Thursday, September 10, 2026

Iran-Linked Hackers Target Oman Ministries in Webshell and Data Theft Campaign

Iran-linked operators have mounted a broad espionage operation against multiple Omani ministries, abusing exposed webshells, SQL escalation scripts, and a poorly secured C2 server to steal judicial and identity data at scale.

Attacker’s own open directory strongly suggests a Ministry of Intelligence and Security (MOIS) nexus compromised a mailbox , but there are not enough unique artifacts for firm group-level attribution.

An exposed RouterHosting VPS at 172.86.76[.]127 in the UAE hosted the entire toolkit for an active intrusion into Oman’s government networks, including webshells, Python exploit scripts, C2 code, logs, and exfiltrated data.

The primary victim was the Ministry of Justice and Legal Affairs (MJLA), but recovered files show activity against at least 11 government entities, from the Royal Oman Police to the Tax Authority and civil aviation portals.

This campaign follows earlier MOIS-linked abuse of an Omani MFA mailbox in Paris for global spear-phishing, indicating Oman remains a recurring access point and target for Iran-aligned espionage.

Key findings from the exposed server include a custom ASP.NET webshell on mersaltest.mjla.gov[.]om, SQL Server escalation tooling, and evidence of large-scale data theft, including more than 26,000 DotNetNuke user records and Windows registry hives.

Hunt.io IP profile for 172.86.76[.]127 on RouterHosting showing open ports 22, 80, 443 (Source : Hunt.io).
Hunt.io IP profile for 172.86.76[.]127 on RouterHosting showing open ports 22, 80, 443 (Source : Hunt.io).

A README on the VPS labels it “VPS C2 – 172.86.76[.]127,” implying this node is part of a wider but still unmapped infrastructure set.

Iran Hackers Target Oman Ministries

AttackCapture scans first flagged an open directory on port 8000 on April 8, 2026, showing early-stage reconnaissance and exploitation attempts against multiple gov[.]om services.

Targets included the Royal Oman Police eVisa portal, Royal Fleet of Oman and Tax Authority Exchange servers (via ProxyShell), and a State Audit Institution training platform hit with brute-force attempts.

TargetOrganizationObserved Activity
evisa.rop.gov[.]omRoyal Oman Police eVisa portalPassword brute force attempts
mail.rfo.gov[.]omRoyal Fleet of Oman – VIP air transportProxyShell exploitation (CVE-2021-34473/34523/31207)
email.taxoman.gov[.]omTax Authority of OmanProxyShell exploitation (CVE-2021-34473/34523/31207)
sailms.gov[.]omTraining platform for the State Audit Institution (SAI) of OmanPassword brute force attempts

A dedicated proxyshell_01.sh script focused on vulnerable Exchange endpoints, while a separate evisa_cookies.txt file indicates successful credential-based access to the eVisa portal despite no confirmed ProxyShell compromise.

By April 10, a second directory on port 8002 revealed a matured operator workspace with 211 files and 17 subdirectories, including payloads for Chisel tunneling and a scripts/gov[.]om folder containing tailored Python tooling for individual ministries.

Two key webshells underpin this activity: hc2.aspx, recovered directly from the C2 server, and health_check_t.aspx, hardcoded across MJLA-focused scripts and deployed under DotNetNuke’s /Portals/0/ path for command execution.

The operator leveraged the webshell to run PowerShell and SQL commands for credential access, lateral movement, and bulk data extraction.

They enumerated DotNetNuke schemas and targeted aspnet_Membership entries to identify superusers, dumping hashes for offline cracking while pivoting toward a “MOLADB” database.

Queries against the eGov_Person table show a clear focus on national ID records, including citizen names (Arabic and English), birthdates, nationality, and other high-value identity attributes.

C2 logs from April 10, 2026, document a systematic sequence of commands: host profiling, network discovery, database mapping, then export of judicial case data, session attachments, committee decisions, and expert certifications.

In one session, the attacker exfiltrated 26,596 MJLA DotNetNuke user records, capturing staff email addresses and credential data alongside Windows SAM and SYSTEM registry hives staged under C:\Windows\Temp before exfiltration.

Data Theft Campaign

The 172.86.76[.]127 VPS hosted a Python HTTP C2 stack and a PowerShell beacon (new_beacon.ps1) polling every 30 seconds for JSON-formatted tasking over port 8001, with results returned in base64-encoded chunks.

Newly identified server is a replica of Radio Zamaneh, an Amsterdam-based Persian-language media organization serving those in Iran and beyond seeking alternative journalism.

Webpage at myjitsi.mrnajafipour[.]ir mimicking Radio Zamaneh (Source : Hunt.io).
Webpage at myjitsi.mrnajafipour[.]ir mimicking Radio Zamaneh (Source : Hunt.io).

