distribution efficiency, and incrementally reduces overall campaign impact.
Potential Operational Pivots During Major Geopolitical Crisis
The Doppelgänger architecture is highly adaptable and can be rapidly repurposed for influence operations during major geopolitical crises, including the U.S.–Iran conflict. By integrating narrative development, controlled web infrastructure, and multi-platform distribution, it provides a ready mechanism for injecting crisis narratives into Western information environments.
In such scenarios, the system would likely be used to frame events in real time. Feeder sites could publish alternative interpretations of incidents emphasizing escalation, civilian harm, or legal violations while Telegram and X/Twitter amplification insert these narratives into early-stage public discourse.
It can also be used to exacerbate domestic divisions, promoting skepticism about intervention, highlighting economic costs, or questioning strategic legitimacy. Concurrently, the system can introduce multiple, conflicting explanations for key events, generating uncertainty and complicating verification.
The infrastructure supports targeted messaging, enabling narratives tailored to specific audiences, such as economic risk for European audiences, and political or military costs for U.S. audiences across languages and regions. It also facilitates information laundering, where content from pseudo-journalistic sites is recirculated and cited beyond the originating network.
Overall, Doppelgänger functions as a rapid-deployment influence platform. In crisis conditions, it can shape initial interpretations, amplify divisions, and establish persistent narrative frames that influence how conflicts are understood.
Example Crisis Influence Timeline: Narrative Propagation During the First 72 Hours
In a major geopolitical crisis such as the recent military confrontation between the United States and Iran the Doppelgänger influence infrastructure could be rapidly activated to shape early interpretations of events. Because the campaign’s architecture integrates narrative development, feeder website infrastructure, Telegram amplification networks, and coordinated social media activity, it is capable of introducing narratives into the information environment within hours of a triggering event.
The following model outlines how a typical influence operation using the Doppelgänger ecosystem could unfold during the first seventy-two hours following a major geopolitical incident. While the precise timing and scale of each phase may vary depending on operational objectives, documented campaign behavior suggests that the propagation pipeline follows a predictable sequence.
Initial Event Window (0–6 Hours)
The first phase begins immediately after a major geopolitical event becomes public knowledge. During this period, information environments are highly volatile and public understanding of the event is still forming. This stage provides an opportunity for influence operations to introduce interpretive narratives before authoritative reporting stabilizes the factual narrative.
During this window, campaign operators can rapidly produce narrative content aligned with strategic messaging objectives. These narratives may frame the event as evidence of escalation, highlight alleged civilian impacts, question the legitimacy of military actions, or introduce competing explanations regarding responsibility for the event.
Once developed, the narrative is published on one or more feeder websites within the Doppelgänger infrastructure. These articles typically mimic the appearance of legitimate news reporting, enabling them to be shared in social media discussions without immediately revealing their origin within a coordinated campaign.
Amplification Phase (6–24 Hours)
Following initial publication, the narrative enters the Telegram amplification layer, where links to the feeder websites are reposted across established pro-Kremlin Telegram channels. Because many of these channels maintain large subscriber bases and distribute content without algorithmic filtering, this stage can expose the narrative to hundreds of thousands of users within a short period of time.
Large Telegram channels function as distribution hubs that initiate the amplification cascade. Once the narrative appears in one or more of these channels, smaller affiliated channels frequently repost the content, expanding its reach across interconnected communities. This cascade effect can rapidly increase the narrative’s visibility across the Telegram information ecosystem.
At this stage, the narrative begins generating engagement in the form of reposts, comments, and reactions, creating the appearance of active discussion around the topic.
Cross-Platform Injection Phase (24–48 Hours)
Once the narrative has gained traction within Telegram networks, the campaign typically proceeds to cross-platform injection, introducing the content into broader public discussions on platforms such as X/Twitter. Clusters of disposable accounts begin posting links, excerpts, or commentary related to the narrative within active political conversations.
Rather than broadcasting content to followers, these accounts frequently target high-visibility discussion threads, including posts by journalists, politicians, or commentators addressing the crisis. By inserting replies into these conversations, the campaign attempts to expose the narrative to audiences that are not directly connected to the Telegram ecosystem.
This stage significantly expands the potential audience and increases the likelihood that the narrative will be encountered by individuals participating in broader geopolitical discussions.
Secondary Uptake Phase (48–72 Hours)
During the final stage of the initial propagation cycle, the narrative may begin to achieve secondary uptake outside the campaign’s direct infrastructure. Users who encounter the narrative through social media discussions may reference or repeat the claims in additional posts, blogs, forums, or commentary threads.
At this point, the narrative can circulate independently of the original campaign infrastructure. Because the narrative now appears across multiple platforms and sources, it may begin to influence how audiences interpret the underlying geopolitical event.
Even when the narrative itself remains contested, the presence of repeated references and discussions can contribute to information contamination, where the narrative becomes embedded within the broader discourse surrounding the event.
Strategic Implication
This seventy-two-hour propagation model illustrates how the Doppelgänger infrastructure can function as a rapid-deployment influence platform during geopolitical crises. By introducing narratives early in the information cycle and amplifying them across multiple platforms, the campaign can shape initial interpretations of events and inject competing narratives into public discourse before authoritative accounts become widely established.
Because the campaign’s infrastructure is modular and persistent, the same narratives can also be reintroduced in subsequent cycles as new developments occur, allowing influence operations to remain active throughout the duration of a geopolitical crisis.
Analytical Judgment
The Doppelgänger campaign is a resilient, scalable influence system built for sustained, multi-platform operations. It integrates narrative development, controlled web infrastructure, and coordinated social amplification to repeatedly inject and reinforce strategic messaging.
Its durability derives from a modular design that separates creation, hosting, and distribution, enabling rapid replacement of disrupted domains and accounts with minimal impact on operations. Cross-platform amplification extends reach: feeder sites provide controlled publication, Telegram delivers high-volume exposure, and coordinated X/Twitter activity inserts narratives into broader discourse.
Rapid regeneration further reinforces persistence, allowing infrastructure and accounts to be reconstituted quickly after takedowns. Within this model, Telegram functions as the primary reach engine, while X/Twitter enables penetration into high-visibility Western discussions.
Overall, Doppelgänger exemplifies a modern influence architecture that combines traditional propaganda logic with flexible digital infrastructure, sustaining narrative presence despite continuous disruption.
Technical Appendix A: Full Infrastructure Map of the SDA / Structura Ecosystem
MOIS Linked MOIST GRASSHOPPER / Homeland Justice / KarmaBelow80 / Handala Hackers / Campaigns and Evolution
Explore the evolution of MOIS-linked actors Homeland Justice, Karma, and Handala. Analysis of destructive malware, surveillance integration, and the 2026 Stryker incident.
Executive Overview
The evidence examined across this analysis spanning U.S. government reporting, private-sector threat intelligence research, passive DNS and infrastructure enrichment, and longitudinal review of archived web and Telegram content supports a high-confidence assessment that the personas Homeland Justice, Karma, and Handala do not represent discrete or ideologically independent hacktivist groups. Rather, they constitute a coordinated, MOIS-aligned cyber influence ecosystem operating under multiple branded identities that serve distinct but complementary operational roles.
This assessment is supported by multiple converging lines of evidence, including clear temporal continuity, operational consistency, infrastructure linkage, and behavioral alignment. Activity transitions seamlessly from Homeland Justice operations targeting Albania in 2022 to Karma campaigns against Israeli entities in late 2023, and subsequently to Handala-branded operations from 2024 onward. Across these phases, the actors consistently employ a repeatable pattern of intrusion, data exfiltration, disruptive or destructive action, and rapid public disclosure through controlled infrastructure. This is reinforced by shared or cross-referenced domains, persistent use of Telegram for amplification and coordination, and common hosting and obfuscation strategies. The personas also exhibit consistent rhetorical framing, target selection logic, and methods of psychological coercion. Taken together, these indicators support the conclusion that these identities function as operational layers applied to a single underlying capability, enabling segmentation of audiences and messaging while maintaining continuity of tradecraft. This modular branding approach aligns with broader state-aligned cyber operations that leverage multiple personas to project decentralization while masking centralized control.
Since its emergence in 2022, the campaign has evolved from a destructive intrusion operation into a multi-functional cyber influence framework. The initial Albania operation combined long-term compromise with ransomware-style encryption, disk wiping, and public attribution, already indicating that technical disruption was paired with narrative objectives. Over time, the campaign expanded to incorporate espionage, persistent access, structured data exfiltration, and coordinated hack-and-leak activity designed to shape perception and behavior. The addition of surveillance capabilities, particularly those leveraging Telegram-based command-and-control, marks a further shift toward continuous monitoring and transnational repression targeting both institutions and individuals. In its current form, the campaign represents a cohesive and adaptive system in which intrusion, disruption, surveillance, and information operations are integrated into a unified strategy aligned with MOIS objectives, capable of applying sustained pressure across both cyber and cognitive domains.
Ministry of Intelligence and Security (MOIS) Connection
The operational ecosystem encompassing Handala, Homeland Justice, and the persona cluster associated with Karma and KarmaBelow80 is most coherently understood not as a loose federation of ideologically aligned actors, but as a structured, state-directed campaign operating under the authority of Iran’s Ministry of Intelligence and Security (MOIS). When viewed through the lens of command-and-control, tradecraft consistency, and synchronized effects, the activity attributed to these brands reflects the hallmarks of an intelligence service executing coordinated cyber operations in support of national objectives rather than independent or purely proxy-driven behavior.
At the center of this structure is the reported involvement of Seyed Yahya Hosseini Panjaki, an individual assessed to be affiliated with MOIS and linked to its internal security and counter-terrorism apparatus. The significance of this attribution lies less in the identity of the individual operator and more in what it implies structurally. His role represents a command-level function within an institutional hierarchy, indicating that these cyber operations are subject to formal tasking, oversight, and strategic alignment. This shifts the analytical framing away from contractor-driven or semi-deniable activity and toward a model in which operations are integrated into the broader intelligence mandate of the Iranian state.
Within this framework, the distinct public-facing identities of Handala, Homeland Justice, and KarmaBelow80 function as operational veneers rather than discrete entities. Each brand aligns with a specific subset of MOIS objectives while drawing from a shared pool of capabilities, infrastructure, and tradecraft. Handala’s activity is most closely aligned with psychological and information operations, characterized by curated leaks, narrative shaping, and the deliberate amplification of politically resonant material. The timing and framing of these disclosures indicate coordination with broader messaging goals, suggesting that the technical intrusion component is only one phase of a larger influence cycle.
Homeland Justice, by contrast, represents the disruptive and punitive arm of this ecosystem. Its operations, particularly those conducted against Albanian government infrastructure, demonstrate a full-spectrum intrusion lifecycle in which long-term access is leveraged to enable data exfiltration, destructive deployment, and overt attribution. The combination of wiper activity, ransomware-style encryption, and coordinated public messaging reflects a model of calibrated escalation designed to impose both operational and reputational costs on the target. This is consistent with MOIS mandates involving internal security and retaliatory action against perceived adversaries.
The Karma and KarmaBelow80 personas introduce an additional layer of flexibility into the ecosystem. Rather than being tied to a single operational profile, these identities appear to function as adaptive interfaces that can be deployed across different phases of an operation. They enable the same underlying capability set to be presented under different contextual narratives, enhancing deniability while maintaining continuity of effect. This is particularly relevant in environments where attribution pressure is high, as it allows operators to fragment their public footprint without fragmenting their operational infrastructure.
The coherence across these actor clusters is most evident in the structure of their operations. Intrusions frequently follow a repeatable progression: initial access is established through credential compromise or exploitation of exposed services, followed by the deployment of webshells or other persistence mechanisms. Once footholds are secured, actors conduct internal reconnaissance and lateral movement using enterprise-scale tooling, enabling them to map the target environment and identify high-value data stores. Exfiltration is then carried out in a controlled manner, often staged to support subsequent public release. The final phase varies depending on strategic intent, ranging from silent intelligence collection to destructive action or coordinated leak publication.
What distinguishes this ecosystem is the degree to which these phases are integrated and interchangeable. The same intrusion can evolve from a covert surveillance operation into a disruptive attack or an influence campaign without requiring a fundamental shift in tooling or access. This reflects the modular architecture described earlier, but at an organizational level it also implies centralized capability management. MOIS oversight provides the mechanism through which these modules can be allocated, combined, and sequenced in accordance with mission objectives.
The involvement of a command-level figure such as Panjaki provides a unifying explanation for this consistency. It accounts for the alignment between technical operations and information effects, the disciplined escalation observed in target engagements, and the reuse of infrastructure and tooling across ostensibly separate actor brands. It also explains the resilience of the ecosystem. Disrupting one public-facing identity or infrastructure cluster does not degrade the underlying capability, because those assets are components of a larger, centrally managed system.
From an analytical standpoint, this structure necessitates treating Handala, Homeland Justice, and KarmaBelow80 as manifestations of a single operational apparatus rather than independent threat actors. Their differences are functional rather than organizational, reflecting the segmentation of roles within a coordinated campaign. The strategic value of this model lies in its flexibility: MOIS can conduct espionage, disruption, and influence operations in parallel, or transition between them as conditions dictate, all while maintaining a coherent operational footprint.
This convergence of command authority, modular capability, and multi-domain execution underscores the maturation of MOIS cyber operations into a fully integrated instrument of state power. It is not simply the presence of advanced tooling or destructive capability that defines this ecosystem, but the way in which those capabilities are orchestrated under centralized direction to produce layered, cumulative effects across technical and informational domains.
Campaign Expansion and Evolution
Initial Emergence in Albania (2022)
Homeland Justice[.]org website
The campaign first became publicly visible during the 2022 attacks against the Government of Albania, which established both its technical baseline and its enduring operational model. Iranian state actors operating under the Homeland Justice persona achieved initial access approximately fourteen months prior to public disclosure by exploiting an internet-facing Microsoft SharePoint vulnerability. This early foothold indicates a deliberate pre-positioning phase, consistent with long-dwell intrusion strategies observed across MOIS-aligned operations.
Following initial compromise, the actors transitioned into a structured post-exploitation workflow designed to ensure persistence, expand access, and map the target environment. Webshells were deployed on compromised servers, providing durable and low-friction access while enabling command execution without reliance on large malware payloads. From this foothold, operators conducted systematic internal reconnaissance, enumerating network topology, identifying key systems, and mapping trust relationships across the enterprise.
Credential harvesting was a central component of this phase. Through a combination of mailbox access, credential dumping, and account manipulation, the actors obtained privileged credentials that enabled lateral movement and escalation. Movement across the environment was conducted using standard administrative protocols, including Remote Desktop Protocol (RDP), Server Message Block (SMB), and File Transfer Protocol (FTP), allowing activity to blend with legitimate administrative traffic and reducing the likelihood of early detection.
The compromise of Microsoft Exchange infrastructure further expanded access. By leveraging Exchange, the actors were able to access and manipulate mailboxes, create or modify accounts, and extract large volumes of sensitive communications. This email corpus provided both intelligence value and material for later disclosure, aligning with the campaign’s hack-and-leak model.
Data exfiltration occurred in parallel with lateral expansion, with operators systematically staging and extracting large datasets from across the environment. Only after sufficient access, intelligence collection, and data acquisition had been achieved did the actors transition to the destructive phase. This sequencing – extended pre-positioning, comprehensive collection, and delayed disruption – demonstrates a disciplined operational approach in which technical compromise is leveraged to maximize both intelligence yield and downstream psychological impact.
