Hey Nineteen (Newsletters)

Published on: 
August 14, 2026

For once, I am *not* starting this newsletter by talking about the weather. The weather in Seattle that is, instead let’s talk about what passes for “ weather” in Las Vegas! Astute readers may notice that this edition of my newsletter is coming out a week later than usual. Vegas is the reason for that, more specifically, my team and I spent the first week of August at Hacker Summer Camp, where it stayed in the triple-digits for nearly 10 days straight, topping out at 115 F (46 C for my international readers!). Meanwhile, in Seattle, the AQI pm2.5 value was closing in on 200, which combined with 84 F (29 C) heat made for unpleasant days.

While the heat in Vegas was unpleasant to say the least, our team kept busy staying in the air conditioned spaces of BSides LV, BlackHat, DefCon, and various other hacker gatherings.  After a week of talking to our colleagues in the field, and hearing about the work they’ve been doing, we are back in Seattle where the temperature stays safely below the triple digits.

The whole of July was more than packing for Summer Camp though,and  my team kept up the pace publishing research on the Iranian hacktivist ecosystem and scarcity scams. I also had the chance to contribute an Expert Insight to our friends at Cyber Security News based on our research into the threat actors that make up Iran’s Hacktivist Ecosystem. To end the month, we published the findings of a year-long investigation into the ZedXion Cryptocurrency Exchange and the network of affiliated entities used by the IRGC to evade sanctions. Now, let’s dive in and get you up to speed.

 

Hot Off the Presses 

Threat Intelligence Report: The Pro-Iran Hacktivist Ecosystem 2026

To kick off July, the DTI team broke down the threat actor ecosystem supporting Iranian interests in 2026. The current pro-Iran“Axis of Resistance” is decentralized, blending hacktivist groups, ideological cyber militias, influence operators, and jihadist cyber propagandists, functioning as a loose knit cyber mobilization network. DTI researchers analyzed the individual actors in the ecosystem, assessing their capabilities and tradecraft as part of the larger collective. The groups’ behavior shows how modern cyber conflict is moving beyond traditional espionage toward more influence operations. Much of their activity is built for wartime influence by leveraging public visibility for asymmetric pressure against perceived enemies.

Our research found that most of the actors rely on basic tradecraft, including DDoS attacks, defacements, credential reuse, recycled breach data, public claims, and propaganda amplification to effect. These methods are often low-end but still create real impact when many groups act at once during geopolitical escalation. The main defensive challenge is not only intrusion prevention, but also managing disruption, reputational risk, and alert fatigue across public-facing systems.

Read the breakdown here

Scarcity Scams

When government backlogs create scarcity, scammers step in. DTI analysts exposed the mechanics of these "scarcity scams", from replica portals to weaponized session-recording tools, in July’s security snack. We uncovered a years-long campaign targeting Mexican citizens with a scam themed as a fast track service for government documents they branded as “Mexican Cita Express” or “Cita Express SRE México”. This scam alleges there is a fast track service to process government documents. Based on this investigation, our team expanded the investigation to hunt for similar scams based on shared conditions and methods. 

Read the snack here

Intelligence Report: The Zedxion Corporate Nexus for Illicit Iranian Financial Funds Transfer for IRGC Entities

In July 2025, DomainTools Investigations began investigating the Zedxion Cryptocurrency Exchange after an external partner came to us with the question “Does anything look strange about this domain?” Our researchers continued the investigation into the Zedxion Exchange in partnership with TRM Labs who first published their own research on the Exchange in January 2026. Signals point to Zedxion, and the BZ Group, as part of a larger constellation of entities tied to the IRGC moving towards establishing regional banking app(s) spanning the United Kingdom and the United Arab Emirates in order to more effectively obscure their transactions and mitigate disruption or takedown. When examined holistically, the constellation does not resemble a conventional cryptocurrency enterprise. Instead, it presents as a layered financial architecture in which legal entities, branding assets, governance actors, and digital infrastructure perform distinct and compartmentalized functions.

