Newsletter 11 Could Take Forever

Published on: 
December 4, 2025

The title of this month’s newsletter is a deep cut taken from the height of my favorite music genre, the admittedly awkwardly titled “Alternative Music.” What can I say, the 1990s in Seattle were wild, man - you had to be there. 

Speaking of being there, last week was the Thanksgiving Holiday here in the United States. Normally my newsletter goes out on the last Tuesday of the month, but considering a lot of security professionals in the US got Thursday and likely Friday off, we decided to push publication by a week, so hopefully more of you can enjoy this edition instead of it getting buried under mashed potatoes and gravy!

The weather here in the Pacific NorthWest has firmly settled into “damp mode” (IYKYK), and the temperatures have started to creep below 40 degrees Fahrenheit (below 4 degrees Celsius for my international friends). I refuse to call it “The Big Dark” however - stop trying to make “The Big Dark” happen, Gretchen! Despite the cold, I’m happy to report that the intensity of DomainTools Investigations’ research output is only heating up. 

Our flagship research for November, “Inside the Great Firewall,” is a three-part series based on a recent dump of documents and technical details of China’s censorship infrastructure. This massive leak provided us with over 500 gigabytes of internal operational data. I had the pleasure of joining Dave Bittner on the Research Saturday podcast from N2K | CyberWire to discuss our team’s work. 

In addition to this deep dive, we also published a threat intelligence report based on leaked internal documents from APT35 (Charming Kitten). This report maps the Iranian state-sponsored actor's organization, tool kit, and campaign strategies. It details their campaigns against Lebanon, Kuwait, Türkiye, Saudi Arabia, Korea, and domestic Iranian targets, with a focus on their use of Microsoft Exchange attack chains. As a former Exchange Admin, I took personal note of that detail and was glad those days were behind me!

Last but not least, my team and I attended CYBERWARCON in Arlington, Virginia a couple of weeks ago. It was great to connect with the community, we had a small sponsorship booth and had many excellent conversations with fellow practitioners. I personally like the timing of this one-day conference, as it’s a nice bookend to its sister conference SLEUTHCON, which we attended earlier this year.

November was packed with research and tasty threat intelligence, so let's dive right in and get you up to speed!

Hot off the Presses

Inside the Great Firewall Part 1: The Dump

In September 2025, a historic breach of China’s censorship infrastructure leaked over 500 gigabytes of internal data detailing the infrastructure, design, and companies involved with the Great Firewall (GFW). DTI researchers analyzed more than 100,000 documents, internal source code, work logs, configuration files, emails, technical manuals, and operational runbooks. 

Part 1 covers the human machinery behind the GFW and the consequences of the leak. This data links specific engineers and administrators to their roles across state-run ISPs (China Telecom, China Unicom, China Mobile), academic research institutions, and Ministry of State Security (MSS)-linked vendors.

🔗Read the report here

Inside the Great Firewall Part 2: Technical Infrastructure

In Part 2, DTI analysts offer a forensic reconstruction of the Great Firewall’s technical infrastructure. From spreadsheets detailing app endpoint behavior, user monitoring intervals, and hardware configurations to blueprint files illustrating node relationships and control flows, the data illustrates a highly centralized yet distributed architecture, built on cooperation between state-run ISPs, telecom vendors, university research labs, and policy-design entities. Using this data, our researchers mapped the operational logic, software structure, and institutional alignment driving the digital surveillance regime.

🔍Read the full technical deep dive here 

Inside the Great Firewall Part 3: Geopolitical and Societal Ramifications

In the final part of the series, our team analyzes the strategic doctrine behind the Great Firewall. This analysis reveals the GFW as a cornerstone of China’s broader governance model, extending internal social control mechanisms into the digital realm while also projecting power abroad. The regime serves a dual purpose of insulating the domestic population from undesired narratives and foreign influence, while exporting technologies, protocols, and ideological models of digital sovereignty to other authoritarian or aspiring technocratic regimes.

