Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Shahid Hemmat

Also known as: Yellow Liderc, the BM-120, Al, Beijing Tianhua International Co, Ltd, 239 Factory, Anvik Technologies, Bob Jefferson

Description

Shahid Hemmat is an alleged Iranian state‑sponsored threat actor linked to the Islamic Revolutionary Guard Corps – Cyber Command (IRGC‑CEC). Intelligence analysts trace activities attributed to this group under the public banner of Yellow Liderc, with additional aliases including Beijing Tianhua International Co, humanized names such as "Bob Jefferson" and corporate identifiers like "239 Factory". The group's operations focus on disruptive sabotage rather than financial gain. Their most documented incident involved a sophisticated intrusion into a municipal water system in Aliquippa, Pennsylvania, where they deployed a RAT payload that disabled a booster station, causing a temporary loss of potable water for the region. In addition to water‑utility targets, Shahid Hemmat has been linked to attacks against defense contractors, aerospace firms, and other sectors critical to national security. Technologically, the group fields an eclectic toolbox: they routinely use widespread banking trojans such as Emotet and supply‑chain malware like PlugX; employ remote access tools including Brute Ratel C4, Poison Ivy, Ghost RAT, and legacy assets such as Agent Tesla for credential harvesting. Recent reports also associate them with fast‑flux domain generation, command‑and‑control over HTTP/HTTPS, and the use of cloud or bullet‑proof hosting to stage malicious infrastructure.

Goals & Targeting

Targeted Sectors

Defense
Nuclear
Aerospace
Chemical
Financial services
Education
Government
Transportation
Aviation
Information technology
Non profit
Energy
Food agriculture

Targeted Countries / Regions

IR
CN
US

AI Analysis

Grounded in web research
· 22 hours ago

Executive Summary

Shahid Hemmat, an Iranian IRGC‑CEC affiliated actor also known as Yellow Liderc, has repeatedly targeted U.S. critical infrastructure, most notably the Municipal Water Authority in Aliquippa, Pennsylvania where they allegedly disabled a booster station and disrupted drinking water supply. The U.S. government is offering a $10 million reward for information on key personnel such as Manouchehr Akbari and Amir Hossein Hoseini.

Goals & Targeting

Shahid Hemmat’s strategic objectives revolve around political coercion through disruptive sabotage of critical U.S. infrastructure. By targeting defense, aerospace, aviation, transportation, energy, water, and financial‐services sectors—particularly entities deemed vital for national security—the group seeks to undermine confidence in the U.S. domestic supply chain and exert leverage against Iranian sanctions or diplomatic pressures. Their chosen victims are typically large corporations with high public profiles or small municipal utilities that provide essential services, enabling a disproportionate impact relative to the effort required.

Enhanced Description

Key Capabilities

  • Advanced spear‑phishing campaigns with macro‑laden Office documents
  • Use of a broad range of RATs including PlugX, Brute Ratel C4, Poison Ivy, and Ghost RAT
  • Credential harvesting via Agent Tesla and Mimikatz derivatives
  • Exploitation of supply chains and third‑party services to deliver malware
  • Remote administration through Windows Admin Shares (SMB) and PowerShell scripts
  • Command‑and‑control over HTTPS/HTTP with domain generation algorithms
  • Fast‑flux DNS for resilient C2 infrastructure
  • Lateral movement via remote services and stolen credentials
  • Evidence of exfiltration over established command‑and‑control channels
  • Potential use of water‑system SCADA hijacking techniques

MITRE ATT&CK Tactics

Initial Access
Execution
Persistence
Privilege Escalation
Defense Evasion
Credential Access
Discovery
Lateral Movement
Collection
Exfiltration
Impact

ATT&CK Techniques

T1193 - Spearphishing Attachment
T1059.001 - Command & Scripting Interpreter: PowerShell
T1077 - Windows Admin Shares (Remote Services)
T1003.001 - Credential Dumping: Mimikatz
T1021 - Remote Services
T1041 - Exfiltration Over Command and Control Channel
T1105 - Ingress Tool Transfer
T1059.003 - Windows Command Shell
T1070.003 - Indicator Removal on Host
T1115 - Clipboard Data Manipulation

Software / Tooling

Emotet
PlugX
Brute Ratel C4
Poison Ivy
Ghost RAT
Agent Tesla
Cobalt Strike
SUNBURST
Mimikatz
Shamoon
Explosive

Campaigns & Victims

Shahid Hemmat typically pursues low‑profile, yet high‑impact campaigns that focus on critical infrastructure. Operational tempo appears sporadic, with each engagement taking weeks to plan and months to execute, emphasizing thorough staging and post‑exploitation controls. The group leverages widely available malware families alongside custom script modules for lateral movement and persistence. Prior operations have included the Aliquippa water sabotage, suspected infiltrations of defense procurement vendors, and potential compromise of aviation maintenance facilities. Their attacks often surface after a prolonged dormant period, suggesting a strategic waiting game designed to maximize disruption when an organization’s security posture is weakest.

IOC Patterns

  • Spear‑phishing emails containing malicious macro‑laden Office documents
  • Use of compromised third‑party sites or watering holes for initial download
  • Command‑and‑control over HTTPS/HTTP with domain generation algorithms (fast‑flux)
  • Exfiltration via established C2 channels using encrypted tunnels
  • Hosting command servers on bullet‑proof hosting platforms
  • Suspicious usage of .gov domains to mimic legitimate communications

Recommended Actions

  • Deploy enterprise‑level email security that blocks macro attachments and scans links for malicious payloads
  • Segregate critical infrastructure networks from corporate LANs and enforce least‑privileged access controls
  • Implement endpoint detection and response solutions capable of detecting RAT behaviors such as persistence scripts, SMB lateral movement, and credential dumping
  • Monitor SCADA/PLC traffic for anomalies or unauthorized command sequences
  • Apply timely patches to Office suite and other commonly targeted software
  • Conduct regular phishing awareness training focusing on suspicious attachments and domain spoofing
  • Integrate threat‑intel feeds to block known malicious domains and IPs associated with Shahid Hemmat activity
  • Enhance logging of water‑system control equipment and perform continuous anomaly detection for operational technology

Suggested Tags

APT
State‑Sponsored
Iranian
Critical Infrastructure Sabotage
Disruption
Cyber Espionage
Water Supply Attacks
Defence Contractor Targeting

Confidence Assessment

High confidence that Shahid Hemmat is an IRGC‑CEC affiliated entity based on multiple public intelligence reports linking the group to the actor known as Yellow Liderc and corroborating documentation from U.S. agencies offering rewards for key members. Confidence in specific tool usage (e.g., PlugX, Brute Ratel C4) is moderate; attribution relies on observed malware samples and associated IOC patterns rather than confirmed insider testimony. Activity dates are sparse beyond the noted Aliquippa incident, creating a data gap regarding the group's current operational tempo and recent campaign evolution.

ATT&CK Techniques

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Intel Summary

10

Techniques

40

Tools

0

Campaigns

37

IOCs

0

Observed Data

1

Tactics

Tags

Healthcare Targeting
Critical Infrastructure
Government Targeting
APT
State-sponsored
Water sector
State‑Sponsored
Iranian
Critical Infrastructure Sabotage
Disruption
Cyber Espionage
Water Supply Attacks
Defence Contractor Targeting

Details

Type
Unknown
Primary Motivation
Disruption
Country of Origin
I
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.