Dark Scepter is a recently identified Iranian-aligned cyber threat cluster assessed to overlap with APT34, also known as OilRig. The actor has been associated with infrastructure patterns and operational tradecraft consistent with broader Iranian state-linked intrusion activity. Reporting links Dark Scepter to shared or overlapping command-and-control provisioning with Dust Specter, suggesting either common infrastructure management or a shared upstream operational support element. Dark Scepter is notable for using Cloudflare to proxy parts of its infrastructure and obscure backend hosting, complicating attribution and infrastructure-based detection. Infrastructure analysis has tied the cluster to reused certificate subject alternative names and recurring web presentation artifacts, indicating deliberate infrastructure reuse and operational consistency. The overlap with APT34/OilRig places Dark Scepter within the ecosystem of Iranian espionage-focused operators historically associated with targeting government, financial, energy, and defense-related organizations in the United States, Israel, and allied regions. High-confidence reporting in this context supports Dark Scepter’s relationship to reconnaissance and post-compromise infrastructure operations, but does not provide sufficient direct evidence to attribute a fuller malware or victimology profile specifically to Dark Scepter beyond its overlap with APT34/OilRig and shared infrastructure patterns with Dust Specter. The actor is best characterized as an Iranian-aligned intrusion cluster using concealed and reusable infrastructure in support of likely espionage-oriented operations.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
15 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Cluster associated with overlapping infrastructure and backend reuse with Dust Specter, suggesting shared provisioning or operational linkage.
Recently identified Iran-linked cluster overlapping APT34 (OilRig), using Cloudflare proxying/fronting and certificate/SAN and webpage-title reuse patterns to manage and conceal C2 infrastructure.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.