At the corporate level, the UK serves as a recurring incorporation platform. Companies are formed with high nominal capitalization, frequently £1,000,000, yet file dormant or non-trading accounts and exhibit no verifiable operating revenue. These entities are restructured, mirrored, or dissolved as exposure increases. ZEDXION EXCHANGE LTD and ZEDCEX EXCHANGE LTD reflect this pattern: structurally similar exchange vehicles, one absorbing litigation and regulatory pressure while the other preserves brand continuity and operational optionality. The dissolution of BZ BROKER LIMITED and the short lifecycle of BZ DIAMOND LTD reinforce the conclusion that UK entities function primarily as disposable regulatory interfaces rather than durable operating companies.

Read the investigation here 

Where We’ll Be

  • ‍Boston Security Meetup, Boston, MA, 20 August

Final Thoughts

As always, thank you to my returning readers! If you’re new, I hope you found this newsletter informational, helpful, and worthy of sharing with your peers. And of course I hope you will be coming back to read future editions!

We share this newsletter via email as well - if you’d prefer to get it to your inbox, sign up here.

If you missed last month's content, here are some quick links:

Thanks for reading & see you next month!

-Daniel

https://www.linkedin.com/in/schwalbe/

https://infosec.exchange/@danonsecurity

Related Content

Newsletters
Hey Nineteen (Newsletters)

Heatwaves in Vegas, high AQI in Seattle, and fresh threat research. Inside this edition: Iran’s growing hacktivist network, Mexican document scarcity scams, and the layered crypto architecture powering IRGC financial transfers.

For once, I am *not* starting this newsletter by talking about the weather. The weather in Seattle that is, instead let’s talk about what passes for “ weather” in Las Vegas! Astute readers may notice that this edition of my newsletter is coming out a week later than usual. Vegas is the reason for that, more specifically, my team and I spent the first week of August at Hacker Summer Camp, where it stayed in the triple-digits for nearly 10 days straight, topping out at 115 F (46 C for my international readers!). Meanwhile, in Seattle, the AQI pm2.5 value was closing in on 200, which combined with 84 F (29 C) heat made for unpleasant days.

While the heat in Vegas was unpleasant to say the least, our team kept busy staying in the air conditioned spaces of BSides LV, BlackHat, DefCon, and various other hacker gatherings.  After a week of talking to our colleagues in the field, and hearing about the work they’ve been doing, we are back in Seattle where the temperature stays safely below the triple digits.

The whole of July was more than packing for Summer Camp though,and  my team kept up the pace publishing research on the Iranian hacktivist ecosystem and scarcity scams. I also had the chance to contribute an Expert Insight to our friends at Cyber Security News based on our research into the threat actors that make up Iran’s Hacktivist Ecosystem. To end the month, we published the findings of a year-long investigation into the ZedXion Cryptocurrency Exchange and the network of affiliated entities used by the IRGC to evade sanctions. Now, let’s dive in and get you up to speed.

 

Hot Off the Presses 

Threat Intelligence Report: The Pro-Iran Hacktivist Ecosystem 2026

To kick off July, the DTI team broke down the threat actor ecosystem supporting Iranian interests in 2026. The current pro-Iran“Axis of Resistance” is decentralized, blending hacktivist groups, ideological cyber militias, influence operators, and jihadist cyber propagandists, functioning as a loose knit cyber mobilization network. DTI researchers analyzed the individual actors in the ecosystem, assessing their capabilities and tradecraft as part of the larger collective. The groups’ behavior shows how modern cyber conflict is moving beyond traditional espionage toward more influence operations. Much of their activity is built for wartime influence by leveraging public visibility for asymmetric pressure against perceived enemies.

Our research found that most of the actors rely on basic tradecraft, including DDoS attacks, defacements, credential reuse, recycled breach data, public claims, and propaganda amplification to effect. These methods are often low-end but still create real impact when many groups act at once during geopolitical escalation. The main defensive challenge is not only intrusion prevention, but also managing disruption, reputational risk, and alert fatigue across public-facing systems.

Read the breakdown here

Scarcity Scams

When government backlogs create scarcity, scammers step in. DTI analysts exposed the mechanics of these "scarcity scams", from replica portals to weaponized session-recording tools, in July’s security snack. We uncovered a years-long campaign targeting Mexican citizens with a scam themed as a fast track service for government documents they branded as “Mexican Cita Express” or “Cita Express SRE México”. This scam alleges there is a fast track service to process government documents. Based on this investigation, our team expanded the investigation to hunt for similar scams based on shared conditions and methods. 