Establishment of the Operational Model
The impact phase of the Albania operation combined ransomware-style encryption with destructive wiping, employing tools such as GoXML.exe and cl.exe, supported by propagation utilities and raw disk access drivers that enabled direct manipulation of underlying storage. These capabilities were deployed in a coordinated manner to maximize operational disruption, impair system recovery, and degrade institutional functionality. The sequencing of encryption followed by wiping reflects a deliberate approach designed not only to deny access to systems and data, but to ensure lasting damage and complicate remediation efforts.
More significant than the tooling itself, however, was the deliberate integration of public-facing infrastructure into the attack lifecycle. The Homeland Justice persona was used to claim responsibility, disseminate messaging, and frame the operation within a broader political and ideological narrative. Websites and Telegram channels functioned as controlled dissemination platforms through which the actors published statements, amplified claims, and selectively exposed information. This layer transformed what would otherwise have been a destructive cyber incident into a visible and ongoing influence operation.
This approach established a foundational operational model in which technical compromise and information operations were inseparably linked. Cyber intrusion and destruction served as enabling mechanisms for narrative exploitation, with the ultimate objective extending beyond disruption to include coercion, reputational damage, and behavioral influence. In this model, the value of the operation was realized not solely through the technical impact, but through the controlled release of information and the shaping of perception in the aftermath of the attack.
Continued Activity and Tooling Refinement (2023)
In late 2023, the Homeland Justice campaign re-emerged with renewed activity targeting Albanian entities, demonstrating clear continuity in both target selection and operational methodology. This phase reinforced that the earlier Albania operations were not isolated incidents, but part of a sustained and adaptive campaign. The actors maintained their focus on politically relevant targets while reapplying the same core model of intrusion followed by destructive impact, indicating both persistence of intent and retention of operational access or capability.
During this period, the introduction of the No-Justice Wiper marked a refinement in destructive tooling. Designed for rapid and irreversible disruption, the malware emphasized system incapacitation, including preventing successful operating system boot. The use of signed binaries suggests an increased emphasis on evasion and trust abuse, while PowerShell-based propagation reflects a growing reliance on native system capabilities to enable flexible and low-friction deployment. Together, these developments indicate an evolution toward more efficient, harder-to-detect operations while preserving the campaign’s core objective of high-impact disruption.
Geographic Expansion and Rebranding: Karma Phase (2023-2024)
Following the Israel-Hamas conflict in October 2023, the campaign expanded geographically and adopted the Karma persona.
Despite this rebranding, the underlying tradecraft remained consistent. Operations targeted Israeli organizations and employed a hybrid approach combining custom tooling with publicly available utilities, including bespoke webshells, credential validation tools, reverse SSH tunneling, and destructive mechanisms such as BiBi Wiper.
Actors increasingly relied on hands-on-keyboard techniques, including manual file deletion and disk formatting, prioritizing speed and operational impact. Evidence from this phase suggests a division of labor between intrusion and destructive operators, indicating a modular and coordinated ecosystem.
Maturation and Specialization: Handala Phase (2024 Present)
Handala-hack.tw 2026
The expansion of the Handala infrastructure set with the inclusion of handala-hack[.]ps and, more importantly, handala-hack[.]tw, provides a clearer view into how the actor operationalizes its domain layer over time. These domains are not isolated artifacts. They are part of a repeatable system in which naming conventions, narrative timing, and platform coordination matter more than persistence of any single asset. The repeated appearance of the handala-hack string across multiple TLDs indicates that the domain itself is not intended to endure. It is intended to be recognized, replaced, and reactivated, carrying forward an identity that survives takedown actions and jurisdictional pressure.
The .tw variant is particularly instructive when placed in historical context. Earlier iterations of the ecosystem relied heavily on .to infrastructure, which has long been associated with abuse-tolerant hosting and low-friction registration. The shift into .ps and .tw reflects both symbolic and operational adaptation. The .ps domain carries clear political signaling aligned with the actor’s ideological framing, reinforcing the Palestinian narrative embedded throughout the campaign. By contrast, handala-hack[.]tw appears to serve a different function: jurisdictional dispersion and operational redundancy. Taiwan’s namespace does not inherently carry the same ideological weight, which suggests its use is pragmatic rather than symbolic. In effect, the actor is separating message-layer signaling (.ps) from resilience-layer infrastructure (.tw).
When mapped against the historical leak cadence observed across the full archive, these domains align with distinct phases of campaign activity. Early in the lifecycle, Handala has relied on single-domain publication points tied to specific claim sets. These initial leaks focused on individual targets, often framed as penetrations of named Israeli intelligence or defense figures. The content emphasized access mailboxes, communications, and internal correspondence without attempting to demonstrate systemic reach. Domains in this phase acted as announcement boards, each tied to a discrete narrative event.
As the campaign matured, the scale of claims expanded. The archive shows repeated assertions of large-volume email exfiltration, often in the range of tens of thousands to over one hundred thousand messages. These claims were accompanied by broader institutional framing, suggesting not just individual compromise but organizational penetration. It is in this phase that domain rotation becomes more pronounced. Rather than maintaining a single persistent site, the actor begins to distribute content across multiple similarly branded domains, each capable of hosting or referencing new disclosures. The emergence of domains like handala-hack[.]to and handala-redwanted[.]to reflect this shift toward functionally differentiated nodes, one for breach claims, another for intimidation or doxxing.
The introduction of handala-hack[.]tw appears to correspond with the later stages of this evolution, where the campaign moves beyond exposure into strategic signaling and maximalist claims. Posts associated with this period increasingly reference infrastructure targeting, large-scale destructive capability, and systemic access. Claims such as multi-petabyte data wipes or pre-mapped critical infrastructure targets emerge alongside continued email leak narratives. The domain layer, in this context, becomes less about hosting data and more about anchoring the claim itself. The presence of a new domain signals a new phase of activity, regardless of whether the underlying data is verifiable.
Historically, each wave of leaks follows a recognizable pattern. A new or resurfaced domain appears, often with the familiar handala-hack naming structure. Within a short time window, posts are published asserting compromise of a high-value target. These posts are then amplified through Telegram channels now including identifiers such as @HANDALA_INTEL and further propagated via X accounts. The domain serves as the canonical reference point, but the operational impact is generated through distribution. Even when domains are seized or taken offline, the narrative persists because it has already been exported to other channels.
The content associated with these domains consistently emphasizes three categories of disclosure. The first is email data, which remains the dominant theme across the archive. Whether targeting individuals like Eran Ortal or broader institutional mailboxes, the actor repeatedly frames access to communications as evidence of deep penetration. The second category is identity and contact data, including phone numbers and membership lists, often used in campaigns against dissidents or civilian networks. The third is strategic or infrastructural intelligence, where the actor claims to possess detailed knowledge of critical systems such as water and electricity networks. Each category serves a distinct psychological function: exposure, intimidation, and deterrence.
The inclusion of corporate targets, such as Stryker Corporation, marks another important shift visible in the historical record. Earlier phases of the campaign were tightly focused on Israeli state and intelligence entities. Later phases expand outward, incorporating Western corporate actors to demonstrate global reach. The claims associated with these targets are often the most extreme, including assertions of large-scale data destruction. Whether or not these claims are technically accurate is secondary to their narrative role. They signal that the actor’s reach is not confined to a single geography or sector.
Across all these phases, the domain layer including handala-hack[.]tw remains structurally consistent. The sites themselves are simple, often WordPress-based, with minimal technical sophistication. They do not host malware, nor do they expose command-and-control infrastructure. Instead, they function as narrative anchors, providing a stable URL that can be cited, shared, and referenced across platforms. The real operational activity occurs elsewhere, in the intrusion layer (which remains opaque) and the amplification layer (Telegram and X). The domain is simply the point where those layers intersect publicly.
What emerges from the full dataset, now augmented by the newly observed domains, is a clear pattern: Handala’s infrastructure is designed to be expendable, but its identity is designed to persist. Domains are created, used, and abandoned. Telegram channels are taken down and reconstituted. Yet the naming conventions handala-hack, HANDALA_ and the narrative structure remain constant. This allows the actor to survive disruption without losing coherence. Each new domain, including handala-hack[.]tw, is not a fresh start but a continuation of an ongoing campaign.
In historical context, the leaks themselves should be understood not as isolated incidents but as components of a sustained psychological operation. Early disclosures establish credibility, mid-phase leaks expand perceived capability, and later claims introduce strategic and deterrent messaging. The domain infrastructure evolves in parallel, moving from single-use publication points to a distributed, rotating set of narrative nodes. The result is a system in which the appearance of a new domain is itself a signal, an indication that the next cycle of claims, amplification, and psychological effect is underway.
Ultimately, the addition of handala-hack[.]tw does not represent a new capability. It represents the continued refinement of an existing model. The actor does not depend on any specific domain to achieve its objectives. Instead, it relies on the predictable regeneration of infrastructure combined with consistent narrative execution. In that sense, the domain is not the asset. The campaign is.
Adverse Effects and Real-World Impact of Handala Leak Operations
Analysis of the Handala archive, corroborated with external reporting, demonstrates a consistent divergence between claimed impact and verified operational consequences. While the group presents its activities as large-scale, destructive cyber intrusions, the observable real-world effects fall into a narrower set of categories: operational disruption (rare), exposure and reputational damage (common), and psychological or coercive effects (systematic).
The most clearly substantiated case of material operational impact is the attack against Stryker Corporation. Reporting indicates that the intrusion disrupted core business functions, including order processing, manufacturing, and shipment operations, with recovery extending over multiple days. The incident also reportedly resulted in the remote wiping of tens of thousands of devices, affecting employees across multiple regions and, in some cases, impacting personally owned devices enrolled in enterprise systems. This represents a genuine destructive and operational cyber event, distinguishing it from the majority of Handala’s activity. The scale and severity of this incident further triggered a law enforcement response, including domain seizures targeting Handala infrastructure, indicating that the event crossed the threshold from influence activity into infrastructure-level concern.
A second category of confirmed impact involves high-profile personal data exposure, exemplified by the breach of Kash Patel. In this case, the publication of personal emails, images, and documents created reputational harm and potential counterintelligence risk, even though the exposed material was not assessed as containing sensitive government information. The significance of this event lies less in technical compromise and more in its function as a public humiliation and signaling operation, consistent with Handala’s broader objectives of intimidation and reputational pressure against Western officials.
Other reported incidents fall into a more ambiguous category. The claimed attack against Hebrew University of Jerusalem, involving tens of terabytes of wiped and exfiltrated data, represents a credible, but not fully independently verified, destructive event. While multiple secondary sources describe the incident, there is limited primary confirmation of the full scale of impact. This pattern — where claims are partially supported but not conclusively validated — is characteristic of the Handala ecosystem and complicates direct attribution of operational consequences.
In contrast, some claims appear to have produced primarily reputational or narrative effects without technical confirmation. The alleged compromise of Verifone, for example, was publicly denied by the company, with no evidence of disruption or data loss. In such cases, the adverse effect is not system compromise but forced defensive communication, in which the targeted organization must respond to public allegations, thereby amplifying the narrative regardless of its validity.
A substantial portion of the archive consists of operations targeting individuals within the Israeli intelligence and security ecosystem, including Sima Shine, Ilan Steiner, Deborah Oppenheimer, and Eran Ortal. In these cases, the adverse effects are consistently limited to exposure of alleged communications, reputational damage, and intelligence-related pressure. Although large-scale email leaks are claimed, there is no strong independent evidence of downstream operational disruption, institutional failure, or policy impact. These incidents function primarily as hack-and-leak influence operations, designed to erode trust and project vulnerability rather than to degrade capability.
The campaign also includes a distinct category of identity exposure and intimidation, illustrated by the targeting of VahidOnline. The leak of tens of thousands of user identities and phone numbers associated with dissident networks constitutes a form of digital repression, exposing individuals to harassment, surveillance, or potential physical risk. Unlike corporate or institutional targets, the impact here is distributed across a population, amplifying fear and discouraging participation in opposition or media activities.
Beyond digital exposure, the archive and supporting reporting indicate a pattern of coercive escalation into the physical domain. Handala has been linked to doxxing campaigns against individuals such as defense-sector employees, including alleged exposure of personal details of engineers associated with defense contractors. These actions are often accompanied by explicit threats, transforming cyber activity into psychological coercion with potential real-world implications. Even when the accuracy of the leaked data is uncertain, the act of publication itself generates fear and imposes a defensive burden on victims.
Taken together, these cases demonstrate that Handala’s operational impact is best understood across three tiers. At the highest tier are rare but significant operational disruptions, such as the Stryker incident, which produce measurable effects on systems and services. At the intermediate tier are verified exposures of personal or organizational data, which create reputational and intelligence risks but do not necessarily disrupt operations. At the lowest tier are narrative-driven claims and unverified leaks, which nonetheless generate psychological and informational effects by forcing responses and sustaining uncertainty.
The overall pattern supports a clear analytical conclusion: Handala’s effectiveness does not depend on consistent technical success. Instead, it derives from the ability to convert a limited number of real or plausibly real intrusions into a sustained campaign of perception management, intimidation, and coercive signaling. The majority of adverse events observed are therefore not technical in nature, but psychological and reputational, aligning closely with the broader doctrine of cyber-enabled influence operations.
Parallel Surveillance and Influence Operations
Expansion into Surveillance (2023-2026)
In parallel with its destructive and hack-and-leak operations, the campaign expanded significantly into surveillance and transnational repression beginning in late 2023 and continuing through 2026. This shift represents a broadening of operational scope from institutional disruption to targeted monitoring of individuals, particularly dissidents, journalists, activists, and members of opposition networks. Rather than relying solely on network exploitation, the actors adopted a more tailored approach centered on social engineering and user-level compromise, indicating both improved targeting intelligence and a strategic intent to exert pressure beyond traditional cyber domains.
Access in this surveillance branch is typically achieved through trojanized applications masquerading as legitimate software, including messaging tools, password managers, and media utilities. These lures are often aligned with the expected behavior and digital environment of the target, suggesting prior reconnaissance and profiling. Upon execution, these files deploy staged malware chains that establish persistence and initiate communication with operator-controlled infrastructure. The second-stage implants are modular and designed for continuous data collection, including screen capture, audio interception (with specific capability to monitor conferencing platforms), file harvesting, and credential access. Data is often staged locally, compressed, and prepared for exfiltration in a manner that minimizes detection while maximizing collection efficiency.
A defining characteristic of this surveillance capability is its use of Telegram as a command-and-control channel, leveraging the legitimate Telegram API to transmit instructions and exfiltrated data. This approach allows malicious traffic to blend with normal user activity, complicating network-based detection while simultaneously enabling rapid, distributed control of infected hosts. In some cases, the same platform is used for both covert communication and overt messaging, reinforcing the campaign’s broader integration of technical and informational operations. Taken together, this surveillance expansion demonstrates a transition toward a persistent, person-centric operational model, in which intrusion, monitoring, and psychological pressure are applied in tandem to influence both institutional behavior and individual decision-making.
Telegram as Dual-Use Infrastructure
Telegram occupies a central and multifaceted role within this ecosystem, functioning simultaneously as a covert command-and-control (C2) channel and an overt platform for messaging, amplification, and audience engagement. This dual-use design is not incidental; it reflects a deliberate operational choice to consolidate multiple functions, control, communication, and influence within a single, widely trusted platform. By embedding operational activity within a legitimate and globally used service, the actors reduce their reliance on dedicated infrastructure while increasing resilience against disruption. At the same time, the platform’s scale and accessibility allow it to serve as a high-capacity distribution mechanism for narrative content, enabling rapid dissemination of messaging to both targeted and broad audiences.
