Fortinet reported that an Iranian state-backed threat group maintained a long-running intrusion inside a major critical national infrastructure organization in the Middle East, using stolen VPN credentials for initial access and sustaining operations from at least May 2023 through February 2025, with possible compromise indicators dating back to 2021. Investigators said the attackers focused on espionage and strategic prepositioning rather than ransomware, deploying web shells and backdoors including Havoc, HanifNet, HXLibrary, NeoExpressRAT, SystemBC, and MeshCentral, while harvesting credentials, collecting email, and moving laterally across the environment.
The attackers also used proxying and tunneling tools such as plink, Ngrok, glider proxy, and ReverseSocks5 to bypass segmentation and probe restricted networks tied to virtualization and operational technology, though Fortinet said it found no conclusive evidence that the OT network itself was breached or disrupted. After remediation began in late 2024, the group escalated efforts to retain or regain access through removed web shells, RDP and VPN logins, exploitation of an unpatched ZKTeco ZKBioTime server, and phishing sent from compromised third-party email accounts, with Fortinet assessing the activity overlaps tradecraft associated with Lemon Sandstorm, Pioneer Kitten, and Fox Kitten.

TTPs, infrastructure, and targeting history in one profile.
23 events from the most recent confirmed update back to the earliest known activity.
FortiGuard publicly disclosed its investigation and attributed the campaign to an Iranian state-sponsored threat group, describing espionage and strategic prepositioning against a Middle East critical national infrastructure organization.
FortiGuard reported that the intrusion persisted until at least February 2025, marking the end of the observed campaign window.
Following containment, the attackers also used compromised third-party email accounts to conduct targeted phishing aimed at stealing administrator or privileged staff credentials.
After losing access, the adversary attempted to regain entry by exploiting an unpatched ZKTeco ZKBioTime server, a technique FortiGuard said had not previously been reported in the wild.
From December 2024 onward, the victim successfully removed the attackers' access from the environment as remediation progressed.
During the post-containment escalation phase spanning late 2024, the attackers deployed additional web shells along with SystemBC and MeshCentral to maintain access and target deeper restricted segments.
From late November 2024, the victim started remediation and containment efforts, after which the adversary increased activity and deployed additional persistence tooling to retain access.
In November 2024, FortiGuard Incident Response began investigating unusual activity originating from a Microsoft Exchange server in the victim's critical infrastructure network.
On 14 October 2024, the adversary carried out another RemoteInjector and Havoc deployment using altered command-and-control infrastructure and disguised scheduled tasks.
The victim's endpoint protection logs showed malicious password filter DLLs synapy.dll and synapx.dll were detected and deleted on 29 August 2024.
FortiGuard identified another RemoteInjector and Havoc deployment on 28 August 2024 as the attackers continued expanding persistence with masqueraded scheduled tasks.
On 11 May 2024, the attackers distributed RdMP_II.zip containing a nanodump variant and used it to dump LSASS memory on multiple systems.
On 7 May 2024, the attackers used vssadmin to create a shadow copy on EXCH-2 and copied the SAM hive for credential access.
On 30 April 2024, the adversary deployed a simple command web shell named SplitScreen.aspx on WEB-4, which FortiGuard calls RecShell.
On 19 April 2024, the attackers deployed RemoteInjector and a Havoc payload on DC-1 using a scheduled task named SpaceManagerTaskMngr.
On 27 November 2023, the adversary deployed CredInterceptor as prce64.dll on SERV-4 to hook LSASS authentication functions and harvest credentials.
On 12 October 2023, the adversary installed a second HanifNet instance named mapi.exe on SERV-2 to maintain persistence.
On 10 October 2023, the attackers registered the malicious IIS module Microsoft.WSMan.Management.Activities.dll on WEB-5, which FortiGuard tracks as HXLibrary.
On 6 August 2023, the attackers deployed the custom .NET backdoor HanifNet via a scheduled task named CleanupTemporay on SERV-6.
On 20 May 2023, the adversary reconnected through the VPN-connected endpoint and carried out network scanning and SMB brute-force activity.
FortiGuard assessed that an Iranian state-backed threat group began a long-running intrusion by at least 15 May 2023 using stolen SSL VPN credentials to access the victim environment.
During the initial phase of the intrusion, the attackers deployed web shells including default.aspx and UpdateChecker.aspx on EXCH-1 and EXCH-2 to support command execution, file operations, and reconnaissance.
FortiGuard found traces of compromise in the victim network dating back to 15 May 2021, indicating possible attacker presence well before the main intrusion period.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.