Alpha Cyber

Unmasking Rana (APT‑39) Infrastructure Map Centered on the redjewelry.biz Malicious Domain

APT‑39, also known as “Chafer” or “Remix Kitten”, is a sophisticated Iranian cyber espionage group primarily associated with Iran’s Islamic Revolutionary Guard Corps (IRGC) and its intelligence agencies.

Alpha Cyber Research3 min readupdated 1 Apr 2026
Rana Android Malware

Title: Unmasking Rana (APT‑39) Infrastructure Map Centered on the redjewelry.biz Malicious Domain

APT‑39, also known as “Chafer” or “Remix Kitten”, is a sophisticated Iranian cyber espionage group primarily associated with Iran’s Islamic Revolutionary Guard Corps (IRGC) and its intelligence agencies. This group is primarily focused on espionage and intelligence gathering, often targeting organizations in telecommunications, energy, aerospace, and IT sectors worldwide.

Key Characteristics of APT‑39:

Tactics: APT‑39’s operations are highly targeted, with a focus on credential theft, email compromise, and data exfiltration. They often use spear-phishing and watering-hole attacks to gain initial access to networks.
Tools & Techniques: The group is known for using customized malware, often relying on web shells and backdoors to maintain long-term access. They employ credential harvesting tools, keyloggers, and web-based exploits.
Infrastructure: APT‑39 has a history of using custom domains (like redjewelry.biz) to serve malware and maintain C2 (Command & Control) communication, often leveraging encrypted channels to remain undetected.
Goals: The group’s operations are not financially motivated; instead, they focus on surveillance and intelligence collection to support Iran’s geopolitical objectives.

APT‑39’s activities suggest a high degree of sophistication and long-term planning, with a clear interest in political, economic, and military intelligence. Their ability to blend into legitimate network traffic and maintain persistence for extended periods makes them a significant threat to national security and private sector interests alike.

Observed IOC (ingest this into your telemetry)Domain: redjewelry.biz

(Treat any connection to this domain as high priority for investigation and containment.)

Infrastructure map, high level

APT-39 AKA Rana redjewelry.biz Graph

1. Reconnaissance & Target Selection

Open‑source research, social profiling, credential harvesting, and targeted spear‑phishing lists.
2. Initial Access

Spear‑phishing emails, credential stuffing, watering‑hole compromises, and malicious attachments/links that redirect to asset‑hosted payloads or credential collection pages (e.g., redjewelry.biz).
3. Delivery & Execution

Web‑based implants, staged payloads, or custom tooling delivered via compromised web pages or email attachments.
4. Command & Control (C2)

Encrypted C2 channels using legitimate protocols over obfuscated domains and proxy infrastructure; periodic beaconing to domains like redjewelry.biz or related names.
5. Credential Harvesting & Lateral Movement

Use of harvested credentials to access internal resources, establish persistence, and escalate privileges.
6. Data Collection & Exfiltration

Selective exfiltration of emails, documents, telemetry and session cookies, often via covert, low‑volume channels to avoid detection.
7. Infrastructure Reuse & Layering

Use of multiple domain aliases, fast‑flux hosting, bulletproof providers, and sometimes shared infrastructure across campaigns to obfuscate attribution.

Technical indicators & defensive signals to monitor

Network: DNS queries or HTTP/S connections to redjewelry.biz or newly registered, similar domains; unusual POSTs with small, frequent payloads; anomalous SNI values or TLS fingerprints.
Email: Incoming emails with links redirecting to unusual domains, attachments with odd macro behavior, or sender addresses that impersonate trusted partners.
Endpoints: New or unexpected service processes, unusual scheduled tasks, presence of unknown web shells or reverse‑proxy tools, and logins from atypical geolocations or after hours.
Identity: Multiple failed logins followed by a successful access, unusual token exchanges, and MFA bypass attempts.

IOC TypeIndicatorFirst Observed (UTC)CountNotes
FileHash-SHA2567d6941590e5a405d412c577da3ccea56c8ace91222fed4c822e7d2b4ab3eb51bDec 8, 2020, 17:23:511
FileHash-SHA128fa9354be6ce503ee7c1f7615a26cdd99d7b801Dec 8, 2020, 17:23:511
FileHash-SHA1c2694dae46fd2846368731d92e810f32c2c9a2f9Dec 8, 2020, 17:23:511
FileHash-SHA1c552f74bf23211428b7fab141a72db9073a98729Dec 8, 2020, 17:23:511
domainfullplayersoftware.comDec 8, 2020, 17:23:5159Observed high frequency (block/monitor)
domainsoftwareplayertop.comUnknownUnknownNo timestamp/count provided, recommend investigation

Example non‑actionable hunt queries

DNS logs: dns.question.name == “redjewelry.biz” OR dns.question.name : “redjewelry”
Web proxy: http.request.method == “POST” && http.host : “redjewelry.biz”
Authentication logs: event.action == “login_success” AND src.geoip.country != expected_country AND user NOT in exception_list

Rapid containment checklist

1. Block redjewelry.biz at DNS and web gateway layers.
2. Isolate hosts that resolved or connected to the domain; collect full disk, memory, and network captures.
3. Force password resets and re‑issue credentials for impacted accounts; enforce MFA where not already in place.
4. Hunt for lateral movement using harvested credentials and review logs for additional domain/IP correlations.
5. Update detection rules with telemetry signatures and share phishing samples with mail filtering teams.

Why this matters

APT‑39 campaigns are often targeted, patient, and focused on intelligence collection. Early detection of infrastructure artifacts like redjewelry.biz significantly reduces dwell time and limits data loss. Mapping the attacker’s infrastructure from initial phish to C2 lets defenders prioritize controls, harden identity, and stop intrusions before they escalate.

How we help

We produce prioritized, operational infrastructure maps and correlate IOCs across network, email, and identity telemetry then deliver playbooks your SOC can apply immediately. Want a tailored investigation or a full infrastructure map for your environment?

Request a custom analysis

Keep reading

Related research

Daxin Rootkit
Threat ReportsTLP:AMBER

Daxin Returns: A 13-Year-Old China-Linked Rootkit That Never Called Home

Symantec found the Daxin kernel rootkit still operational on a Taiwan manufacturing subsidiary in 2026, alongside a previously undocumented backdoor, Stupig, that runs SYSTEM commands from the Windows logon screen before anyone signs in.

6 min readAPT

Contact

Talk to someone who has seen this before.

You speak directly to the people doing the work, wherever in the world you operate.

Or email [email protected]