Home Cyber Attack Iranian-Nexus Hackers Target Oman Ministries In Data Theft Campaign

Iranian-Nexus Hackers Target Oman Ministries In Data Theft Campaign

0
Iranian-Nexus Hackers Target Oman Ministries In Data Theft Campaign

A significant operational security failure by Iranian-nexus threat actors has exposed an active cyberespionage campaign against the Omani government.

An exposed staging server hosted on a United Arab Emirates virtual private network exposed the attackers’ entire playbook in plain sight, including their command-and-control infrastructure, exploit toolkits, and stolen data.

The primary victim of this intrusion was the Ministry of Justice and Legal Affairs. However, multiple other government entities were targeted in a broader effort to compromise judicial records and citizen identity data.

Iranian Hackers Target Oman

The compromised staging server was discovered in early April 2026 on a RouterHosting virtual private server. Security researchers identified two open directories that documented different phases of the active operation.

The first directory revealed extensive reconnaissance and initial access attempts against multiple Omani ministries.

The attackers conducted persistent password brute-force attacks against the Royal Oman Police eVisa portal and the State Audit Institution training platform.

Hunt.io IP profile for 172.86.76[.]127 on RouterHosting showing open ports 22, 80, 443 (Source: hunt.io)
Hunt.io IP profile for 172.86.76[.]127 on RouterHosting showing open ports 22, 80, 443 (Source: hunt.io)

Additionally, they deployed specific exploit scripts targeting ProxyShell vulnerabilities on the mail servers of the Royal Fleet of Oman and the Tax Authority of Oman.

While the ProxyShell attacks appeared unsuccessful, recovered session cookies indicated the attackers successfully bypassed authentication on the eVisa portal via credential-based means.

The second open directory provided a rare look into the attackers’ heavily structured post-compromise environment. A custom webshell embedded within the Ministry of Justice network provided threat actors with persistent access.

Hunt.io domain profile for dubai-10.vaermb[.]com displaying a registration date of 2025-05-04 using NameSilo, LLC (Source: hunt.io)
Hunt.io domain profile for dubai-10.vaermb[.]com displaying a registration date of 2025-05-04 using NameSilo, LLC (Source: hunt.io)

The operators used a suite of highly tailored Python scripts to exploit various ministry portals, targeting vulnerabilities ranging from DotNetNuke server-side request forgery to SQL Server privilege escalation.

Over fifty distinct scripts were cataloged on the server, demonstrating a versatile toolkit capable of bypassing web application firewalls and attacking enterprise appliances.

According to hunt.io research, the operators utilized an iterative coding process, actively leaving their failure notes directly in the exposed files.

Screenshot of the ProxyShell exploit script proxyshell-01.sh (Source: hunt.io)
Screenshot of the ProxyShell exploit script proxyshell-01.sh (Source: hunt.io)

For instance, they deployed multiple versions of the Windows privilege escalation tool GodPotato.

When their initial execution method was blocked by security software, they quickly pivoted to a reflective loading technique that executed the payload entirely in memory to evade detection.

The attackers’ command-and-control setup operated across multiple network ports, using standard web ports for reverse shells, port 7777 for encrypted Chisel tunnels, and ports in the 8000 range for beacon listening and data exfiltration.

Indicators of Compromise

TypeIndicatorResolving Domain(s)Hosting
IP Address172.86.76[.]127dubai-10.vaermb[.]comRouterHosting LLC, UAE
IP Address172.86.76[.]101dubai-1.vaermb[.]com, regorixa[.]comRouterHosting LLC, UAE
IP Address172.86.76[.]94dubai-2.vaermb[.]comRouterHosting LLC, UAE
IP Address172.86.76[.]108dubai-3.vaermb[.]com, myjitsi.exceptionnotfound[.]irRouterHosting LLC, UAE

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Follow us on Google News , LinkedIn and X to Get More Instant UpdatesSet Cyberpress as a Preferred Source in Google.

NO COMMENTS

LEAVE A REPLY

Please enter your comment!
Please enter your name here