<?xml version="1.0" encoding="utf-8"?><feed xmlns="http://www.w3.org/2005/Atom" ><generator uri="https://jekyllrb.com/" version="3.10.0">Jekyll</generator><link href="https://plausible-deniability.co/feed.xml" rel="self" type="application/atom+xml" /><link href="https://plausible-deniability.co/" rel="alternate" type="text/html" /><updated>2026-06-25T10:22:13+02:00</updated><id>https://plausible-deniability.co/feed.xml</id><title type="html">Plausible Deniablility</title><subtitle>Forensic, reverse engineering, CTI...  I get up and I do it ?</subtitle><author><name>{&quot;name&quot;=&gt;&quot;&quot;, &quot;avatar&quot;=&gt;&quot;/assets/images/avatar-round.svg&quot;, &quot;bio&quot;=&gt;&quot;Cyber Threat Intelligence. Allegedly.&quot;, &quot;links&quot;=&gt;[{&quot;label&quot;=&gt;&quot;Twitter&quot;, &quot;icon&quot;=&gt;&quot;fab fa-fw fa-twitter-square&quot;, &quot;url&quot;=&gt;&quot;https://twitter.com/4rchib4ld&quot;}, {&quot;label&quot;=&gt;&quot;GitHub&quot;, &quot;icon&quot;=&gt;&quot;fab fa-fw fa-github&quot;, &quot;url&quot;=&gt;&quot;https://github.com/4rchib4ld&quot;}, {&quot;label&quot;=&gt;&quot;LinkedIn&quot;, &quot;icon&quot;=&gt;&quot;fab fa-fw fa-linkedin&quot;, &quot;url&quot;=&gt;&quot;https://www.linkedin.com/in/axel-z-9a9a38117/&quot;}]}</name></author><entry><title type="html">Pulling the Thread: Two Unreported Infrastructure Clusters Linked to Chinese Espionage Tooling</title><link href="https://plausible-deniability.co/blog/PullingTheThread-ChineseEspionnage/" rel="alternate" type="text/html" title="Pulling the Thread: Two Unreported Infrastructure Clusters Linked to Chinese Espionage Tooling" /><published>2026-06-24T00:00:00+02:00</published><updated>2026-06-24T00:00:00+02:00</updated><id>https://plausible-deniability.co/blog/PullingTheThread-ChineseEspionnage</id><content type="html" xml:base="https://plausible-deniability.co/blog/PullingTheThread-ChineseEspionnage/"><![CDATA[<h2 id="introduction">Introduction</h2>

<p>This post documents two infrastructure findings made during a recent client engagement. Neither cluster has appeared in public threat intelligence reporting at the time of writing. I am publishing now to maximise the defensive value of the indicators before the infrastructure rotates.</p>

<p>The two findings are analytically independent but share a common thread: both connect to tooling associated with Chinese state-sponsored espionage, and both extend clusters that have been partially documented by other researchers. I will walk through the pivot chain for each, state my confidence assessments explicitly, and flag where the chain is inferential versus technically anchored.</p>

<p>IOCs are available as a STIX 2.1 bundle on request. All indicators carry confidence scores and sourcing on every object.</p>

<p class="notice--info">💡 : The analysis cut-off for this investigation is May 28th 2026</p>

<hr />

<h2 id="finding-1--unreported-shadowpad-infrastructure-cluster">Finding 1 — Unreported ShadowPad Infrastructure Cluster</h2>

<h3 id="detection-anchor">Detection Anchor</h3>

<p><strong>ShadowPad</strong> C2 infrastructure can be fingerprinted via a characteristic HTML body hash: <code class="language-plaintext highlighter-rouge">e760bb9ce1e83e274def380574509c7b9e9088ff</code>. Searching on this hash returns a consistent set of hosts with overlapping provider distribution and naming conventions documented by Hunt.io<sup id="fnref:1" role="doc-noteref"><a href="#fn:1" class="footnote" rel="footnote">1</a></sup> in their February 2024 tracking of ShadowPad via non-standard certificates.</p>

<p>Applying this search returned 23 hosts. Three of these—<code class="language-plaintext highlighter-rouge">172.64.80.1</code>, <code class="language-plaintext highlighter-rouge">104.21.96.85</code>, <code class="language-plaintext highlighter-rouge">172.67.175.133</code>—are Cloudflare shared infrastructure fronting the domains and are excluded from the indicator set to avoid false positives. The remaining 20 hosts had not appeared in any public reporting.</p>

<h3 id="two-unreported-domains">Two Unreported Domains</h3>

<p>Two domains in the cluster stood out immediately based on naming convention:</p>

<ul>
  <li><code class="language-plaintext highlighter-rouge">cashmicrosoft[.]com</code></li>
  <li><code class="language-plaintext highlighter-rouge">googledrivecloud[.]com</code></li>
</ul>

<p>Both follow the Microsoft and Google impersonation pattern consistently observed in ShadowPad operator infrastructure. Both are proxied behind Cloudflare. The HTML body hash match gives medium-high confidence on both as ShadowPad-linked.</p>

<p><strong>Confidence: medium-high</strong></p>

<h3 id="the-afghan-ministry-of-interior-pivot">The Afghan Ministry of Interior Pivot</h3>

<p>On 2026-05-14, <code class="language-plaintext highlighter-rouge">cashmicrosoft[.]com</code> was observed in Validin presenting a host certificate for <code class="language-plaintext highlighter-rouge">moi.gov[.]af</code>—the Afghan Ministry of Interior. Presenting a government ministry certificate is consistent with infrastructure prepared for operations involving Afghan government entities, although certificate reuse alone is insufficient to establish active targeting.</p>

<table>
  <thead>
    <tr>
      <th style="text-align: center"><img src="/assets/images/chinese_espionnage/image.webp" alt="" /></th>
    </tr>
  </thead>
  <tbody>
    <tr>
      <td style="text-align: center"><em>Screenshot of the certificate on Validin. Sadly, the result is not available anymore in the Community Edition</em></td>
    </tr>
  </tbody>
</table>

<p>I pivoted on this certificate behaviour and identified a second host exhibiting the same pattern: <code class="language-plaintext highlighter-rouge">195.86.120[.]2</code>.</p>

<p><strong>Confidence on targeting inference: medium</strong></p>

<h3 id="pivot-to-the-intel-certificate-cluster">Pivot to the Intel Certificate Cluster</h3>

<p><code class="language-plaintext highlighter-rouge">195.86.120[.]2</code> had previously resolved a single domain for approximately two weeks: <code class="language-plaintext highlighter-rouge">rallyracingglobal[.]com</code>. No other domain has ever resolved to this IP. Investigating <code class="language-plaintext highlighter-rouge">rallyracingglobal[.]com</code> revealed a self-signed TLS certificate impersonating Intel Corporation:</p>

<div class="language-plaintext highlighter-rouge"><div class="highlight"><pre class="highlight"><code>C=US, ST=CA, L=Santa Clara, O=Intel Corporation, CN=Intel Corporation - Client Components Group
</code></pre></div></div>

<p>This certificate is observed on 9 hosts globally since February 2026. I am unaware of any legitimate Intel Corporation deployment that would expose a self-signed certificate with this subject on internet-facing infrastructure.</p>

<p>The tradecraft mirrors the Dell Data Vault certificate cluster documented by Hunt.io<sup id="fnref:1:1" role="doc-noteref"><a href="#fn:1" class="footnote" rel="footnote">1</a></sup> as ShadowPad infrastructure: self-signed certificates impersonating US hardware vendors on Nginx-serving hosts with characteristic ShadowPad HTTP response patterns.</p>

<p>The nine hosts are:</p>

<ul>
  <li><code class="language-plaintext highlighter-rouge">38.60.255[.]134</code></li>
  <li><code class="language-plaintext highlighter-rouge">38.60.208[.]77</code></li>
  <li><code class="language-plaintext highlighter-rouge">65.20.67[.]90</code></li>
  <li><code class="language-plaintext highlighter-rouge">139.180.137[.]3</code></li>
  <li><code class="language-plaintext highlighter-rouge">103.140.187[.]9</code></li>
  <li><code class="language-plaintext highlighter-rouge">103.140.186[.]81</code></li>
  <li><code class="language-plaintext highlighter-rouge">193.56.255[.]178</code></li>
  <li><code class="language-plaintext highlighter-rouge">rallyracingglobal[.]com</code></li>
  <li><code class="language-plaintext highlighter-rouge">www.rallyracingglobal[.]com</code></li>
</ul>

<p><strong>Confidence on Intel cert cluster as ShadowPad-related: medium</strong></p>

<h3 id="infrastructure-cohesion--3860xx">Infrastructure Cohesion — 38.60.x.x</h3>

<p>The most significant observation in this dataset is the <code class="language-plaintext highlighter-rouge">38.60.x.x</code> /16 overlap across the two sub-clusters:</p>

<ul>
  <li><code class="language-plaintext highlighter-rouge">38.60.250[.]74</code> — present in the HTML body hash cluster</li>
  <li><code class="language-plaintext highlighter-rouge">38.60.255[.]134</code> — present in the Intel cert cluster</li>
  <li><code class="language-plaintext highlighter-rouge">38.60.208[.]77</code> — present in the Intel cert cluster</li>
</ul>

<p>Three IPs in the same /16 block across two independently-derived pivot chains is a meaningful infrastructure cohesion signal. It is consistent with a single operator managing both sub-clusters from the same VPS provider block, and it upgrades the Intel cert cluster from a tradecraft-similarity inference to a <em>plausible</em> infrastructure overlap.</p>

<p>The ShadowPad assessment rests on converging infrastructure signals rather than direct malware telemetry; absent payload recovery, the relationship should be considered provisional.</p>

<h3 id="attribution-note">Attribution Note</h3>

<p>ShadowPad is shared across at minimum APT41, APT27, APT15, Earth Lusca, Tick, Team Tonto, and Webworm. I am not attributing this cluster to any specific group.</p>

<p>The <code class="language-plaintext highlighter-rouge">moi.gov[.]af</code> certificate behaviour is consistent with multiple actors with South and Central Asian targeting interests. Attribution would require additional TTP or sample evidence.</p>

<hr />

<h2 id="finding-2--winnti-elf-c2-infrastructure-extension">Finding 2 — Winnti ELF C2 Infrastructure Extension</h2>

<h3 id="starting-point">Starting Point</h3>

<p>Researcher @TuringAlex<sup id="fnref:5" role="doc-noteref"><a href="#fn:5" class="footnote" rel="footnote">2</a></sup> published two SHA256 hashes for confirmed Winnti ELF samples in May 2026:</p>

<ul>
  <li><code class="language-plaintext highlighter-rouge">c83e768f3020119dc44392a46f587366c3ef70659592fbafb6cf94f08676bf3b</code></li>
  <li><code class="language-plaintext highlighter-rouge">de155feb28a98a18ae7962ed321c262d80e332b646da6fe8af65d0708167faef</code></li>
</ul>

<p>Both samples use <code class="language-plaintext highlighter-rouge">linux.tklolasi[.]com</code> as their C2 domain. This extends the Winnti ELF cloud credential harvester cluster documented by Breakglass Intelligence in April 2026<sup id="fnref:2" role="doc-noteref"><a href="#fn:2" class="footnote" rel="footnote">3</a></sup>, which identified a backdoor targeting AWS, GCP, Azure, and Alibaba Cloud instance metadata endpoints, using SMTP port 25 as a covert C2 channel and Alibaba Cloud typosquat domains for infrastructure camouflage.</p>

<p>The <code class="language-plaintext highlighter-rouge">linux</code> subdomain prefix is consistent with the ELF targeting profile of this specific tool.</p>

<p><strong>Confidence: high</strong></p>

<h3 id="dns-pivot">DNS Pivot</h3>

<p><code class="language-plaintext highlighter-rouge">linux.tklolasi[.]com</code> resolved to <code class="language-plaintext highlighter-rouge">106.15.148[.]44</code> for approximately two days. Short resolution windows of this kind are consistent with active operational infrastructure being rotated to avoid blocklisting—not indicative of a parked or sinkholed domain.</p>

<p><strong>Confidence on IP as operational C2: medium-high</strong></p>

<h3 id="three-alibaba-lookalike-domains">Three Alibaba Lookalike Domains</h3>

<p>On <code class="language-plaintext highlighter-rouge">106.15.148[.]44</code>, three additional domains were co-resolving during the same window:</p>

<ul>
  <li><code class="language-plaintext highlighter-rouge">ayuncs[.]com</code> — drops <code class="language-plaintext highlighter-rouge">ali</code> from <code class="language-plaintext highlighter-rouge">aliyuncs.com</code></li>
  <li><code class="language-plaintext highlighter-rouge">aliyunbs[.]com</code> — swaps <code class="language-plaintext highlighter-rouge">cs</code> for <code class="language-plaintext highlighter-rouge">bs</code></li>
  <li><code class="language-plaintext highlighter-rouge">aliyuncs[.]me</code> — mirrors the CN on a <code class="language-plaintext highlighter-rouge">.me</code> TLD</li>
</ul>

<p>All three impersonate Alibaba Cloud’s primary object storage domain. This is a direct tradecraft match with the confirmed Breakglass cluster, which uses <code class="language-plaintext highlighter-rouge">ai.aliyuncs[.]help</code>, <code class="language-plaintext highlighter-rouge">ns1.a1iyun[.]top</code>, and <code class="language-plaintext highlighter-rouge">ai.qianxing[.]co</code> — all Alibaba Cloud impersonators. The operational logic is coherent: a cloud credential harvester targeting Alibaba Cloud workloads camouflages its C2 behind Alibaba-lookalike domains.</p>

<p>Co-resolution on a shared IP does not alone confirm same operator. But the specificity of the Alibaba impersonation pattern, in combination with the confirmed sample linkage to the same IP, makes coincidence unlikely.</p>

