Iranian Threat Actors Breach 12 Omani Ministries, Exposing 26,000 Records
- Actor Motivations: Espionage,Exfiltration
- Attack Vectors: Brute-force,SQL injection,Vulnerability Exploitation,Backdoor,Downloader
- Attack Complexity: Medium
- Threat Risk: High Impact/High Probability
Threat Overview
An Iranian-nexus threat actor targeted 12 Omani government ministries, with a primary focus on the Ministry of Justice and Legal Affairs. Utilizing an exposed UAE-based virtual private server, the operator inadvertently revealed their entire operational toolkit, command-and-control infrastructure, and stolen data. The campaign heavily targeted Oman's government, judicial, law enforcement, and administrative sectors to extract citizen identity data, immigration details, and judicial records. The attackers achieved access via ProxyShell and DotNetNuke vulnerabilities, deploying custom webshells and tools like GodPotato for persistent access and privilege escalation. Ultimately, the operation successfully exfiltrated over 26,000 citizen records and critical system registry hives.
Detected Targets
| Type | Description | Confidence |
|---|---|---|
| Case | Authority for Public Services Regulation The Authority for Public Services Regulation is the institution responsible for regulating and monitoring the public services sector in the Sultanate of Oman. Authority for Public Services Regulation has been targeted by APT34 as the main target. | Verified |
| Case | Civil Aviation Authority Civil Aviation Authority in Government Agencies and Services Aerospace sector located in Oman has been targeted by APT34 as the main target. | Verified |
| Case | Information Technology Authority (ITA) Information Technology Authority (ITA) has been targeted by APT34 as the main target. | Verified |
| Case | Ministry of Justice and Legal Affairs Ministry of Justice and Legal Affairs has been targeted by APT34 as the main target. | Verified |
| Case | Ministry of Transport, Communications and Information Technology Ministry of Transport, Communications and Information Technology in Government Agencies and Services Transportation sector located in Oman has been targeted by APT34 as the main target. | Verified |
| Case | Oman Ministry of Finance Oman Ministry of Finance in Financial Government Agencies and Services sector located in Oman has been targeted by APT34 as the main target. | Verified |
| Case | Oman Public Prosecution Oman Public Prosecution in Government Agencies and Services sector located in Oman has been targeted by APT34 as the main target. | Verified |
| Case | Royal Court Affairs (Diwan of Royal Court) Royal Court Affairs (Diwan of Royal Court) has been targeted by APT34 as the main target. | Verified |
| Case | Royal Flight of Oman The Royal Flight of Oman is the VIP air transport capability embedded within the Sultan of Oman's Royal Household. Royal Flight of Oman has been targeted by APT34 as the main target. | Verified |
| Case | Royal Oman Police Royal Oman Police has been targeted by APT34 as the main target. | Verified |
| Case | State Financial and Administrative Audit Authority State Financial and Administrative Audit Authority in Government Agencies and Services sector located in Oman has been targeted by APT34 as the main target. | Verified |
| Case | Sultanate of Oman Tax Authority Sultanate of Oman Tax Authority has been targeted by APT34 as the main target. | Verified |
| Sector | Government Agencies and Services | Verified |
| Region | Oman | Verified |
Extracted IOCs
- dubai-1.vaermb.comregorixa[.]com
- dubai-2.vaermb[.]com
- dubai-3.vaermb.commyjitsi.exceptionnotfound[.]ir
- dubai-4.vaermb.coms5.sideliner[.]ir
- dubai-5.vaermb[.]com
- dubai-6.vaermb[.]com
- dubai-7.vaermb.comsuanefllix.combrnettlix.combrttfrixx.comrealprimefix.comidentificara[.]com
- dubai-8.vaermb[.]com
- dubai-9.vaermb[.]com
- myjitsi.mrnajafipour[.]ir
- price.exceptionnotfound[.]ir
- shop.exceptionnotfound[.]ir
- tools.exceptionnotfound[.]ir
- 104[.]21.27.95
- 172[.]67.142.35
- 172[.]86.76.101
- 172[.]86.76.108
- 172[.]86.76.112
- 172[.]86.76.120
- 172[.]86.76.121
- 172[.]86.76.124
- 172[.]86.76.129
- 172[.]86.76.130
- 172[.]86.76.94
- 45[.]59.114.60
Tip: 25 related IOCs (12 IP, 13 domain, 0 URL, 0 email, 0 file hash) to this threat have been found.
FAQs
Omani Government Cyber Intrusion
An active cyberattack compromised multiple Omani government networks, exposing internal systems and extracting sensitive data. The attackers accidentally left their digital staging server open to the public, allowing security researchers to directly observe their tools, session logs, and the stolen files in plain sight.
While a specific group is not definitively named, the tactics, infrastructure, and targets strongly align with Iranian state-sponsored threat actors. The behaviors observed heavily overlap with groups known for Middle Eastern cyberespionage, such as APT34 and MuddyWater.
The attack was a highly targeted cyberespionage campaign designed to infiltrate government networks and quietly extract highly sensitive citizen and judicial records. The operators focused on gathering intelligence and maintaining long-term, hidden access to these government systems.
The attackers cast a wide net, targeting at least 12 distinct Omani ministry offices. Compromised systems included the Ministry of Justice and Legal Affairs, the Royal Oman Police, and the Tax Authority of Oman.
Yes, the primary targets were government institutions, specifically databases holding judicial records, committee decisions, and national identity data. Over 26,000 Ministry of Justice user records, including national ID numbers, birthdates, and full names in both Arabic and English, were exposed.
The attackers gained entry by exploiting vulnerabilities in web applications and mail servers, as well as by guessing passwords. Once inside, they used specialized tools to elevate their access, hide their tracks, systematically steal databases, and communicate with the infected systems via a remote server.
Government ministries hold vast amounts of centralized intelligence, including legal, financial, and personal citizen data. Access to this highly sensitive information provides a strategic advantage for foreign espionage, political leverage, and the ability to track specific individuals.
Organizations should immediately apply security updates to all public-facing web applications and email servers. Additionally, they must monitor their networks for unusual access patterns, enforce multi-factor authentication across all user accounts, and ensure sensitive databases are strictly monitored for unauthorized access.
This was a highly targeted operation aimed specifically at Omani government infrastructure. However, the software vulnerabilities exploited by the attackers are common worldwide, meaning any organization failing to patch their systems could be susceptible to similar attacks from various threat groups.