From a technical perspective, the use of Telegram as C2 is enabled through abuse of the Telegram Bot API, which allows malware to communicate with operator-controlled bots over encrypted channels that are indistinguishable from normal application traffic. This design significantly complicates detection, as network telemetry alone is often insufficient to differentiate benign from malicious use. Implants can issue commands, upload exfiltrated data, and receive tasking through standard API calls, effectively turning Telegram into a low-cost, low-visibility control infrastructure. Because Telegram traffic is commonly permitted in enterprise and personal environments, this approach provides a reliable communication channel that blends seamlessly into expected user behavior, reducing the likelihood of interception or blocking.
Concurrently, Telegram channels associated with the campaign function as public-facing dissemination nodes, distributing propaganda, operational claims, and references to leaked data. Channels such as those linked to the Homeland Justice persona serve as hubs where messaging is curated, amplified, and framed within ideological or political narratives. The presence of archive files, named data releases, and coordinated messaging indicates that these channels are not passive outlets, but active components of the operational workflow. This convergence of covert C2 and overt communication within the same platform effectively bridges the technical and informational domains, allowing the actors to move seamlessly from intrusion and data collection to public exposure and psychological influence, all within a unified infrastructure.
Malware and Operational Evolution
Evolutionary Overview
The campaign demonstrates a progression from discrete, high-impact destructive events into a modular and adaptive operational toolkit capable of supporting a wide range of objectives across multiple target sets. Early activity, particularly during the Albania operations, was centered on singular, coordinated events in which long-term access culminated in ransomware-style encryption, wiping, and public attribution. Over time, however, these capabilities were not abandoned; instead, they were retained and integrated into a broader operational framework that supports espionage, surveillance, disruption, and influence operations in parallel.
This evolution is distinctly additive rather than substitutive. Earlier destructive tools and techniques such as disk wiping, scripted propagation, and webshell-based persistence remain in active use, while newer capabilities have been layered on top. These include modular malware implants for surveillance, Telegram-based command-and-control, enterprise-scale tooling for network enumeration and control, and structured leak infrastructure for public disclosure. The result is a toolkit that can be dynamically assembled based on operational requirements, allowing actors to shift between stealthy collection, overt disruption, and psychological operations without fundamentally altering their underlying tradecraft.
The modular nature of this toolkit also enables operational flexibility and resilience. Components can be deployed independently or in combination, depending on the target environment and desired outcome. For example, an intrusion may begin as a surveillance operation, transition into data exfiltration, and culminate in either destructive action or controlled leak publication, all using elements of the same toolkit. This layered approach reduces dependency on any single capability and allows the campaign to adapt to defensive pressures, infrastructure disruption, or shifting strategic priorities while maintaining continuity of effect.
Phase I: Destructive Intrusion Model
The Albania campaign established a repeatable model centered on prolonged, covert access followed by synchronized destructive impact and overt attribution. Operators achieved initial entry well in advance of the impact phase, maintained persistence through webshells and credential reuse, and conducted systematic reconnaissance and lateral movement across the environment. During this period, they harvested credentials, mapped network topology, and accessed email systems, enabling large-scale data exfiltration and the prepositioning of tools required for coordinated execution. This extended preparation phase indicates a deliberate emphasis on operational depth and positioning, rather than opportunistic disruption.
The transition to the impact phase was tightly orchestrated. Encryption and wiping components were deployed in sequence to maximize disruption, degrade recovery options, and ensure sustained operational impact across affected systems. The use of propagation mechanisms and administrative access allowed the actors to execute these actions broadly and nearly simultaneously, amplifying the scale of disruption. This was not a simple ransomware event; it was a destructive operation designed to disable systems, disrupt services, and create immediate strategic effect, particularly within government infrastructure.
Equally important was the deliberate and immediate move to public attribution and narrative control. Under the Homeland Justice persona, the actors claimed responsibility, released messaging, and framed the attack within a political and ideological context. This transformed the operation from a purely technical incident into a hybrid cyber–influence event, where the technical damage served as the foundation for broader psychological and reputational impact. The Albania campaign thus established a durable operational model: gain long-term access, prepare the environment, execute coordinated destruction, and rapidly exploit the event through controlled public disclosure to achieve strategic influence.
Phase II: Iterative Destructive Refinement
The introduction of the No-Justice Wiper reflects a clear refinement in the actor’s destructive capability, emphasizing speed, reliability, and operational efficiency. Compared to earlier tooling that combined encryption and wiping in a more sequential and resource-intensive manner, the No-Justice variant appears optimized for rapid execution and immediate impact. Its design prioritizes system incapacitation, including corruption of critical structures required for operating system startup, thereby preventing recovery through conventional means. This shift indicates a move toward direct, irreversible disruption, reducing the time between execution and effect while minimizing the opportunity for defensive response.
At the same time, the use of signed binaries demonstrates an increased focus on evasion through trust abuse. By leveraging code-signing mechanisms, the actors are able to bypass or reduce scrutiny from endpoint protection systems that rely on signature-based trust models. This reflects a more sophisticated understanding of defensive controls and suggests that the tooling has been adapted based on prior detection and mitigation efforts. The combination of trusted execution and destructive functionality allows the malware to operate with a lower likelihood of immediate detection, increasing the probability of successful deployment across multiple systems.
The reliance on PowerShell-based propagation and execution further underscores a transition toward living-off-the-land techniques. By utilizing native system capabilities, the actors reduce their dependency on large or complex malware payloads, enabling more flexible and stealthy deployment within compromised environments. PowerShell scripts can be rapidly modified, obfuscated, and distributed using existing administrative channels, allowing for efficient lateral spread and coordinated execution. Together, these elements – streamlined destructive logic, trust-based evasion, and native execution – illustrate a broader evolution toward leaner, more adaptable tooling that enhances both effectiveness and survivability within contested network environments.
Phase III: Hybrid Operational Model
The Karma phase introduced a distinctly hybrid operational approach that combined bespoke tooling with hands-on-keyboard techniques and widely available utilities, enabling flexible execution across heterogeneous environments. Rather than relying exclusively on custom malware, operators blended lightweight webshells and purpose-built components with native administrative tools and publicly available software. This reduced development overhead, shortened deployment time, and allowed rapid adaptation to differences in target infrastructure whether on-premises Windows domains, Linux servers, or mixed environments while preserving the ability to execute high-impact actions.
A defining feature of this phase was the increased emphasis on manual tradecraft and living-off-the-land techniques. Operators leveraged standard system utilities and administrative protocols such as RDP for lateral movement, built-in command-line tools, and common utilities like SDelete or disk formatting to perform destructive actions without introducing large, easily detectable binaries. Custom elements, including webshells (e.g., Karma Shell) and credential validation tools (e.g., do.exe), were used selectively to maintain access and verify privileges, while publicly available tools such as reGeorg enabled post-compromise control. This blend allowed operators to pivot quickly within compromised networks, execute tasks with minimal friction, and evade signature-based defenses by masking activity as legitimate administration.
The result was a modular, operator-driven execution model that prioritized flexibility, speed, and reliability over stealth alone. By combining custom implants with manual techniques and off-the-shelf tools, the actors could tailor operations to the specific constraints of each target, escalate privileges, propagate across systems, and initiate disruption with minimal dependency on a single capability. This hybridization also improved resilience: if one tool or method was detected or blocked, operators could readily substitute alternatives without disrupting the overall operation. In effect, the Karma phase marked a transition toward a more adaptable and scalable approach, capable of sustaining coordinated campaigns across diverse technical environments while maintaining alignment with the campaign’s broader objectives of disruption and influence.
Phase IV: Multi-Vector Destruction and Enterprise Tooling
Under the Handala persona, operations expanded into a coordinated, multi-method destruction model that reflects a clear increase in operational maturity and planning discipline. Rather than relying on a single payload or technique, actors began employing parallel destructive mechanisms, including custom wipers, PowerShell-based recursive deletion, and encryption via legitimate tools such as VeraCrypt. These methods were often executed in tandem across multiple systems, ensuring redundancy in effect and significantly reducing the likelihood of recovery. This approach demonstrates a shift from opportunistic disruption to deliberate, layered impact engineering, where multiple techniques reinforce one another to guarantee system failure and data loss.
At the same time, the incorporation of enterprise-scale tooling enabled the actors to operate more effectively within complex network environments. Tools such as NetBird facilitated persistent internal connectivity and remote control across segmented networks, while ADRecon provided comprehensive visibility into Active Directory structures, users, and permissions. This combination allowed operators to map target environments in detail, identify high-value systems, and coordinate execution across domains with greater precision. The use of Group Policy and administrative scripting further enabled centralized deployment of destructive actions, amplifying scale and synchronizing impact across large portions of the network.
These developments collectively indicate a transition toward a structured, scalable operational model capable of sustaining complex campaigns within enterprise environments. The reliance on both custom and legitimate tools, combined with coordinated execution and network-wide visibility, reflects an evolution beyond isolated incidents into systematic, organization-level disruption capability. Under Handala, the campaign demonstrates not only technical sophistication, but also an increased ability to integrate access, control, and destruction into a cohesive and repeatable operational framework aligned with broader strategic objectives.
Phase V: Surveillance Integration
Telegram-based malware campaigns introduced a persistent monitoring layer that materially expanded the campaign’s scope beyond episodic disruption into continuous intelligence collection. Initial access is commonly achieved through trojanized applications tailored to the target’s context, such as messaging clients, password managers, or media tools suggesting prior reconnaissance and profiling. Once executed, staged loaders deploy modular implants that establish persistence and enable ongoing telemetry collection, including screen capture, keystroke or clipboard capture, file harvesting, and, in some cases, audio interception of conferencing applications. Data is typically staged locally, compressed, and queued for exfiltration, allowing operators to control the cadence of collection and minimize anomalies that might trigger detection.
A defining feature of this capability is the use of Telegram’s Bot API as command-and-control, which allows implants to communicate over encrypted channels indistinguishable from normal Telegram traffic. This design provides a resilient, low-cost infrastructure that blends into expected network behavior and is difficult to block without disrupting legitimate use. Operators can issue tasking, retrieve data, and manage multiple hosts via bot commands, effectively turning Telegram into a distributed control plane. Because Telegram is widely permitted across enterprise and personal environments, this approach increases reliability while reducing dependence on bespoke infrastructure that is more easily identified and taken down.
Operationally, this surveillance layer supports transnational repression by enabling targeted, person-centric campaigns against dissidents, journalists, and opposition figures. Continuous monitoring yields sensitive personal and organizational insights that can be selectively disclosed, used to intimidate, or leveraged to shape narratives in subsequent leak operations. This tight coupling between covert collection and overt exposure allows actors to move seamlessly from surveillance to psychological pressure, aligning technical activity with influence objectives. The result is a persistent, adaptive capability that extends the campaign’s reach from network disruption to sustained coercion of individuals and communities across borders.
Phase VI: Convergence (Stryker-Era Operations)
Recent activity, particularly the Stryker incident (March 2026), demonstrates a clear convergence of destructive, surveillance, and influence capabilities into a unified operational model, while also marking a significant evolution in how these effects are delivered. Unlike earlier phases that relied heavily on malware deployment within compromised networks, emerging reporting indicates that Handala-linked actors achieved administrative access to enterprise management infrastructure, specifically Microsoft Intune, and used it as a force-multiplier for both disruption and scale. (Cyber Magazine)
In the Stryker case, investigators and multiple reports suggest that attackers compromised an Intune administrative account or management console, allowing them to issue remote commands directly to enrolled endpoints. Intune, as a cloud-based endpoint management platform, is designed to enforce policies, deploy software, and remotely wipe devices. By gaining privileged access to this system, the actors were able to bypass traditional malware deployment entirely and instead execute a centralized wipe command across tens of thousands of devices simultaneously. Reports indicate that as many as 80,000–200,000 devices, including laptops and mobile endpoints, were wiped, while approximately 50 terabytes of data were exfiltrated prior to the destructive action. (TechRadar)
This technique represents a fundamental shift in operational tradecraft. Rather than relying on endpoint-level persistence and execution, the actors targeted the control plane of the enterprise itself. With access to Intune, they effectively inherited the organization’s own administrative authority, allowing them to push destructive actions at scale with minimal friction and high reliability. As one analysis noted, once inside such a system, “an adversary… just need[s] to press a button,” highlighting how legitimate enterprise tooling can be weaponized for immediate, large-scale impact.
The implications of this approach are significant. First, it dramatically reduces the need for detectable malware artifacts, complicating traditional detection strategies that rely on endpoint indicators. Second, it enables near-instantaneous, synchronized disruption across globally distributed infrastructure, as seen in the simultaneous impact across dozens of countries in the Stryker event. Third, it allows actors to combine data exfiltration, destructive wiping, and public attribution within a tightly compressed timeline, reinforcing the campaign’s hack-and-leak model while increasing operational tempo. (Tenable)
Critically, this evolution does not replace earlier capabilities but integrates with them. The same ecosystem that previously relied on wipers, PowerShell scripts, and Telegram-based command-and-control now demonstrates the ability to pivot into identity and access compromise at the enterprise management layer, effectively collapsing the distinction between intrusion, execution, and impact. In this model, surveillance capabilities provide intelligence and targeting, administrative compromise enables execution at scale, and influence infrastructure websites and Telegram amplify the effects through public messaging and data release.
Taken together, the Stryker incident illustrates the campaign’s progression into a fully converged operational framework, where destructive, surveillance, and influence capabilities are no longer sequential phases but simultaneous, interdependent components. The abuse of Intune marks a notable escalation in both technical sophistication and strategic impact, demonstrating that the actors are not only adapting their tooling, but are increasingly targeting the centralized control mechanisms of modern enterprise environments to achieve rapid, large-scale disruption aligned with broader geopolitical objectives.
Operational Model: Hack-and-Leak as Psychological Operations
The Homeland Justice and Handala campaigns are best understood as state-directed hack-and-leak operations engineered for psychological impact, in which technical intrusion serves as a means to produce exploitable narratives rather than an end in itself. From their earliest manifestation, these operations have been structured to convert access into influence: compromise enables collection, collection enables disclosure, and disclosure is shaped to achieve coercive or reputational effects. This framing distinguishes the activity from financially motivated ransomware or purely clandestine espionage, positioning it instead within a model of cyber-enabled information warfare aligned with state objectives.
From the Albania campaign onward, data theft has been systematically paired with controlled, curated public disclosure through actor-operated infrastructure, including websites and Telegram channels such as @Homeland Justice1. These platforms function as dissemination nodes where messaging is crafted, amplified, and aligned with political narratives. The release of stolen material, often selective, staged, or thematically framed, is designed to maximize audience impact, reinforce claims of legitimacy, and sustain attention over time. In this sense, the infrastructure is not merely a repository for leaked data, but an active component of the operational workflow, bridging the gap between technical compromise and public perception.