<p><strong>Confidence on three lookalike domains: medium</strong></p>

<hr />

<h2 id="cross-finding-observation">Cross-Finding Observation</h2>

<p>One IP appeared across both investigations: <code class="language-plaintext highlighter-rouge">121.201.109[.]98</code>. This IP is present in the DragonEgg C2 indicators published by Lookout<sup id="fnref:3" role="doc-noteref"><a href="#fn:3" class="footnote" rel="footnote">4</a></sup> in July 2023 and in the LightSpy/DeepData indicators published by Volexity<sup id="fnref:4" role="doc-noteref"><a href="#fn:4" class="footnote" rel="footnote">5</a></sup> in November 2024 — both attributed to APT41. It did not directly feature in my pivot chains but its presence in both public clusters and its proximity to infrastructure I identified is worth flagging for other researchers to investigate.</p>

<hr />

<h2 id="ioc-summary">IOC Summary</h2>

<p>All IOCs can also be found <a href="https://github.com/4rchib4ld/plausible-deniability-iocs/blob/main/chinese_espionage.csv">here</a></p>

<p><strong>ShadowPad cluster — HTML body hash confirmed (medium-high confidence)</strong></p>

<p><code class="language-plaintext highlighter-rouge">cashmicrosoft[.]com</code>, <code class="language-plaintext highlighter-rouge">googledrivecloud[.]com</code>, <code class="language-plaintext highlighter-rouge">45.77.176[.]85</code>, <code class="language-plaintext highlighter-rouge">64.176.65[.]222</code>, <code class="language-plaintext highlighter-rouge">207.148.97[.]65</code>, <code class="language-plaintext highlighter-rouge">65.20.76[.]151</code>, <code class="language-plaintext highlighter-rouge">104.238.148[.]158</code>, <code class="language-plaintext highlighter-rouge">38.60.250[.]74</code>, <code class="language-plaintext highlighter-rouge">64.176.50[.]187</code>, <code class="language-plaintext highlighter-rouge">149.28.128[.]65</code>, <code class="language-plaintext highlighter-rouge">149.28.145[.]214</code>, <code class="language-plaintext highlighter-rouge">64.176.229[.]94</code>, <code class="language-plaintext highlighter-rouge">149.28.159[.]61</code>, <code class="language-plaintext highlighter-rouge">65.20.97[.]249</code>, <code class="language-plaintext highlighter-rouge">139.180.211[.]117</code>, <code class="language-plaintext highlighter-rouge">149.104.104[.]76</code>, <code class="language-plaintext highlighter-rouge">80.240.16[.]246</code>, <code class="language-plaintext highlighter-rouge">95.179.254[.]241</code>, <code class="language-plaintext highlighter-rouge">65.20.75[.]136</code></p>

<p><strong>ShadowPad cluster — Intel cert / pivot chain (medium confidence)</strong></p>

<p><code class="language-plaintext highlighter-rouge">195.86.120[.]2</code>, <code class="language-plaintext highlighter-rouge">38.60.255[.]134</code>, <code class="language-plaintext highlighter-rouge">38.60.208[.]77</code>, <code class="language-plaintext highlighter-rouge">65.20.67[.]90</code>, <code class="language-plaintext highlighter-rouge">139.180.137[.]3</code>, <code class="language-plaintext highlighter-rouge">103.140.187[.]9</code>, <code class="language-plaintext highlighter-rouge">103.140.186[.]81</code>, <code class="language-plaintext highlighter-rouge">193.56.255[.]178</code>, <code class="language-plaintext highlighter-rouge">rallyracingglobal[.]com</code></p>

<p><strong>Hunting lead — Intel Corporation TLS certificate</strong></p>

<p><code class="language-plaintext highlighter-rouge">C=US, ST=CA, L=Santa Clara, O=Intel Corporation, CN=Intel Corporation - Client Components Group</code> on TCP/443, first observed February 2026, 9 hosts globally.</p>

<p><strong>Winnti ELF extension</strong></p>
<ul>
  <li>Sample linkage: high confidence</li>
  <li>Operational C2 IP: medium-high confidence</li>
  <li>Additional lookalike domains: medium confidence</li>
</ul>

<p><code class="language-plaintext highlighter-rouge">c83e768f3020119dc44392a46f587366c3ef70659592fbafb6cf94f08676bf3b</code>, <code class="language-plaintext highlighter-rouge">de155feb28a98a18ae7962ed321c262d80e332b646da6fe8af65d0708167faef</code>, <code class="language-plaintext highlighter-rouge">linux.tklolasi[.]com</code>, <code class="language-plaintext highlighter-rouge">106.15.148[.]44</code>, <code class="language-plaintext highlighter-rouge">ayuncs[.]com</code>, <code class="language-plaintext highlighter-rouge">aliyunbs[.]com</code>, <code class="language-plaintext highlighter-rouge">aliyuncs[.]me</code></p>

<hr />

<h2 id="stix-bundle">STIX Bundle</h2>

<p>A STIX 2.1 bundle containing all indicators with confidence scores, sourcing, and analytical notes is available on request. Objects authored by Axel / Plausible Deniability are marked TLP:WHITE in the public release. Anchor objects referencing APT41, POISONPLUG.SHADOW, and the Winnti ELF malware family are included for analytical context. Inclusion of these objects should not be interpreted as attribution.</p>

<hr />

<h2 id="references">References</h2>

<div class="footnotes" role="doc-endnotes">
  <ol>
    <li id="fn:1" role="doc-endnote">
      <p><a href="https://hunt.io/blog/tracking-shadowpad-infrastructure-via-non-standard-certificates">Hunt.io — Tracking ShadowPad Infrastructure Via Non-Standard Certificates (February 2024)</a> <a href="#fnref:1" class="reversefootnote" role="doc-backlink">&#8617;</a> <a href="#fnref:1:1" class="reversefootnote" role="doc-backlink">&#8617;<sup>2</sup></a></p>
    </li>
    <li id="fn:5" role="doc-endnote">
      <p><a href="https://x.com/TuringAlex/status/1918667466810798335">@TuringAlex — Winnti ELF sample hashes (May 2026)</a> <a href="#fnref:5" class="reversefootnote" role="doc-backlink">&#8617;</a></p>
    </li>
    <li id="fn:2" role="doc-endnote">
      <p><a href="https://intel.breakglass.tech/post/apt41-winnti-elf-backdoor-cloud-credential-harvester-alibaba-typosquat">Breakglass Intelligence — APT41 Winnti ELF Backdoor: Cloud Credential Harvester with Alibaba Typosquat C2 (April 2026)</a> <a href="#fnref:2" class="reversefootnote" role="doc-backlink">&#8617;</a></p>
    </li>
    <li id="fn:3" role="doc-endnote">
      <p><a href="https://www.lookout.com/threat-intelligence/article/wyrmspy-dragonegg-surveillanceware-apt41">Lookout — WyrmSpy and DragonEgg Surveillanceware Attributed to APT41 (July 2023)</a> <a href="#fnref:3" class="reversefootnote" role="doc-backlink">&#8617;</a></p>
    </li>
    <li id="fn:4" role="doc-endnote">
      <p><a href="https://www.volexity.com/blog/2024/11/15/brazenbamboo-weaponizes-forticlient-vulnerability-to-steal-vpn-credentials-via-deepdata/">Volexity — BrazenBamboo Weaponizes FortiClient Vulnerability (November 2024)</a> <a href="#fnref:4" class="reversefootnote" role="doc-backlink">&#8617;</a></p>
    </li>
  </ol>
</div>]]></content><author><name>{&quot;name&quot;=&gt;&quot;&quot;, &quot;avatar&quot;=&gt;&quot;/assets/images/avatar-round.svg&quot;, &quot;bio&quot;=&gt;&quot;Cyber Threat Intelligence. Allegedly.&quot;, &quot;links&quot;=&gt;[{&quot;label&quot;=&gt;&quot;Twitter&quot;, &quot;icon&quot;=&gt;&quot;fab fa-fw fa-twitter-square&quot;, &quot;url&quot;=&gt;&quot;https://twitter.com/4rchib4ld&quot;}, {&quot;label&quot;=&gt;&quot;GitHub&quot;, &quot;icon&quot;=&gt;&quot;fab fa-fw fa-github&quot;, &quot;url&quot;=&gt;&quot;https://github.com/4rchib4ld&quot;}, {&quot;label&quot;=&gt;&quot;LinkedIn&quot;, &quot;icon&quot;=&gt;&quot;fab fa-fw fa-linkedin&quot;, &quot;url&quot;=&gt;&quot;https://www.linkedin.com/in/axel-z-9a9a38117/&quot;}]}</name></author><category term="Blog" /><category term="analysis" /><category term="China" /><summary type="html"><![CDATA[Two unreported infrastructure clusters linked to Chinese espionage tooling uncovered through infrastructure pivoting.]]></summary></entry><entry><title type="html">Pulling the Thread: Pivoting on DPRK IT Worker Infrastructure</title><link href="https://plausible-deniability.co/blog/PullingTheThread-DPRKWorkers/" rel="alternate" type="text/html" title="Pulling the Thread: Pivoting on DPRK IT Worker Infrastructure" /><published>2026-04-30T00:00:00+02:00</published><updated>2026-04-30T00:00:00+02:00</updated><id>https://plausible-deniability.co/blog/PullingTheThread-DPRKWorkers</id><content type="html" xml:base="https://plausible-deniability.co/blog/PullingTheThread-DPRKWorkers/"><![CDATA[<p>Team Cymru recently published a <a href="https://www.team-cymru.com/post/dprk-fake-it-worker-cyber-threat-actors-infrastructure">solid analysis of fake IT worker infrastructure</a>, pivoting from <code class="language-plaintext highlighter-rouge">luckyguys[.]site</code> using X.509 certificates and NetFlow data. If you haven’t read it, start there.</p>

<p>One question came to mind after reading it: are there other domains following the same naming pattern, registered around the same time?</p>

<h2 id="the-search">The search</h2>

<p>I searched for domains following a luckyguys naming convention, combined with similar registration timing and exposed services. One result stood out: <strong><code class="language-plaintext highlighter-rouge">luckyguys[.]cloud</code></strong>. The domain was registered January 6, 2026, one month after <code class="language-plaintext highlighter-rouge">luckyguys[.]site</code> (December 2, 2025) with the same registrar (Hostinger).</p>

<table>
  <thead>
    <tr>
      <th style="text-align: center"><img src="/assets/images/pivoting_dprk/luckyguys_site_WHOIS.png" alt="" /></th>
      <th style="text-align: center"><img src="/assets/images/pivoting_dprk/luckyguys_cloud_WHOIS.png" alt="" /></th>
    </tr>
  </thead>
  <tbody>
    <tr>
      <td style="text-align: center"><em><code class="language-plaintext highlighter-rouge">luckyguys[.]site</code> WHOIS record</em></td>
      <td style="text-align: center"><em><code class="language-plaintext highlighter-rouge">luckyguys[.]cloud</code> WHOIS record</em></td>
    </tr>
  </tbody>
</table>

<p>It also hosts a Gitea instance. These characteristics are consistent with those observed on <code class="language-plaintext highlighter-rouge">luckyguys[.]site</code>.</p>

<table>
  <thead>
    <tr>
      <th style="text-align: center"><img src="/assets/images/pivoting_dprk/luckyguys_site_git.png" alt="" /></th>
      <th style="text-align: center"><img src="/assets/images/pivoting_dprk/luckyguys_cloud_git.png" alt="" /></th>
    </tr>
  </thead>
  <tbody>
    <tr>
      <td style="text-align: center"><em><code class="language-plaintext highlighter-rouge">git.luckyguys[.]site</code> hosting a Gitea instance (source: Validin)</em></td>
      <td style="text-align: center"><em><code class="language-plaintext highlighter-rouge">luckyguys[.]cloud</code> displaying a Gitea Welcome Page (via <a href="https://urlscan.io/result/019cbe1a-44a5-739b-9a56-228b7806b480/">urlscan.io</a>)</em></td>
    </tr>
  </tbody>
</table>

<h2 id="what-made-it-interesting">What made it interesting</h2>
<p>IP <code class="language-plaintext highlighter-rouge">45.15.167[.]146</code> hosts all <code class="language-plaintext highlighter-rouge">luckyguys[.]cloud</code> subdomains. Its PTR record resolves to <code class="language-plaintext highlighter-rouge">rbluckyguys[.]com</code>. And the exposed login panel references “RB Luckyguys Management.”</p>

<table>
  <thead>
    <tr>
      <th style="text-align: center"><img src="/assets/images/pivoting_dprk/rb_luckyguys_panel.png" alt="" /></th>
    </tr>
  </thead>
  <tbody>
    <tr>
      <td style="text-align: center"><em>Panel available on luckyguys[.]cloud/login (<a href="https://urlscan.io/result/019bb4ad-bec5-7619-9822-0731fbedd763/">via urlscan.io on January 13, 2026</a>)</em></td>
    </tr>
  </tbody>
</table>

<p>The naming linkage extends beyond the primary domain, appearing in PTR records and application artifacts. It suggests a consistent ‘Luckyguys’ naming reuse across this infrastructure.</p>

<p>The subdomains also hint at an instant messaging interface (message.luckyguys[.]cloud and msg.luckyguys[.]cloud). This is consistent with the interface observed on <code class="language-plaintext highlighter-rouge">luckyguys[.]site</code> on April 8, 2026 (via <a href="https://urlscan.io/result/019d6c23-ddea-751d-a0f5-89426437ef69/">urlscan.io</a>).</p>

<table>
  <thead>
    <tr>
      <th style="text-align: center"><img src="/assets/images/pivoting_dprk/luckyguys_site_msg.png" alt="" /></th>
    </tr>
  </thead>
  <tbody>
    <tr>
      <td style="text-align: center"><em>Login panel found on <code class="language-plaintext highlighter-rouge">luckyguys[.]site/login</code></em></td>
    </tr>
  </tbody>
</table>

