216.73.216.6

Threat Hunting on potential APT35 Servers

· Published 27/09/2025 09:36 · Modified 29/09/2025 08:51

Export JSON

Essential information

Published
27/09/2025 09:36
Modified
29/09/2025 08:51
Tags
2025-09-27 infrastructure tracking iranian apt phishing threat hunting typosquatting video conferencing
Related entities
1 intrusion sets (apt), 1 techniques (mitre), 5 others

Description

The article discusses the discovery of two servers sharing similarities with those reported by Check Point on APT35, an Iranian threat group. The servers are active and resolve multiple domains used for purposes. The analysis focuses on the HTML page displayed on some domains, which contains four colored dots. Using the SilentPush platform, the team crafted a query to hunt for similar pages, finding matches related to previously reported IPv4 addresses and two undocumented ones. The servers resolve domains mostly used for , masquerading as related sites. The ongoing campaign still targets Israel, and the article provides methods for tracking new domains associated with APT35 activities.

External references