PULSE NAME
Iranian-Nexus Operation Against Oman's Government: 12 Ministries Hit and 26,000 Citizen Records Exposed
WHITE AlienVault 2026-05-05 Modified: 2026-05-06
29
IOCs
MEDIUM VOLUME
An exposed command and control server on RouterHosting infrastructure revealed an active Iranian-nexus intrusion campaign targeting twelve Omani government ministries. The operation primarily focused on the Ministry of Justice and Legal Affairs, deploying custom webshells that provided persistent access through April 2026. Over 26,000 user records containing judicial case data, committee decisions, and registry hives were exfiltrated. The attacker utilized ProxyShell exploits, DotNetNuke vulnerabilities, and custom Python scripts targeting Exchange servers, SQL databases, and Oracle systems. Infrastructure analysis revealed connections to spoofed Iranian diaspora media and censorship circumvention tools, with tactical overlaps indicating MOIS-linked groups such as APT34 and MuddyWater. The campaign specifically targeted judicial records, immigration systems, and citizen identity data across multiple government entities.
Indicators of Compromise (29)
All FileHash-SHA256 domain hostname
TYPEINDICATORDESCRIPTIONCREATED
FileHash-SHA256 ecc3611f7dcbaa53acf44e67de2f10d78a26e03b3c77ba28bbd3ee16b2e66437 2026-05-05
domain brnettlix.com 2026-05-05
domain brttfrixx.com 2026-05-05
domain identificara.com 2026-05-05
domain mjla.gov.om 2026-05-05
domain realprimefix.com 2026-05-05
domain regorixa.com 2026-05-05
domain sailms.gov.om 2026-05-05
domain suanefllix.com 2026-05-05
domain vaermb.com 2026-05-05
hostname dubai-1.vaermb.com 2026-05-05
hostname dubai-10.vaermb.com 2026-05-05
hostname dubai-2.vaermb.com 2026-05-05
hostname dubai-3.vaermb.com 2026-05-05
hostname dubai-4.vaermb.com 2026-05-05
hostname dubai-5.vaermb.com 2026-05-05
hostname dubai-6.vaermb.com 2026-05-05
hostname dubai-7.vaermb.com 2026-05-05
hostname dubai-8.vaermb.com 2026-05-05
hostname dubai-9.vaermb.com 2026-05-05
hostname email.taxoman.gov.om 2026-05-05
hostname mail.rfo.gov.om 2026-05-05
hostname mersaltest.mjla.gov.om 2026-05-05
hostname myjitsi.exceptionnotfound.ir 2026-05-05
hostname myjitsi.mrnajafipour.ir 2026-05-05
hostname price.exceptionnotfound.ir 2026-05-05
hostname s5.sideliner.ir 2026-05-05
hostname shop.exceptionnotfound.ir 2026-05-05
hostname tools.exceptionnotfound.ir 2026-05-05