Listener ports covered SSH, multiple reverse shells, Chisel, registry exfiltration, and SOCKS5 tunneling, while a catch-all POST handler logged all inbound traffic, mixing beacon activity with external scanner noise.

Infrastructure pivoting from dubai-10.vaermb[.]com exposed a broader “dubai-#” cluster on the same RouterHosting ASN, plus a linked Swiss IP hosting cloned Iranian diaspora media and Psiphon-themed content, all consistent with Iranian state-aligned information operations and regional espionage tradecraft.

The operators attempted persistence via a scheduled task named MicrosoftEdgeUpdate, which Defender blocked, and experimented with turning off antivirus and evolving privilege escalation scripts using GodPotato and reflective loading.

While no single artifact conclusively ties this campaign to a known APT, the TTPs, targets, and infrastructure all sit firmly within the Iranian state-nexus space.

Indicators of Compromise

TypeIndicatorResolving Domain(s)Hosting
IP172.86.76[.]101dubai-1.vaermb[.]com
regorixa[.]com
RouterHosting LLC, UAE
IP172.86.76[.]94dubai-2.vaermb[.]comRouterHosting LLC, UAE
IP172.86.76[.]108dubai-3.vaermb[.]com
myjitsi.exceptionnotfound[.]ir
RouterHosting LLC, UAE
IP172.86.76[.]112dubai-4.vaermb[.]com
s5.sideliner[.]ir
RouterHosting LLC, UAE
IP172.86.76[.]120dubai-5.vaermb[.]comRouterHosting LLC, UAE
IP172.86.76[.]121dubai-6.vaermb[.]comRouterHosting LLC, UAE
IP172.86.76[.]124dubai-7.vaermb[.]com
suanefllix[.]com
brnettlix[.]com
brttfrixx[.]com
realprimefix[.]com
identificara[.]com
RouterHosting LLC, UAE
IP172.86.76[.]129dubai-8.vaermb[.]comRouterHosting LLC, UAE
IP172.86.76[.]130dubai-9.vaermb[.]comRouterHosting LLC, UAE
IP45.59.114[.]60shop.exceptionnotfound[.]ir
price.exceptionnotfound[.]ir
myjitsi.mrnajafipour[.]ir
RouterHosting LLC, CH
IP104.21.27[.]95
172.67.142[.]35
tools.exceptionnotfound[.]irCloudflare

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Follow us on Google NewsLinkedIn, and X to Get Instant Updates and Set GBH as a Preferred Source in Google.

Mayura Kathir
Mayura Kathirhttps://gbhackers.com/
Mayura Kathir is a cybersecurity reporter at GBHackers News, covering daily incidents including data breaches, malware attacks, cybercrime, vulnerabilities, zero-day exploits, and more.

Hot this week

How To Access Dark Web Anonymously and know its Secretive and Mysterious Activities

What is Deep Web The deep web, invisible web, or...

How to Build and Run a Security Operations Center (SOC Guide) – 2023

Today’s Cyber security operations center (CSOC) should have everything...

Russian Hackers Bypass EDR to Deliver a Weaponized TeamViewer Component

TeamViewer's popularity and remote access capabilities make it an...

Web Server Penetration Testing Checklist – 2026

Web server pentesting is performed under three significant categories: identity,...

ATM Penetration Testing – Advanced Testing Methods to Find The Vulnerabilities

ATM Penetration testing, Hackers have found different approaches to...

OpenMatter Network Realigns Leadership Team to Accelerate Global Commercial Growth

Melbourne, Florida, September 10th, 2026, CyberNewswire With its Verification Architecture...

Hackers Can Turn Vulnerable LiteLLM AI Gateways Into Root Access and Cloud Credential Theft

Nearly one in 10 internet-exposed LiteLLM AI gateways accepted...

Skullcandy Dime 3 Bluetooth Flaw Lets Nearby Attackers Hijack Audio and Microphone

Skullcandy Dime 3 wireless earbuds have a serious vulnerability...

Hackers Steal Active Directory Password Hashes Without Attacking Domain Controllers Directly

Threat actors are increasingly exploiting Active Directory replication mechanisms...

Fake GTA 6 Installer Steals Browser Passwords, Discord Tokens and Crypto Data From Gamers

Threat actors are exploiting anticipation around Grand Theft Auto...

Apple Xcode Integer Underflow Flaw Lets Crafted Archives Leak Memory and Crash Builds

A recently disclosed integer-underflow vulnerability in Apple’s modern Mach-O...

Palo Alto PAN-OS Buffer Overflow Lets Attackers Execute Arbitrary Code as Root

Palo Alto Networks has announced a high-severity buffer overflow...

New Phishing Attack Uses Blob URLs to Hide Malicious Pages From Security Scanners

A phishing campaign that moves the credential-harvesting page out...

Related Articles

Recent News