<h2 id="the-abandonment-pattern">The abandonment pattern</h2>
<p>The domain resolves to significantly more subdomains than <code class="language-plaintext highlighter-rouge">luckyguys[.]site</code> (18 vs 5). Per urlscan.io snapshots, the apex domain was reachable in January and March 2026. None of the endpoints respond at the time of writing. It is consistent with infrastructure torn down following public disclosure, as documented in the original Team Cymru post.</p>

<table>
  <thead>
    <tr>
      <th style="text-align: center"><img src="/assets/images/pivoting_dprk/luckyguys_site_sub.png" alt="" /></th>
      <th style="text-align: center"><img src="/assets/images/pivoting_dprk/luckyguys_cloud_sub.png" alt="" /></th>
    </tr>
  </thead>
  <tbody>
    <tr>
      <td style="text-align: center"><em><code class="language-plaintext highlighter-rouge">luckyguys[.]site</code> subdomains</em></td>
      <td style="text-align: center"><em><code class="language-plaintext highlighter-rouge">luckyguys[.]cloud</code> subdomains</em></td>
    </tr>
  </tbody>
</table>

<h2 id="attribution">Attribution</h2>
<p>Moderate confidence. Overlap in naming, infrastructure, and artifacts is suggestive, not conclusive. No direct IP overlap with the infrastructure documented by Team Cymru was identified, suggesting this may represent a separate but potentially related infrastructure segment.</p>

<p><strong>IOCs (observed subdomains and related infrastructure)</strong></p>
<div class="language-plaintext highlighter-rouge"><div class="highlight"><pre class="highlight"><code>luckyguys[.]cloud
rbluckyguys[.]com
admin.luckyguys[.]cloud
api.luckyguys[.]cloud
cdn.luckyguys[.]cloud
chat.luckyguys[.]cloud
check.luckyguys[.]cloud
clients.socket.luckyguys[.]cloud
ext.luckyguys[.]cloud
file.luckyguys[.]cloud
git.luckyguys[.]cloud
main.socket.luckyguys[.]cloud
manage.luckyguys[.]cloud
message.luckyguys[.]cloud
msg.luckyguys[.]cloud
rdweb.luckyguys[.]cloud
rustdesk.luckyguys[.]cloud
socket.luckyguys[.]cloud
</code></pre></div></div>]]></content><author><name>{&quot;name&quot;=&gt;&quot;&quot;, &quot;avatar&quot;=&gt;&quot;/assets/images/avatar-round.svg&quot;, &quot;bio&quot;=&gt;&quot;Cyber Threat Intelligence. Allegedly.&quot;, &quot;links&quot;=&gt;[{&quot;label&quot;=&gt;&quot;Twitter&quot;, &quot;icon&quot;=&gt;&quot;fab fa-fw fa-twitter-square&quot;, &quot;url&quot;=&gt;&quot;https://twitter.com/4rchib4ld&quot;}, {&quot;label&quot;=&gt;&quot;GitHub&quot;, &quot;icon&quot;=&gt;&quot;fab fa-fw fa-github&quot;, &quot;url&quot;=&gt;&quot;https://github.com/4rchib4ld&quot;}, {&quot;label&quot;=&gt;&quot;LinkedIn&quot;, &quot;icon&quot;=&gt;&quot;fab fa-fw fa-linkedin&quot;, &quot;url&quot;=&gt;&quot;https://www.linkedin.com/in/axel-z-9a9a38117/&quot;}]}</name></author><category term="Blog" /><category term="analysis" /><category term="DPRK" /><summary type="html"><![CDATA[A simple naming pattern search on DPRK-linked infrastructure — and one domain that kept giving.]]></summary></entry><entry><title type="html">Pulling the Thread: Invite Only</title><link href="https://plausible-deniability.co/blog/PullingTheThread-InviteOnly/" rel="alternate" type="text/html" title="Pulling the Thread: Invite Only" /><published>2026-04-21T00:00:00+02:00</published><updated>2026-04-21T00:00:00+02:00</updated><id>https://plausible-deniability.co/blog/PullingTheThread-InviteOnly</id><content type="html" xml:base="https://plausible-deniability.co/blog/PullingTheThread-InviteOnly/"><![CDATA[<h2 id="starting-with-a-hunch">Starting with a hunch</h2>

<p>Last week, I shared a small phishing campaign encountered during routine monitoring. This post focuses on what came next: how a single artifact can uncover infrastructure, tooling, and ultimately a likely operator.</p>

<p>Both pages in the screenshot share the same filename: <code class="language-plaintext highlighter-rouge">invite.php</code>. I was wondering “isn’t this <code class="language-plaintext highlighter-rouge">invite.php</code> suspicious? Is it used for legitimate purposes?” What you should do with your assumptions is to:</p>
<ol>
  <li>Make them clear</li>
  <li>Test them</li>
</ol>

<p>So let’s do it. On urlscan.io (URL scanning service), I got 3230 results for the query <code class="language-plaintext highlighter-rouge">page.url:"/invite.php"</code>.</p>

<p class="notice--info"><strong>Disclaimer:</strong> urlscan.io has a bias toward suspicious URL. As it is crowdsourced, so you depend on user submissions, which are biased toward suspicious URLs.</p>

<table>
  <thead>
    <tr>
      <th style="text-align: center"><img src="/assets/images/invite-only/image-20260418113446860.png" alt="" /></th>
    </tr>
  </thead>
  <tbody>
    <tr>
      <td style="text-align: center"><em>urlscan.io search for <code class="language-plaintext highlighter-rouge">/invite.php</code></em></td>
    </tr>
  </tbody>
</table>

<p>Looking at the results, you can also see that some URLs have the path: <code class="language-plaintext highlighter-rouge">root.tld/Windows/invite.php</code>. Since this path appears multiple times and suggests a structured deployment (/Windows/invite.php), I’ll use it as a starting point to test whether we’re looking at a shared template or infrastructure.</p>

<h2 id="what-does-the-page-tell-us">What does the page tell us?</h2>

<p>First, we should determine how we would assess that they are—or not—the same page. What I usually do is straightforward: I open the HTML file and look for anything specific. I try not to be too attached to terms related to Microsoft Teams, but more on the structure of the <a href="https://urlscan.io/result/019d9193-fbcb-723b-9cfc-e523d45f8757/dom/">page</a>.</p>

<p>The page has:</p>
<ul>
  <li>a title: Microsoft Teams Voicemail Update</li>
  <li>a link to a google fonts: Roboto:wght@400;50</li>
  <li>an embedded stylesheet: zoom-blue: #0072c6, text-color: #555, bg-color: #f4f7fa, border-color: #0072c6, button-hover-bg: #0072c6</li>
  <li>a script block</li>
</ul>

<p>The script starts by initializing variables related to element ID, then a preloader message transition and a redirect countdown. At the end, it calls the function <code class="language-plaintext highlighter-rouge">startRedirect</code> which writes “Redirecting” in the <code class="language-plaintext highlighter-rouge">download-info</code> element and redirects the user to the page <code class="language-plaintext highlighter-rouge">microsoft-store.php</code>.</p>

<table>
  <thead>
    <tr>
      <th style="text-align: center"><img src="/assets/images/invite-only/image-20260420110909640.png" alt="" /></th>
    </tr>
  </thead>
  <tbody>
    <tr>
      <td style="text-align: center"><em><code class="language-plaintext highlighter-rouge">invite.php</code> DOM from teams-connect-voice[.]online</em></td>
    </tr>
  </tbody>
</table>

<p>There is a lot more than you can extract. For instance, the <code class="language-plaintext highlighter-rouge">manualDownload</code> element has a href to <code class="language-plaintext highlighter-rouge">microsoft-store.php</code> and the image is located at <code class="language-plaintext highlighter-rouge">./img/micro.png</code>. All those small elements will become quite handy when we will need to compare with others pages. Taken together, these elements form a reusable fingerprint that can be used for detection or retro-hunting.</p>

<p>Now that we have a clear idea of what to look for, we can start comparing pages. From there, I pick a random urlscan.io result.</p>

<p>When opening the result from lankystocks[.]com, we see a 404 page. It is common on urlscan.io to have this kind of behavior. urlscan.io performs on-demand scans, so some scans occur after the page or site has already gone offline.</p>

<table>
  <thead>
    <tr>
      <th style="text-align: center"><img src="/assets/images/invite-only/image-20260420103113193.png" alt="" /></th>
    </tr>
  </thead>
  <tbody>
    <tr>
      <td style="text-align: center"><em>404 page from lankystocks[.]com on urlscan.io.</em></td>
    </tr>
  </tbody>
</table>

<p>To make sure, always check the full scanning history, and starts from the beginning. This will allow you to get an understanding of what happened on the website according to urlscan.io data. It is important to remember, what you see here is only URLs submitted to urlscan.io, not every page available.</p>

<table>
  <thead>
    <tr>
      <th style="text-align: center"><img src="/assets/images/invite-only/image-20260420103556667.png" alt="" /></th>
    </tr>
  </thead>
  <tbody>
    <tr>
      <td style="text-align: center"><em>lankystocks[.]com scanning history on urlscan.io</em></td>
    </tr>
  </tbody>
</table>

<p>From there, you can see that the domain was first scanned 2 months ago (February 06), and the first URL with <code class="language-plaintext highlighter-rouge">invite</code> submitted the a week after, on February 13th. You can also see that the page <code class="language-plaintext highlighter-rouge">download.php</code>downloads an executable file named <code class="language-plaintext highlighter-rouge">ZoomWorkspaceClientSetup.exe</code>(sha256: <code class="language-plaintext highlighter-rouge">5701dabdba685b903a84de6977a9f946accc08acf2111e5d91bc189a83c3faea</code>). Both the file and domains were reported by Microsoft as part of a <a href="https://www.microsoft.com/en-us/security/blog/2026/03/03/signed-malware-impersonating-workplace-apps-deploys-rmm-backdoors/">“Signed malware impersonating workplace apps deploys RMM backdoors”</a>. So we are onto something. But what about this <a href="https://urlscan.io/result/019c5704-5118-7579-ae97-7b14821fbca6/dom/">page</a> ?</p>

<p>We can see that the title is different (Zoom Client Update). The script block is similar, but this time it has comments and a different preloader message transitions.</p>

<table>
  <thead>
    <tr>
      <th style="text-align: center"><img src="/assets/images/invite-only/image-20260420111715069.png" alt="" /></th>
    </tr>
  </thead>
  <tbody>
    <tr>
      <td style="text-align: center"><em>lankystocks[.]com <code class="language-plaintext highlighter-rouge">invite.php</code> DOM, this time related to Zoom</em></td>
    </tr>
  </tbody>
</table>

<p>This is clearly the same template, with minor variations. It can be because one of the page was modified by someone to make it easier to manage—which explains the comments—or that on the contrary someone removed comments altogether.</p>

<p>I looked at other HTML documents, and I always found the same page. If it is always the same, you can search for the hash instead of always opening and manually viewing the DOM.  I found 252 results with <code class="language-plaintext highlighter-rouge">hash:902ca83e4b0047d965ecea1059cd8d2212c386c4751f534cafc9287bc230fa64</code> for 88 domains. The oldest one is from 9 months ago.</p>

<p>At this stage, we’ve established that multiple domains reuse the same phishing template, suggesting either a shared kit or a coordinated campaign.</p>

<h2 id="clustering-the-infrastructure">Clustering the infrastructure</h2>

<p>When you have a lot of data, what is interesting is to create clusters. This allows you to see details under a new light and split the work.</p>

<p>Now let’s cluster based on hosting. As I stated earlier, it is not because the HTML page is the same that it is always the same person—or group of persons—behind. To further our work, we will cluster every page based on hosting behaviors. At some point, it is possible that we regroup clusters together, based on other elements. To make the clustering easier, it is best to set the option “Details: Visible” on urlscan.io. I also collapsed results by Hostname.</p>

<p>Clusters can be quickly identified with a simple search within the page.</p>

<table>
  <thead>
    <tr>
      <th style="text-align: center"><img src="/assets/images/invite-only/image-20260420141303729.png" alt="" /></th>
    </tr>
  </thead>
  <tbody>
    <tr>
      <td style="text-align: center"><em>A simple CTRL+F on urlscan.io is just what you need to make this clusters</em></td>
    </tr>
  </tbody>
</table>

<p>We end up with three main clusters:</p>
<ul>
  <li>The <strong>SHOCK ASN</strong> cluster: 47 domains are hosted on this ASN.</li>
  <li>The <strong>CloudFlare hosted Cluster</strong>, with 17 domains.</li>
  <li>The <strong>NameCheap cluster</strong> with 4 domains.</li>
</ul>

<p>The rest of the domains are hosted on ASN, but there are only one or two at a time. Clustering them would take time and create a lot of small clusters. It is something you might want to do if you are concerned about this threat, but I will leave it there in this blogpost.</p>

<p>Clustering gave us a new insight: more than half of the domains we found are shared on the same ASN, which strongly points to a group or individual.</p>

<h2 id="a-small-opsec-mistake">A small OPSEC mistake</h2>

<p>The main interest here is the <strong>SHOCK ASN</strong> cluster, with more than half domains included in this cluster. Looking at the hosting of some domains on Validin, I found two points of interest.</p>

<table>
  <thead>
    <tr>
      <th style="text-align: center"><img src="/assets/images/invite-only/image-20260420151332740.png" alt="" /></th>
    </tr>
  </thead>
  <tbody>
    <tr>
      <td style="text-align: center"><em>DNS records for usz00mczyiee[.]store on Validin</em></td>
    </tr>
  </tbody>
</table>

