xHunt
Named by Palo AltoSuspected state sponsor: Islamic Republic of IranxHunt is a campaign designation used by Palo Alto Networks Unit 42 to track a series of Iranian cyber espionage operations targeting Kuwaiti government and shipping organizations, first documented in 2019. The campaign deployed a custom toolset including the Hisoka, Sakabota, Gon, and EtherBurn backdoors, many of which use DNS tunneling or email-based protocols for covert command and control. Unit 42 assessed xHunt infrastructure and tooling overlaps with the OilRig cluster, suggesting shared operators or tooling development within Iranian MOIS-linked cyber espionage infrastructure. The campaign targeted maritime, energy, and government sectors across Kuwait and the broader Gulf region.
Targeted Regions
KuwaitKuwait
Jul 2018 ~ Nov 2020
Jul 2018 ~ Nov 2020
Jul 2018 ~ Nov 2020
Jul 2018 ~ Nov 2020
Jul 2018 ~ Nov 2020
Jul 2018 ~ Nov 2020
Jul 2018 ~ Nov 2020
Targeted Sectors
Disclaimer: We are working on indexing and analyzing relevant data and this process is not fully completed yet. Therefore, displayed details and statistics may will change in the future.