🔗Read our analysis here

Threat Intelligence Report: APT35 Internal Leak of Hacking Campaigns Against Lebanon, Kuwait, Turkey, Saudi Arabia, Korea, and Domestic Iranian Targets

In October, internal documents from APT35, also referred to as Charming Kitten, were leaked on Github. Our researchers reviewed and analyzed the leaked documents to form a tightly linked forensic trail that maps both technique and organization. In this report, we broke down APT35’s tool kit which covers reconnaissance, initial access, and post-exploitation tooling optimized for large-scale, quota-driven compromise operations. Our team analyzed the actor’s operational profile and campaign strategies, identifying an emphasis on weaponizing exchange attack chains (ProxyShell, Autodiscover, EWS enumeration, and PowerShell driven tasks) to extract mailbox contents and Global Address Lists, maintain mailbox-level persistence, HUMINT extraction, and iterative phishing loops based on harvested address books.

🔗Learn more here

What We’re Reading 

In case you’re behind on your cybersecurity reading homework, DTI team member Ian Campbell’s monthly recommended reading list will get you up to speed! 

📚Checkout the full reading list here📚

Where We’ll Be 

  • SANS Cyber Threat Summit 2025, London, UK, 3-4 December

Final Thoughts

As always, thank you to my returning readers! If you’re new, I hope you found this newsletter informational, helpful, and worthy of sharing with your peers. And of course I hope you will be coming back to read future editions!

We share this newsletter via email as well - if you’d prefer to get it to your inbox, sign up here.

If you missed last month's content, here are some quick links:

Thanks for reading - see you next month!

-Daniel

https://www.linkedin.com/in/schwalbe

https://infosec.exchange/@danonsecurity

https://www.linkedin.com/in/schwalbe

https://infosec.exchange/@danonsecurity

Related Content

Newsletters
Hey Nineteen (Newsletters)

Heatwaves in Vegas, high AQI in Seattle, and fresh threat research. Inside this edition: Iran’s growing hacktivist network, Mexican document scarcity scams, and the layered crypto architecture powering IRGC financial transfers.

For once, I am *not* starting this newsletter by talking about the weather. The weather in Seattle that is, instead let’s talk about what passes for “ weather” in Las Vegas! Astute readers may notice that this edition of my newsletter is coming out a week later than usual. Vegas is the reason for that, more specifically, my team and I spent the first week of August at Hacker Summer Camp, where it stayed in the triple-digits for nearly 10 days straight, topping out at 115 F (46 C for my international readers!). Meanwhile, in Seattle, the AQI pm2.5 value was closing in on 200, which combined with 84 F (29 C) heat made for unpleasant days.

While the heat in Vegas was unpleasant to say the least, our team kept busy staying in the air conditioned spaces of BSides LV, BlackHat, DefCon, and various other hacker gatherings.  After a week of talking to our colleagues in the field, and hearing about the work they’ve been doing, we are back in Seattle where the temperature stays safely below the triple digits.

The whole of July was more than packing for Summer Camp though,and  my team kept up the pace publishing research on the Iranian hacktivist ecosystem and scarcity scams. I also had the chance to contribute an Expert Insight to our friends at Cyber Security News based on our research into the threat actors that make up Iran’s Hacktivist Ecosystem. To end the month, we published the findings of a year-long investigation into the ZedXion Cryptocurrency Exchange and the network of affiliated entities used by the IRGC to evade sanctions. Now, let’s dive in and get you up to speed.

 

Hot Off the Presses 

Threat Intelligence Report: The Pro-Iran Hacktivist Ecosystem 2026

To kick off July, the DTI team broke down the threat actor ecosystem supporting Iranian interests in 2026. The current pro-Iran“Axis of Resistance” is decentralized, blending hacktivist groups, ideological cyber militias, influence operators, and jihadist cyber propagandists, functioning as a loose knit cyber mobilization network. DTI researchers analyzed the individual actors in the ecosystem, assessing their capabilities and tradecraft as part of the larger collective. The groups’ behavior shows how modern cyber conflict is moving beyond traditional espionage toward more influence operations. Much of their activity is built for wartime influence by leveraging public visibility for asymmetric pressure against perceived enemies.

Our research found that most of the actors rely on basic tradecraft, including DDoS attacks, defacements, credential reuse, recycled breach data, public claims, and propaganda amplification to effect. These methods are often low-end but still create real impact when many groups act at once during geopolitical escalation. The main defensive challenge is not only intrusion prevention, but also managing disruption, reputational risk, and alert fatigue across public-facing systems.

