A Network IoC Analysis for 8 Iran-Affiliated APT Groups

Amid the ongoing conflict involving Iran, we examined whether geopolitical tensions have extended into cyberspace. Building on findings from S2W’s Iran APT Landscape Report1, we traced the DNS footprint of eight Iran-affiliated APT groups, including APT42, APT34, and MuddyWater.

After a closer look at the original IoC list, we analyzed 191 IoCs in all comprising four subdomains, 136 domains, and 51 IP addresses. Using our homegrown tools to investigate the threat, we uncovered these findings:

  • 9,849 unique client IP addresses communicated with nine domain IoCs
  • One domain IoC was bulk-registered with two look-alikes
  • 73 domain IoCs were likely to have been registered with malicious intent
  • 1,841 distinct potential victim-owned IP addresses communicated with 31 IP IoCs
  • 731 email-connected domains
  • 10 additional IP addresses, all of which turned out to be malicious
  • 865 IP-connected domains, 13 of which turned out to be malicious
  • 1,959 string-connected domains, seven of which turned out to be malicious

Download a sample of the threat research materials now or contact sales to discuss your intelligence needs for threat detection and response or other cybersecurity use cases.

  • [1] https://s2w.inc/en/resource/detail/1041
Try our WhoisXML API for free
Get started