Also known as: Yellow Liderc, the BM-120, Al, Beijing Tianhua International Co, Ltd, 239 Factory, Anvik Technologies, Bob Jefferson
Shahid Hemmat is an alleged Iranian state‑sponsored threat actor linked to the Islamic Revolutionary Guard Corps – Cyber Command (IRGC‑CEC). Intelligence analysts trace activities attributed to this group under the public banner of Yellow Liderc, with additional aliases including Beijing Tianhua International Co, humanized names such as "Bob Jefferson" and corporate identifiers like "239 Factory". The group's operations focus on disruptive sabotage rather than financial gain. Their most documented incident involved a sophisticated intrusion into a municipal water system in Aliquippa, Pennsylvania, where they deployed a RAT payload that disabled a booster station, causing a temporary loss of potable water for the region. In addition to water‑utility targets, Shahid Hemmat has been linked to attacks against defense contractors, aerospace firms, and other sectors critical to national security. Technologically, the group fields an eclectic toolbox: they routinely use widespread banking trojans such as Emotet and supply‑chain malware like PlugX; employ remote access tools including Brute Ratel C4, Poison Ivy, Ghost RAT, and legacy assets such as Agent Tesla for credential harvesting. Recent reports also associate them with fast‑flux domain generation, command‑and‑control over HTTP/HTTPS, and the use of cloud or bullet‑proof hosting to stage malicious infrastructure.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
Shahid Hemmat, an Iranian IRGC‑CEC affiliated actor also known as Yellow Liderc, has repeatedly targeted U.S. critical infrastructure, most notably the Municipal Water Authority in Aliquippa, Pennsylvania where they allegedly disabled a booster station and disrupted drinking water supply. The U.S. government is offering a $10 million reward for information on key personnel such as Manouchehr Akbari and Amir Hossein Hoseini.
Goals & Targeting
Shahid Hemmat’s strategic objectives revolve around political coercion through disruptive sabotage of critical U.S. infrastructure. By targeting defense, aerospace, aviation, transportation, energy, water, and financial‐services sectors—particularly entities deemed vital for national security—the group seeks to undermine confidence in the U.S. domestic supply chain and exert leverage against Iranian sanctions or diplomatic pressures. Their chosen victims are typically large corporations with high public profiles or small municipal utilities that provide essential services, enabling a disproportionate impact relative to the effort required.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Shahid Hemmat typically pursues low‑profile, yet high‑impact campaigns that focus on critical infrastructure. Operational tempo appears sporadic, with each engagement taking weeks to plan and months to execute, emphasizing thorough staging and post‑exploitation controls. The group leverages widely available malware families alongside custom script modules for lateral movement and persistence. Prior operations have included the Aliquippa water sabotage, suspected infiltrations of defense procurement vendors, and potential compromise of aviation maintenance facilities. Their attacks often surface after a prolonged dormant period, suggesting a strategic waiting game designed to maximize disruption when an organization’s security posture is weakest.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
High confidence that Shahid Hemmat is an IRGC‑CEC affiliated entity based on multiple public intelligence reports linking the group to the actor known as Yellow Liderc and corroborating documentation from U.S. agencies offering rewards for key members. Confidence in specific tool usage (e.g., PlugX, Brute Ratel C4) is moderate; attribution relies on observed malware samples and associated IOC patterns rather than confirmed insider testimony. Activity dates are sparse beyond the noted Aliquippa incident, creating a data gap regarding the group's current operational tempo and recent campaign evolution.
No campaigns linked yet.
No observed data linked yet.
10
Techniques
40
Tools
0
Campaigns
37
IOCs
0
Observed Data
1
Tactics