@Homeland Justice1 Telegram Channel
Within this model, destructive actions serve primarily to amplify visibility and urgency, creating conditions that heighten the impact of subsequent disclosures. Wiping, encryption, and service disruption draw attention to the incident and signal capability, but the strategic value is realized through narrative amplification of how the event is presented, interpreted, and circulated. The transition to the Handala persona reflects a further refinement of this approach, with increased segmentation of infrastructure to support distinct functions such as leak publication, propaganda, and targeted exposure of individuals. This specialization indicates a maturing operational framework in which success is measured less by persistence or financial return, and more by the ability to shape perception, apply pressure, and influence behavior across both institutional and individual targets.
Infrastructure and Domain Ecosystem
The infrastructure supporting the Homeland Justice and Handala campaigns reflects a deliberate, layered architecture designed to separate public-facing operations from backend control while enabling specialized functions across the ecosystem. Core domains such as Homeland Justice[.]org, handala-hack[.]to, handala-redwanted[.]to, and karmabelow80[.]org operate as visible nodes for messaging, leak publication, and intimidation, serving as the primary interface through which the actors communicate with both targets and broader audiences. These platforms are used to disseminate propaganda, frame narratives, and release or reference stolen data, transforming technical intrusions into publicly consumable events aligned with the campaign’s psychological objectives.
Behind this visible layer, additional domains such as homelandjustice[.]cx and Homeland Justice[.]ru likely function as alternate or backend infrastructure, supporting operational continuity and resilience. This separation suggests an architecture in which public-facing assets can be replaced or rotated without disrupting underlying capabilities, thereby reducing exposure while maintaining persistence. Within this system, each domain appears to serve a distinct and purpose-driven role, contributing to a modular framework that supports narrative framing, data publication, and targeted exposure. This functional segmentation reinforces the broader operational model, enabling the actors to coordinate technical compromise with controlled disclosure and messaging in a cohesive and scalable manner.
Tactics, Techniques, and Procedures (TTPs)
The campaign demonstrates a high degree of consistency in its tactics, techniques, and procedures (TTPs) across all observed phases, reflecting a mature and repeatable operational playbook. Initial access is typically achieved through a combination of exploitation of internet-facing services and targeted social engineering depending on the operational context. In earlier phases, actors leveraged vulnerabilities in externally exposed systems such as Microsoft SharePoint or Exchange to gain footholds within enterprise environments. In parallel, particularly in later surveillance-oriented activity, access has been obtained through user-centric compromise, including phishing and the delivery of trojanized applications tailored to specific targets. This dual approach allows the actors to flexibly pursue either broad network intrusion or highly targeted individual access depending on mission requirements.
Once access is established, persistence is maintained through a mix of webshell deployment and registry-based mechanisms, enabling continued control over compromised systems even in the face of remediation efforts. Webshells, often deployed on IIS or similar web servers, provide durable remote access and are frequently reused or redeployed as needed. Registry modifications and scheduled tasks are used to ensure execution at startup or at defined intervals, supporting long-term presence within the environment. Lateral movement is conducted using standard administrative protocols such as RDP, SMB, and Windows Management Instrumentation (WMI), often leveraging harvested credentials to blend activity with legitimate administrative behavior. This reliance on native protocols reduces the need for specialized tooling and helps evade detection by appearing consistent with normal network operations.
Credential access is a critical component of the campaign and is achieved through both credential harvesting and memory dumping techniques. Actors extract credentials from configuration files, email systems, and browser stores, while also leveraging native Windows components such as rundll32 and comsvcs.dll to dump LSASS memory and obtain plaintext credentials or hashes. These credentials are then used to escalate privileges and expand access across the network. Execution throughout the campaign frequently relies on PowerShell and command-line utilities, reflecting a strong preference for living-off-the-land techniques. PowerShell scripts are used for payload delivery, lateral movement, and destructive actions, and can be easily obfuscated or modified to evade detection while maintaining operational flexibility.
Data exfiltration is conducted using a combination of traditional methods and platform abuse, depending on the target environment and desired level of stealth. Files are typically staged locally, compressed, and transferred using standard protocols such as HTTP(S), FTP, or cloud storage services. In more advanced phases, particularly those involving surveillance, the actors leverage Telegram-based exfiltration, using the platform’s API to transmit data through encrypted channels that blend with legitimate traffic. This approach provides both resilience and deniability, as it reduces dependence on dedicated command-and-control infrastructure and leverages widely permitted network activity.
The impact phase integrates multiple destructive techniques, including disk wiping, file encryption, and manual system destruction, often executed in a coordinated manner across numerous endpoints. Custom wipers, PowerShell-based deletion scripts, and legitimate tools such as disk formatting utilities or encryption software are used in combination to maximize damage and complicate recovery. In some cases, actors manually execute commands to delete critical files or disable services, reinforcing the overall impact. This phase is frequently followed by immediate public disclosure, with the actors claiming responsibility and releasing messaging or data through controlled infrastructure. This rapid transition from technical action to public exposure is a defining characteristic of the campaign, linking operational execution directly to its broader objective of psychological influence and coercion.
Evolution of Personas
The progression from Homeland Justice to Karma and ultimately Handala reflects deliberate rebranding rather than a change in the underlying actor set. Core tradecraft, targeting logic, infrastructure patterns, and operational sequencing remain consistent, indicating continuity of capability and control. Homeland Justice was tightly aligned with the Albania campaign, emphasizing retaliation and coercive political messaging. As operations expanded, particularly after the Israel-Hamas conflict, the Karma persona enabled repositioning within a broader ideological frame while preserving the same methods. Handala represents a further evolution toward a durable, scalable identity suited for sustained, multi-theater activity.
These personas function as operational “skins” layered over a stable technical and organizational foundation. Each is tailored to specific audiences and narratives: Homeland Justice to Albanian political dynamics and the MEK (Mojahedin-e-Khalq), Karma to anti-Israeli messaging, and Handala to broader symbolic framing applicable across conflicts. This segmentation optimizes psychological resonance while complicating attribution by creating the appearance of distinct groups.
Multiple personas also manage exposure and risk. Branding shifts allow actors to distance current activity from prior campaigns, reset perception, and adapt to changing conditions without abandoning infrastructure or tradecraft. Parallel operations can run under different identities, reinforcing perceived decentralization. Despite this, consistent use of hack-and-leak workflows, Telegram and leak sites, and similar tooling confirms these are not separate entities but components of a unified, centrally directed ecosystem.
Strategic Assessment
These campaigns represent a state-directed, cyber-enabled influence capability that aligns closely with the operational doctrine of Iran’s Ministry of Intelligence and Security (MOIS), in which cyber operations are employed not solely for intelligence collection or disruption, but as instruments of coercion, signaling, and psychological pressure. The integration of intrusion, disruption, and narrative manipulation into a single operational system reflects a deliberate strategy in which technical access is leveraged to produce effects in the information domain. In this model, network compromise enables data acquisition and operational positioning; disruption amplifies visibility and urgency; and controlled disclosure shapes perception, imposes reputational cost, and pressures decision-making. These elements are not sequential but interdependent, forming a cohesive framework designed to influence both institutional behavior and individual actors across geopolitical contexts.
Recent infrastructure activity over the last several weeks provides direct, empirical support for this assessment and demonstrates that this capability remains active, adaptive, and operationally synchronized. Between 19 March and 23 March 2026, the actor cluster executed a compressed domain registration burst, provisioning at least eight new domains across all three personas: Handala, Karma/KarmaBelow80, and Homeland Justice. The majority of these domains are Handala-branded, including handala-hack[.]pro, handala-hack[.]shop, handala-hack[.]tw, handala-redwanted[.]cc, and handala-redwant[.]to, indicating that Handala remains the primary outward-facing operational identity. In parallel, the registration of karmabelow80[.]biz, karmabelow80[.]st, and notably Homeland Justice[.]info demonstrates that legacy personas are being actively reconstituted rather than retired.
This pattern is analytically significant. It indicates that personae evolution within this ecosystem is not linear but additive and concurrent. The actors are not transitioning from one identity to another; instead, they are maintaining multiple branded layers simultaneously, enabling them to pivot narratives, distribute operational risk, and complicate attribution. The near-simultaneous reactivation of Homeland Justice alongside active Handala expansion suggests deliberate attribution shaping and historical continuity signaling, reinforcing the perception of a persistent, ideologically driven campaign lineage.
The temporal characteristics of this activity further reinforce its operational intent. The tight clustering of registrations within a five-day window is consistent with pre-operational staging or infrastructure regeneration following disruption rather than routine domain churn. The inclusion of both “hack”-labeled domains and “redwanted”-style domains within this burst indicates parallel preparation for both intrusion-linked branding and leak-and-shame operations, which are central to this ecosystem’s influence model. This aligns with prior observed behavior in which compromised data is rapidly operationalized for public dissemination and psychological effect.
Comparable operational patterns can be observed in other state-aligned ecosystems, including Russian influence campaigns such as those associated with the Doppelgänger campaigns and hack-and-leak operations attributed to GRU-linked actors, and DPRK multi-cluster activity, where distinct operational units specialize in intrusion, financial operations, or disruption. However, the Homeland Justice / Handala ecosystem is distinguished by its consistent and tightly coupled integration of hack-and-leak operations with overt psychological messaging. Whereas Russian operations often separate intrusion from amplification, and DPRK activity frequently prioritizes financial or espionage outcomes, this campaign persistently merges technical compromise with immediate public attribution, curated disclosure, and ideological framing. The latest domain registrations reinforce this distinction by showing that infrastructure supporting both compromise and narrative dissemination is provisioned in parallel, not sequentially.
Accordingly, this activity should not be interpreted as a series of isolated incidents or campaigns, but as a persistent, evolving capability embedded within a broader state strategy. The newly observed domain registrations demonstrate that this capability can be rapidly reconstituted, expanded, and rebranded on demand, even in the face of prior takedowns or disruptions. The reuse of naming conventions, the continuity of tradecraft, the simultaneous operation of multiple personas, and the structured expansion of domain infrastructure all indicate an enduring operational framework rather than ad hoc activity. This capability can be activated, scaled, or redirected in response to changing geopolitical conditions, allowing it to remain relevant across multiple theaters and target sets. As such, it represents a sustained mechanism through which the state can project influence, apply pressure, and shape narratives in the cyber and information domains over time.
Persistent integration with information operations
Appendix B – MITRE ATT&CK Matrix by Campaign Phase
his appendix presents a matrix-style mapping of the Homeland Justice / Karma / Handala ecosystem across the MITRE ATT&CK Enterprise framework, broken down by campaign phase. It highlights how capabilities evolved while maintaining continuity across tactics.
B.1 Albania Campaign (2022) – Homeland Justice
Tactic
Techniques
Initial Access
T1190 Exploit Public-Facing Application
Execution
T1059 Command Interpreter, T1059.001 PowerShell
Persistence
T1505.003 Web Shell
Privilege Escalation
T1078 Valid Accounts
Defense Evasion
T1070 Indicator Removal
Credential Access
T1003.001 LSASS Memory
Discovery
T1087 Account Discovery
Lateral Movement
T1021.001 RDP, T1021.002 SMB
Collection
T1114.002 Remote Email Collection
Command & Control
T1105 Ingress Tool Transfer
Exfiltration
T1041 Exfiltration Over C2
Impact
T1486 Data Encryption, T1561.001 Disk Wipe, T1485 Data Destruction
B.2 No-Justice Wiper Phase (Late 2023)
Tactic
Techniques
Execution
T1059.001 PowerShell
Persistence
T1078 Valid Accounts
Defense Evasion
T1218 System Binary Proxy Execution, T1036 Masquerading
Lateral Movement
T1021 Remote Services
Command & Control
T1105 Ingress Tool Transfer
Impact
T1561.001 Disk Wipe, T1485 Data Destruction, T1490 Inhibit Recovery
B.3 Karma Phase (Israel Operations 2023–2024)
Tactic
Techniques
Initial Access
T1190 Exploit Public-Facing Application
Execution
T1059, T1059.001 PowerShell
Persistence
T1505.003 Web Shell
Privilege Escalation
T1078 Valid Accounts
Defense Evasion
T1070 File Deletion, T1562 Impair Defenses
Credential Access
T1003.001 LSASS Memory
Discovery
T1018 Remote System Discovery
Lateral Movement
T1021.001 RDP, T1021.002 SMB
Collection
T1005 Data from Local System
Command & Control
T1105 Ingress Tool Transfer
Exfiltration
T1041 Exfiltration Over C2
Impact
T1485 Data Destruction, T1561 Disk Wipe
B.4 Handala Phase (2024–Present)
Tactic
Techniques
Initial Access
T1190, T1566 Phishing
Execution
T1059.001 PowerShell, T1218.011 Rundll32
Persistence
T1547 Boot/Logon Autostart
Privilege Escalation
T1078 Valid Accounts
Defense Evasion
T1036 Masquerading, T1562 Impair Defenses
Credential Access
T1003.001 LSASS, T1555 Credential Stores
Discovery
T1087 Account Discovery, T1069 Permission Groups
Lateral Movement
T1021 RDP/SMB
Collection
T1005 Local Data
Command & Control
T1105 Tool Transfer
Exfiltration
T1041 Exfiltration
Impact
T1485 Data Destruction, T1486 Encryption, T1490 Inhibit Recovery
B.5 Telegram Surveillance Campaign (2023–2026)
Tactic
Techniques
Initial Access
T1566 Phishing, T1204 User Execution
Execution
T1059.001 PowerShell
Persistence
T1547 Registry Run Keys
Defense Evasion
T1036 Masquerading
Credential Access
T1555 Credential Stores
Discovery
T1087 Account Discovery
Collection
T1113 Screen Capture, T1123 Audio Capture, T1005 Data Collection
Command & Control
T1071.001 Web Protocols (Telegram API)
Exfiltration
T1041 Exfiltration via C2
Impact
(Indirect – psychological/repression rather than system destruction)
B.6 Persona / Influence Infrastructure Layer
Tactic
Techniques
Resource Development
T1583.001 Domains, T1583.003 VPS
Establish Accounts
T1585.001 Social Media Accounts
Stage Capabilities
T1608 Upload/Stage Data
Command & Control
T1102 Web Service (Telegram as platform)
B.7 Cross-Phase ATT&CK Heat Map (Summary)
Tactic
Consistency Level
Initial Access
High
Execution (PowerShell / CLI)
Very High
Persistence
High
Credential Access
Very High
Lateral Movement
Very High
Collection
High
Command & Control
High
Exfiltration
High
Impact
Very High
Influence / Persona Ops
Unique / Defining
APPPENDIX C Leaks Impact
Victim
Leak (Relative Timeline)
Claimed Data
Confirmed Adverse Event
Impact Type
Confidence
Stryker Corporation
Late (T10)
Large-scale data + "wipe"
Operational disruption to manufacturing, ordering, and shipments; systems restoration required; ~80,000 devices reportedly wiped
Operational + destructive
HIGH
Kash Patel
External (not in TW mirror but linked campaign)
Emails, personal data
Public exposure of personal emails and documents; reputational and counterintelligence risk
Exposure / reputational
HIGH
Hebrew University of Jerusalem
Late (parallel campaign)
40–48 TB wiped, 23 TB exfil (claimed)
Claimed destructive attack; partial reporting, no strong independent confirmation of full scale
Operational (claimed)
MEDIUM
Verifone
Mid–late (external claim)
Payment system compromise (claimed)
Company denied breach; no confirmed disruption
Reputational only
LOW
VahidOnline
Mid (T5)
~180,000 users + phone numbers
Doxxing and exposure of identities; intimidation risk to dissident network
Identity exposure / intimidation
MEDIUM-HIGH
Sima Shine
Mid (T4)
~100,000 emails (claimed)
Public leak claims; reputational and intelligence exposure; no confirmed operational disruption
Exposure / reputational
MEDIUM
Ilan Steiner
Early–Mid (T3)
~50,000 emails (claimed)
Public leak claims; financial/internal exposure narrative; no confirmed secondary impact
Exposure / reputational
MEDIUM
Deborah Oppenheimer
Early (T2)
Private communications (claimed)
Public exposure claims; limited external corroboration of downstream effects
Exposure / reputational
LOW-MEDIUM
Eran Ortal
Early (T1)
Strategic documents (claimed)
Narrative exposure of military planning; no confirmed operational consequence
Exposure / narrative
LOW-MEDIUM
Israeli Security Institutions (aggregate)
Mid–Late (T7)
~50,000+ emails (claimed)
Systemic compromise narrative; no confirmed service disruption or institutional failure
Exposure / perception
MEDIUM
Mossad-linked "Treasury"
Mid–Late (T6)
Financial/internal documents (claimed)
Corruption/financial exposure narrative; no confirmed operational impact
Narrative / reputational
LOW-MEDIUM
Israeli Water Infrastructure
Late (T8)
Target database (claimed)
No confirmed breach; deterrence signaling only
Strategic signaling
LOW
Israeli Energy Grid
Late (T9)
Target database (claimed)
No confirmed breach; deterrence messaging
Strategic signaling
LOW
Lockheed Martin engineers (Israel)
External campaign
Personal data (dox)
Doxxing + threats; intimidation campaign; limited validation of dataset accuracy
Handala: MOIS Linked Cyber Influence Ecosystem Threat Intelligence Assessment
Discover how Handala, Homeland Justice, and Karma function as a unified MOIS-linked cyber influence ecosystem. This threat intelligence assessment reveals how Iran uses "hack-and-leak" operations to weaponize perception over technical complexity.