Read the breakdown here

Scarcity Scams

When government backlogs create scarcity, scammers step in. DTI analysts exposed the mechanics of these "scarcity scams", from replica portals to weaponized session-recording tools, in July’s security snack. We uncovered a years-long campaign targeting Mexican citizens with a scam themed as a fast track service for government documents they branded as “Mexican Cita Express” or “Cita Express SRE México”. This scam alleges there is a fast track service to process government documents. Based on this investigation, our team expanded the investigation to hunt for similar scams based on shared conditions and methods. 

Read the snack here

Intelligence Report: The Zedxion Corporate Nexus for Illicit Iranian Financial Funds Transfer for IRGC Entities

In July 2025, DomainTools Investigations began investigating the Zedxion Cryptocurrency Exchange after an external partner came to us with the question “Does anything look strange about this domain?” Our researchers continued the investigation into the Zedxion Exchange in partnership with TRM Labs who first published their own research on the Exchange in January 2026. Signals point to Zedxion, and the BZ Group, as part of a larger constellation of entities tied to the IRGC moving towards establishing regional banking app(s) spanning the United Kingdom and the United Arab Emirates in order to more effectively obscure their transactions and mitigate disruption or takedown. When examined holistically, the constellation does not resemble a conventional cryptocurrency enterprise. Instead, it presents as a layered financial architecture in which legal entities, branding assets, governance actors, and digital infrastructure perform distinct and compartmentalized functions.

At the corporate level, the UK serves as a recurring incorporation platform. Companies are formed with high nominal capitalization, frequently £1,000,000, yet file dormant or non-trading accounts and exhibit no verifiable operating revenue. These entities are restructured, mirrored, or dissolved as exposure increases. ZEDXION EXCHANGE LTD and ZEDCEX EXCHANGE LTD reflect this pattern: structurally similar exchange vehicles, one absorbing litigation and regulatory pressure while the other preserves brand continuity and operational optionality. The dissolution of BZ BROKER LIMITED and the short lifecycle of BZ DIAMOND LTD reinforce the conclusion that UK entities function primarily as disposable regulatory interfaces rather than durable operating companies.

Read the investigation here 

Where We’ll Be

  • ‍Boston Security Meetup, Boston, MA, 20 August

Final Thoughts

As always, thank you to my returning readers! If you’re new, I hope you found this newsletter informational, helpful, and worthy of sharing with your peers. And of course I hope you will be coming back to read future editions!

We share this newsletter via email as well - if you’d prefer to get it to your inbox, sign up here.

If you missed last month's content, here are some quick links:

Thanks for reading & see you next month!

-Daniel

https://www.linkedin.com/in/schwalbe/

https://infosec.exchange/@danonsecurity

Learn More
Newsletters
Eighteen Newsletters and a Dozen Roses

June’s roundup of research - from cyberattacks on water infrastructure OT and ICS to DNS hijacking and an AiTM campaign targeting Microsoft365 users. 

June was unusually warm here in Seattle, which for a region that claims “June-uary” as a Season, is noteworthy. We made the best of it by watching Team USA defeat the Socceroos in a 2-0 victory at our beloved “Seattle Stadium” - Did you hear we have been ranked the #1 World Cup stadium this time around?. Of course it all came to an end yesterday, when the Belgian “Red Devils” (who have claimed that name for longer than Manchester United) gave the Team USA a soccer lesson they won’t soon forget. That 4-1 defeat stung, especially since it was the last game Seattle hosted this time around. Well, there are always the Mariners.

Despite heat and soccer, we still spent the month investigating emerging threats, talking about our already emerged research, and preparing for Hacker Summer Camp. We started with an investigation into an attacker-in-the-middle credential-harvesting kit targeting Microsoft365 and EntraID identities. Next our team analyzed Russian-linked cyber operations targeting SOHO routers for DNS-hijacking and adversary-in-the-middle intelligence collection, as well as communications-layer collection from messaging platforms like Signal and WhatsApp. 

The team and I also attended SLEUTHCON in Arlington, VA; if you didn’t get a chance to say hi and grab a T-shirt, we will be in Las Vegas for Hacker Summer Camp next month with lots of swag. Ending the month, we published research on the targeting of water systems by Russian, Iranian, and PRC-aligned threat actors. As an added bonus, our friends at Dark Reading picked up the story and published their own article based on our research - I highly recommend giving it a read. I also had the pleasure of joining CyberWire’s Dave Bittner for an episode of his Research Saturday podcast talking about last month’s related research on the ZionSiphon OT malware sample. Now, let’s dive in and get you up to speed.  

