Alpha Cyber

Infrastructure Unmasked: The Evolution of Emennet Pasargad

(ASA) In mid-2024, a joint advisory from the U.S. Department of Treasury, and the Israel National Cyber Directorate sounded a critical alarm.

Alpha Cyber Research2 min readupdated 1 Apr 2026
Emennet Pasargad Hackers

In mid-2024, a joint advisory from the U.S. Department of Treasury, and the Israel National Cyber Directorate sounded a critical alarm. The Iranian cyber group Emennet Pasargad long known by aliases such as Cotton Sandstorm, Marnanbridge, and Haywire Kitten has undergone a strategic rebranding.

The group now operates under the corporate front Aria Sepehr Ayandehsazan (ASA). Their goal? To professionalize their interference and espionage operations under the guise of a legitimate IT services company.

The New Architecture of Interference

The group has shifted away from simple hacking, moving toward a “service provider” model. Their modern infrastructure is built on:

  • Fictitious Hosting Resellers: ASA has established its own hosting entities (like “Server-Speed” and “VPS-Agent”) to provision servers to their own actors and regional affiliates in Lebanon. This provides a layer of plausible deniability.

  • AI-Enabled Disinformation: The group is leveraging artificial intelligence to create highly convincing video and voice modulation for psychological operations.

  • IP Camera Harvesting: A disturbing new project involves mass-scanning for vulnerable IP cameras to harvest live content, particularly targeting infrastructure in Israel and Western media outlets.

Critical Indicators of Compromise (IOCs)

To protect your perimeter, our SOC team recommends immediately blacklisting the following assets associated with recent ASA campaigns.

TypeIndicator
Domainonlinelive[.]info, zeusistalking[.]io, zeusistalking[.]net, zeusistalking[.]com
Domainrgud-group[.]net, rgud-group[.]com, cyberflood[.]io, cybercourt[.]io
Domainpro-today[.]org, il-cert[.]net
FilenameFirst.exe
SHA2564431b2a4d7758907f81fb1a0c1e36b2ce03e08d43123b1c398487770afd20727
SHA2566f765dda126e830c6cd2c7938dbb970d03be728e82c00388903a4ef3f9ecc853
IPv45[.]230[.]56[.]148, 77[.]91[.]74[.]158, 195[.]26[.]87[.]80, 213[.]109[.]147[.]97
IPv4185[.]110[.]188[.]112, 45[.]140[.]146[.]139, 45[.]84[.]0[.]237, 45[.]140[.]146[.]197
IPv445[.]140[.]146[.]137, 45[.]84[.]0[.]254, 45[.]142[.]212[.]21, 45[.]140[.]146[.]108
IP Range85[.]206[.]170[.]160/27, 85[.]206[.]167[.]224/27
IP Range85[.]206[.]169[.]64/28, 85[.]206[.]169[.]80/28

On VirusTotal, the connection between the onlinelive[.]info domain and the Bublik Trojan (often linked to Emennet Pasargad activity) is made visible through the platform’s Relations and Graph features. Specifically, when analyzing the domain, VirusTotal identifies it as a distribution point or Command and Control (C2) server for specific malicious files. Many of the PE (Portable Executable) files communicating with this URL are flagged by multiple antivirus engines with signatures such as Trojan.Win32.Bublik or Backdoor.Bublik. By pivoting through the Communicating Files section, researchers can see that these Bublik-infected samples consistently reach out to the onlinelive[.]info infrastructure to download secondary payloads or exfiltrate victim data, effectively mapping the domain as a core pillar of the Trojan’s operational lifecycle.

  • Communicating Files: Shows a list of SHA-256 hashes (Bublik samples) that have been observed connecting to the domain.

  • Detection Labels: Displays the specific “Bublik” naming convention used by engines like Kaspersky, ESET, or Microsoft for the files associated with the URL.

  • Graph Visualizer: Creates a web showing the domain at the center, with spider-web lines connecting it to various malware samples that have been clustered by threat intelligence groups as part of the Emennet Pasargad toolkit.

VirusTotal emennet pasargad Bubik Graph

Is Your Infrastructure a Target?

Recent Microsoft intelligence suggests this group is actively probing media outlets and election-related websites. Their tradecraft is no longer just about data theft it is about influence.

At Alpha Cyber, we specialize in mapping these hidden threats before they reach your firewall. We provide:

  • Active Threat Hunting targeting APT-specific TTPs.

  • Brand Protection to identify and take down fake news personas.

  • Infrastructure Audits to secure your IP camera and IoT fleet.

Stay ahead of the next campaign.

Keep reading

Related research

Daxin Rootkit
Threat ReportsTLP:AMBER

Daxin Returns: A 13-Year-Old China-Linked Rootkit That Never Called Home

Symantec found the Daxin kernel rootkit still operational on a Taiwan manufacturing subsidiary in 2026, alongside a previously undocumented backdoor, Stupig, that runs SYSTEM commands from the Windows logon screen before anyone signs in.

6 min readAPT

Contact

Talk to someone who has seen this before.

You speak directly to the people doing the work, wherever in the world you operate.

Or email [email protected]