Researchers reported a malware campaign built around a previously undocumented BORZ command-and-control framework that used a dual-process loader to launch a legitimate Slack application as a decoy while retrieving a second-stage payload from 94.232.46[.]16:8081/dl. The payload reportedly established persistence, dropped a text artifact containing the phrase "Khorramshahr-4 loaded", and communicated with C2 services over ports 27015 and 27016; the associated panel was hosted at 94.232.46[.]16:8081/login and was offline at the time of reporting.
The infrastructure was tied to AS48080, a Moscow-registered ASN associated with Dmitriy Panchenko, and the surrounding 94.232.46.0/24 range was described as having a significant abuse history consistent with bulletproof or covert hosting. Analysts said BORZ does not match any publicly documented C2 panel family and found no overlap with known IOC databases or prior investigations, concluding that the mix of Iranian missile naming, Chechen branding, Russian hosting, and game-server-associated ports is inconsistent with established Iranian APT tradecraft and more likely reflects a custom framework used in a false-flag, hacktivist, or cybercriminal operation.

Get the actors, campaigns, and ATT&CK mapping behind it.
3 events from the most recent confirmed update back to the earliest known activity.
As of 2026-04-17, the BORZ C2 panel and payload download endpoint at 94.232.46[.]16:8081 were offline. The associated infrastructure was tied to AS48080, registered to Dmitriy Panchenko in Moscow, and the surrounding 94.232.46.0/24 range was noted as having substantial abuse history.
Breakglass reported that BORZ did not match any publicly documented C2 panel family and found no overlap with its existing investigations or IOC databases. The assessment said the mix of Iranian missile naming, Chechen branding, Russian hosting, and game-server-associated ports was inconsistent with known Iranian APT tradecraft, favoring a false-flag, hacktivist, or cybercriminal explanation over a confirmed Iranian state link.
A malware campaign used a dual-process loader that launched a legitimate Slack application as a decoy while downloading a second-stage payload from 94.232.46[.]16:8081/dl. The payload established persistence, dropped a text artifact containing the phrase "Khorramshahr-4 loaded," and communicated with command-and-control infrastructure on ports 27015 and 27016 via a BORZ C2 panel hosted at 94.232.46[.]16:8081/login.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 13 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
2 references tracked. Mallory keeps watching after this page renders.
intel.breakglass.tech
Open sourceintel.breakglass.tech
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.