<p>In the DNS Start of Authority (SOA) records, you can see that the SOA_MNAME points to ns7.loominost[.]com and that the email johnseamus89@gmail[.]com is used as SOA_RNAME. Sometimes, less experienced operators have so little OPSEC that it makes them a breeze to track. In a previous role, I was able to track a similar individual with this exact technique. He had more than 5 000 domains.</p>

<p>Validin’s data says that the email is related to 1458 domains. By a quick look, I found that the more recent ones all look like ClickFix/Video Conferencing related domains.</p>

<table>
  <thead>
    <tr>
      <th style="text-align: center"><img src="/assets/images/invite-only/image-20260420152355409.png" alt="" /></th>
    </tr>
  </thead>
  <tbody>
    <tr>
      <td style="text-align: center"><em>All domains related to johnseamus89@gmail[.]com according to Validin</em></td>
    </tr>
  </tbody>
</table>

<p>A <a href="https://intel.breakglass.tech/post/johnseamus89-loominost-fakemeeting-terry-johnson-ga-pivot">report from BreakingGlass intelligence</a> mentions the email and its related activities. The report identifies ClickFix domains linked to johnseamus89@gmail[.]com. They also found that loominost[.]com and phishing pages share the same Google Analytics ID: G-XDVX0QEYVC. Finally, it states that the team could not link the email—johnseamus89@gmail[.]com—and the loominost operator with enough confidence. This aligns with their conclusion: at this stage, the link between the email address and the Loominost operator remains unconfirmed.</p>

<p>However, by pivoting further—specifically by correlating the email address with external forum activity—we can introduce an additional layer of context that was not explored in their analysis.</p>

<h2 id="kevin">Kevin</h2>

<p>At this stage, the infrastructure pivot (SOA email + nameserver) provides a strong lead—but not yet an attribution. To go further, I looked for external references to the email address.</p>

<p>Searching for johnseamus89@gmail[.]com returns a thread on BlackHatWorld[.]com, an internet marketing forum.</p>

<table>
  <thead>
    <tr>
      <th style="text-align: center"><img src="/assets/images/invite-only/image-20260421105254477.png" alt="" /></th>
    </tr>
  </thead>
  <tbody>
    <tr>
      <td style="text-align: center"><em>BlackHatWorld user toufic complains about not being able to reach Kevin with email johnseamus89@gmail[.]com]</em></td>
    </tr>
  </tbody>
</table>

<p>In a thread titled “<strong>Kevin</strong>’s PBN”, a user references this email address as a contact point for an individual operating under the handle <em>eatingMemory</em>. While forum content should always be treated cautiously, this establishes a potential link between the email observed in DNS records and an online persona. The original post also shares two ways of contacting eatingMemory:</p>
<ul>
  <li>the skype address kevinleeck</li>
  <li>the email adsynced@outlook.com</li>
</ul>

<table>
  <thead>
    <tr>
      <th style="text-align: center"><img src="/assets/images/invite-only/image-20260420154533691.png" alt="" /></th>
    </tr>
  </thead>
  <tbody>
    <tr>
      <td style="text-align: center"><em>End of eatingMemory first post on the Kevin’s PBN thread on BlackHatWorld</em></td>
    </tr>
  </tbody>
</table>

<p>Separately, the same <em>eatingMemory</em> account advertises, on July 11th, 2023, a hosting service named <strong>Loominost</strong>.</p>

<table>
  <thead>
    <tr>
      <th style="text-align: center"><img src="/assets/images/invite-only/image-20260420154513789.png" alt="" /></th>
    </tr>
  </thead>
  <tbody>
    <tr>
      <td style="text-align: center"><em>eatingMemory post about Loominost on BlackHatWorld</em></td>
    </tr>
  </tbody>
</table>

<p>This is particularly interesting given that:</p>
<ul>
  <li>the SOA records observed earlier reference ns7.loominost[.]com</li>
  <li>the same infrastructure is tied to phishing domains using the identified template</li>
  <li>the email address appears both in DNS data and in forum discussions referencing eatingMemory</li>
</ul>

<p>Taken together, these elements suggest that:</p>
<ul>
  <li>the Loominost service,</li>
  <li>the email address johnseamus89@gmail[.]com,</li>
  <li>and the eatingMemory persona</li>
</ul>

<p>are likely connected and may be operated by the same individual (referred to as “Kevin” in the forum thread).</p>

<p>While BreakingGlass did not establish a confident link between the email and the Loominost operator, combining infrastructure pivots with forum intelligence provides a stronger—though still circumstantial—case for overlap.</p>

<p>What can be stated with more confidence is the behavioral pattern:</p>
<ul>
  <li>large-scale domain registration (≈1500 domains linked to the email)</li>
  <li>recurring use of shared phishing templates</li>
  <li>overlap with ClickFix / fake conferencing lures</li>
  <li>continued activity within SEO and marketing forums</li>
</ul>

<p>This suggests an operator with a background in SEO-driven infrastructure, repurposed for phishing and malware delivery at scale.</p>

<p>I will not attempt to go further in identifying the individual behind these activities.</p>

<p>At this point, we’ve moved from a single suspicious filename to a reused phishing template, clustered infrastructure, and a likely operator—entirely by pivoting on small technical details.</p>

<h2 id="whats-next">What’s next</h2>

<p>From a defensive perspective, simple artifacts like file paths (<code class="language-plaintext highlighter-rouge">/invite.php</code>) or shared assets can serve as reliable pivot points for detection and retro-hunting. You can find all related IoCs <a href="https://github.com/4rchib4ld/plausible-deniability-iocs/blob/main/invite-only.csv">here</a>.</p>

<p>There’s more to explore around the ‘Invite Only’ ClickFix sub-technique, which I’ll cover in a follow-up post, but that’s a thread worth pulling separately.</p>]]></content><author><name>{&quot;name&quot;=&gt;&quot;&quot;, &quot;avatar&quot;=&gt;&quot;/assets/images/avatar-round.svg&quot;, &quot;bio&quot;=&gt;&quot;Cyber Threat Intelligence. Allegedly.&quot;, &quot;links&quot;=&gt;[{&quot;label&quot;=&gt;&quot;Twitter&quot;, &quot;icon&quot;=&gt;&quot;fab fa-fw fa-twitter-square&quot;, &quot;url&quot;=&gt;&quot;https://twitter.com/4rchib4ld&quot;}, {&quot;label&quot;=&gt;&quot;GitHub&quot;, &quot;icon&quot;=&gt;&quot;fab fa-fw fa-github&quot;, &quot;url&quot;=&gt;&quot;https://github.com/4rchib4ld&quot;}, {&quot;label&quot;=&gt;&quot;LinkedIn&quot;, &quot;icon&quot;=&gt;&quot;fab fa-fw fa-linkedin&quot;, &quot;url&quot;=&gt;&quot;https://www.linkedin.com/in/axel-z-9a9a38117/&quot;}]}</name></author><category term="Blog" /><category term="analysis" /><category term="opinion" /><category term="cybercrime" /><category term="clickfix" /><summary type="html"><![CDATA[How a suspicious filename led to 88 phishing domains, a shared hosting cluster, and an operator who probably should have used a different email address.]]></summary></entry><entry><title type="html">Fragmentation and Blackout: How War Is Reshaping Iran’s Cyber Operations</title><link href="https://plausible-deniability.co/blog/Fragmentation-and-Blackout-in-Iran/" rel="alternate" type="text/html" title="Fragmentation and Blackout: How War Is Reshaping Iran’s Cyber Operations" /><published>2026-04-14T00:00:00+02:00</published><updated>2026-04-14T00:00:00+02:00</updated><id>https://plausible-deniability.co/blog/Fragmentation-and-Blackout-in-Iran</id><content type="html" xml:base="https://plausible-deniability.co/blog/Fragmentation-and-Blackout-in-Iran/"><![CDATA[<p>Iran has been in an overt war against the United States and Israel since January 2026. This conflict has been marked, for Iran, by significant losses among its military and political leadership early in the war<sup id="fnref:1" role="doc-noteref"><a href="#fn:1" class="footnote" rel="footnote">1</a></sup>, creating a power vacuum. It seems that the <em>Islamic Revolutionary Guard Corps</em> (IRGC) filled this vacuum and now appears to exert greater control over the state than before the war<sup id="fnref:2" role="doc-noteref"><a href="#fn:2" class="footnote" rel="footnote">2</a></sup>. To avoid being vulnerable to airstrikes, the IRGC also fragmented its operations with many senior officials reportedly going into hiding. At the same time, Iran completely shut down its Internet.</p>

<p>Together, these shifts suggest a paradox: Iran’s cyber operations may be becoming less coordinated—but more unpredictable.</p>

<h1 id="the-fragmentation-of-the-irgc">The fragmentation of the IRGC</h1>

<p>The airstrikes delivered by the U.S. and Israel forced the Iranian
military to divide into smaller operating cells to reduce the impact of
strikes. This decentralization makes units smaller, but also more
autonomous<sup id="fnref:2:1" role="doc-noteref"><a href="#fn:2" class="footnote" rel="footnote">2</a></sup>. Historically, forced decentralization has produced more
autonomous but less coordinated units—as seen with the IRA’s shift to
cell-based structure in the 1980s, or Al-Qaeda’s fragmentation after 2001. In both cases, the result was less central coherence but greater
operational unpredictability.</p>

<p>Losing senior commanders in such a short time might disrupt the chain of
command, and units might lose their central coordination. For cyber
units—especially those linked to IRGC, known publicly as APT33, APT35,
APT42, Cyber Av3ngers and Cotton Sandstorm—it could mean less
coordination, but also more freedom to act, perhaps independently.</p>

<p>Fragmentation may not just decentralize operations—it may also reshape incentives.
Units operating with greater autonomy may seek to demonstrate their value through more
visible or more aggressive activity, particularly in a context where central oversight is weakened. At the time of writing, there are no public reports of a noticeable change, but the conflict is not over. CISA published an advisory about
Iranian-affiliated cyber actors targeting the critical infrastructure in
the U.S.<sup id="fnref:3" role="doc-noteref"><a href="#fn:3" class="footnote" rel="footnote">3</a></sup>. Despite not providing a clear attribution, the advisory
seems to be related to Cyber Av3ngers, a group related to IRGC-CEC.</p>

<p>Iran has long relied on <em>plausible deniability</em> for its cyber
operations—sponsoring groups that could be disowned when needed. In an
overt conflict, this matters less. When missiles are already flying,
denying a cyberattack does not change much for escalation management.
But deniability does not go away, it changes audience. Third-party
states and post-conflict diplomacy still create incentives to keep some
operations technically unattributed. Fragmentation cuts both ways here. Units operating without central
oversight may conduct operations Tehran never sanctioned—making
deliberate deniability harder to manage. But decentralized cells also
look exactly like non-state actors. Attribution becomes harder, and
deniability emerges by accident rather than design.</p>

<p>Fragmentation may also push some units toward external dependencies they
would not have relied on previously. Russia is reported to provide Iran
with satellite imagery and collaborate on cyber operations<sup id="fnref:4" role="doc-noteref"><a href="#fn:4" class="footnote" rel="footnote">4</a></sup>. There is
already a report about MuddyWater—a group likely related to the
Ministry Of Intelligence and Security (MOIS)—usage of a Russian
Malware-As-A-Service toolkit. While the report states that the tools
were bought “off the shelves”, they also might have been handed out
willingly by Russia given the historically permissive relationship
between Russian authorities and cybercriminal ecosystems. In the past,
members of the Federal Security Service (FSB) were directly connected to
cybercrime groups, like in the Evil Corp case<sup id="fnref:5" role="doc-noteref"><a href="#fn:5" class="footnote" rel="footnote">5</a></sup>.</p>

<h1 id="internet-blackout">Internet Blackout</h1>

<p>Since January 2026, Iran has shut down its Internet access. While some
privileged individuals were handed “white SIM cards”—granting them
unlimited, unfiltered Internet access—the vast majority of citizens
can only access a downgraded domestic network<sup id="fnref:6" role="doc-noteref"><a href="#fn:6" class="footnote" rel="footnote">6</a></sup>.</p>

<p>The regime’s stated reasoning is that cutting Internet access helps
prevent incoming cyber attacks, yet it remains unclear how much it does.
This is not the first time that Iran uses this tactic; it did the same
in the 2025 conflict<sup id="fnref:7" role="doc-noteref"><a href="#fn:7" class="footnote" rel="footnote">7</a></sup>. Knowing this, it is <em>plausible</em> that military
strategists planned ahead and did enough pre-positioning without relying
too much on Internet connectivity after the start of the conflict. In reality, it is more likely that the Internet shutdown is a convenient
disguise for digital censorship. The shutdown happens just after a
massive crackdown where thousands of Iranians were reportedly killed<sup id="fnref:8" role="doc-noteref"><a href="#fn:8" class="footnote" rel="footnote">8</a></sup>. Restricting access to the Internet might also be a way to avoid the
spread of information about the killings, both within Iran and abroad and to make it harder for citizens to organize.</p>

<p>Iranian cyber actors should still retain Internet access broadly comparable to pre-conflict levels. But it is likely that they had
to relocate some services and tooling outside of local servers, and
possibly out of Iran, to be more agile. It is unclear which organization is responsible for the Internet
shutdown in Iran, but if IRGC is the leader, it might abuse its position
to pressure or undermine competing agencies such as MOIS.</p>

<p>Taken together, these dynamics—fragmented command structures and
disrupted infrastructure—create compounded uncertainty. Iranian cyber
units may be operating with less oversight, less coordination, and less
stable tooling simultaneously. This is not necessarily a sign of
weakness: it may produce more erratic, harder-to-predict behavior. But
it also creates friction that even well-resourced threat actors cannot
fully absorb.</p>