Operational Structure and Attribution
The activity attributed to Homeland Justice, Karma/KarmaBelow80, and Handala is most accurately assessed as a single, coordinated cyber influence ecosystem aligned with Iran’s Ministry of Intelligence and Security (MOIS; وزارت اطلاعات جمهوری اسلامی ایران), rather than a collection of independent hacktivist groups. These personas function as interchangeable operational veneers applied to a consistent underlying capability. Their purpose is not to reflect organizational separation, but to enable segmentation of messaging, targeting, and attribution while preserving continuity of infrastructure and tradecraft.
The use of the name “Handala” itself reinforces the ideological framing of the campaign. Handala (حنظلة) is a well-known Palestinian symbol created by cartoonist Naji al-Ali, depicting a barefoot child who has turned his back on the world in protest of injustice and dispossession. Within the context of this cyber campaign, the adoption of the Handala identity serves to anchor operations within a broader “resistance” narrative, signaling alignment with anti-Israeli and anti-Western themes while providing a culturally resonant and emotionally charged brand for influence operations.
Across all observed phases, the actors exhibit clear temporal continuity, shared infrastructure patterns, and a repeatable operational workflow. The persistence of these elements, despite rebranding, indicates centralized direction and capability management. The use of multiple identities is therefore best understood as a mechanism for narrative flexibility and operational deniability, rather than evidence of distinct actor groups.
Evolution of the Operational Model
The campaign first became visible under the Homeland Justice brand during the 2022 Albania operations, which established its foundational model: long-term access, structured data exfiltration, destructive or disruptive action, and immediate public disclosure. From the outset, technical operations were tightly coupled with messaging, indicating that disruption alone was not the objective. Instead, cyber activity was used to enable narrative exploitation and psychological impact.
Subsequent phases reflect an additive evolution rather than a replacement of capabilities. The Karma phase introduced a hybrid execution model combining custom tooling, publicly available utilities, and hands-on-keyboard tradecraft. This increased operational flexibility and reduced reliance on bespoke malware. The Handala phase further expanded this model into a multi-vector framework integrating destruction, surveillance, and influence operations. The addition of Telegram-based command-and-control and surveillance tooling marked a shift toward persistent, person-centric targeting, extending the campaign’s reach beyond institutions to individuals.
Convergence of Capabilities
Recent activity demonstrates a convergence of previously distinct operational components into a unified framework. Intrusion, surveillance, disruption, and influence are no longer sequential phases, but simultaneous and interdependent functions. The Stryker incident illustrates this evolution, where large-scale data exfiltration, enterprise-level disruption through administrative control systems, and immediate narrative amplification were executed in a tightly integrated manner.
This shift reflects a broader transition away from malware-centric operations toward identity and access compromise at the control-plane level, enabling rapid, scalable impact with minimal reliance on detectable artifacts. It also demonstrates an increased ability to align technical execution with strategic messaging in near real time.
Infrastructure and Amplification Model
The ecosystem is supported by a layered infrastructure designed to separate operational functions while maintaining resilience. Public-facing domains and Telegram channels act as dissemination and amplification nodes, where messaging is curated, claims are published, and stolen data is selectively exposed. These platforms are integral to the operational workflow, bridging the gap between technical compromise and public perception.
Twitter April 2026 Amplification acct
Telegram Amplification Accounts Over Time
Infrastructure is intentionally ephemeral. Domains are frequently rotated, and personas are rebranded or reactivated as needed. However, naming conventions, messaging patterns, and distribution channels remain consistent, allowing the campaign to maintain coherence despite disruption. This results in a system where infrastructure is disposable, but identity and narrative persist.
Operational Effects and Impact
The observable impact of this ecosystem reveals a consistent divergence between claimed and verified outcomes. While the actors present their operations as large-scale destructive intrusions, confirmed system-level disruption is relatively rare. Instead, the majority of activity produces data exposure, reputational damage, and psychological pressure, often targeting both institutions and individuals.
Media hype cycle of low hanging fruit hack of FBI director’s 2009 email account
Sensationalized Reward Offer for Trump or Netanyahu 2026
Many claims remain partially verified or unverified, yet still generate significant downstream effects. Organizations are compelled to investigate and respond, media coverage amplifies the narrative, and uncertainty is sustained. In practice, the perception of compromise often produces effects equivalent to confirmed compromise, enabling the actors to achieve disproportionate impact relative to their demonstrated technical capability.
Role of Telegram and Surveillance Integration
Telegram plays a central role within this ecosystem as both a command-and-control channel and a public dissemination platform. By leveraging a widely trusted service, the actors reduce infrastructure overhead and increase operational resilience. Malware can communicate with operator-controlled bots using encrypted channels indistinguishable from legitimate traffic, while Telegram channels simultaneously serve as hubs for messaging and amplification.
The integration of surveillance capabilities further expands the campaign’s scope. Trojanized applications and user-targeted lures enable persistent monitoring of individuals, particularly dissidents and opposition networks. This allows the actors to move seamlessly from covert collection to overt exposure, reinforcing the link between technical activity and psychological pressure.
Strategic Assessment
This ecosystem represents a state-directed instrument of cyber-enabled influence, in which technical operations are tightly integrated with narrative manipulation and media amplification dynamics to achieve coercive and strategic effects. Intrusion enables access, access enables collection, and collection enables controlled disclosure. However, the decisive phase is the conversion of that disclosure into a high-visibility narrative event. Incidents such as the compromise of Kash Patel demonstrate how relatively limited technical access can be operationalized through the modern news cycle, where rapid reporting, social media propagation, and secondary analysis amplify the perceived scale and significance of the breach. In this model, the hype cycle is not incidental; it is a core component of the operation, transforming modest compromises into strategic effects.
The maintenance of multiple concurrent personas, the rapid regeneration of infrastructure, and the consistent integration of cyber and information operations indicate a mature and adaptive capability optimized for this environment. These personas allow the actors to continuously seed new events into the information ecosystem, while disposable domains and Telegram channels ensure persistence of messaging even as infrastructure is disrupted. Each operation is effectively designed as a trigger for a predictable amplification loop: initial claim, media pickup, public discourse, and institutional response. This loop imposes reputational and operational costs on targets regardless of the underlying technical depth.
As a result, the system can be activated, scaled, or redirected in response to geopolitical conditions with minimal reliance on sustained intrusion capability. Its effectiveness lies in the ability to synchronize cyber activity with the tempo of the information environment, using the hype cycle to magnify impact across multiple theaters and target sets. In practical terms, this means that perception, attention, and narrative momentum are treated as operational objectives on par with access and disruption, allowing the actors to remain effective even when technical outcomes are limited.
Conclusion
Homeland Justice, Karma, and Handala should be treated as components of a unified operational apparatus, not discrete threat actors. Their effectiveness does not derive from sustained technical superiority or advanced intrusion tradecraft, but from their ability to fuse low-to-moderate cyber capability with disciplined psychological and informational operations to create a cohesive and scalable system.
Across observed incidents, the underlying modus operandi is consistent with opportunistic, identity-layer compromise rather than sophisticated exploitation. Initial access is frequently achieved through relatively low-complexity methods such as password guessing, credential stuffing, phishing, exploitation of weak or reused credentials, and poor security hygiene in externally exposed services. Even in higher-impact cases such as Stryker Corporation, the available indicators suggest that compromise likely originated from weak identity and access controls or misconfigured management infrastructure, rather than novel vulnerabilities or advanced malware deployment. This aligns with a broader pattern in which targets are selected not for hardened defenses, but for accessible attack surfaces and exploitable operational gaps.
In this sense, these actors operate closer to low-tier intrusion crews or access brokers in their technical execution. However, what differentiates them is not how they gain access, but what they do with it. Limited footholds – often no more than a compromised account, exposed dataset, or peripheral system – are systematically transformed into hack-and-leak operations designed for maximum psychological and media impact. Small or ambiguous datasets are framed as large-scale breaches; partial access is presented as systemic compromise; and unverified claims are released in ways that ensure rapid amplification.
This is where the integration with influence operations becomes decisive. The ecosystem relies heavily on timing, narrative construction, and media exploitation to convert low-level technical events into high-visibility incidents. The breach and leak involving Kash Patel is illustrative: a compromise of a personal account technically limited in scope was rapidly elevated into a widely covered event, generating disproportionate attention relative to its technical impact. This reflects a deliberate strategy in which the news cycle functions as an extension of the operation, amplifying reach and reinforcing perceived capability.
Targets are therefore often targets of opportunity, selected for their symbolic value, media relevance, or potential to generate secondary effects. The objective is not persistent access or long-term control, but event generation creating moments that can be exploited for narrative gain. Each operation is structured to trigger a predictable response cycle: disclosure, media coverage, public reaction, and institutional response. This cycle imposes real costs on victims and defenders, regardless of the underlying technical depth of the compromise.
The result is a model in which technical simplicity coexists with strategic effectiveness. Low-level intrusions, when paired with coordinated amplification and ambiguity, produce outcomes typically associated with more advanced actors. The distinction between hacking and influence is therefore not incidental but intentional. Cyber activity provides the entry point, but the primary objective is the shaping of perception, the erosion of confidence, and the projection of capability.
This approach reflects a broader evolution in state-aligned cyber operations. Rather than investing exclusively in high-end capabilities, actors can achieve comparable strategic effects by combining accessible intrusion techniques with sophisticated information operations. In this framework, success is measured not by the depth of compromise, but by the ability to control the narrative surrounding that compromise.
Accordingly, Homeland Justice, Karma, and Handala should be understood not as elite intrusion actors, but as hybrid operators leveraging low-cost cyber access to generate high-impact psychological effects. Their significance lies in demonstrating that, in the current information environment, perception can be weaponized as effectively as technical capability. Furthermore, it demonstrates that even modest breaches can be scaled into strategic events when amplified through media and narrative control.
DPRK Malware Modularity: Diversity and Functional Specialization
Explore the DPRK’s modular malware architecture. Analyze how North Korea uses compartmentalized toolchains for espionage, crypto theft, and strategic signaling.
Executive Summary
North Korea’s cyber program has evolved into a deliberately fragmented malware ecosystem, optimized for mission specialization, operational resilience, and attribution resistance. Analysis of multiple vendor, government, academic, and secondary reporting confirms that what appears externally as a “fracture” is, in practice, a mature portfolio model: parallel malware development pipelines aligned to discrete strategic objectives.
This structure enables the DPRK to conduct simultaneous espionage, revenue generation, and disruptive operations without cross-contaminating tooling, infrastructure, or exposure. Compartmentalization and diversity is therefore assessed as a feature of program maturity, not decentralization or degradation.
Strategic Drivers
The current compartmentalization and diversity of North Korea’s malware ecosystem is not an accidental byproduct of growth or internal disorder; it is a rational response to sustained and cumulative strategic pressure. Over more than a decade, international sanctions have progressively constricted the regime’s access to hard currency, elevating cyber operations from an auxiliary intelligence function to a core mechanism of economic survival. At the same time, increasingly coordinated law-enforcement actions and intelligence disclosures have reduced the lifespan of individual campaigns, forcing DPRK operators to assume that any exposed tool, infrastructure cluster, or technique will eventually be neutralized.
This pressure has been compounded by the repeated public exposure of specific malware families and campaign narratives. Once-effective tools are now rapidly fingerprinted, attributed, and disseminated across defensive communities, collapsing their operational utility. Parallel to this, target environments particularly in finance, technology, and government have become more defensively mature, with improved telemetry, faster incident response cycles, and greater cross-sector information sharing. In aggregate, these factors have raised the cost of persistence and reduced the viability of monolithic, long-lived malware platforms.
In response, the DPRK has adapted by restructuring its cyber program around principles of resilience rather than longevity. Malware development and operations are increasingly compartmentalized, both technically and organizationally, ensuring that exposure in one mission area does not cascade across the entire program. Toolchains are treated as consumable assets: designed to be burned, replaced, and reconstituted with minimal strategic loss. This loss-tolerant posture enables multiple teams to operate in parallel, pursuing espionage, revenue generation, and disruptive objectives simultaneously without competing for the same infrastructure or codebase.
Crucially, this model also maximizes ambiguity. By separating tooling, infrastructure, and operational patterns along mission lines, the DPRK complicates attribution and slows defender decision-making. What emerges is not compartmentalization and diversity as weakness, but compartmentalization and diversity as control: a cyber apparatus engineered to absorb pressure, survive exposure, and continue functioning even as individual components are repeatedly stripped away.
Compartmentalized Malware Architecture
Espionage Oriented Malware Track
The espionage-oriented malware track represents the most traditional and strategically conservative pillar of the DPRK cyber program. Its purpose is not disruption or immediate financial return, but the quiet, sustained extraction of intelligence from institutions that shape policy, security planning, and strategic decision-making. Targets are selected for their informational value rather than their economic utility, encompassing government ministries, defense contractors, academic research centers, think tanks, and organizations operating at the margins of policy formation.
Operations within this track are characterized by restraint and patience. Activity is deliberately low-noise, with operators prioritizing extended dwell time over rapid exploitation. Initial access is leveraged to establish durable footholds that enable credential harvesting, mailbox surveillance, and systematic document collection. Once embedded, the objective is to observe, monitor, and siphon information continuously, often for months or years, with minimal operational disruption to the victim environment. Destructive actions and monetization are intentionally avoided, as they increase detection risk and prematurely terminate access.