Hot Off the Presses 

SecuritySnack - Hijacking Corporate Sessions

DTI researchers kicked off June with an investigation into a fully operational Adversary-in-the-Middle (AiTM) credential-harvesting kit targeting Microsoft 365 and Entra ID identities. The kit runs through a three-to-five stage funnel starting from financial, recruiting, and document related domain name themes. The funnels typically begin with an anti-analysis CAPTCHA gate to filter sandboxes, followed by a corporate email harvest stage that builds trust by dynamically rendering the victim's employer logo and filtering out personal email addresses. The final stage is a pixel-perfect, AiTM reverse proxy of the Microsoft sign-in page, which brokers the live authentication flow and successfully intercepts every credential, Multi-Factor Authentication (MFA) code (including Push, TOTP, and SMS), and post-authentication session cookie.

Read the snack here

Threat Intelligence Report: Russia, Router, DNS, and Messaging-Layer Collection Operations

The DTI team pivoted to an analysis of Russian-linked cyber operations targeting SOHO routers for DNS-hijacking and adversary-in-the-middle intelligence collection, as well as communications-layer collection from messaging platforms like Signal and WhatsApp. By targeting routers and bending DNS, Russian operators are able to watch traffic, steer chosen victims, and steal credentials without putting malware on the machine. Meanwhile, their work against Signal, WhatsApp, Telegram, and Microsoft 365 gives them access to messages, contacts, trusted names, and private conversations. 

Russia is increasingly treating edge infrastructure and messaging platforms as persistent intelligence-collection terrain. Router compromise provides GRU-linked operators with a passive upstream vantage point over victim traffic, while messaging-account compromise provides visibility into human networks, operational discussions, authentication workflows, and trusted social relationships. Together, these operations support long-duration intelligence collection, access persistence, credential interception, social-graph mapping, and pre-positioning for future contingency operations.

Read our full analysis here

Threat Intelligence Report: Nation-State Targeting of Water Systems 2024–2026

To wrap up the month, our researchers took a deep dive into the targeting of water systems by Russian, Iranian, and PRC-aligned threat actors. Recent activity targeting water systems includes Iranian IRGC-linked targeting of exposed programmable logic controllers (PLCs), Russian and pro-Russian access to municipal water-control environments, and PRC-linked pre-positioning in U.S. critical infrastructure, including water and wastewater systems. U.S. federal agencies, including CISA, FBI, NSA, and EPA, have warned that many utilities remain exposed through internet-facing human-machine interfaces (HMIs) and PLCs, weak credentials, shared accounts, legacy devices, limited monitoring, and poor IT/OT segmentation. 

While each nation uses a slightly different model for these operations, they all are used as shaping tools rather than destructive actions. Russia tends to pair infrastructure access with pressure and destabilization. Iran often blends symbolic retaliation, psychological signaling, and opportunistic disruption. In contrast, China places more emphasis on long-term pre-positioning and strategic persistence.

Read the breakdown here 

Where We’ll Be

  • ‍Hacker Summer Camp, Las Vegas, NV, 01-09 August

Final Thoughts

As always, thank you to my returning readers! If you’re new, I hope you found this newsletter informational, helpful, and worthy of sharing with your peers. And of course I hope you will be coming back to read future editions!

We share this newsletter via email as well - if you’d prefer to get it to your inbox, sign up here.

If you missed last month's content, here are some quick links:

Thanks for reading & see you next month!

-Daniel

https://www.linkedin.com/in/schwalbe/

https://infosec.exchange/@danonsecurity

Learn More
Newsletters
Edge of Seventeen (Newsletters)

We haven’t talked about the weather in Seattle for a bit. Just kidding, I ALWAYS talk about the weather here! Did you know that the Seattle Weather is officially one of the most difficult to accurately forecast? This is due (in part) to the so-called “Puget Sound Convergence Zone.” But also the fact that the area goes from sea level to 14,000 feet (4300m) within a 60 mile (97km) radius. And that we’re sandwiched between two mountain ranges and have a large patch of ocean that isn’t really the ocean because it’s a sound 🤷

In any case, today we reached 72 degrees Fahrenheit (22C), tomorrow will be 83 degrees (28C). June-uary better get here fast, I need three more weeks of gray and rain to adequately hydrate before summer starts on July 5th! But maybe the weather decided to “play along” and show the visitors that are coming to town for the FIFA World Cup a good time. Seattle is hosting four matches, including the US National Team 🇺🇸against the Socceroos 🇦🇺! And just like Matt Turner will keep close tabs on Jordan Bos and Nestory Irankunda, the DTI team has been busy keeping track of the latest threats. 

