216.73.216.6

Iranian-Nexus Operation Against Oman's Government: 12 Ministries Hit and 26,000 Citizen Records Exposed

· Published 05/05/2026 21:00 · Modified 06/05/2026 10:40

Export JSON

Essential information

Published
05/05/2026 21:00
Modified
06/05/2026 10:40
Source / Author
AlienVault
Confidence
100/100
Report type(s)
threat-report
Labels / Tags
apt34 dotnetnuke iranian-nexus proxyshell
Tags
2026-05-05 apt34 dotnetnuke iranian-nexus proxyshell
Related entities
29 indicators, 29 observables, 22 techniques (mitre), 2 malware, 29 others

Description

An exposed command and control server on RouterHosting infrastructure revealed an active intrusion campaign targeting twelve Omani government ministries. The operation primarily focused on the Ministry of Justice and Legal Affairs, deploying custom webshells that provided persistent access through April 2026. Over 26,000 user records containing judicial case data, committee decisions, and registry hives were exfiltrated. The attacker utilized exploits, vulnerabilities, and custom Python scripts targeting Exchange servers, SQL databases, and Oracle systems. Infrastructure analysis revealed connections to spoofed Iranian diaspora media and censorship circumvention tools, with tactical overlaps indicating MOIS-linked groups such as and MuddyWater. The campaign specifically targeted judicial records, immigration systems, and citizen identity data across multiple government entities.

External references