Technically, this restraint is reflected in the tooling. Malware associated with espionage missions favors script-heavy loaders, most commonly PowerShell or VBS that blend into normal administrative activity and reduce the need for large, easily detected binaries. Backdoors are frequently memory-resident, minimizing on-disk artifacts and complicating forensic recovery. Initial access commonly relies on weaponized documents or carefully crafted lures tailored to the professional context of the target, reinforcing the emphasis on social engineering over exploit development.
Once access is established, trusted cloud services are routinely abused for command-and-control and staging. By operating through platforms already embedded in enterprise workflows, operators obscure malicious traffic within legitimate usage patterns and benefit from the implicit trust afforded to major service providers. This approach further reduces operational noise while extending persistence in environments with increasingly mature perimeter defenses.
This espionage track is most commonly associated with Kimsuky, which has long been assessed as a primary intelligence-collection component within the DPRK cyber ecosystem. Its campaigns exemplify the regime’s preference for slow, methodical access to high-value information streams, reinforcing the view that espionage remains a foundational mission even as financial and disruptive cyber operations expand alongside it.
Financial Operations Malware Track
The financially oriented malware track reflects the most adaptive and economically consequential arm of the DPRK cyber program. Its overriding purpose is revenue generation: converting access into currency in order to blunt the effects of international sanctions and directly fund regime priorities, including strategic weapons development. Unlike espionage operations, success in this track is measured not in persistence or insight, but in speed, scale, and yield.
Operations in this category are characterized by a markedly faster tempo. Campaigns are designed to move quickly from initial access to monetization, accepting shorter dwell times and higher exposure risk in exchange for financial return. Targeting is broad and opportunistic, with a pronounced focus on cryptocurrency exchanges, blockchain developers, decentralized finance platforms, and the software supply chains that underpin them. Rather than selecting victims for their strategic influence, operators select ecosystems where a single compromise can yield outsized financial gain or cascade into downstream access.
This operational urgency is mirrored in infrastructure management. Hosting, domains, and delivery mechanisms are treated as disposable, with rapid churn used to stay ahead of takedowns and blacklist propagation. Infrastructure longevity is not a priority; instead, it is optimized for brief windows of effectiveness before inevitable exposure. This burn-and-replace mindset distinguishes financial campaigns from the more conservative espionage track and underscores their role as an economic instrument rather than a long-term intelligence platform.
Technically, tooling within this track is purpose-built for theft. Wallet stealers and browser injectors are used to intercept credentials, private keys, and transaction workflows directly at the user layer. Clipboard hijacking exploits habitual behaviors to silently redirect cryptocurrency transfers. Increasingly, operators have demonstrated sophistication in compromising trust boundaries within the developer ecosystem itself, embedding malicious code into open-source packages or trojanizing software updates relied upon by exchanges and development teams. By inserting malware upstream, they convert trusted tooling into a scalable access vector.
Compromise of exchange infrastructure and developer environments further amplifies impact, allowing attackers to move laterally across platforms, users, and assets with minimal additional effort. These techniques reflect a deep understanding of how modern financial and crypto ecosystems are built and where their implicit trust assumptions can be subverted.
This revenue-focused track is most commonly associated with Lazarus Group, which has evolved from a primarily espionage-linked actor into a central pillar of the DPRK’s sanctions-evasion strategy. Its operations illustrate how malware has been weaponized not just as a tool of intrusion, but as a mechanism of state finance, tightly coupled to the regime’s broader strategic objectives.
Disruptive / Coercive Malware Track
The disruptive and coercive malware track represents the most overt and politically expressive component of the DPRK cyber program. Unlike espionage or financially motivated operations, its primary purpose is not persistence or profit, but strategic signaling. These operations are designed to demonstrate capability, impose costs, or deliver retaliation during periods of heightened geopolitical tension, serving as a cyber analogue to more traditional forms of state messaging and coercion.
Operationally, this track prioritizes impact over longevity. Dwell times are intentionally short, as operators expect rapid detection once payloads are deployed. Rather than avoiding attention, these campaigns are constructed to generate it, producing effects that are immediately visible to victims, governments, and, in some cases, the broader public. Tooling and infrastructure are treated as expendable, with a clear willingness to burn assets in exchange for a decisive, time-bound outcome.
The technical execution of these operations reflects this mindset. Payloads frequently take the form of wipers or ransomware-like tools capable of inflicting widespread disruption across enterprise environments. Once initial access is achieved, operators emphasize rapid lateral movement to maximize reach before containment measures can be enacted. Domain-wide execution is a common objective, enabling simultaneous impact across large portions of a target organization and amplifying both operational and psychological effect.
Timing is a critical element. Deployments are often aligned with external political, military, or diplomatic events, reinforcing the interpretive link between the cyber operation and broader state intent. This temporal coordination strengthens the signaling function of the attack, ensuring that the disruption is read not as isolated cybercrime, but as an intentional act within a wider strategic context.
This disruptive track is most commonly associated with Andariel, which has been linked to campaigns emphasizing sabotage, rapid execution, and overt impact. Within the fragmented DPRK malware ecosystem, this track functions as the regime’s blunt instrument: less subtle than espionage, less financially focused than theft, but uniquely suited to delivering unmistakable signals when strategic conditions demand it.
Cross-Track Technical Invariants
Despite the visible compartmentalization and diversity of tooling and operations, analysis across the full body of known malware reporting reveals a set of persistent unifying elements that cut across mission lines. These commonalities indicate that divergence at the payload and campaign level does not equate to independence at the development or strategic level. Instead, they point to shared standards, reuse patterns, and centralized oversight shaping how disparate malware tracks are built and deployed.
At the technical layer, recurring cryptographic routines and packing styles appear across otherwise distinct malware families. While implementations are often modified to frustrate signature-based detection, the underlying design choices remain recognizable, suggesting common developer playbooks or shared internal libraries. Similarly, loader architectures show strong familial resemblance: lightweight initial components designed to stage or decrypt secondary payloads, reused across campaigns with incremental variation rather than wholesale redesign.
Infrastructure analysis reinforces this picture. Even as domains and servers are rapidly rotated at the campaign level, overlap persists at lower layers of the stack, including registrars, hosting providers, and preferred geographic regions. This reuse reflects both operational convenience and institutional familiarity, revealing constraints and preferences that are difficult to fully obfuscate even in a fragmented model.
Perhaps most importantly, all tracks continue to rely heavily on social engineering as the primary initial access vector. Whether the objective is espionage, financial theft, or disruption, operators consistently exploit human trust rather than novel technical exploits. This dependence underscores a strategic assessment that human-mediated access remains more reliable, scalable, and adaptable than vulnerability-driven intrusion, particularly against increasingly hardened technical defenses.
Once access is achieved, there is a consistent preference for operating within trusted ecosystems. Cloud platforms, developer tooling, and collaboration services are repeatedly abused for command-and-control, staging, or lateral movement. By embedding malicious activity within environments already sanctioned and trusted by enterprises, operators reduce detection risk and leverage the implicit legitimacy of widely used services.
Taken together, these patterns demonstrate that compartmentalization and diversity exists primarily at the operational and payload level, not at the level of governance or development philosophy. The DPRK malware ecosystem is best understood as a collection of specialized instruments built from a common toolkit, governed by shared standards and strategic direction, even as execution diverges to meet distinct mission objectives.
Why Compartmentalization and Diversity Matters
Operationally, compartmentalization and diversity confers a high degree of resilience on the DPRK cyber program. Because malware families, infrastructure, and delivery mechanisms are compartmentalized by mission, the exposure or neutralization of one toolchain has limited impact beyond its immediate operational context. When a specific malware family is detected, attributed, and burned, the loss is contained; parallel mission tracks continue to function largely unaffected. This loss tolerance allows operators to assume compromise as a routine condition rather than an exceptional failure, encouraging aggressive use of tooling without risking systemic degradation of the broader program.
This resilience is reinforced by deliberate attribution friction. Divergent malware families, distinct infrastructure clusters, and varying tradecraft across campaigns complicate efforts to collapse activity into a single coherent actor model. Defenders and analysts are forced to disentangle overlapping indicators, slowing attribution and increasing uncertainty about scope and intent. Campaign clustering becomes more difficult as shared characteristics are diluted by intentional variation, while residual commonalities remain subtle enough to require sustained analytic effort to identify.
At the policy level, this ambiguity has concrete effects. Unclear attribution complicates decision-making around response options, escalation thresholds, and public messaging. When activity cannot be cleanly assigned to a single actor or mission set, responses tend to be slower, more cautious, and less coordinated. In this way, compartmentalization and diversity functions not only as a technical or operational safeguard, but as a strategic instrument shaping how adversary actions are interpreted while also constraining the speed and confidence with which states and organizations can respond.
Parallel Execution
Compartmentalization and diversity enables the DPRK cyber program to operate on multiple fronts simultaneously without the internal friction that would otherwise arise from shared tooling, infrastructure, or operational dependencies. By separating malware families and operational workflows along mission lines, distinct teams can pursue diplomatic, financial, and technological targets in parallel, each optimized for its own objectives and risk profile. This structure avoids the bottlenecks and trade-offs inherent in monolithic campaigns, where a single exposure can force a pause or redesign across all activity.
Against diplomatic and policy-oriented targets, espionage-focused operations can proceed patiently, maintaining long-term access and information flow without being disrupted by the higher-noise activities of financial theft or disruptive attacks. At the same time, financially motivated campaigns can move aggressively against cryptocurrency exchanges, developer communities, and related infrastructure, burning tooling and infrastructure as needed without jeopardizing sensitive intelligence footholds elsewhere. Disruptive operations, when activated, can deliver rapid and visible impact without revealing or contaminating the quieter channels of access maintained in parallel.
This separation of concerns allows the DPRK to treat its cyber operations as a portfolio of independent but strategically coordinated efforts. Each mission track operates according to its own tempo, tolerance for exposure, and technical requirements, yet all contribute to overarching state objectives. The result is a cyber apparatus capable of sustained, multi-domain engagement across diplomatic, economic, and technological domains without mutual interference or cascading operational risk.
Defender Implications
The fragmented structure of the DPRK malware ecosystem fundamentally alters the detection problem for defenders. Static malware signatures degrade rapidly as tooling is routinely modified, re-packed, or replaced altogether. Even when individual samples are successfully identified, their utility is short-lived, offering only fleeting defensive value before variants emerge. Similarly, campaign-level indicators of compromise once effective for clustering activity no longer generalize across operations, as distinct mission tracks deliberately minimize shared surface indicators.
As a result, malware-focused detection in isolation is increasingly insufficient. Focusing on payloads alone risks missing the broader operational context in which access is gained, maintained, and exploited. In a segmented model, the absence of a known malware signature does not imply the absence of DPRK activity; it may simply reflect a different mission track employing different tooling, infrastructure, or delivery mechanisms.
Effective defense therefore requires a shift in priorities. Behavioral analytics become critical for identifying anomalous patterns of access, execution, and data movement that persist regardless of specific malware families. Identity and access monitoring is particularly important, as many DPRK operations across espionage, financial, and disruptive tracks depend on credential abuse and trusted account usage rather than exploit-driven compromise. Strengthening security around supply chains and developer ecosystems is equally essential, given the regime’s demonstrated willingness to compromise upstream tooling to achieve scalable access. Cloud telemetry correlation, spanning authentication events, API usage, and cross-service activity, provides the visibility necessary to detect abuse within trusted platforms.
Organizations that frame DPRK activity too narrowly by treating it exclusively as espionage or, alternatively, as financial cybercrime risk creating analytical blind spots. The segmented nature of the threat means that focusing defenses on a single “type” of activity can leave other mission tracks undetected. Instead, a holistic approach, grounded in behavior, identity, and ecosystem trust relationships, is required to account for the full breadth of DPRK cyber operations.
Malware compartmentalization and diversity in the Broader APT Landscape
The deliberate burn-and-replace approach observed in DPRK malware campaigns is not without precedent among advanced state-aligned threat actors. However, comparative analysis shows that while similar tactics exist elsewhere, the degree of institutionalization and mission coupling seen in DPRK operations is unusually pronounced.
Several other APT actors have adopted rapid malware turnover, modular tooling, and payload rotation to evade detection and extend campaign viability under defensive pressure.
Russian intelligence–linked actors, such as APT29, have repeatedly evolved malware families over time, transitioning from early Duke variants to successive, distinct frameworks. These shifts demonstrate intentional tool refresh cycles designed to defeat signature-based detection, but they largely occur within a single strategic mission space of long-term espionage rather than across parallel, economically distinct objectives.
Similarly, APT28has historically rotated between multiple malware families across campaigns, adapting tooling to geopolitical context and operational exposure. While this reflects a willingness to abandon burned tools, the activity remains more campaign-reactive than structurally segmented.
Chinese-linked APT41 presents a closer analogue in that it has demonstrably conducted both state-aligned espionage and financially motivated operations, often with overlapping personnel and infrastructure. APT41’s use of supply-chain compromise, rapid tool replacement, and diverse malware frameworks mirrors aspects of the DPRK model. However, public reporting indicates less rigid separation between mission toolchains, with greater reuse across objectives.
Iranian actors such as Charming Kitten likewise exhibit frequent shifts in malware payloads and delivery mechanisms, particularly in response to exposure. These changes improve survivability but do not rise to the level of a fully articulated portfolio model; tool churn here appears tactically driven, rather than strategically compartmentalized.
Finally, disruptive-focused Russian activity attributed to Sandworm demonstrates an extreme willingness to burn tooling entirely, particularly in wiper and destructive campaigns. However, this behavior is episodic and event-driven, rather than embedded in a standing, multi-mission cyber architecture.
Below is a comparative table showing how DPRK actors stand relative to other major nation-state APT actors (Russia, China, and Iran) in terms of tool churn, mission separation, and burn tolerance. This is based on multiple public sources outlining state-aligned cyber capabilities, campaign evolution, and malware practices.
High — Frequent tool replacement across multiple distinct malware families; new tooling expected as exposed. Part of intentional program design (burn/rebuild).
Moderate — Malware families evolve (e.g., MiniDuke → OnionDuke → CosmicDuke), but changes are often adaptive rather than systematic churn.
Wikipedia
Moderate to High — Some modular platforms (ShadowPad) persist with evolving variants; APT41 leverages diverse malware and reuses components across operations.
SentinelOne
Low to Moderate — Generally stable toolsets with iterative updates; malware families deployed repeatedly across campaigns rather than replaced entirely.
Low–Moderate — Primarily espionage and disruption; mission roles are contextual but not structurally separated as distinct portfolios.
Wikipedia
Moderate — APT41 uniquely combines espionage + financial operations, but toolsets are often reused between missions.
TerraZone
Low — Focused primarily on espionage; mission separation is less pronounced.
Picus Security
Burn Tolerance (willingness to discard tools)
Very High — Tool loss anticipated and baked into design; "burn and replace" is normative.
Moderate — Tools are refreshed when detection risk becomes too high, but not as a planned operational norm.
Moderate — Tools evolve to evade detection; often reused rather than fully discarded; some long-lived frameworks.
Low–Moderate — Tools persist across campaigns; not typically discarded unless externally exposed.
Malware Modularity
High — Early-stage loaders, persistence, and mission payloads frequently have distinct and individual modules.
High — Uses modular backdoors and plugin architectures (e.g., Cozy Bear's Duke variants).
Wikipedia
High — Both modular backdoors (ShadowPad) and custom/third-party tools used.
SentinelOne
Moderate — Modular in some groups (e.g., OilRig's PowerShell modules) but less generalized than for large nation actors.
