🚨 CYBER INTELLIGENCE ALERT: NETWORK TOPOLOGY AND INFRASTRUCTURE — MCI / HAMRAH-E-AVAL 🇮🇷
⚠️ CRITICAL THREAT: ACTOR "EBONCHERUB" SELLS INTERNAL MAPS AND ASSETS OF IRAN'S MAIN TELECOMMUNICATOR
[STATUS: UNDER ANALYSIS / UNCONFIRMED]
Through tactical monitoring of social media and hacktivist channels, a post by the threat actor identified as EbonCherub on the X/Twitter platform has been detected. The attacker is advertising the sale of confidential information and complete network maps belonging to the Mobile Telecommunications Company of Iran (MCI), also known commercially as Hamrah-e-Aval.
🎯 Affected Entity: MCI / Hamrah-e-Aval (Critical Telecommunications Sector, Islamic Republic of Iran).
👤 Threat Actor: EbonCherub
📂 Incident Type: Sale of Network Intelligence, Exposure of Internal Infrastructure, and Document Identification.
📊 TECHNICAL BREAKDOWN AND IMPACT VECTORS
The forensic analysis of the proof of concept (PoC) shared by the actor reveals that this is not a simple leak of user data, but rather a compromise of the telecommunications company's core network architecture:
🖧 Network Maps and Addressing:
The attacker claims to possess the "complete network map" and internal IP addresses of the infrastructure, allowing a secondary actor to bypass perimeter defenses and move laterally through MCI's network.
🖥️ Server and Operating System Inventory:
The table below details the roles of the assets (dashboard, ecommerce) and reveals the use of Red Hat Linux 7.6 in the critical infrastructure.
A detailed list of Red Hat package managers and repositories is exposed, making it easier for attackers to identify specific, unpatched vulnerabilities (CVEs) within that version of the system.
📞 Documentary and Contact Data:
Fragments of documents in Persian—including landline numbers and email addresses—have been observed; these expose internal switchboard numbers (e.g., [number]) and internal domains (e.g.,
ci.ir), which are useful for social engineering campaigns (Spear-Phishing) targeting network engineers.
⚡ MONITORING AND ASSESSMENT
🌐 Intelligence System:
analyzer.vecert.io
🛡️ Quickly assess your website's security with:
monitor.vecert.io/
#CyberSecurity #DataBreach #Iran #MCI #HamrahEAval #APT #CyberWarfare #EbonCherub #NetworkMap #ThreatIntelligence #CiberAlerta #VECERT #Infosec
نه به اینترنت پرو
نه به فیلترینگ
نه به فیلترشکن
تیم ما اطلاعات محرمانه و کامل از نقشه شیکه همراه اول به فروش می گذارد.
تمامی گروه های هکر و apt که خواهان کمک به مردم هستن می تواند از این اطلاعات را درخواست کنند.
@IranIntlbrk @leakfarsi @tapandegan @NarimanGharib