For once, I am *not* starting this newsletter by talking about the weather. The weather in Seattle that is, instead let’s talk about what passes for “ weather” in Las Vegas! Astute readers may notice that this edition of my newsletter is coming out a week later than usual. Vegas is the reason for that, more specifically, my team and I spent the first week of August at Hacker Summer Camp, where it stayed in the triple-digits for nearly 10 days straight, topping out at 115 F (46 C for my international readers!). Meanwhile, in Seattle, the AQI pm2.5 value was closing in on 200, which combined with 84 F (29 C) heat made for unpleasant days.
While the heat in Vegas was unpleasant to say the least, our team kept busy staying in the air conditioned spaces of BSides LV, BlackHat, DefCon, and various other hacker gatherings. After a week of talking to our colleagues in the field, and hearing about the work they’ve been doing, we are back in Seattle where the temperature stays safely below the triple digits.
The whole of July was more than packing for Summer Camp though,and my team kept up the pace publishing research on the Iranian hacktivist ecosystem and scarcity scams. I also had the chance to contribute an Expert Insight to our friends at Cyber Security News based on our research into the threat actors that make up Iran’s Hacktivist Ecosystem. To end the month, we published the findings of a year-long investigation into the ZedXion Cryptocurrency Exchange and the network of affiliated entities used by the IRGC to evade sanctions. Now, let’s dive in and get you up to speed.
Hot Off the Presses
Threat Intelligence Report: The Pro-Iran Hacktivist Ecosystem 2026
To kick off July, the DTI team broke down the threat actor ecosystem supporting Iranian interests in 2026. The current pro-Iran“Axis of Resistance” is decentralized, blending hacktivist groups, ideological cyber militias, influence operators, and jihadist cyber propagandists, functioning as a loose knit cyber mobilization network. DTI researchers analyzed the individual actors in the ecosystem, assessing their capabilities and tradecraft as part of the larger collective. The groups’ behavior shows how modern cyber conflict is moving beyond traditional espionage toward more influence operations. Much of their activity is built for wartime influence by leveraging public visibility for asymmetric pressure against perceived enemies.
Our research found that most of the actors rely on basic tradecraft, including DDoS attacks, defacements, credential reuse, recycled breach data, public claims, and propaganda amplification to effect. These methods are often low-end but still create real impact when many groups act at once during geopolitical escalation. The main defensive challenge is not only intrusion prevention, but also managing disruption, reputational risk, and alert fatigue across public-facing systems.

Scarcity Scams
When government backlogs create scarcity, scammers step in. DTI analysts exposed the mechanics of these "scarcity scams", from replica portals to weaponized session-recording tools, in July’s security snack. We uncovered a years-long campaign targeting Mexican citizens with a scam themed as a fast track service for government documents they branded as “Mexican Cita Express” or “Cita Express SRE México”. This scam alleges there is a fast track service to process government documents. Based on this investigation, our team expanded the investigation to hunt for similar scams based on shared conditions and methods.

Intelligence Report: The Zedxion Corporate Nexus for Illicit Iranian Financial Funds Transfer for IRGC Entities
In July 2025, DomainTools Investigations began investigating the Zedxion Cryptocurrency Exchange after an external partner came to us with the question “Does anything look strange about this domain?” Our researchers continued the investigation into the Zedxion Exchange in partnership with TRM Labs who first published their own research on the Exchange in January 2026. Signals point to Zedxion, and the BZ Group, as part of a larger constellation of entities tied to the IRGC moving towards establishing regional banking app(s) spanning the United Kingdom and the United Arab Emirates in order to more effectively obscure their transactions and mitigate disruption or takedown. When examined holistically, the constellation does not resemble a conventional cryptocurrency enterprise. Instead, it presents as a layered financial architecture in which legal entities, branding assets, governance actors, and digital infrastructure perform distinct and compartmentalized functions.
At the corporate level, the UK serves as a recurring incorporation platform. Companies are formed with high nominal capitalization, frequently £1,000,000, yet file dormant or non-trading accounts and exhibit no verifiable operating revenue. These entities are restructured, mirrored, or dissolved as exposure increases. ZEDXION EXCHANGE LTD and ZEDCEX EXCHANGE LTD reflect this pattern: structurally similar exchange vehicles, one absorbing litigation and regulatory pressure while the other preserves brand continuity and operational optionality. The dissolution of BZ BROKER LIMITED and the short lifecycle of BZ DIAMOND LTD reinforce the conclusion that UK entities function primarily as disposable regulatory interfaces rather than durable operating companies.

Where We’ll Be
- Boston Security Meetup, Boston, MA, 20 August
Final Thoughts
As always, thank you to my returning readers! If you’re new, I hope you found this newsletter informational, helpful, and worthy of sharing with your peers. And of course I hope you will be coming back to read future editions!
We share this newsletter via email as well - if you’d prefer to get it to your inbox, sign up here.
If you missed last month's content, here are some quick links:
- SecuritySnack - Hijacking Corporate Sessions
- Threat Intelligence Report: Russia, Router, DNS, and Messaging-Layer Collection Operations
- Threat Intelligence Report: Nation-State Targeting of Water Systems 2024–2026
Thanks for reading & see you next month!
-Daniel
https://www.linkedin.com/in/schwalbe/
https://infosec.exchange/@danonsecurity