Read the snack here

Intelligence Report: The Zedxion Corporate Nexus for Illicit Iranian Financial Funds Transfer for IRGC Entities

In July 2025, DomainTools Investigations began investigating the Zedxion Cryptocurrency Exchange after an external partner came to us with the question “Does anything look strange about this domain?” Our researchers continued the investigation into the Zedxion Exchange in partnership with TRM Labs who first published their own research on the Exchange in January 2026. Signals point to Zedxion, and the BZ Group, as part of a larger constellation of entities tied to the IRGC moving towards establishing regional banking app(s) spanning the United Kingdom and the United Arab Emirates in order to more effectively obscure their transactions and mitigate disruption or takedown. When examined holistically, the constellation does not resemble a conventional cryptocurrency enterprise. Instead, it presents as a layered financial architecture in which legal entities, branding assets, governance actors, and digital infrastructure perform distinct and compartmentalized functions.

At the corporate level, the UK serves as a recurring incorporation platform. Companies are formed with high nominal capitalization, frequently £1,000,000, yet file dormant or non-trading accounts and exhibit no verifiable operating revenue. These entities are restructured, mirrored, or dissolved as exposure increases. ZEDXION EXCHANGE LTD and ZEDCEX EXCHANGE LTD reflect this pattern: structurally similar exchange vehicles, one absorbing litigation and regulatory pressure while the other preserves brand continuity and operational optionality. The dissolution of BZ BROKER LIMITED and the short lifecycle of BZ DIAMOND LTD reinforce the conclusion that UK entities function primarily as disposable regulatory interfaces rather than durable operating companies.

Read the investigation here 

Where We’ll Be

  • ‍Boston Security Meetup, Boston, MA, 20 August

Final Thoughts

As always, thank you to my returning readers! If you’re new, I hope you found this newsletter informational, helpful, and worthy of sharing with your peers. And of course I hope you will be coming back to read future editions!

We share this newsletter via email as well - if you’d prefer to get it to your inbox, sign up here.

If you missed last month's content, here are some quick links:

Thanks for reading & see you next month!

-Daniel

https://www.linkedin.com/in/schwalbe/

https://infosec.exchange/@danonsecurity

Learn More
Newsletters
Eighteen Newsletters and a Dozen Roses

June’s roundup of research - from cyberattacks on water infrastructure OT and ICS to DNS hijacking and an AiTM campaign targeting Microsoft365 users. 

June was unusually warm here in Seattle, which for a region that claims “June-uary” as a Season, is noteworthy. We made the best of it by watching Team USA defeat the Socceroos in a 2-0 victory at our beloved “Seattle Stadium” - Did you hear we have been ranked the #1 World Cup stadium this time around?. Of course it all came to an end yesterday, when the Belgian “Red Devils” (who have claimed that name for longer than Manchester United) gave the Team USA a soccer lesson they won’t soon forget. That 4-1 defeat stung, especially since it was the last game Seattle hosted this time around. Well, there are always the Mariners.

Despite heat and soccer, we still spent the month investigating emerging threats, talking about our already emerged research, and preparing for Hacker Summer Camp. We started with an investigation into an attacker-in-the-middle credential-harvesting kit targeting Microsoft365 and EntraID identities. Next our team analyzed Russian-linked cyber operations targeting SOHO routers for DNS-hijacking and adversary-in-the-middle intelligence collection, as well as communications-layer collection from messaging platforms like Signal and WhatsApp. 

The team and I also attended SLEUTHCON in Arlington, VA; if you didn’t get a chance to say hi and grab a T-shirt, we will be in Las Vegas for Hacker Summer Camp next month with lots of swag. Ending the month, we published research on the targeting of water systems by Russian, Iranian, and PRC-aligned threat actors. As an added bonus, our friends at Dark Reading picked up the story and published their own article based on our research - I highly recommend giving it a read. I also had the pleasure of joining CyberWire’s Dave Bittner for an episode of his Research Saturday podcast talking about last month’s related research on the ZionSiphon OT malware sample. Now, let’s dive in and get you up to speed.  

