216.73.216.6

Iranian Botnet Exposed via Open Directory: 15-Node Relay Network and Active C2

· Published 17/03/2026 15:07 · Modified 17/03/2026 19:48

Export JSON

Essential information

Published
17/03/2026 15:07
Modified
17/03/2026 19:48
Tags
2026-03-17 botnet c2 censorship bypass ddos iranian mhddos open directory relay network ssh
Related entities
16 observables, 9 techniques (mitre), 1 malware, 15 others

Description

An threat actor's operational infrastructure was exposed through an , revealing a 15-node spanning Finland and Iran, an -based framework, and an active command and control server. The exposed bash history documented the full operation, including tunnel deployment, tooling development, and creation. The actor used on-host compilation to evade detection and leveraged a Python script for mass deployment. The client, compiled and renamed 'hex' on infected hosts, showed automatic reconnection capabilities. This operation appears to be financially or personally motivated rather than state-directed, with infrastructure dual-purposed for and attack operations.

External references