<h1 id="conclusion">Conclusion</h1>

<p>If some of what I am writing is true, it means that in the upcoming days
we may witness Iranian threat actors adapting to the situation in their
own ways and diverging from their known TTPs. It could also mean some operations become more opportunistic or that some units seize the
opportunity to shine above their rival units.</p>

<p>These are not predictions but hypotheses—meant to be tested against
the behavior of Iranian cyber actors in the coming weeks. This analysis was produced under the banner of <em>Plausible Deniability</em>—a
fitting name, perhaps, for a piece about a regime that has always
preferred to keep it that way.</p>

<p><strong>References</strong></p>

<div class="footnotes" role="doc-endnotes">
  <ol>
    <li id="fn:1" role="doc-endnote">
      <p><a href="https://en.wikipedia.org/w/index.php?title=List_of_Iranian_officials_killed_during_the_2026_Iran_war&amp;oldid=1348352549">List of Iranian officials killed during the 2026 Iran war</a>. Wikipedia. 2026 Apr. <a href="#fnref:1" class="reversefootnote" role="doc-backlink">&#8617;</a></p>
    </li>
    <li id="fn:2" role="doc-endnote">
      <p><a href="https://www.economist.com/middle-east-and-africa/2026/03/25/the-revolutionary-guards-are-taking-over-iran">The Revolutionary Guards are taking over Iran</a>. The Economist. 2026 Mar. <a href="#fnref:2" class="reversefootnote" role="doc-backlink">&#8617;</a> <a href="#fnref:2:1" class="reversefootnote" role="doc-backlink">&#8617;<sup>2</sup></a></p>
    </li>
    <li id="fn:3" role="doc-endnote">
      <p>CISA. <a href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-097a">Iranian-Affiliated Cyber Actors Exploit Programmable Logic Controllers Across US Critical Infrastructure</a>; 2026. <a href="#fnref:3" class="reversefootnote" role="doc-backlink">&#8617;</a></p>
    </li>
    <li id="fn:4" role="doc-endnote">
      <p>Tom Balmforth, John Irish. <a href="https://www.reuters.com/world/europe/russia-supplies-iran-with-cyber-support-spy-imagery-hone-attacks-ukraine-says-2026-04-07/">Exclusive: Russia supplies Iran with cyber support, spy imagery to hone attacks, Ukraine says. Reuters</a>. 2026 Apr. <a href="#fnref:4" class="reversefootnote" role="doc-backlink">&#8617;</a></p>
    </li>
    <li id="fn:5" role="doc-endnote">
      <p>National Crime Agency. <a href="https://www.nationalcrimeagency.gov.uk/who-we-are/publications/732-evil-corp-behind-the-screens/file">Evil Corp: Behind the Screens</a>. Nation Crime Agency; 2024 Oct. <a href="#fnref:5" class="reversefootnote" role="doc-backlink">&#8617;</a></p>
    </li>
    <li id="fn:6" role="doc-endnote">
      <p>Daisy Johnston. <a href="https://warontherocks.com/2026/04/irans-other-front-the-war-over-the-internet/">Iran’s Other Front: The War Over the Internet</a>. War on the Rocks. 2026. <a href="#fnref:6" class="reversefootnote" role="doc-backlink">&#8617;</a></p>
    </li>
    <li id="fn:7" role="doc-endnote">
      <p>Lorenzo Franceschi-Bicchierai. <a href="https://techcrunch.com/2025/06/20/irans-government-says-it-shut-down-internet-to-protect-against-cyberattacks/">Iran’s government says it shut down internet to protect against cyberattacks</a>. TechCrunch. 2025. <a href="#fnref:7" class="reversefootnote" role="doc-backlink">&#8617;</a></p>
    </li>
    <li id="fn:8" role="doc-endnote">
      <p><a href="https://www.amnesty.org/en/latest/campaigns/2026/01/what-happened-at-the-protests-in-iran/">What happened at the protests in Iran?</a> Amnesty International. 2026. <a href="#fnref:8" class="reversefootnote" role="doc-backlink">&#8617;</a></p>
    </li>
  </ol>
</div>]]></content><author><name>{&quot;name&quot;=&gt;&quot;&quot;, &quot;avatar&quot;=&gt;&quot;/assets/images/avatar-round.svg&quot;, &quot;bio&quot;=&gt;&quot;Cyber Threat Intelligence. Allegedly.&quot;, &quot;links&quot;=&gt;[{&quot;label&quot;=&gt;&quot;Twitter&quot;, &quot;icon&quot;=&gt;&quot;fab fa-fw fa-twitter-square&quot;, &quot;url&quot;=&gt;&quot;https://twitter.com/4rchib4ld&quot;}, {&quot;label&quot;=&gt;&quot;GitHub&quot;, &quot;icon&quot;=&gt;&quot;fab fa-fw fa-github&quot;, &quot;url&quot;=&gt;&quot;https://github.com/4rchib4ld&quot;}, {&quot;label&quot;=&gt;&quot;LinkedIn&quot;, &quot;icon&quot;=&gt;&quot;fab fa-fw fa-linkedin&quot;, &quot;url&quot;=&gt;&quot;https://www.linkedin.com/in/axel-z-9a9a38117/&quot;}]}</name></author><category term="Blog" /><category term="analysis" /><category term="opinion" /><category term="iran" /><summary type="html"><![CDATA[War is reshaping Iran's cyber operations. IRGC fragmentation, a near-total internet shutdown, and the loss of senior commanders are creating compounded uncertainty—and Iranian threat actors may not be exempt from the fallout.]]></summary></entry><entry><title type="html">Threat Actors are playing the META</title><link href="https://plausible-deniability.co/blog/ThreatActors-playing-META/" rel="alternate" type="text/html" title="Threat Actors are playing the META" /><published>2026-04-07T00:00:00+02:00</published><updated>2026-04-07T00:00:00+02:00</updated><id>https://plausible-deniability.co/blog/ThreatActors-playing-META</id><content type="html" xml:base="https://plausible-deniability.co/blog/ThreatActors-playing-META/"><![CDATA[<p class="notice--info">💡 : Originally published February 2025 on another platform. Lightly revised for clarity.</p>

<p>On January 2025, Trellix published an <a href="https://www.trellix.com/blogs/research/blurring-the-lines-how-nation-states-and-cybercriminals-are-becoming-alike/">article</a> named “Blurring the Lines”. It discuss the fact that it is increasingly difficult to tell cyber-crime and APT groups from each other with TTPs. Even if the title of the article promised to explain “how”, I did not really get it. So I wrote what I think is how threat actors all use the same TTPs: they just do what is most likely to work.</p>

<p>Information systems are still vulnerable. threat actors want to be the most efficient possible when exploiting them. In competitive video games, this is what is called the <em>Most Effective Tactics Available</em> (META). In the context of cyber threats, it is all the Tactics, Techniques and Procedures (TTPs) that are the most likely to achieve the threat actor objective without detection and at the lowest possible cost. The META is dynamic. The threat actors learn and adapt to the cyber ecosystem, just as defenders do. If a tactic or technique is too well countered by the defenders, threat actors will change accordingly. For instance, macro-embedded documents were the go-to for initial access. Microsoft finally decided that it was time to consider this seriously, so it is a technique that belongs almost to the past. I still encounter some macro-related documents once in a while. These documents exploit old vulnerabilities like CVE-2017-11882. Some people did not install the patch, even today.</p>

<p>We tend to forget, but threat actors are like penetration teams<sup id="fnref:china" role="doc-noteref"><a href="#fn:china" class="footnote" rel="footnote">1</a></sup>. They have at their disposal the sharing of knowledge from the offensive cyber community, especially their tooling. These tools are as efficient as custom-made tools—sometimes even better—and they are free. Because anyone can use them, attributing the usage to a particular group is not possible. Some of these tools are well established in the META.</p>

<p>The META also targets the insecurity by default of information systems and the difficulty to monitor them. Defense evasion techniques exploit legitimate tools and functionalities of the operating system. Living of the Land  binaries are first used by the operating system, applications, and administrators. Windows is designed to allow process injection and loading DLLs. Command and control infrastructures are similar. Some legitimate services offer the same functionalities, like uploading files and sending data. Detecting the nefarious intent behind those behaviors on a large information system is a big challenge.</p>

<p>For threat actors, what has been spared in R&amp;D costs is paid by reduced chances of success against defenders aware of the META. This is a risk cybercriminals—especially the least advanced—are more willing to take. They can always find a new target. For groups affiliated with governments and the military, they might prefer to have every chance on their side, that is if the target is worth the effort. They will more likely use their own tools and infrastructure to avoid detection.</p>

<p>Not every corporation can—let alone be willing to—watch over each PowerShell script execution, or block access to Dropbox. The amount of doors that can be opened by attackers is massive, and they only need one to be successful. As every group is using it, implementing defenses against the META can mutualize the effort<sup id="fnref:defendersTools" role="doc-noteref"><a href="#fn:defendersTools" class="footnote" rel="footnote">2</a></sup> and keep your organization safer against a lot of threats. The META is not a failure of attribution—it is a reminder that efficiency is universal. Nation-state actors and cybercriminals converge not because they collaborate, but because they operate in the same ecosystem and respond to the same incentives. Defenders who understand this stop chasing group labels and start focusing on behaviors. That is where they can deal with threat actors the best.</p>

<div class="footnotes" role="doc-endnotes">
  <ol>
    <li id="fn:china" role="doc-endnote">
      <p>In China, some threat actors are literally cybersecurity firms—for example I-Soon (FishMonger) and Chengdu 404 (APT41). <a href="#fnref:china" class="reversefootnote" role="doc-backlink">&#8617;</a></p>
    </li>
    <li id="fn:defendersTools" role="doc-endnote">
      <p>Common offensive tools are often used as benchmarks when evaluating security products or services. A SOC team or an EDR not able to detect them is at least a waste of money. <a href="#fnref:defendersTools" class="reversefootnote" role="doc-backlink">&#8617;</a></p>
    </li>
  </ol>
</div>]]></content><author><name>{&quot;name&quot;=&gt;&quot;&quot;, &quot;avatar&quot;=&gt;&quot;/assets/images/avatar-round.svg&quot;, &quot;bio&quot;=&gt;&quot;Cyber Threat Intelligence. Allegedly.&quot;, &quot;links&quot;=&gt;[{&quot;label&quot;=&gt;&quot;Twitter&quot;, &quot;icon&quot;=&gt;&quot;fab fa-fw fa-twitter-square&quot;, &quot;url&quot;=&gt;&quot;https://twitter.com/4rchib4ld&quot;}, {&quot;label&quot;=&gt;&quot;GitHub&quot;, &quot;icon&quot;=&gt;&quot;fab fa-fw fa-github&quot;, &quot;url&quot;=&gt;&quot;https://github.com/4rchib4ld&quot;}, {&quot;label&quot;=&gt;&quot;LinkedIn&quot;, &quot;icon&quot;=&gt;&quot;fab fa-fw fa-linkedin&quot;, &quot;url&quot;=&gt;&quot;https://www.linkedin.com/in/axel-z-9a9a38117/&quot;}]}</name></author><category term="Blog" /><category term="analysis" /><category term="opinion" /><summary type="html"><![CDATA[Cybercriminals and nation-state actors are converging on the same TTPs—not because they collaborate, but because efficiency is universal. They're all playing the META.]]></summary></entry><entry><title type="html">Beyond the Wiper — What Unit42’s Iran Analysis Misses</title><link href="https://plausible-deniability.co/blog/BeyondWiper/" rel="alternate" type="text/html" title="Beyond the Wiper — What Unit42’s Iran Analysis Misses" /><published>2026-03-19T00:00:00+01:00</published><updated>2026-03-19T00:00:00+01:00</updated><id>https://plausible-deniability.co/blog/BeyondWiper</id><content type="html" xml:base="https://plausible-deniability.co/blog/BeyondWiper/"><![CDATA[<p>Unit42 published an interesting article<sup id="fnref:1" role="doc-noteref"><a href="#fn:1" class="footnote" rel="footnote">1</a></sup> this week about the evolution of Iranian cyber capabilities. It makes a good overview of wipers allegedly used by Iran since 2012 and their reliance on administrative tools. While Unit42 focuses on the technical progression, this article explores the strategic and geopolitical drivers behind Iran’s cyber operations.</p>

<p>A quick note: In the following article, I refer directly to Iran, rather than specific entities such as MOIS or IRGC. I believe that it makes the reading easier, without altering the statements. For a deeper dive into the ecosystem, I recommend to read Sekoia’s overview, from which I also used for reference.<sup id="fnref:2" role="doc-noteref"><a href="#fn:2" class="footnote" rel="footnote">2</a></sup></p>

<h2 id="stuxnet-the-wake-up-call">Stuxnet: The Wake-Up Call</h2>

<p>First, the development of Iranian cyber capabilities and their usage should be understood as a direct result of lessons learned from Stuxnet. Right from the start, Iran has been the target of two of the biggest cyber powers in the world. And Iran considers them both their arch enemies. Stuxnet tried to disrupt Iran’s nuclear program, a strategic asset, potentially military in nature. Stuxnet also sent a message to every country in the world: cyber can be used to achieve kinetic objectives and it is considered fair game. The impact on Iran’s thinking about cyber is unknown for sure, but what is clear is that they understood what can be done with it, and worked on it<sup id="fnref:3" role="doc-noteref"><a href="#fn:3" class="footnote" rel="footnote">3</a></sup>. The same can be said about other major players, mainly China.</p>

<h2 id="cyber-attack-as-retaliation">Cyber attack as retaliation</h2>

<p>Iran was not trying to use cyber attacks only as a plausible deniable tool, but also as both a weapon and a message. The first reported usage of Shamoon in August 2012 against Saudi Aramco—Saudi Arabia’s state owned oil company—happens right after a cyberattack on Iran’s oil terminals on April 2012<sup id="fnref:4" role="doc-noteref"><a href="#fn:4" class="footnote" rel="footnote">4</a></sup>. There is no official statement linking the two events, but it is hard not to see a possible retaliation. The attack on Iran’s oil terminals was thought to be carried out by the U.S., and a retaliation against one of their biggest allies, Saudi Arabia, on the same sector can be interpreted as a response in kind. If Iran needs more stealth, it could use it too.</p>

