Threats Feed|APT34|Last Updated 08/05/2026|AuthorCertfa Radar|Publish Date05/05/2026

Iranian Threat Actors Breach 12 Omani Ministries, Exposing 26,000 Records

  • Actor Motivations: Espionage,Exfiltration
  • Attack Vectors: Brute-force,SQL injection,Vulnerability Exploitation,Backdoor,Downloader
  • Attack Complexity: Medium
  • Threat Risk: High Impact/High Probability

Threat Overview

An Iranian-nexus threat actor targeted 12 Omani government ministries, with a primary focus on the Ministry of Justice and Legal Affairs. Utilizing an exposed UAE-based virtual private server, the operator inadvertently revealed their entire operational toolkit, command-and-control infrastructure, and stolen data. The campaign heavily targeted Oman's government, judicial, law enforcement, and administrative sectors to extract citizen identity data, immigration details, and judicial records. The attackers achieved access via ProxyShell and DotNetNuke vulnerabilities, deploying custom webshells and tools like GodPotato for persistent access and privilege escalation. Ultimately, the operation successfully exfiltrated over 26,000 citizen records and critical system registry hives.

Detected Targets

TypeDescriptionConfidence
CaseAuthority for Public Services Regulation
The Authority for Public Services Regulation is the institution responsible for regulating and monitoring the public services sector in the Sultanate of Oman. Authority for Public Services Regulation has been targeted by APT34 as the main target.
Verified
CaseCivil Aviation Authority
Civil Aviation Authority in Government Agencies and Services Aerospace sector located in Oman has been targeted by APT34 as the main target.
Verified
CaseInformation Technology Authority (ITA)
Information Technology Authority (ITA) has been targeted by APT34 as the main target.
Verified
CaseMinistry of Justice and Legal Affairs
Ministry of Justice and Legal Affairs has been targeted by APT34 as the main target.
Verified
CaseMinistry of Transport, Communications and Information Technology
Ministry of Transport, Communications and Information Technology in Government Agencies and Services Transportation sector located in Oman has been targeted by APT34 as the main target.
Verified
CaseOman Ministry of Finance
Oman Ministry of Finance in Financial Government Agencies and Services sector located in Oman has been targeted by APT34 as the main target.
Verified
CaseOman Public Prosecution
Oman Public Prosecution in Government Agencies and Services sector located in Oman has been targeted by APT34 as the main target.
Verified
CaseRoyal Court Affairs (Diwan of Royal Court)
Royal Court Affairs (Diwan of Royal Court) has been targeted by APT34 as the main target.
Verified
CaseRoyal Flight of Oman
The Royal Flight of Oman is the VIP air transport capability embedded within the Sultan of Oman's Royal Household. Royal Flight of Oman has been targeted by APT34 as the main target.
Verified
CaseRoyal Oman Police
Royal Oman Police has been targeted by APT34 as the main target.
Verified
CaseState Financial and Administrative Audit Authority
State Financial and Administrative Audit Authority in Government Agencies and Services sector located in Oman has been targeted by APT34 as the main target.
Verified
CaseSultanate of Oman Tax Authority
Sultanate of Oman Tax Authority has been targeted by APT34 as the main target.
Verified
SectorGovernment Agencies and Services
Verified
RegionOman
Verified

Extracted IOCs

  • dubai-1.vaermb.comregorixa[.]com
  • dubai-2.vaermb[.]com
  • dubai-3.vaermb.commyjitsi.exceptionnotfound[.]ir
  • dubai-4.vaermb.coms5.sideliner[.]ir
  • dubai-5.vaermb[.]com
  • dubai-6.vaermb[.]com
  • dubai-7.vaermb.comsuanefllix.combrnettlix.combrttfrixx.comrealprimefix.comidentificara[.]com
  • dubai-8.vaermb[.]com
  • dubai-9.vaermb[.]com
  • myjitsi.mrnajafipour[.]ir
  • price.exceptionnotfound[.]ir
  • shop.exceptionnotfound[.]ir
  • tools.exceptionnotfound[.]ir
  • 104[.]21.27.95
  • 172[.]67.142.35
  • 172[.]86.76.101
  • 172[.]86.76.108
  • 172[.]86.76.112
  • 172[.]86.76.120
  • 172[.]86.76.121
  • 172[.]86.76.124
  • 172[.]86.76.129
  • 172[.]86.76.130
  • 172[.]86.76.94
  • 45[.]59.114.60
download

Tip: 25 related IOCs (12 IP, 13 domain, 0 URL, 0 email, 0 file hash) to this threat have been found.

FAQs

Omani Government Cyber Intrusion

An active cyberattack compromised multiple Omani government networks, exposing internal systems and extracting sensitive data. The attackers accidentally left their digital staging server open to the public, allowing security researchers to directly observe their tools, session logs, and the stolen files in plain sight.

While a specific group is not definitively named, the tactics, infrastructure, and targets strongly align with Iranian state-sponsored threat actors. The behaviors observed heavily overlap with groups known for Middle Eastern cyberespionage, such as APT34 and MuddyWater.

The attack was a highly targeted cyberespionage campaign designed to infiltrate government networks and quietly extract highly sensitive citizen and judicial records. The operators focused on gathering intelligence and maintaining long-term, hidden access to these government systems.

The attackers cast a wide net, targeting at least 12 distinct Omani ministry offices. Compromised systems included the Ministry of Justice and Legal Affairs, the Royal Oman Police, and the Tax Authority of Oman.

Yes, the primary targets were government institutions, specifically databases holding judicial records, committee decisions, and national identity data. Over 26,000 Ministry of Justice user records, including national ID numbers, birthdates, and full names in both Arabic and English, were exposed.

The attackers gained entry by exploiting vulnerabilities in web applications and mail servers, as well as by guessing passwords. Once inside, they used specialized tools to elevate their access, hide their tracks, systematically steal databases, and communicate with the infected systems via a remote server.

Government ministries hold vast amounts of centralized intelligence, including legal, financial, and personal citizen data. Access to this highly sensitive information provides a strategic advantage for foreign espionage, political leverage, and the ability to track specific individuals.

Organizations should immediately apply security updates to all public-facing web applications and email servers. Additionally, they must monitor their networks for unusual access patterns, enforce multi-factor authentication across all user accounts, and ensure sensitive databases are strictly monitored for unauthorized access.

This was a highly targeted operation aimed specifically at Omani government infrastructure. However, the software vulnerabilities exploited by the attackers are common worldwide, meaning any organization failing to patch their systems could be susceptible to similar attacks from various threat groups.

About Affiliation
APT34
APT34 is Mandiant's designation for the Iranian MOIS-linked threat cluster known as OilRig. Active since at least 2014, Mandiant identified APT34 as an advanced persistent threat focused on long-term espionage against government, energy, and financial organizations in the Middle East. Mandiant has documented the group's evolution over more than a decade, including its use of DNS-based command and control, LinkedIn-based social engineering lures, and a continuously expanding custom malware arsenal. APT34 remains one of the most thoroughly documented Iranian state-sponsored actors in public threat intelligence.
View APT34's Insights