We started May (or technically ended April if we’re being specific) with a look at the DPRK’s “Contagious Interview” campaign that weaponizes legitimate hiring workflows to compromise developer environments. The rest of May was spent taking a deeper dive into the Doppelganger campaigns we covered in March and looking at their operational pipeline and strategic significance. We rounded out the month with a look at the ZionSiphon malware sample, the OT malware designed to target Israeli water facilities with some critical flaws in its programming. 

Let’s dive in and get you up to speed!  

Hot Off the Presses 

Threat Intelligence Report: ZionSiphon OT Malware First Attempts? Psyops? Both?

DTI researchers analyzed the ZionSiphon malware sample (“SCADA_SecurityPatch_v8.4.exe”) that has been circulating in public sandboxes since 2025. The malware is designed to target and sabotage water treatment and desalination facilities in Israel only. In our analysis, our team identified a critical bug in the malware’s geographic validation logic that prevents the malware’s payload from activating in its intended environment. Beyond the flaw in its geographic validation logic, the malware also lacks any external communication stack or command-and-control (C2) channel. 

Based on our analysis, our team determined ZionSiphon operates entirely at the Windows host layer, using registry persistence, PowerShell-based execution, and USB-oriented propagation logic. It is a real, functioning implant in terms of execution mechanics, but the XOR bug prevents it from transitioning into an active sabotage phase, rendering it effectively non-operational as an ICS attack tool. 

Read the full technical breakdown here

Threat Intelligence Report: The SDA / Structura / Doppelgänger, Influence Operations, Infrastructure, Reach, and Potential

After our first investigation into Doppelgänger in March, the DTI team took another deep dive into the Doppelgänger campaigns and their operational model. We broke down the narrative distribution model into four stages: content creation, telegram amplification, X/twitter injection, and narrative propagation. Our research determined the Doppelgänger campaign is engineered for visibility, not direct persuasion. Its architecture–feeder websites, Telegram amplification, and coordinated X/Twitter activity–prioritizes rapid distribution and repeated exposure across platforms to maximize encounter frequency. Using this analysis, our team modeled the first 72 hours of a Doppelgänger campaign during a geopolitical crisis. 

We also placed Doppelgänger in the larger doctrinal context of Russia’s “information confrontation” strategy. The operational structure of the Doppelgänger campaign demonstrates clear continuity with Soviet-era Active Measures, a category of covert influence operations. Historically, Active Measures campaigns relied on a combination of forged publications, front organizations, and intermediary actors to introduce narratives into foreign information environments. The Doppelgänger campaign represents the digital transformation of the same strategy. 

Read our full analysis here

DPRK Contagious Interview: Developer Workflow Compromise

Our team kicked off May with an analysis of the DPRK’s “Contagious Interview” campaign that weaponizes legitimate hiring workflows to induce execution of malicious code within trusted developer environments. The campaign targets software developers and technical personnel through fraudulent job interview processes conducted across platforms such as GitHub, LinkedIn, and direct messaging channels.

Read the breakdown here 

What We’re Reading 

In case you’re behind on your cybersecurity reading homework, DTI team member Ian Campbell’s monthly recommended reading list will get you up to speed! 

‍📚See the full reading list here

Where We’ll Be

  • SLEUTHCON, Arlington, VA - 05 June
  • ‍Hacker Summer Camp, Las Vegas, NV, 01-09 August

Final Thoughts

As always, thank you to my returning readers! If you’re new, I hope you found this newsletter informational, helpful, and worthy of sharing with your peers. And of course I hope you will be coming back to read future editions!

We share this newsletter via email as well - if you’d prefer to get it to your inbox, sign up here.

If you missed last month's content, here are some quick links:

Thanks for reading & see you next month!

-Daniel

https://www.linkedin.com/in/schwalbe/
https://infosec.exchange/@danonsecurity

Learn More