<p>Iran was—or at least tried to be—stealthy. The original article omits all espionage activities attributed to Iran, whether they are domestic or abroad. The first documented campaign is from 2007, so 5 years before the Shamoon attack. It was somehow stealthy because it did not get publicly reported until 2016<sup id="fnref:5" role="doc-noteref"><a href="#fn:5" class="footnote" rel="footnote">5</a></sup>. APT35, APT42, Infy, MuddyWater or Oilrig deserves mention when discussing Iran’s cyber capabilities because they were developed alongside wipers and information warfare, not in isolation.</p>

<p>Iran can also use its wide network of proxies to at least avoid direct attribution. For instance, the BiBi wiper is reported to be used by a “Pro-Hamas” group, but Check Point Research has assessed Void Manticore, an Iran-linked group, as the actor behind BiBi<sup id="fnref:6" role="doc-noteref"><a href="#fn:6" class="footnote" rel="footnote">6</a></sup>. The same can be said about Handala and other persona: they first appear as legitimate Palestinian group, but turned out to be operated by Iran’s Ministry of Intelligence and Security (MOIS) according to Check Point Research<sup id="fnref:7" role="doc-noteref"><a href="#fn:7" class="footnote" rel="footnote">7</a></sup>. Iran might even—if it is not already the case— give them tools and methodologies to carry out cyber attacks like they give them weapons and cash, making attribution even more challenging.</p>

<p>While visibility has played a role in some Iranian cyber operations, Unit42’s framing this as a priority over stealth overlooks Iran’s parallel investments in espionage and proxy networks. The truth is more nuanced: Iran’s cyber strategy is context-dependent, balancing overt retaliation with covert influence and intelligence gathering.</p>

<h2 id="adaptation-over-innovation-irans-cyber-pragmatism">Adaptation Over Innovation: Iran’s Cyber Pragmatism</h2>

<p>Iran has already introduced plausible deniability in their cyber operation since at least 2007 with their first espionage campaign. So ransomware was not that much of a smokescreen. This is not to say that it was not used in that way in some occurrences. But again, it needs a bit of context.</p>

<p>The 2020-2022 period was a big boom for ransomware activities: infrastructures needed to adapt to COVID restrictions and the state of crypto meant that it was easier to get paid with it than it was a decade ago. Groups started to emerge, cause mayhem and gain a lot of money: more than $1 billion in payments reported in the U.S. only in the period 2020-2021<sup id="fnref:8" role="doc-noteref"><a href="#fn:8" class="footnote" rel="footnote">8</a></sup>. Not only cybercriminals were interested.</p>

<p>It was a golden opportunity for some states: you can attack the western economy, and make some money at the same time. This is not lost on countries that were under heavy sanctions from the West, mainly Iran and North Korea. Iran-aligned actors did engage in ransomware operations, and not only as a <em>plausible deniability</em> cover<sup id="fnref:8:1" role="doc-noteref"><a href="#fn:8" class="footnote" rel="footnote">8</a></sup> <sup id="fnref:9" role="doc-noteref"><a href="#fn:9" class="footnote" rel="footnote">9</a></sup>. Other states, like Russia and China, adopt a more hands-off approach, allowing domestic hackers to operate with minimal oversight—sometimes benefiting from their actions while avoiding direct responsibility. Just as Iran adapted to the ransomware boom, it also capitalized on the growing reliance on administrative tools.</p>

<p>Administrative tools and EDR solutions did not exist, or not widely used in the previous decade. Now, they are powerful solutions for any IT department handling an infrastructure. It is also a great gift for threat actors, as MDM/RMM tools literally holds the key to the kingdom. Back in the day, you had to find a way to access the network, map it, make lateral movement and privilege escalation, until you are satisfied and launch your attack with your signature wiper. That’s a lot of things to do, and a lot of detection opportunities, and a good EDR might catch it.</p>

<p>Now, threat actors just have to find a way to get the RMM administrator account and type a small set of commands. No need for custom development, and less room for attribution. It makes detection significantly harder, as activity can blend with legitimate administrative operations. Iran evolved its cyber capabilities and interest accordingly, which shows that they are well aware of their environment. It also highlights that Iran’s cyber strategy is less about innovation than about pragmatic adaptation to constraints and opportunities. Economic constraints likely reinforced Iran’s preference for cost-effective, high-impact cyber operations.</p>

<h2 id="conclusion">Conclusion</h2>

<p>The conclusion of Unit42’s article is hard to dispute, defenders should take a very close look at their identity management and the rights they give to administrative tools. If they fall in the wrong hands, it could be a catastrophe. Unit42’s warning about identity weaponization is valid and urgent. However, by focusing solely on this tactical shift, we risk losing sight of the broader strategic picture: Iran’s cyber operations are not just about tools but about adapting to achieve long-term geopolitical goals. Iran-aligned actors didn’t just adopt ransomware as a smokescreen—they leveraged it as a dual-purpose tool, blending financial gain with strategic disruption. This adaptability reflects a broader pattern: Iran’s cyber operations evolve in response to environmental opportunities, such as the rise of cryptocurrency or the proliferation of administrative tools. Understanding Iran’s cyber operations requires looking beyond tools and tactics to the strategic logic that drives their use.</p>

<p><strong>References</strong></p>

<div class="footnotes" role="doc-endnotes">
  <ol>
    <li id="fn:1" role="doc-endnote">
      <p>https://unit42.paloaltonetworks.com/evolution-of-iran-cyber-threats/ <a href="#fnref:1" class="reversefootnote" role="doc-backlink">&#8617;</a></p>
    </li>
    <li id="fn:2" role="doc-endnote">
      <p>https://blog.sekoia.io/iran-cyber-threat-overview/ <a href="#fnref:2" class="reversefootnote" role="doc-backlink">&#8617;</a></p>
    </li>
    <li id="fn:3" role="doc-endnote">
      <p>https://www.atlanticcouncil.org/blogs/new-atlanticist/iran-s-growing-cyber-capabilities-in-a-post-stuxnet-era/ <a href="#fnref:3" class="reversefootnote" role="doc-backlink">&#8617;</a></p>
    </li>
    <li id="fn:4" role="doc-endnote">
      <p>https://www.nytimes.com/2012/04/24/world/middleeast/iranian-oil-sites-go-offline-amid-cyberattack.html <a href="#fnref:4" class="reversefootnote" role="doc-backlink">&#8617;</a></p>
    </li>
    <li id="fn:5" role="doc-endnote">
      <p>https://unit42.paloaltonetworks.com/prince-of-persia-infy-malware-active-in-decade-of-targeted-attacks/ <a href="#fnref:5" class="reversefootnote" role="doc-backlink">&#8617;</a></p>
    </li>
    <li id="fn:6" role="doc-endnote">
      <p>https://research.checkpoint.com/2024/bad-karma-no-justice-void-manticore-destructive-activities-in-israel/ <a href="#fnref:6" class="reversefootnote" role="doc-backlink">&#8617;</a></p>
    </li>
    <li id="fn:7" role="doc-endnote">
      <p>https://research.checkpoint.com/2026/handala-hack-unveiling-groups-modus-operandi/ <a href="#fnref:7" class="reversefootnote" role="doc-backlink">&#8617;</a></p>
    </li>
    <li id="fn:8" role="doc-endnote">
      <p>https://home.treasury.gov/news/press-releases/jy0948 <a href="#fnref:8" class="reversefootnote" role="doc-backlink">&#8617;</a> <a href="#fnref:8:1" class="reversefootnote" role="doc-backlink">&#8617;<sup>2</sup></a></p>
    </li>
    <li id="fn:9" role="doc-endnote">
      <p>https://www.bleepingcomputer.com/news/security/n3tw0rm-ransomware-emerges-in-wave-of-cyberattacks-in-israel/ <a href="#fnref:9" class="reversefootnote" role="doc-backlink">&#8617;</a></p>
    </li>
  </ol>
</div>]]></content><author><name>{&quot;name&quot;=&gt;&quot;&quot;, &quot;avatar&quot;=&gt;&quot;/assets/images/avatar-round.svg&quot;, &quot;bio&quot;=&gt;&quot;Cyber Threat Intelligence. Allegedly.&quot;, &quot;links&quot;=&gt;[{&quot;label&quot;=&gt;&quot;Twitter&quot;, &quot;icon&quot;=&gt;&quot;fab fa-fw fa-twitter-square&quot;, &quot;url&quot;=&gt;&quot;https://twitter.com/4rchib4ld&quot;}, {&quot;label&quot;=&gt;&quot;GitHub&quot;, &quot;icon&quot;=&gt;&quot;fab fa-fw fa-github&quot;, &quot;url&quot;=&gt;&quot;https://github.com/4rchib4ld&quot;}, {&quot;label&quot;=&gt;&quot;LinkedIn&quot;, &quot;icon&quot;=&gt;&quot;fab fa-fw fa-linkedin&quot;, &quot;url&quot;=&gt;&quot;https://www.linkedin.com/in/axel-z-9a9a38117/&quot;}]}</name></author><category term="Blog" /><category term="attribution" /><category term="analysis" /><category term="iran" /><category term="opinion" /></entry><entry><title type="html">Nothing but dotnet when we shoot</title><link href="https://plausible-deniability.co/blog/Nothing-but-dotnet-when-we-shoot/" rel="alternate" type="text/html" title="Nothing but dotnet when we shoot" /><published>2022-11-20T00:00:00+01:00</published><updated>2022-11-20T00:00:00+01:00</updated><id>https://plausible-deniability.co/blog/Nothing-but-dotnet-when-we-shoot</id><content type="html" xml:base="https://plausible-deniability.co/blog/Nothing-but-dotnet-when-we-shoot/"><![CDATA[<p>While doing some threat hunting, I pivoted to a range of domains. Every time there was a .NET delivered by one of this domain, I already knew it was a RAT/Stealer type of malware. Because I love to ask dumb questions on the internet to understand the world better, <a href="https://twitter.com/4rchib4ld/status/1593288968828817414">I asked why is that so</a>. The rest of this blog post will be around the question of the development of malware in .NET.</p>

<h1 id="first-of-all-what-is-net-">First of all, what is .NET ?</h1>

<p><img src="/assets/images/Drawing 2022-11-19 17.32.00.excalidraw.png" alt="" /></p>

<ul>
  <li>C# programs run on <strong>.NET</strong>, a virtual execution system called the <strong>common language runtime (CLR)</strong> and a set of class libraries. The CLR is the implementation by Microsoft of the <strong>common language infrastructure (CLI)</strong>, an international standard. The CLI is the basis for creating execution and development environments in which languages and libraries work together seamlessly.</li>
  <li>Source code written in C# is compiled into an <a href="https://learn.microsoft.com/en-us/dotnet/standard/managed-code">intermediate language (IL)</a> that conforms to the CLI specification.</li>
  <li>When the C# program is executed, the assembly is loaded into the CLR. The CLR performs Just-In-Time (JIT) compilation to convert the IL code to native machine instructions. The CLR provides other services related to automatic garbage collection, exception handling, and resource management. Code that’s executed by the CLR is sometimes referred to as “managed code.” “Unmanaged code,” is compiled into native machine language that targets a specific platform.</li>
</ul>

<h2 id="more-on-c">More on C#</h2>
<blockquote>
  <p>C# is an object-oriented, <em><strong>component-oriented</strong></em> programming language. C# provides language constructs to directly support these concepts, making C# a natural language in which to create and use software components. Since its origin, C# has added features to support new workloads and emerging software design practices. At its core, C# is an <em><strong>object-oriented</strong></em> language. You define types and their behavior.</p>
</blockquote>

<ul>
  <li>Some of the cool features that C# has a program language includes :
    <ul>
      <li><strong>Garbage Collection</strong> : automatically reclaims memory occupied by unreachable unused objects</li>
      <li><strong>Nullable Types</strong> : guard against variables that don’t refer to allocated objects</li>
      <li><strong>Exception Handling</strong> : provides a structured and extensible approach to error detection and recovery.</li>
      <li><strong>Lambda Expressions</strong> : support functional programming techniques</li>
      <li><strong>Language Integrated Query</strong> : syntax creates a common pattern for working with data from any source</li>
      <li><strong>Support Asynchronous Operations</strong> : provides syntax for building distributed systems.</li>
      <li>C# allows dynamic allocation of objects and in-line storage of lightweight structures.
        <ul>
          <li>C# supports generic methods and types, which provide increased type safety and performance. C# provides iterators, which enable implementers of collection classes to define custom behaviors for client code.</li>
        </ul>
      </li>
    </ul>
  </li>
</ul>

<p>That’s for the managed code part. C# also allows the code to be unmanaged. You see all the features I listed above ? You can still say, screw this, I’m going to do it my own way. Unmanaged code doesn’t run inside the CLR and thus are considered <em>unsafe</em>.</p>

<p class="notice--info">💡 : There is a <a href="https://learn.microsoft.com/en-us/dotnet/core/deploying/native-aot/">functionnality</a> called <strong>Ahead Of Time</strong> that compiles the code directly to native code and doesn’t need the JIT compiler to run while still being managed code. It’s brand new in .NET7 !
	- It only supports a limited number of libraries in .NET 7.</p>

<h1 id="c-in-the-context-of-malware">C# in the context of malware</h1>
<p>C# is very popular in malware. First because it’s an easy language with powerful features, as we have seen above. You can also have access to Windows functionality rather easily. With just these arguments, it’s easy to imagine why Threat Actors might be interested in this language. Even more when you take into account the amount of open-source code available to do what you want (even bad things, like a RAT).</p>

