Dark Scepter is a recently identified Iranian-aligned cyber threat cluster assessed to overlap with APT34, also known as OilRig. The actor has been associated with infrastructure patterns and operational tradecraft consistent with broader Iranian state-linked intrusion activity. Reporting links Dark Scepter to shared or overlapping command-and-control provisioning with Dust Specter, suggesting either common infrastructure management or a shared upstream operational support element. Dark Scepter is notable for using Cloudflare to proxy parts of its infrastructure and obscure backend hosting, complicating attribution and infrastructure-based detection. Infrastructure analysis has tied the cluster to reused certificate subject alternative names and recurring web presentation artifacts, indicating deliberate infrastructure reuse and operational consistency. The overlap with APT34/OilRig places Dark Scepter within the ecosystem of Iranian espionage-focused operators historically associated with targeting government, financial, energy, and defense-related organizations in the United States, Israel, and allied regions. High-confidence reporting in this context supports Dark Scepter’s relationship to reconnaissance and post-compromise infrastructure operations, but does not provide sufficient direct evidence to attribute a fuller malware or victimology profile specifically to Dark Scepter beyond its overlap with APT34/OilRig and shared infrastructure patterns with Dust Specter. The actor is best characterized as an Iranian-aligned intrusion cluster using concealed and reusable infrastructure in support of likely espionage-oriented operations.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Attributed origin per open-source reporting.
15 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Cluster associated with overlapping infrastructure and backend reuse with Dust Specter, suggesting shared provisioning or operational linkage.
Recently identified Iran-linked cluster overlapping APT34 (OilRig), using Cloudflare proxying/fronting and certificate/SAN and webpage-title reuse patterns to manage and conceal C2 infrastructure.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.