Iranian Hackers Infiltrate Vital National Systems with Covert Webshells and Backdoors

Iranian Hackers Infiltrate Vital National Systems with Covert Webshells and Backdoors

Long-Term Cyber Espionage Operation Disrupts Critical Infrastructure in Middle East

A prolonged and stealthy cyber campaign has come to light, revealing the compromise of vital infrastructure systems across the Middle East. The activity, attributed to a threat actor aligned with Iranian state interests, reflects a deeply strategic, intelligence-driven assault on national resilience.

Spanning nearly two years—from May 2023 through February 2025—the intrusion underscores a high level of technical sophistication, particularly in its sustained targeting of key public services. Forensic analysis, however, suggests this operation had roots going back to at least May 2021, signaling a patient and calculated effort to establish long-term access.

Attackers initially leveraged stolen VPN credentials to infiltrate exposed systems. Once inside, they rapidly deployed multiple web shells on externally accessible servers, securing durable control points for future operations.

From these beachheads, the adversaries escalated their intrusion by deploying a suite of tailored backdoors, including Havoc, HXLibrary, NeoExpressRAT, and the newly observed HanifNet. These implants allowed attackers to execute commands, manipulate files, and survey the compromised environments with surgical precision.

A key discovery by Fortinet analysts was the group’s attempt to dismantle traditional network segmentation—a critical safeguard against lateral movement. The intruders used an arsenal of open-source tunneling tools such as plink, Ngrok, glider proxy, and ReverseSocks5 to bypass these restrictions and extend their reach toward protected segments, possibly including industrial control systems.

Tailored Malware & Persistent Access

One of the operation’s most technically revealing components was its deployment of custom-developed malware. Chief among these was HanifNet, a .NET-based implant crafted for long-term persistence, showcasing a deep understanding of system internals and evasion techniques.

This campaign is a stark reminder of the evolving threat landscape and the growing boldness of state-aligned actors in pursuing strategic digital footholds within national infrastructures.

Adaptive Toolset Evolution Marks Advanced Iranian Cyber Campaign

A recently uncovered timeline reveals the evolving sophistication of tools employed by an Iranian-linked threat group during a multi-phase intrusion campaign, as analyzed by Fortinet researchers.

Rather than relying on conventional communication channels, the group engineered stealthy command-and-control (C2) mechanisms designed to slip past typical detection layers. Their communication strategies were deliberately masked, allowing them to operate within the victim environment for extended periods without triggering alerts.

Key forensic evidence shows that the attackers cleverly mimicked legitimate Windows system behavior to maintain persistence. For instance, they created scheduled tasks disguised as Windows Update activities, embedding malicious PowerShell payloads within seemingly routine system operations:

Further along the attack timeline, two significant tools were deployed to expand control over compromised infrastructure. One was HXLibrary, a trojanized IIS module offering direct system-level manipulation of Microsoft web servers. The other, NeoExpressRAT, was a compact, Go-based remote access trojan (RAT) hardcoded to communicate with attacker-controlled servers, ensuring reliable command execution across sessions.

These developments underscore a strategic and adaptive toolkit aligned with long-term espionage goals. The incorporation of web server implants, obfuscated scripting, and resilient C2 architecture signals a growing level of maturity in Iranian offensive cyber operations—posing ongoing risks to critical systems worldwide.

More Articles & Posts