<p>The advantage of using C# is that you can easily implement functionality and modules and focus on evasion. To do so, Threat Actors use packing and/or obfuscation. For example, <a href="https://malpedia.caad.fkie.fraunhofer.de/details/win.agent_tesla">AgentTesla</a> (of course it’s a RAT) can look like this :</p>

<p><img src="/assets/images/Pasted image 20221102155131.png" alt="" />
You can read a cool AgentTesla Analysis <a href="https://t.co/Wjx4wFxdvj">here</a> if you are interested to see packing/obfuscation in action</p>

<p>Moreover, Threat Actors can even leverage specific .NET functionalities.
If you did the FlareOn 9, for your greatest pleasure, you had to deal with two .NET challenges. They are both inspired by real world malwares and abuses <a href="https://www.mandiant.com/sites/default/files/2022-11/06-alamode.pdf">Mixed Mode Assemblies</a> and <a href="https://www.mandiant.com/sites/default/files/2022-11/08-backdoor.pdf">Dynamic Methods</a>.</p>

<h2 id="net-reverse-engineering">.NET Reverse Engineering</h2>

<p>As we saw, .NET malware can be hard to work with, because of the various mechanisms Threat Actors uses. But they do so because .NET by design is rather easy to analyze.
Remember the schema I did just before? We can actually decompile the generated executable with awesome tools like DnSpy.</p>

<p class="notice--info">💡 :Just to be exact, when using .NET decompilers we see <em>decompiled code</em> based on the IL, so be aware that Threat Actors might modify the IL directly.</p>

<p><img src="/assets/images/Csharp 2022-11-19 22.11.04.excalidraw.png" alt="" /></p>

<p>By default, .NET executable also contains a lot of metadata. My favorite one is the GUIDs. It’s an awesome pivot to try, you might find APT related code well hidden on GitHub (just imagine…). You can read more about them <a href="https://www.virusbulletin.com/virusbulletin/2015/06/using-net-guids-help-hunt-malware/#citation.3">here</a>. VirusTotal also implement them, and you can pivot directly from there !</p>

<h2 id="going-further">Going further</h2>

<p>If you are interested in .NET analysis, I can’t recommend enough <a href="https://media.defcon.org/DEF%20CON%2027/DEF%20CON%2027%20presentations/DEFCON-27-Alexandre-Borges-dotNET-Malware-Threats.pdf">this paper</a> from <a href="https://twitter.com/ale_sp_brazil">Alexandre Borges</a>
There is also interesting people on Twitter :</p>
<ul>
  <li><a href="https://twitter.com/dr4k0nia">@dr4k0nia</a></li>
  <li><a href="https://twitter.com/washi_dev">@washi_dev</a></li>
  <li><a href="https://twitter.com/vinopaljiri">@vinopaljiri</a></li>
</ul>

<h1 id="conclusion">Conclusion</h1>
<p>I was really surprised with the engagement of my <em>dumb</em> question, and I thought that it could be interesting to compile (pun intended) everything that was said and add some more information. Doing a blog post is easier than replying to all conversations. Let me know if you found this interesting. I know I haven’t been that deep into .NET shenanigans, but others already explained everything</p>]]></content><author><name>{&quot;name&quot;=&gt;&quot;&quot;, &quot;avatar&quot;=&gt;&quot;/assets/images/avatar-round.svg&quot;, &quot;bio&quot;=&gt;&quot;Cyber Threat Intelligence. Allegedly.&quot;, &quot;links&quot;=&gt;[{&quot;label&quot;=&gt;&quot;Twitter&quot;, &quot;icon&quot;=&gt;&quot;fab fa-fw fa-twitter-square&quot;, &quot;url&quot;=&gt;&quot;https://twitter.com/4rchib4ld&quot;}, {&quot;label&quot;=&gt;&quot;GitHub&quot;, &quot;icon&quot;=&gt;&quot;fab fa-fw fa-github&quot;, &quot;url&quot;=&gt;&quot;https://github.com/4rchib4ld&quot;}, {&quot;label&quot;=&gt;&quot;LinkedIn&quot;, &quot;icon&quot;=&gt;&quot;fab fa-fw fa-linkedin&quot;, &quot;url&quot;=&gt;&quot;https://www.linkedin.com/in/axel-z-9a9a38117/&quot;}]}</name></author><category term="Blog" /><category term="ReverseEngineering" /><category term="MalwareAnalysis" /><summary type="html"><![CDATA[Little talk about dotnet and its use in malware]]></summary></entry><entry><title type="html">It’s getting hot in here</title><link href="https://plausible-deniability.co/ctf/Barbahack2022-Satan/" rel="alternate" type="text/html" title="It’s getting hot in here" /><published>2022-08-29T00:00:00+02:00</published><updated>2022-08-29T00:00:00+02:00</updated><id>https://plausible-deniability.co/ctf/Barbahack2022-Satan</id><content type="html" xml:base="https://plausible-deniability.co/ctf/Barbahack2022-Satan/"><![CDATA[<h1 id="intro">Intro</h1>

<p>I went to the CTF with a new laptop, and so I didn’t have everything setup. It means that I didn’t have a Windows VM available, so no dynamic analysis for me !
It’s fine, I tend to prefer analysing stastically because it forces you to understand deeply what’s going on, instead of just watching the stack/registers for a string !</p>

<p>I also take this opportunity to showcase how I use Ghidra to give a more detailed analysis.</p>

<p>So, let’s analyse this little malware, shall we ?</p>

<h1 id="analysis">Analysis</h1>

<blockquote>
  <p><code class="language-plaintext highlighter-rouge">Satan helped me to create a new malware :), finding what it does will lead you to the flag !</code></p>
</blockquote>

<p>As it’s a CTF challenge, I didn’t do the usual MD5/SHA reconnaissance, I opened it straight into Ghidra.</p>

<p>The beginning of the functions looks like this :</p>

<p><img src="/assets/images/bb_satan_entry.png" alt="" /></p>

<p>A lot of things is happening, but we don’t really care : most of it is the CRT making various checks.</p>

<p>What we want to look further is <code class="language-plaintext highlighter-rouge">FUN_140001c00</code></p>

<p><img src="/assets/images/bb_first.png" alt="" /></p>

<p>We got two things going on :</p>
<ul>
  <li>A function that uses the GS register and the unicode for “ntdll.dll”</li>
  <li>Another function that uses the return value from the first function</li>
</ul>

<p class="notice--info">💡 : FS and GS are two segments registers. You can use the FS register on Windows 32-bit to access the TEB, and the GS register for Windows 64-bit.
You can read more about segment registers and why they aren’t used anymore here : https://stackoverflow.com/questions/10810203/what-is-the-fs-gs-register-intended-for</p>

<p>So now that we know that the in_GS_OFFSET relates to the TEB, we just need to know what the <code class="language-plaintext highlighter-rouge">0x60</code> offset relates to. We have the answer <a href="https://www.geoffchappell.com/studies/windows/km/ntoskrnl/inc/api/pebteb/teb/index.htm?tx=219">here</a> : 0x60 offset points to the PEB</p>

<p>So the two parameters for the function FUN_140001000 are actually :</p>
<ul>
  <li>unicode “ntdll.dll”</li>
  <li>PEB</li>
</ul>

<p><img src="/assets/images/2022-08-29-Barbahack2022-Satan.md.png" alt="" /></p>

<p>With that information, it makes it easier to understand what’s going on here : This functions searches for the ntdll base address by enumerating the <em>InMemoryOrderModuleList</em>.</p>

<p>Going back to the calling function, we understand it deeper :
<img src="/assets/images/done_entrypoint-Barbahack2022-Satan.md.png" alt="" /></p>

<p>With that in mind, we can move forward to the second function. In it, we can see what looks like stack-strings, and a function called several times with some arguments not changing :</p>

<p><img src="/assets/images/ss_before-Barbahack2022-Satan.png" alt="" /></p>

<p>Looking into this function, it’s what we got :</p>

<p><img src="/assets/images/xor_func-Barbahack2022-Satan.png" alt="" /></p>

<p>It’s a simple xor decryption routine. A little clean-up :</p>

<p><img src="/assets/images/clean_xor-Barbahack2022-Satan.png" alt="" /></p>

<p class="notice--info">💡 : Little tip when dealing with stackstring in Ghidra, once you know the size of the data, assign it as an array. For example, <code class="language-plaintext highlighter-rouge">local_60</code> seems to have a size of 24, as we can see in the xor_decode function. Retyping the variable to a byte[24] give an easier way to visualize :</p>

<p><img src="/assets/images/local60-Barbahack2022-Satan.png" alt="" /></p>

<p><img src="/assets/images/retype_var-Barbahack2022-Satan.png" alt="" /></p>

<p>Now we can decode the variables with the xor key <code class="language-plaintext highlighter-rouge">0x7861786f</code> which gives us :</p>
<ul>
  <li><strong>NtAllocateVirtualMemory</strong></li>
  <li><strong>NtWriteVirtualMemory</strong></li>
  <li><strong>NtCreateThreadEx</strong></li>
  <li><strong>NtWaitForSingleObject</strong></li>
</ul>

<p>You might have see it, but one decryption uses a different key than the rest. Decoding it, it isn’t a string… What can this be ? We will check it later.</p>

<p>I forgot to ask : with the API names we just decrypted and the description of the challenge, did you found what’s next ? No ? Let’s continue and see what happens.</p>

<p>The API names are used as parameters for two functions after their decryption: <code class="language-plaintext highlighter-rouge">FUN_14000010f0</code> and <code class="language-plaintext highlighter-rouge">FUN_140001200</code></p>

<p><img src="/assets/images/table_entry_Barbahack2022-Satan.png" alt="" />
<code class="language-plaintext highlighter-rouge">FUN_14000010f0</code></p>

<p>We can see here that <code class="language-plaintext highlighter-rouge">FUN_14000010f0</code> looks in NTDLL Export Directory for the address of the function passed as the third parameter.</p>

<p><img src="/assets/images/check_entrypoint-Barbahack2022-Satan.png" alt="" /></p>

<p><code class="language-plaintext highlighter-rouge">FUN_140001200</code> then looks at the retrieved address and validates that it’s a syscall stub.</p>

<p>Wait, syscall I said ? With those APIs, what we just saw and the description, we have enough clues to understand what’s going on : It’s an implentation of Hell’s Gate !</p>

<p>If you don’t know about Hell’s Gate, it’s a technique used to bypass EDR hooks.
If you want to dig deeper into Hell’s Gate and/or EDR bypass, be sure to check this <a href="https://alice.climent-pommeret.red/posts/direct-syscalls-hells-halos-syswhispers2/">article</a> by <a href="https://twitter.com/AliceCliment">AliceCliment</a> as everything is beautifuly explained !</p>

<p>Here is little drawing of the inner working of the program :</p>

<p><img src="/assets/images/excalidraw-Barbahack2022-Satan.png" alt="" /></p>

<p>Now we just need to decrypt the payload and understand what it does in order to find the flag !</p>

<p>I have done it using <a href="https://gchq.github.io/CyberChef/#recipe=From_Hex('Auto')XOR(%7B'option':'Hex','string':'0x5a64767a33324c6158564d586b42'%7D,'Standard',false)&amp;input=MHgxNzU3OWIzYjY2N2JmMDE4MTUzYWFmMzM4YWZiMjUyZGM4NjEwYzNjZDU0MmZlY2U0ZjE1NThhNDFiMzAzYWYxZDc3MzEwMjAwNDk1">this cyberchef recipe</a>. The output is the shellcode we want.</p>

<p>Opening it in Ghidra, and manually disassemble gives this :</p>

<p><img src="/assets/images/shellcode_Barbahack2022-Satan.png" alt="" /></p>

<p>Be careful, you can’t XOR decode this one in Cyberchef. To do so I used this python one liner :</p>

<p><code class="language-plaintext highlighter-rouge">&gt;&gt;&gt;bytes.fromhex(hex(0x7fb9e16be26c4d79 ^ 0x298a623990e3f1b)[2:]).decode('utf-8')[::-1]</code></p>

<p><code class="language-plaintext highlighter-rouge">'brb{HG!}'</code></p>

<p>And here we go ! We got our flag !</p>

<h2 id="wrapping-up">Wrapping up</h2>

<p>I really liked this challenge. First because it wasn’t a crackme like often in the Reverse category, and more interesting it’s a technique I haven’t reversed yet so it’s pretty cool !</p>]]></content><author><name>{&quot;name&quot;=&gt;&quot;&quot;, &quot;avatar&quot;=&gt;&quot;/assets/images/avatar-round.svg&quot;, &quot;bio&quot;=&gt;&quot;Cyber Threat Intelligence. Allegedly.&quot;, &quot;links&quot;=&gt;[{&quot;label&quot;=&gt;&quot;Twitter&quot;, &quot;icon&quot;=&gt;&quot;fab fa-fw fa-twitter-square&quot;, &quot;url&quot;=&gt;&quot;https://twitter.com/4rchib4ld&quot;}, {&quot;label&quot;=&gt;&quot;GitHub&quot;, &quot;icon&quot;=&gt;&quot;fab fa-fw fa-github&quot;, &quot;url&quot;=&gt;&quot;https://github.com/4rchib4ld&quot;}, {&quot;label&quot;=&gt;&quot;LinkedIn&quot;, &quot;icon&quot;=&gt;&quot;fab fa-fw fa-linkedin&quot;, &quot;url&quot;=&gt;&quot;https://www.linkedin.com/in/axel-z-9a9a38117/&quot;}]}</name></author><category term="CTF" /><category term="ReverseEngineering" /><category term="MalwareAnalysis" /><summary type="html"><![CDATA[WriteUp of the satan challenge from Barbhack 2022]]></summary></entry><entry><title type="html">Turla, the Snake of Attribution</title><link href="https://plausible-deniability.co/blog/TurlaSnakeOfAttribution/" rel="alternate" type="text/html" title="Turla, the Snake of Attribution" /><published>2022-04-29T00:00:00+02:00</published><updated>2022-04-29T00:00:00+02:00</updated><id>https://plausible-deniability.co/blog/TurlaSnakeOfAttribution</id><content type="html" xml:base="https://plausible-deniability.co/blog/TurlaSnakeOfAttribution/"><![CDATA[<h1 id="turla-the-snake-of-attribution">Turla, the Snake of Attribution</h1>

