PULSE NAME
Iranian APT Infrastructure in Focus: Mapping State-Aligned Clusters During Geopolitical Escalation
WHITE MuddyWater AlienVault 2026-03-04 Modified: 2026-04-03
15
IOCs
MEDIUM VOLUME
The analysis examines Iranian state-aligned threat actors and their infrastructure patterns during heightened geopolitical tensions. It focuses on mapping network infrastructure, ASN patterns, TLS fingerprints, and hosting clusters associated with various Iranian APT groups. The report highlights the importance of proactive infrastructure monitoring to detect and disrupt potential cyber operations. Key findings include the identification of previously unreported hosts, domains, and servers linked to Iranian operations, as well as insights into the tactics used by groups like MuddyWater and Dark Scepter. The article emphasizes the value of infrastructure intelligence in early threat detection and provides recommendations for organizations to monitor and defend against these threats.
MITRE ATT&CK & Malware Families
ATT&CK TECHNIQUES
MALWARE FAMILIES
FMAPP.exe TameCat Foudre Tonnerre Sliver Tsundere
Indicators of Compromise (15)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256 domain
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 2533307ec1ef8b0611c8896e1460b076 2026-03-04
FileHash-SHA1 324918c73b985875d5f974da3471f2a0a4874687 2026-03-04
FileHash-SHA256 e25892603c42e34bd7ba0d8ea73be600d898cadc290e3417a82c04d6281b743b 2026-03-04
domain anythingshere.shop 2026-03-04
domain cside.site 2026-03-04
domain footballfans.asia 2026-03-04
domain girlsbags.shop 2026-03-04
domain justweb.click 2026-03-04
domain lecturegenieltd.pro 2026-03-04
domain menclub.it 2026-03-04
domain musiclivetrack.website 2026-03-04
domain ntcx.pro 2026-03-04
domain retseptik.info 2026-03-04
domain stone110.store 2026-03-04
domain web14.info 2026-03-04