Hot Off the Presses 

SecuritySnack - Hijacking Corporate Sessions

DTI researchers kicked off June with an investigation into a fully operational Adversary-in-the-Middle (AiTM) credential-harvesting kit targeting Microsoft 365 and Entra ID identities. The kit runs through a three-to-five stage funnel starting from financial, recruiting, and document related domain name themes. The funnels typically begin with an anti-analysis CAPTCHA gate to filter sandboxes, followed by a corporate email harvest stage that builds trust by dynamically rendering the victim's employer logo and filtering out personal email addresses. The final stage is a pixel-perfect, AiTM reverse proxy of the Microsoft sign-in page, which brokers the live authentication flow and successfully intercepts every credential, Multi-Factor Authentication (MFA) code (including Push, TOTP, and SMS), and post-authentication session cookie.

Read the snack here

Threat Intelligence Report: Russia, Router, DNS, and Messaging-Layer Collection Operations

The DTI team pivoted to an analysis of Russian-linked cyber operations targeting SOHO routers for DNS-hijacking and adversary-in-the-middle intelligence collection, as well as communications-layer collection from messaging platforms like Signal and WhatsApp. By targeting routers and bending DNS, Russian operators are able to watch traffic, steer chosen victims, and steal credentials without putting malware on the machine. Meanwhile, their work against Signal, WhatsApp, Telegram, and Microsoft 365 gives them access to messages, contacts, trusted names, and private conversations. 

Russia is increasingly treating edge infrastructure and messaging platforms as persistent intelligence-collection terrain. Router compromise provides GRU-linked operators with a passive upstream vantage point over victim traffic, while messaging-account compromise provides visibility into human networks, operational discussions, authentication workflows, and trusted social relationships. Together, these operations support long-duration intelligence collection, access persistence, credential interception, social-graph mapping, and pre-positioning for future contingency operations.

Read our full analysis here

Threat Intelligence Report: Nation-State Targeting of Water Systems 2024–2026

To wrap up the month, our researchers took a deep dive into the targeting of water systems by Russian, Iranian, and PRC-aligned threat actors. Recent activity targeting water systems includes Iranian IRGC-linked targeting of exposed programmable logic controllers (PLCs), Russian and pro-Russian access to municipal water-control environments, and PRC-linked pre-positioning in U.S. critical infrastructure, including water and wastewater systems. U.S. federal agencies, including CISA, FBI, NSA, and EPA, have warned that many utilities remain exposed through internet-facing human-machine interfaces (HMIs) and PLCs, weak credentials, shared accounts, legacy devices, limited monitoring, and poor IT/OT segmentation. 

While each nation uses a slightly different model for these operations, they all are used as shaping tools rather than destructive actions. Russia tends to pair infrastructure access with pressure and destabilization. Iran often blends symbolic retaliation, psychological signaling, and opportunistic disruption. In contrast, China places more emphasis on long-term pre-positioning and strategic persistence.

Read the breakdown here 

Where We’ll Be

  • ‍Hacker Summer Camp, Las Vegas, NV, 01-09 August

Final Thoughts

As always, thank you to my returning readers! If you’re new, I hope you found this newsletter informational, helpful, and worthy of sharing with your peers. And of course I hope you will be coming back to read future editions!

We share this newsletter via email as well - if you’d prefer to get it to your inbox, sign up here.

If you missed last month's content, here are some quick links:

Thanks for reading & see you next month!

-Daniel

https://www.linkedin.com/in/schwalbe/

https://infosec.exchange/@danonsecurity

Learn More
Newsletters
Edge of Seventeen (Newsletters)

We haven’t talked about the weather in Seattle for a bit. Just kidding, I ALWAYS talk about the weather here! Did you know that the Seattle Weather is officially one of the most difficult to accurately forecast? This is due (in part) to the so-called “Puget Sound Convergence Zone.” But also the fact that the area goes from sea level to 14,000 feet (4300m) within a 60 mile (97km) radius. And that we’re sandwiched between two mountain ranges and have a large patch of ocean that isn’t really the ocean because it’s a sound 🤷

In any case, today we reached 72 degrees Fahrenheit (22C), tomorrow will be 83 degrees (28C). June-uary better get here fast, I need three more weeks of gray and rain to adequately hydrate before summer starts on July 5th! But maybe the weather decided to “play along” and show the visitors that are coming to town for the FIFA World Cup a good time. Seattle is hosting four matches, including the US National Team 🇺🇸against the Socceroos 🇦🇺! And just like Matt Turner will keep close tabs on Jordan Bos and Nestory Irankunda, the DTI team has been busy keeping track of the latest threats. 