<p>Turla (also known as <a href="https://malpedia.caad.fkie.fraunhofer.de/actor/turla_group">Snake and more</a>) is one of the oldest espionnage group known so far. Activities from the Turla group are known since 2006. They are believed to be a Russian State Sponsored group, with interests in Governments, Military and Press.</p>

<p>What is pellicular about Turla is their capabilities and also their behavior regarding attribution. Throughout this article, we are gonna explore it in more details.</p>

<h2 id="technical-geniuses-but-also-morons">Technical geniuses… But also morons</h2>

<p>Turla is known for having a strong technical side. Even if they also uses open source tools (like everyone else), they also develops their own exploits and their malwares are hard to analyze, with heavy use of obfuscation and unknown windows functions.</p>

<p>Throughout the years, Turla campaigns revealed themselves as sophisticated.
They were able to leverage a <a href="https://www.welivesecurity.com/wp-content/uploads/2019/05/ESET-LightNeuron.pdf">Microsoft Exchange Transport Agent to enable persistence on a mail server</a> with LightNeuron, used at least two zero days on the <a href="https://securelist.com/the-epic-turla-operation/65545/">Epic Turla campaign</a>, <a href="https://www.virusbulletin.com/virusbulletin/2014/05/anatomy-turla-exploits/">bypassed driver enforcement</a> and lastly being able to do (supposedly) <a href="https://www.botconf.eu/wp-content/uploads/2018/12/2018-m-faou-j-i-boutin-turla.pdf">MITM attack at the ISP level</a>.
Moreover, they are creative with their TTPs, for instance with the Satellite Turla campaigns (also called MAKERSMARK), where they <a href="https://securelist.com/satellite-turla-apt-command-and-control-in-the-sky/72081/">hijacked satellite internet links</a> (http://blog.passivetotal.org/snakes-in-the-satellites-on-going-turla-infrastructure/).</p>

<p><img src="/assets/images/20220421174151.png" alt="" /></p>

<p>An interesting thing about the satellite Turla campaign is a leaked Canadian Intelligence document, which explains that despite having a highly sophisticated technical side, the OPSEC used by operators seems to be lacking: <a href="https://www.documentcloud.org/documents/3911739-hackers-are-humans-too-partial-redacted">They used compromised infrastructure for personnal browsing</a>. They even describe the campagne as “Designed by genius, implemented by morons”. This is not surprising, considering that APT ties with Intelligence Agencies is not that advanced, they don’t have access to all OPSEC knowledge and processes when doing operations.</p>

<h2 id="you-try-to-false-flags">You try to false flags</h2>

<p>APT groups would rather avoid being detected than misdirect attribution. That’s not really the case with Turla. They are stealthy, but won’t hesistate to cover their tracks by impersonnate another group. We will see two campaigns attributed to Turla that showcase this.</p>

<h3 id="made-in-china-or-not">Made in China… Or not</h3>

<p>In 2012, during an intrusion Turla became aware that they were detected and an IR team was looking for them. They decided to plant a false flag by downloading, installing and desinstalling a malware attributed to a Chinese APT, known as <a href="https://www.darkreading.com/attacks-breaches/russia-based-turla-apt-group-s-infrastructure-activity-traceable">Quarian</a>. It was even more clever than this, because the C2 that they used during this operation was also based in China, to further throw the responders on the wrong road.
However, the planted sample wasn’t even configured and wasn’t used in the operation. The analysts figured out that it was most likely to disturb them and that Turla had just copied this sample from elsewhere.</p>

<h3 id="iranian-take-over">Iranian Take over</h3>

<p>The Middle East is a area of interest for both Iran and Russia. There is no surprise to see them actively operates there. However, what is unusual is the fact that Turla used two Iranian malwares for their operations. They got access to the source code of two malwares (Nautilus and Neuron) and used them as their own. What they didn’t know it that neither of them was previously identified nor attributed to Iran. <a href="https://www.ncsc.gov.uk/news/turla-group-exploits-iran-apt-to-expand-coverage-of-victims">They were only seen with Turla operation</a>.</p>

<p>But it goes deeper than this. In fact it seems that Turla was able to <a href="https://www.ncsc.gov.uk/news/turla-group-exploits-iran-apt-to-expand-coverage-of-victims">completly overtake the Iranian infrastructure and used it for their own operations</a>
It’s the only occurence of an <a href="https://www.computerweekly.com/news/252479984/turlas-use-of-iranian-infrastructure-probably-opportunistic">APT completly taking over another one</a></p>

<h2 id="conclusion">Conclusion</h2>

<p>Turla is a really interesting threat actor by their use of capabilities and the way they play around attribution. As always with attributing incidents and campaigns to a specific threat actor, it’s a tricky exercice done by security companies. It’s never a declaration, but an assessment based on attributes that can (and must) be reexamined in the future.</p>]]></content><author><name>{&quot;name&quot;=&gt;&quot;&quot;, &quot;avatar&quot;=&gt;&quot;/assets/images/avatar-round.svg&quot;, &quot;bio&quot;=&gt;&quot;Cyber Threat Intelligence. Allegedly.&quot;, &quot;links&quot;=&gt;[{&quot;label&quot;=&gt;&quot;Twitter&quot;, &quot;icon&quot;=&gt;&quot;fab fa-fw fa-twitter-square&quot;, &quot;url&quot;=&gt;&quot;https://twitter.com/4rchib4ld&quot;}, {&quot;label&quot;=&gt;&quot;GitHub&quot;, &quot;icon&quot;=&gt;&quot;fab fa-fw fa-github&quot;, &quot;url&quot;=&gt;&quot;https://github.com/4rchib4ld&quot;}, {&quot;label&quot;=&gt;&quot;LinkedIn&quot;, &quot;icon&quot;=&gt;&quot;fab fa-fw fa-linkedin&quot;, &quot;url&quot;=&gt;&quot;https://www.linkedin.com/in/axel-z-9a9a38117/&quot;}]}</name></author><category term="Blog" /><category term="ThreatIntelligence" /><summary type="html"><![CDATA[How Turla tries to avoid attribution]]></summary></entry><entry><title type="html">Tomorrow night ? Honeymoon on Ice(loader) ?</title><link href="https://plausible-deniability.co/blog/HoneymoonOnIceloader/" rel="alternate" type="text/html" title="Tomorrow night ? Honeymoon on Ice(loader) ?" /><published>2021-05-14T00:00:00+02:00</published><updated>2021-05-14T00:00:00+02:00</updated><id>https://plausible-deniability.co/blog/HoneymoonOnIceloader</id><content type="html" xml:base="https://plausible-deniability.co/blog/HoneymoonOnIceloader/"><![CDATA[<p>If you read my blog post religiously, you may have spotted in the <a href="https://4rchib4ld.github.io/blog/IcedIDOnMyNeckImTheCoolest/">article I made about unpacking IcedID</a> that I mentioned that I couldn’t find an automated way to unpack it, and it made me sad.
And what do we do when we are sad ? Yeah, we work on Malware stuff.</p>

<h2 id="lets-get-technical">Let’s get technical</h2>

<p>I tried a couple of things, without much success. The packer uses A LOOOOOOT of <code class="language-plaintext highlighter-rouge">for</code>and <code class="language-plaintext highlighter-rouge">while</code> loop, making it almost impossible for an emulator like <a href="https://github.com/qilingframework/qiling">Qiling</a> to run it. It also makes it harder to understand what is going on.
I let that sink, until one day, <a href="https://twitter.com/c3rb3ru5d3d53c">@c3rb3ru5d3d53c</a> showcased her new project :</p>

<p><img src="/assets/images/2021-05-14-16-34-12.png" alt="" /></p>

<p>I found it very cool, and she gave me a lead on how to proceed with my problem :</p>

<p><img src="/assets/images/2021-05-14-16-30-33.png" alt="" /></p>

<p>I never did this kind of thing, but it was about time !
First I needed to understand exactly how the packer proceed.</p>

<p class="notice--info">💡 : Because of how the code is made, I can’t really show interesting screenshots as execution is scattered in all places</p>

<p>It first loads two chunks of data from its PE sections. At the time of writing, there is three possibility :</p>
<ul>
  <li><code class="language-plaintext highlighter-rouge">.rdata</code> and</li>
  <li><code class="language-plaintext highlighter-rouge">.ndata</code> and <code class="language-plaintext highlighter-rouge">.data</code></li>
  <li><code class="language-plaintext highlighter-rouge">.data</code> (both chunks are inside)</li>
</ul>

<p>One chunk is actually the obfuscated/encrypted/encoded packed executable, the other one is only use during the decryption process.</p>

<p>Then the payload gets decoded, and decrypted using a hard-coded value (it’s the first 4 bytes of <code class="language-plaintext highlighter-rouge">.data</code> divided by 512, I also refer to it as “marker” when in the 3rd variant)
Afterward, there is an obfuscation that takes place, however the code changes between samples… How to overcome this ? Despite not being the same, the code <em>looks</em> the same, meaning I can catch the pattern with a <a href="https://github.com/4rchib4ld/iceloader-unpacker/blob/main/iceloader.yar">Yara rule</a>… Which I did.</p>

<p><img src="/assets/images/codeObfuscatrionVariants.png" alt="" />
<em>comparison of three code variants</em> \n</p>

<p>I get the code, and run it using <a href="https://www.unicorn-engine.org/">Unicorn</a> or <a href="https://github.com/qilingframework/qiling">Qiling</a>.</p>

<p class="notice--info">💡 : As a principle, I always prefer when computers handle the hard work</p>

<p>And here we are, at the final stage ! The second chunk of data is finally used to decrypt the packed executable.</p>

<h2 id="only-icedid-">Only IcedID ?</h2>

<p>When doing this research, I was focused on IcedID. To test my code on multiple samples I made a Yara Rule and a retro hunt using <a href="https://riskmitigation.ch/yara-scan/">Risk Mitigation</a>.</p>

<p class="notice--info">💡 : I couldn’t sell my whole family just to pay for VirusTotal… Sorry about this</p>

<p>Guess what I found ? Not <strong>only</strong> IcedID, but also Bazar, like one from <a href="https://pastebin.com/sCzPqLLb">this campaign</a>.</p>

<p>So either the packer is available for sale on some forums, or the two groups shares tools sometimes.</p>

<p>I couldn’t really find much more info on this, or maybe there is none available. Maybe you, who are reading this, have more info on the subject ! If so, do not hesitate to hit me up on Twitter !</p>

<h2 id="cleaning-our-hands-for-real-this-time">Cleaning our hands, for real this time</h2>

<p>That’s it, now we can really be clean, as I made three scripts in order to automate and make your life easier :</p>

<p>The first one is <a href="https://github.com/4rchib4ld/iceloader-unpacker">a python script</a>, as simple as that. It uses Unicorn for code emulation, and decrypt the IcedID config… If the unpacked executable is an IcedID sample, of course.</p>

<p>The second is a <a href="https://github.com/c3rb3ru5d3d53c/karton-unpacker">Karton Unpacker module</a>, so you can use it in your Karton pipeline.</p>

<p>The last one is a <a href="https://github.com/c3rb3ru5d3d53c/mwcfg">mwcfg module</a>, you can decrypt an IcedID sample config with it.</p>

<h2 id="conclusion">Conclusion</h2>

<p>And here we are. From what I know, it’s the only public work on Iceloader, so it’s like when you find a dinosaur species : you can name it whatever you want. It’s not really my idea, it came from <a href="https://twitter.com/c3rb3ru5d3d53c">@c3rb3ru5d3d53c</a>, but I like it. Otherwise I would have given it a Pokémon name (most likely <a href="https://bulbapedia.bulbagarden.net/wiki/Regice_(Pok%C3%A9mon)">Regice</a>).</p>

<p>Hope you liked what you just read, and also my work !
This was really fun to do, despite not making great advance every day, as I’m doing everything during my free time, so it’s like 1-2hours a day :(. But overall a really cool challenge !</p>]]></content><author><name>{&quot;name&quot;=&gt;&quot;&quot;, &quot;avatar&quot;=&gt;&quot;/assets/images/avatar-round.svg&quot;, &quot;bio&quot;=&gt;&quot;Cyber Threat Intelligence. Allegedly.&quot;, &quot;links&quot;=&gt;[{&quot;label&quot;=&gt;&quot;Twitter&quot;, &quot;icon&quot;=&gt;&quot;fab fa-fw fa-twitter-square&quot;, &quot;url&quot;=&gt;&quot;https://twitter.com/4rchib4ld&quot;}, {&quot;label&quot;=&gt;&quot;GitHub&quot;, &quot;icon&quot;=&gt;&quot;fab fa-fw fa-github&quot;, &quot;url&quot;=&gt;&quot;https://github.com/4rchib4ld&quot;}, {&quot;label&quot;=&gt;&quot;LinkedIn&quot;, &quot;icon&quot;=&gt;&quot;fab fa-fw fa-linkedin&quot;, &quot;url&quot;=&gt;&quot;https://www.linkedin.com/in/axel-z-9a9a38117/&quot;}]}</name></author><category term="Blog" /><category term="ThreatIntelligence" /><category term="MalwareAnalysis" /><summary type="html"><![CDATA[Write up about the packer used by multiple threat actors during the past few months]]></summary></entry></feed>