Alpha Cyber

Hunting the Hunters: How We Discovered the Iranian Spy Network in Your Inbox.

The “SiameseKitten” APT (also known as Lyceum) represents one of the most persistent and calculated threat actors operating out of Iran.

Alpha Cyber Research3 min readupdated 1 Apr 2026
Siamise Iranian Danbot

Behind the Curtain: Mapping the Infrastructure of Iranian Espionage.

The “SiameseKitten” APT (also known as Lyceum) represents one of the most persistent and calculated threat actors operating out of Iran. While many focus on simple phishing, this group builds entire digital ecosystems complete with fake job portals and impersonated HR identities to lure high-value targets.

This post breaks down their latest maneuvers using the Shark Backdoor and Danbot RAT, and how we used advanced infrastructure analysis to expose the hidden architecture behind their campaign.

Executive Summary

SiameseKitten (Lyceum) has evolved beyond basic intrusion. By leveraging high-fidelity impersonation of HR departments and software firms, they deploy a sophisticated dual-malware threat: the Shark Backdoor for initial reconnaissance and the Danbot RAT for long-term persistence and data theft. Our analysis reveals an interconnected web of C2 servers and phishing nodes designed to bypass traditional perimeter defenses.


The Deception: When a Career Opportunity is a Compromise

Most attackers want to break in; SiameseKitten wants to be invited in. Their latest campaign targets IT and communications sectors by creating highly realistic job-seeking scenarios. They register domains that look like legitimate corporate career pages such as softwareagjobs[.]com and use LinkedIn to build rapport with employees.

Once trust is established, the “recruiter” sends a package. This isn’t a resume; it’s a weaponized archive containing the Shark Backdoor.


The Payload: Shark & Danbot

Shark Backdoor: Written in .NET, this is their “scout.” It performs environment checks (like ensuring the screen resolution is wide enough to be a real workstation and not a researcher’s sandbox) and establishes the first line of communication with the command-and-control (C2) server.

Danbot RAT: Once the environment is deemed “safe” by the attackers, they drop the Danbot RAT. This tool allows for full remote control, mimicking legitimate software like UltraVNC or VMware to blend into your process list. From here, the espionage begins in earnest: credential harvesting, file exfiltration, and lateral movement.

VirusTotal Danbot Iran Campaign Graph

Mapping the Shadows: How We Uncovered the Web

To truly understand this threat, we looked beyond the individual files. By analyzing the “digital fingerprints” left by the attackers, we mapped the connections between seemingly unrelated domains and IP addresses.

We identified recurring patterns in how their servers were staged. By pivoting through specific Autonomous System Numbers (ASNs) specifically nodes within Colocrossing and M247 Ltd we uncovered a cluster of infrastructure. By tracing the links between a single phishing domain and its underlying IP, we visualized a hierarchy of C2 servers (like defenderstatus[.]com) that the attackers thought were hidden. This structural view allows us to see not just where they are today, but where they are likely to move tomorrow.


Indicators of Compromise (IOCs)

Immediate action is required. We recommend blocking the following hashes and domains at your firewall and endpoint levels.

EntityType / File NameIndicator (Hash / Domain / IP)
Shark BackdoorSHA-25689ab99f5721b691e5513f4192e7c96eb0981ddb6c2d2b94c1a32e2df896397b8
Shark BackdoorMD5a4185f95c61076590ca2eb96e4697c73
Shark BackdoorSHA-11b990280fd7f13143bddb1cfd69265650aecf49f
Shark ComponentAudioddg[.]exeee98f9fb8050d7232466da064637e8afc285f2c4 (SHA-1)
Shark ComponentWinlangdb[.]exef6ae4f4373510c4e096fab84383b547c8997ccf3673c00660df8a3dc9ed1f3ca (SHA-256)
Shark ExecutableShark[.]exe3a3d600ad9c9615f18003620a1bf5f28 (MD5)
DanBot RATWINVNC[.]exe21ab4357262993a042c28c1cdb52b2dab7195a6c30fa8be723631604dd330b29 (SHA-256)
DanBot RATUltraVNC[.]exed3606e2e36db0a0cb1b8168423188ee66332cae24fe59d63f93f5f53ab7c3029 (SHA-256)
Fake Job DomainPhishingsoftwareagjobs[.]com
Fake Job DomainPhishingJobschippc[.]com (IP: 23.95.218[.]240)
C2 ServerCommand & Controldefenderstatus[.]com (IP: 23.94.22[.]145)
C2 ServerCommand & Controldnsstatus[.]org (IP: 23.95.9[.]100)
C2 ServerCommand & Control185.243.112[.]120 / 185.244.213[.]73

Are You Already in the Web?

The danger of SiameseKitten is their patience. They may spend weeks building a relationship with your IT lead before ever dropping a malicious file. If you haven’t audited your external-facing infrastructure or monitored for these specific C2 patterns, you are operating in the dark.

Our team specializes in advanced threat hunting and infrastructure mapping. We don’t just wait for an alert we proactively dismantle the attacker’s environment before they can pivot into your sensitive data.

In Brief: Your Defense Strategy

SiameseKitten’s campaign relies on the intersection of human psychology and technical stealth. By utilizing job-themed lures and custom RATs like Danbot, they maintain a low profile that evades standard signatures. Defeating them requires proactive infrastructure tracking identifying the malicious nodes and ASNs they inhabit to block the attack at the source.

Would you like us to run a comprehensive scan of your network against these specific SiameseKitten indicators today?

Keep reading

Related research

Daxin Rootkit
Threat ReportsTLP:AMBER

Daxin Returns: A 13-Year-Old China-Linked Rootkit That Never Called Home

Symantec found the Daxin kernel rootkit still operational on a Taiwan manufacturing subsidiary in 2026, alongside a previously undocumented backdoor, Stupig, that runs SYSTEM commands from the Windows logon screen before anyone signs in.

6 min readAPT

Contact

Talk to someone who has seen this before.

You speak directly to the people doing the work, wherever in the world you operate.

Or email [email protected]