Picus Security
Cross-Campaign Reuse of Family
Low — Malware families are mission distinct and often unique to a given operational track.
Moderate — Reuse of older frameworks with evolution; variants often retain lineage.
Wikipedia
Moderate to High — Some core backdoors reused across different campaign objectives.
SentinelOne
High — Smaller toolsets reused across multiple campaigns with minor updates.
Picus Security
Integration with Financial Crime
Explicit — Financial malware track is part of the core strategy to generate revenue.
Rare — Russian state groups typically avoid financially focused malware as a strategy.
Present — APT41 engages in some financially motivated activity alongside state espionage.
TerraZone
Minimal — Iranian actors mostly focus on espionage or disruption, not economic theft or revenue generation.
Analytic Distinction: Why the DPRK Model Is Different
What distinguishes the DPRK cyber program is not the existence of malware rotation itself, but how completely burn-and-replace logic is integrated into program design.
Across other APT ecosystems, rapid malware turnover is typically:
A response to detection,
Confined to a single mission domain, or
Implemented unevenly across campaigns.
By contrast, DPRK operations demonstrate:
Standing parallel malware portfolios, not ad-hoc replacements,
Acceptance of tool loss as routine, not exceptional,
And centralized strategic coordination despite decentralized execution.
This places DPRK activity closer to an industrialized cyber production model, where malware is treated as a consumable input rather than a prized asset.
In contrast, espionage tooling is expected to retain its emphasis on low-noise persistence. Malware supporting intelligence collection will continue to prioritize stealth, credential abuse, and cloud-based living-off-the-land techniques that enable extended dwell times even in increasingly monitored environments.
Taken together, these trends indicate that compartmentalization and diversity is not a transitional phase but a durable feature of the DPRK cyber program. As defensive pressure increases, diversification by mission will deepen, further entrenching a model built to absorb exposure, frustrate attribution, and sustain operations across multiple strategic domains.
Summary Findings
The DPRK malware ecosystem is not simply more prolific or more chaotic than that of its peers; it is more deliberately structured at a fundamental, programmatic level. Where many advanced persistent threat actors treat malware as a semi-durable asset to be preserved and refined over time, the DPRK treats malware as an inherently expendable input. Tool exposure is not regarded as a failure state; it is an assumed outcome. As a result, operational planning begins from the premise that any given toolchain will eventually be detected, attributed, and neutralized.
This assumption fundamentally reshapes how the DPRK designs and deploys cyber capabilities. Malware is engineered for utility within a limited lifespan rather than for long-term survivability. Development pipelines emphasize speed, modularity, and replaceability over elegance or longevity. When a tool is burned, it is not mourned or patched indefinitely; it is discarded and superseded, often by a parallel or already-prepared alternative. In this sense, compartmentalization and diversity is not a defensive reaction to disruption, but the default state of the ecosystem.
By contrast, many other APT actors burn tools reluctantly and reactively. Russian, Chinese, and Iranian groups typically rotate malware families after exposure, but such decisions are often tied to specific campaigns or incidents. The underlying assumption remains that tools should persist as long as possible, evolving incrementally to preserve prior investment. The DPRK departs from this logic entirely. Its cyber operations reflect an acceptance that persistence at the tool level is illusory, and that strategic continuity must instead be achieved through organizational design and operational redundancy.
Seen in comparative context, DPRK cyber operations are therefore best understood not as an anomaly, but as a mature instantiation of a broader trend among advanced threat actors pushed to its logical extreme by unique economic and political constraints. Persistent sanctions, direct linkage between cyber activity and state revenue, and sustained international scrutiny have compressed the DPRK’s tolerance for operational pause or degradation. Under these conditions, a cyber program built around long-lived platforms would be brittle. A program built around compartmentalization and diversity, parallel execution, and consumable tooling is resilient.
Malware diversity, rapid churn, and concurrent mission execution are not symptoms of disorder or indiscipline. They are the visible mechanics of a system engineered to function under constant pressure, where exposure is continuous and inevitability assumed. In this model, coherence does not reside in individual tools, but in strategy: centralized intent, mission-aligned portfolios, and an operational architecture designed to endure even as its individual components are repeatedly destroyed.
APPENDIX A: Representative DPRK Malware IOCs
Government-Published Malware Variants & Names
These malware families have been documented in U.S. government malware reports and advisories associated with North Korean state actors (often referred to collectively as HIDDEN COBRA by U.S. agencies): (CISA)
BLINDINGCAN – Remote access tool used to maintain persistence and network exploitation. (CISA)
COPPERHEDGE – Manuscrypt family variant attributed to North Korean APT targeting exchanges/crypto ecosystems. (CISA)
TAINTEDSCRIBE – Full-featured beaconing implant used by DPRK actors. (CISA)
PEBBLEDASH – North Korean beaconing implant family. (CISA)
BISTROMATH – Remote access implant with multiple versions observed. (CISA)
SLICKSHOES – Dropper with beaconing capabilities. (CISA)
CROWDEDFLOUNDER – Beaconing payload with packing protections. (CISA)
ELECTRICFISH – Proxy malware for tunnelled traffic. (CISA)
BADCALL – Proxy server malware with Fake TLS methods. (CISA)
Joanap – RAT enabling botnet management and secondary payload execution. (Wikipedia)
Note: CISA malware analysis reports (MARs) frequently include sample hashes, file Thatnames, network indicators, and signatures for these variants. (CISA)
Appendix B: Malware Linked Activities and Attribution Context
Cryptocurrency-Facilitating Malware
AppleJeus – Malware family used to facilitate cryptocurrency theft, often distributed under the guise of fake trading platforms or wallets. (CISA)
Operational Artifacts & TTP Context
While specific IOCs vary by incident and campaign, the following patterns are relevant to detection and triage:
Botnet infrastructure IPs associated with DDoS and proxy relays used by DPRK actors. (CISA)
Credential harvesting and session token theft in spearphishing campaigns (e.g., mobile-delivered QR code phishing vectors). (Internet Crime Complaint Center)
Proxy and beaconing communication over Fake TLS or tunneled channels seen in BADCALL/ELECTRICFISH series. (CISA)
Appendix C: Known Malware Families by Associated Actor
FudModule cbd1634cf7c638f2faf5e3ec79137db6704ec9de8df798fc46aeeed38de3da9b (noted as shared with GOLDEN) (CrowdStrike)
Supplemental “legacy DPRK MAR-derived” hashes (bridging set; keep as non-exclusive DPRK nexus): Use these as heritage/overlap indicators for “DPRK malware ecosystem” rather than hard-binding them to LABYRINTH specifically.
BLINDINGCAN (multiple SHA256)
BISTROMATH (multiple SHA256)
SLICKSHOES, CROWDEDFLOUNDER, BUFFETLINE, BADCALL (SHA256) (These remain useful as “DPRK malware portfolio” IOCs, but they are not the cleanest proof of the three-unit split without additional clustering work.)
Exposure of TLS Private Key for Myclaw 360 in Qihoo 360 “Security Claw” AI Platform
DTI analysis of a leaked TLS private key from Qihoo 360's AI security platform, covering cryptographic validation, threat scenarios, and incident response.
Executive Summary
DTI analyzed the confirmed exposure of a Transport Layer Security (TLS) private key associated with the wildcard certificate *.myclaw[.]360[.]cn, which appears tied to the Security Claw (安全龙虾) artificial-intelligence assistant platform developed by Qihoo 360. Earlier public discussion of the issue relied primarily on screenshots and reposted commentary claiming that the certificate and private key were embedded in the platform’s installer package. The material provided for this investigation includes the full X.509 certificate and corresponding private key. Cryptographic validation confirms that the supplied private key matches the public key contained in the certificate, establishing that the exposed credential is authentic and operational rather than a placeholder or decoy.
The certificate is issued by WoTrus CA Limited under the issuing chain WoTrus RSA DV SSL CA 2. It is a wildcard certificate covering both *.myclaw[.]360[.]cn and myclaw[.]360[.]cn and was originally issued with a validity period spanning 12 March 2026 through 12 April 2027. Because wildcard certificates authenticate any host within the domain namespace, possession of the corresponding private key would allow an attacker to impersonate services across the entire Security Claw infrastructure if the certificate remained trusted and unrevoked.
Subsequent certificate-transparency analysis conducted during this investigation indicates that the certificate has since been rotated and replaced as part of an apparent incident-response action. CT log entries show that on 16 March 2026, a new wildcard certificate for *.myclaw[.]360[.]cn was issued with a new RSA key pair and shortened validity period, replacing the originally exposed certificate. The rapid issuance of the replacement certificate and the change in key material strongly suggest that Qihoo 360 detected the credential exposure and executed emergency key rotation to invalidate the compromised trust material.
Infrastructure analysis further confirms that the parent domain ecosystem (360[.]cn) is registered to Beijing Qihoo Technology Co., Ltd. (北京奇虎科技有限公司) and uses internally controlled DNS and mail infrastructure. This strongly supports attribution of the myclaw[.]360[.]cn namespace to Qihoo 360’s operational domain environment. The exposure therefore represents a confirmed cryptographic trust-material leak, with potential consequences including server impersonation, TLS interception, credential theft, and malicious update delivery within the Security Claw ecosystem. Although the certificate appears to have been rotated following discovery of the issue, the operational impact ultimately depends on whether the compromised key was actively deployed in production services and whether any adversary obtained the key prior to remediation.
Background: Qihoo 360 and the Security Claw Platform
Qihoo 360 is widely recognized as one of China’s largest cybersecurity and internet-technology companies, operating across both consumer and enterprise security markets. Since its founding in the early 2000s, the company has developed a broad portfolio of security and software products that include antivirus platforms, endpoint protection suites, web browsers, vulnerability-scanning tools, and large-scale threat-intelligence services. Through these products, Qihoo 360 has established an extensive user base spanning hundreds of millions of individual users as well as corporate and government customers. Much of the company’s security ecosystem is built around large telemetry pipelines that collect threat data from deployed endpoints and feed it into centralized analytics systems used to detect malware, exploit campaigns, and network intrusions.
In recent years the company has increasingly invested in artificial-intelligence technologies as part of its broader cybersecurity strategy. Like many large security vendors, Qihoo 360 has begun integrating machine-learning models and generative AI capabilities into its defensive tools, both to automate analysis tasks and to provide interactive interfaces for users and analysts. This effort has produced a range of AI-enabled assistants and intelligent agents designed to augment traditional security workflows. These systems typically allow users to query threat data, analyze malware samples, or receive automated recommendations through natural-language interfaces powered by backend AI models.
However, they have started pulling back on this, as they have begun learning about the pitfalls.
The Security Claw (安全龙虾) platform appears to be one of the products emerging from this initiative. Based on publicly available information and artifacts analyzed during this investigation, Security Claw functions as a locally installed client application that interacts with remote services operated by Qihoo 360. Rather than performing all processing locally, the client appears to act as a front-end interface that communicates with cloud-hosted AI infrastructure. These backend services operate within the myclaw.360.cn domain namespace, which appears to serve as the central network environment for the platform’s API endpoints and inference services.
Reports associated with the platform indicate that the client software connects to at least one backend endpoint located at https://myclaw[.]360[.]cn:19798, a service running on a non-standard port rather than the default HTTPS port 443. The use of such ports is common in internal service architectures where applications communicate directly with API gateways or service nodes without passing through standard web-server front ends. The presence of this endpoint suggests that the client communicates with a specialized service interface rather than a conventional public website.
Architecturally, this design reflects a hybrid deployment model commonly used by modern AI assistant platforms. In this model, a lightweight local application acts as a wrapper that manages user interactions, authentication, and system integration while delegating computationally intensive tasks such as natural-language processing, model inference, and large-scale data retrieval to cloud infrastructure. The client collects user prompts and contextual information from the local system and forwards these requests to backend services where AI models perform the actual analysis or generate responses.
Systems built on this architecture typically consist of multiple interconnected backend components. These may include authentication services responsible for validating client identities, API gateways that route requests to the appropriate services, telemetry collectors that gather usage and performance data from deployed clients, and inference endpoints hosting the machine-learning models used to generate responses. Additional components often include update services responsible for delivering model updates or configuration files to the client software. All of these elements operate together to create the user-facing experience of an AI assistant while relying on centralized cloud infrastructure to perform the majority of processing tasks.
Technical Findings
Certificate Structure
Analysis of the certificate associated with the Security Claw infrastructure indicates that it is a standard X.509 server authentication certificate issued for the wildcard domain namespace *.myclaw[.]360[.]cn. The certificate’s Common Name (CN) is configured as *.myclaw[.]360[.]cn, enabling it to authenticate any host operating under that subdomain space. In addition to the wildcard identifier, the certificate’s Subject Alternative Name (SAN) extension explicitly includes both *.myclaw.360[.]cn and the root host myclaw[.]360[.]cn. This configuration allows the certificate to be used by both the base domain and any subordinate services, a design pattern typically employed in microservice architectures where multiple backend services operate under a single domain namespace.
The certificate was issued by WoTrus RSA DV SSL CA 2, a certificate authority chain operated by WoTrus CA Limited, a Chinese certificate authority widely used within domestic cloud infrastructure and enterprise platforms. The certificate’s validity window begins on 12 March 2026 and extends through 12 April 2027, reflecting a relatively long operational lifespan typical of domain-validated certificates used in application backends. Cryptographically, the certificate employs an RSA 2048-bit public key, a widely adopted key size for TLS server authentication that provides an established balance between security strength and compatibility across client platforms.
The certificate is uniquely identified by the serial number 98dfeafdc4c32371f0ab490c8a3c7819, which serves as the certificate authority’s internal identifier for the issued credential. Its cryptographic fingerprint, calculated using the SHA-256 hashing algorithm, is 5a0a0df9695395223a1d342d2ccf82f449b342a281ed056dfa7880965bcbe3ca. This fingerprint provides a reliable mechanism for identifying the certificate across transparency logs, passive TLS telemetry, and network monitoring systems.
Functionally, the certificate is a domain-validated TLS certificate intended solely for server authentication. It does not contain certificate authority privileges and cannot be used to sign subordinate certificates or create additional trust anchors. Instead, its purpose is to enable servers operating under the myclaw[.]360[.]cn namespace to prove domain ownership during TLS handshakes, allowing clients to establish encrypted connections that they believe originate from legitimate Security Claw infrastructure.
The provided certificate is an X.509 server certificate with the following key attributes:
Common Name: *.myclaw.360.cn Subject Alternative Names: *.myclaw.360.cn myclaw.360.cn Issuer: WoTrus RSA DV SSL CA 2 Organization: WoTrus CA Limited Validity Period: Not Before: 2026-03-12 Not After : 2027-04-12 Public Key Algorithm: RSA 2048-bit Certificate Serial Number: 98dfeafdc4c32371f0ab490c8a3c7819 The certificate’s SHA-256 fingerprint is: 5a0a0df9695395223a1d342d2ccf82f449b342a281ed056dfa7880965bcbe3ca
Private Key Validation
Cryptographic analysis confirms that the private key provided in the dataset corresponds directly to the public key embedded within the associated TLS certificate. This relationship was verified by extracting and comparing the RSA modulus from both the certificate and the private key. The modulus values match exactly, demonstrating that the two artifacts form a valid cryptographic key pair.
This verification establishes that the exposed private key is the genuine operational key associated with the certificate rather than unrelated or fabricated data. In other words, the key is capable of performing the cryptographic operations required to authenticate servers presenting the certificate during Transport Layer Security (TLS) negotiations.