We started May (or technically ended April if we’re being specific) with a look at the DPRK’s “Contagious Interview” campaign that weaponizes legitimate hiring workflows to compromise developer environments. The rest of May was spent taking a deeper dive into the Doppelganger campaigns we covered in March and looking at their operational pipeline and strategic significance. We rounded out the month with a look at the ZionSiphon malware sample, the OT malware designed to target Israeli water facilities with some critical flaws in its programming. 

Let’s dive in and get you up to speed!  

Hot Off the Presses 

Threat Intelligence Report: ZionSiphon OT Malware First Attempts? Psyops? Both?

DTI researchers analyzed the ZionSiphon malware sample (“SCADA_SecurityPatch_v8.4.exe”) that has been circulating in public sandboxes since 2025. The malware is designed to target and sabotage water treatment and desalination facilities in Israel only. In our analysis, our team identified a critical bug in the malware’s geographic validation logic that prevents the malware’s payload from activating in its intended environment. Beyond the flaw in its geographic validation logic, the malware also lacks any external communication stack or command-and-control (C2) channel. 

Based on our analysis, our team determined ZionSiphon operates entirely at the Windows host layer, using registry persistence, PowerShell-based execution, and USB-oriented propagation logic. It is a real, functioning implant in terms of execution mechanics, but the XOR bug prevents it from transitioning into an active sabotage phase, rendering it effectively non-operational as an ICS attack tool. 

Read the full technical breakdown here

Threat Intelligence Report: The SDA / Structura / Doppelgänger, Influence Operations, Infrastructure, Reach, and Potential

After our first investigation into Doppelgänger in March, the DTI team took another deep dive into the Doppelgänger campaigns and their operational model. We broke down the narrative distribution model into four stages: content creation, telegram amplification, X/twitter injection, and narrative propagation. Our research determined the Doppelgänger campaign is engineered for visibility, not direct persuasion. Its architecture–feeder websites, Telegram amplification, and coordinated X/Twitter activity–prioritizes rapid distribution and repeated exposure across platforms to maximize encounter frequency. Using this analysis, our team modeled the first 72 hours of a Doppelgänger campaign during a geopolitical crisis. 

We also placed Doppelgänger in the larger doctrinal context of Russia’s “information confrontation” strategy. The operational structure of the Doppelgänger campaign demonstrates clear continuity with Soviet-era Active Measures, a category of covert influence operations. Historically, Active Measures campaigns relied on a combination of forged publications, front organizations, and intermediary actors to introduce narratives into foreign information environments. The Doppelgänger campaign represents the digital transformation of the same strategy. 

Read our full analysis here

DPRK Contagious Interview: Developer Workflow Compromise

Our team kicked off May with an analysis of the DPRK’s “Contagious Interview” campaign that weaponizes legitimate hiring workflows to induce execution of malicious code within trusted developer environments. The campaign targets software developers and technical personnel through fraudulent job interview processes conducted across platforms such as GitHub, LinkedIn, and direct messaging channels.

Read the breakdown here 

What We’re Reading 

In case you’re behind on your cybersecurity reading homework, DTI team member Ian Campbell’s monthly recommended reading list will get you up to speed! 

‍📚See the full reading list here

Where We’ll Be

  • SLEUTHCON, Arlington, VA - 05 June
  • ‍Hacker Summer Camp, Las Vegas, NV, 01-09 August

Final Thoughts

As always, thank you to my returning readers! If you’re new, I hope you found this newsletter informational, helpful, and worthy of sharing with your peers. And of course I hope you will be coming back to read future editions!

We share this newsletter via email as well - if you’d prefer to get it to your inbox, sign up here.

If you missed last month's content, here are some quick links:

Thanks for reading & see you next month!

-Daniel

https://www.linkedin.com/in/schwalbe/
https://infosec.exchange/@danonsecurity

Learn More