Threats Feed|APT39|Last Updated 12/06/2026|AuthorCertfa Radar|Publish Date13/07/2020

Tracking APT39 and APT34: Innovations in C2 Server Profiling

  • Actor Motivations: Espionage,Exfiltration
  • Attack Vectors: Backdoor,Dropper
  • Attack Complexity: Medium
  • Threat Risk: Unknown

Threat Overview

In October 2019, Aaron Stephens introduced the SCANdalous project, which automates the profiling of command and control (C2) servers used by threat groups. Prior to automation, analysts manually identified servers linked to groups like APT39 and APT34. APT39 employed SSH tunneling and specific server characteristics to evade detection, while APT34 used QUADAGENT malware and PowerShell-based tools like POSHC2 and POWERTON. These efforts led to early identification of malicious infrastructure, improving threat tracking capabilities.

Extracted IOCs

  • rdppath[.]com
  • 185[.]161.208.37
  • 51[.]254.93.40
  • 51[.]254.93.47
download

Tip: 4 related IOCs (3 IP, 1 domain, 0 URL, 0 email, 0 file hash) to this threat have been found.

Overlaps

OilRigAdapting and Evolving: A Look at the OilRig's QUADAGENT-Driven Attacks

Source: Palo Alto Networks - July 2018

Detection (one case): rdppath[.]com

Hint: Overlaps are extracted automatically by examining the IOCs associated with all indexed threats and actors.

FAQs

Automated Threat Infrastructure Tracking with SCANdalous

Advanced Practices developed an automated tracking system named SCANdalous to proactively identify adversary infrastructure on the internet. By leveraging third-party network scan data, this system discovers malicious servers and domains long before attackers can use them to compromise target networks.

The system tracks multiple sophisticated threat groups operating globally. This includes notable state-sponsored groups like APT33, APT34, and APT39, alongside prominent financially motivated groups such as FIN6, FIN7, and UNC1878.

Threat actors continuously establish external internet infrastructure to facilitate and manage their cyber intrusions. They set up command and control servers designed to execute remote commands, move laterally through targeted networks, and maintain access to compromised environments.

The automated detection system operates on a massive scale, maintaining over five thousand signatures that track thousands of groups and malware families. Since its inception, the platform has processed over two million hits on suspicious internet infrastructure.

The provided report does not identify specific industries or individuals that these groups targeted. It instead highlights that the identified infrastructure was generally utilized to target FireEye clients, including organizations supported by Managed Defense and Mandiant Incident Response.

Adversaries prepared for their attacks by acquiring domains and utilizing specific hosting providers to host their operations. Once established, they relied on custom backdoors, SSH tunneling, and popular post-exploitation frameworks to remotely manage their access inside victim networks.

The document does not detail the specific underlying motivations or the attractiveness of the targeted entities. The focus of the report is dedicated exclusively to the methodologies defenders can use to track the attackers' external infrastructure.

Organizations should incorporate third-party network scan data into their defensive strategies and actively automate their detection workflows. Defenders must also deploy broad signatures to proactively monitor for common administrative and post-exploitation tools frequently co-opted by attackers.

The ongoing establishment of malicious infrastructure is a deeply widespread issue across the internet. The development of automation was strictly necessary precisely because defenders must continuously track dozens of highly active threat groups and common malware frameworks operating simultaneously around the globe.

About Affiliation
APT39
APT39 is an Iranian state-linked cyber espionage group active since at least 2014, first publicly named by Mandiant in 2019. The group is distinguished by its systematic focus on the theft of personal information — particularly from telecommunications and travel companies — to support Iranian surveillance and tracking operations against individuals of interest. APT39 uses spear phishing, web shell deployment, and a suite of custom backdoors including SEAWEED, CACHEMONEY, and POWBAT. Its operations span the Middle East, Europe, and beyond. Symantec tracks the same cluster as Chafer, and IBM as ITG07.
View APT39's Insights