Within TLS architecture, the private key represents the confidential element of the certificate pair and functions as the mechanism by which a server proves its identity to connecting clients. During the TLS handshake process, the server must demonstrate possession of this secret key in order to validate that it legitimately controls the certificate presented to the client. If the server successfully performs this proof, the client accepts the certificate as authentic and proceeds to establish an encrypted communication channel.
Consequently, possession of the private key enables any system holding it to complete TLS handshakes that appear fully legitimate to clients relying on standard certificate validation. This capability effectively allows the holder of the key to impersonate servers operating under the certificate’s domain namespace and establish encrypted connections that clients would normally interpret as trusted communications with the genuine service.
Infrastructure Attribution
To assess ownership and operational control of the namespace, passive DNS intelligence and domain-registration data indicate that the namespace is part of the broader Qihoo 360 domain ecosystem. This determination provides strong evidence that the infrastructure supporting the Security Claw platform is operated directly within the company’s network environment.
The parent domain 360[.]cn is registered to 北京奇虎科技有限公司 (Beijing Qihoo Technology Co., Ltd.), a major Chinese cybersecurity and internet-technology firm. Domain registration records show that the domain was originally created on 17 March 2003 and is maintained through the registrar Xiamen eName Technology Co., Ltd. These details align with long-standing records identifying Qihoo 360 as the primary operator of the 360[.]cn domain space and its associated services.
The use of dedicated DNS and mail infrastructure under corporate-controlled domains strongly suggests that Qihoo 360 manages its core network services internally rather than outsourcing these functions to third-party providers. This pattern is typical of large security vendors that maintain tight operational control over their infrastructure for security, reliability, and compliance reasons.
Additional enrichment data indicates that the 360.cn domain environment routinely deploys wildcard TLS certificates issued by WoTrus, the same certificate authority responsible for the *.myclaw.360.cn certificate examined in this investigation. The reuse of this certificate authority and wildcard certificate deployment pattern across the broader Qihoo domain ecosystem reinforces the conclusion that the MyClaw certificate originates from the company’s established PKI practices rather than from an unrelated or externally managed infrastructure.
Taken together, the domain registration data, passive DNS records, and PKI deployment patterns provide strong attribution linking the myclaw.360.cn namespace to Qihoo 360’s operational infrastructure, supporting the assessment that the exposed TLS credentials were associated with a service environment under the company’s direct control.
Threat Analysis
The exposure of a Transport Layer Security (TLS) private key associated with a wildcard certificate introduces several potential attack scenarios that could compromise both the integrity and confidentiality of communications within the affected service environment. Because TLS certificates serve as the cryptographic mechanism through which clients authenticate remote servers and establish encrypted channels, possession of the corresponding private key effectively allows an attacker to masquerade as legitimate infrastructure. In this case, the affected certificate covers the wildcard namespace *.myclaw[.]360[.]cn, meaning that any service operating under that domain could theoretically be impersonated if the certificate remained trusted and unrevoked.
One of the most direct risks presented by such an exposure is server impersonation. An attacker in possession of the private key could deploy a malicious server configured to present the same certificate during TLS negotiation. Because the certificate chains to a publicly trusted certificate authority and matches the expected domain namespace, client applications connecting to the attacker’s infrastructure would likely complete the TLS handshake successfully and treat the connection as legitimate. The wildcard nature of the certificate significantly amplifies this risk, as it would allow the attacker to impersonate any host within the myclaw[.]360[.]cn namespace rather than a single specific service endpoint.
A related and potentially more damaging scenario involves man-in-the-middle (MITM) interception. If an attacker were able to manipulate DNS responses, compromise a local network, or otherwise redirect client traffic, they could route requests intended for legitimate MyClaw infrastructure to servers under their control. Because the attacker possesses the correct private key, the TLS handshake would succeed and encrypted sessions would be established without triggering certificate warnings. Under such circumstances, the attacker could decrypt and inspect traffic passing through the connection. Data potentially exposed through such interception could include authentication credentials, session cookies, API tokens used by the application, and the contents of AI prompts or conversation logs exchanged between the client and backend inference services.
Another risk concerns malicious update distribution. Many modern software platforms retrieve updates, configuration files, or model components from backend servers under their operational domain namespace. If the Security Claw client retrieves such resources from endpoints within myclaw[.]360[.]cn, an attacker capable of impersonating those endpoints could deliver modified update packages or configuration files. In the worst case, this could allow the distribution of malicious binaries to client systems, effectively transforming the incident into a supply-chain compromise affecting all users receiving the spoofed updates.
Finally, the exposure creates the possibility of AI response manipulation within the Security Claw platform itself. Because the platform functions as an AI assistant that communicates with backend inference services, impersonating those services could allow attackers to alter responses returned by the AI system. This could enable injection of malicious prompts, manipulation of analysis results, or the insertion of misleading security guidance into automated workflows. In environments where the AI system assists with security analysis or operational decision-making, such manipulation could have cascading effects on downstream processes.
Taken together, these scenarios illustrate how the compromise of TLS trust material, particularly a wildcard certificate, can extend beyond simple traffic interception and potentially affect software distribution mechanisms, AI service integrity, and user trust in the platform’s infrastructure.
The exposure of a private key associated with the wildcard TLS certificate for *.myclaw[.]360[.]cn introduces not only traditional network security risks such as impersonation and interception, but also a set of potential AI-enabled attack vectors that could exploit the architecture of the Security Claw platform itself. Because the platform appears to function as a locally installed AI assistant communicating with cloud-hosted inference services, control over the cryptographic trust boundary between client and backend services could enable adversaries to manipulate the AI system’s behavior in ways that extend beyond conventional software compromise. The integration of AI inference services into the operational workflow effectively creates a new attack surface in which model outputs, prompts, and analytic results become potential targets for adversarial manipulation.
One plausible attack scenario would involve AI response manipulation at the inference layer. If an attacker were able to impersonate backend inference services using the compromised certificate, they could intercept requests from the Security Claw client and return modified outputs generated by a malicious or modified AI model. In practice, this could allow the adversary to alter the results of automated security analyses performed by the platform. For example, malware samples submitted for analysis could be falsely classified as benign, while legitimate system components could be flagged as malicious. Such manipulations could degrade the reliability of the platform’s analytic output and undermine trust in automated security recommendations generated by the system.
Logic Diagram for Potential Attacks From Mistake
Another potential attack vector involves prompt-injection attacks targeting the AI interaction pipeline. Modern AI assistant architectures often rely on structured prompts sent from the client to backend models, where contextual instructions and system policies guide the model’s behavior. An adversary positioned within the communication channel could modify these prompts before they reach the inference service or inject additional instructions into the prompt stream. By manipulating these inputs, attackers could influence the behavior of the AI model, potentially causing it to disclose sensitive data, generate misleading analyses, or execute unintended actions within automated workflows. This type of attack is conceptually similar to adversarial prompt injection techniques observed in other large-language-model deployments.
A related scenario involves model poisoning or model-substitution attacks. If the Security Claw platform retrieves model components, configuration files, or inference instructions from backend servers under the myclaw[.]360[.]cn namespace, an adversary capable of impersonating those endpoints could distribute modified model weights or configuration artifacts to client systems. Such modifications could subtly alter the behavior of the AI system over time. For instance, the modified model might consistently downgrade the severity of certain classes of threats, ignore specific indicators of compromise, or generate outputs designed to mislead analysts reviewing the results. Because AI models often behave probabilistically rather than deterministically, detecting such manipulation could be significantly more difficult than identifying conventional malware.
The compromise could also enable data exfiltration through the AI interaction channel. Security Claw appears to operate as an assistant capable of processing user prompts, system telemetry, and potentially sensitive security data. If adversaries intercepted or controlled the backend inference endpoint, they could capture large volumes of input data sent from client systems. This data could include malware samples, internal network information, security logs, configuration data, or investigative notes submitted by analysts interacting with the AI assistant. Over time, such data collection could yield valuable intelligence about organizational networks, defensive tools, and investigative workflows.
Another possible attack vector would involve AI-driven social engineering and influence operations directed at analysts using the platform. If attackers controlled the AI responses returned to users, they could craft outputs designed to subtly influence human decision-making. For example, the AI might recommend specific remediation steps that inadvertently weaken security controls, suggest the dismissal of legitimate alerts, or provide misleading threat-intelligence summaries. Because users may perceive AI-generated recommendations as authoritative, particularly when the platform is marketed as a cybersecurity assistant, such manipulation could have cascading operational consequences within security operations centers or incident-response teams.
The exposure could further facilitate autonomous reconnaissance and exploitation capabilities embedded within the AI service architecture. If the adversary were able to modify backend AI services rather than merely impersonate them, they could theoretically integrate automated reconnaissance capabilities into the system itself. In this scenario, the AI service might analyze telemetry collected from client systems and automatically identify exploitable vulnerabilities or network configurations. Rather than simply returning analytic results to the user, the compromised system could covertly transmit reconnaissance data to attacker infrastructure or generate tailored exploit payloads targeting discovered weaknesses.
Finally, there is the possibility of supply-chain amplification through AI-driven automation. Security Claw’s architecture suggests that it may be integrated with broader Qihoo security services, potentially including threat-intelligence feeds, malware analysis pipelines, or automated defensive tooling. If attackers were able to manipulate the AI system at the backend level, they could leverage this integration to propagate malicious outputs across multiple connected services. For example, manipulated threat classifications could influence automated detection signatures distributed to endpoint security products, potentially degrading detection capability across a large installed base of users.
Taken together, these scenarios illustrate how the compromise of cryptographic trust material in an AI-enabled platform could enable attack techniques that extend beyond traditional network security threats. In conventional systems, the theft of a TLS private key primarily enables impersonation or interception attacks. In AI-integrated architectures, however, control over the communication channel between client and inference service also enables adversaries to manipulate the informational outputs of the system itself. Because users increasingly rely on AI-generated analysis to support operational decisions, such manipulation could have downstream effects that propagate through automated workflows, investigative processes, and defensive strategies.
Root Cause Assessment
The most plausible explanation for the exposure of the TLS private key is a failure within the software build and packaging pipeline used to produce the Security Claw client installer. Evidence associated with the incident indicates that the certificate and its corresponding private key were present within files bundled in the application’s installation package, suggesting that sensitive credential material was inadvertently included during the software build process.
In contemporary software development environments, application installers are frequently generated automatically through continuous integration and continuous delivery (CI/CD) pipelines. These pipelines often assemble installation packages directly from development repositories or build directories that may contain configuration files, test certificates, and other credentials used during internal development and debugging. If the build pipeline does not explicitly exclude such files through filtering rules or packaging controls, sensitive artifacts can unintentionally become part of the final distribution bundle.
This type of exposure is consistent with a broader class of supply-chain vulnerabilities in which development credentials are mistakenly distributed alongside production software. Similar incidents have been documented across the software industry, including cases where application installers or container images contained embedded API keys, code-signing certificates, or cloud service credentials. In each case, the root cause typically involved insufficient separation between development assets and production build artifacts, allowing confidential materials to propagate into publicly accessible software packages.
Analytical Assessment
The exposure of a private key associated with a wildcard TLS certificate constitutes a serious failure in the protection of cryptographic trust material. Within modern internet security architecture, TLS certificates serve as the foundation of authenticated encrypted communication between clients and servers. The corresponding private key is the critical secret that enables a server to prove its identity during the TLS handshake process. When this key is exposed outside of controlled infrastructure, the integrity of the entire trust relationship established by the certificate is compromised. In this case, the risk is amplified by the fact that the certificate is a wildcard credential for the domain namespace *.myclaw[.]360[.]cn, meaning that the key could theoretically authenticate any service operating under that domain hierarchy. As a result, possession of the private key could allow an attacker to impersonate multiple services across the platform rather than a single isolated endpoint.
Although the ultimate operational consequences depend on several factors including whether the certificate was actively deployed in production infrastructure and how quickly the credential was revoked or replaced, the discovery of the key in a publicly accessible software artifact strongly suggests that sensitive trust material was mishandled during the platform’s build or distribution process. Software installers and packaged binaries should never contain cryptographic secrets intended for server-side authentication. Their presence in distributed software indicates that development or deployment environments likely included credential files that were not properly excluded during packaging. Such mistakes are typically symptomatic of weaknesses in build pipeline controls, including insufficient separation between development assets and production artifacts, inadequate secret-scanning procedures, or a lack of automated checks designed to prevent sensitive files from being included in release builds.
The incident is particularly notable because it involves Qihoo 360, a company whose core business is cybersecurity. As a major provider of antivirus software, enterprise security tools, and threat-intelligence services, Qihoo 360 operates infrastructure that supports hundreds of millions of users. Organizations of this scale are expected to maintain mature security engineering practices, including strict credential management policies, secure build pipelines, and rigorous release validation procedures. The appearance of operational cryptographic material in distributed software raises questions about the robustness of those internal controls.
Even if the certificate was never deployed in production systems or if the exposure window was short due to rapid incident response and key rotation, the leak nonetheless highlights systemic risks associated with credential management within modern software development environments. Large-scale platforms frequently rely on numerous certificates, API keys, and other authentication secrets to operate complex distributed architectures. Without strong safeguards, these secrets can inadvertently propagate through development repositories, build directories, or installer packaging processes.
In this context, the exposure should be understood not only as a discrete technical vulnerability but also as an indicator of broader process weaknesses. Effective security engineering requires strict segregation of sensitive credentials, automated detection mechanisms for secrets in build artifacts, and clear procedures for revocation and rotation when exposure occurs. The presence of a valid TLS private key in publicly distributed software suggests that at least some of these controls were insufficiently implemented or failed during the platform’s release cycle. As AI-enabled platforms like Security Claw become more deeply integrated into security workflows and enterprise environments, ensuring the integrity of the cryptographic infrastructure underpinning these systems becomes increasingly critical.
Conclusion
Cryptographic validation confirms that the exposed material is a legitimate and operational TLS key pair for *.myclaw[.]360[.]cn. The RSA modulus in the certificate and private key match exactly, proving authenticity. The certificate chains to WoTrus RSA DV SSL CA 2, a publicly trusted authority, meaning any server using this key would be accepted as legitimate by clients.
The certificate’s structure aligns with Qihoo 360’s broader PKI practices, which rely on WoTrus-issued, domain-validated wildcard certificates to secure microservice-based architectures. As such, compromise of the private key represents a direct breach of the platform’s cryptographic trust boundary.
If deployed in production, the impact is substantial. An attacker with the key could impersonate any host within the myclaw.360.cn namespace, enabling seamless TLS-authenticated connections that appear legitimate. This extends beyond single-host compromise to full namespace-level impersonation. Under traffic redirection conditions (e.g., DNS or network manipulation), the same capability enables decryption and inspection of encrypted sessions, exposing credentials, tokens, and AI interaction data.
The risk also extends into platform integrity. Impersonated endpoints could deliver malicious updates or configuration data, while spoofed inference services could manipulate AI outputs or inject instructions into the interaction pipeline.
Impact ultimately hinges on deployment status and response timing. Evidence indicates the certificate was rapidly rotated, suggesting effective incident response and a potentially limited exposure window. However, if the key was obtained prior to rotation, exploitation during that interval remains plausible.
Further analysis should focus on certificate transparency logs, passive DNS telemetry, and any vendor disclosures to establish timeline, exposure scope, and whether the compromised certificate was ever actively used.