Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors DieNet

Also known as: Shiite_Harvest, MuddyWater, tracked as, Cyber Av3ngers, Storm-0784, DarkStorm, ransomware, MRHELL112, INC Ransomware

Description

DieNet emerged in March 2025 as a politically driven hacktivist collective, proclaiming support for its Shiite affiliates through coordinated attacks on entities tied to political figures. The group’s first noted operations targeted ten Iraqi websites and later a Trump‑aligned business network, utilizing #DieNet and #Shiite_Harvest hashtags to broadcast their intent. Since 2025 DieNet has expanded beyond DDoS, incorporating advanced techniques such as token manipulation, container abuse, and sophisticated Kerberos ticket forgery to gain persistence, evade detection, and achieve lateral movement. The group’s toolkit includes trusted developer utilities (MSBuild, ClickOnce, JamPlus), Docker/Kubernetes orchestration, and a suite of command‑line and script based payloads that support audio/video capture, data encoding, and exfiltration. DieNet demonstrates a clear operational shift toward multi‑vector campaigns: high‑volume Reflection DDoS using large botnets; credential‑reuse tactics (Pass the Hash/Ticket); exploitation of industrial control PLCs from Rockwell Automation/Allen‑Bradley platforms; and an emerging ransomware presence linked to Dark Storm Team / MRHELL112. These capabilities reveal a group ready to adapt tools across multiple environments—cloud, on‑prem, and OT—to maximize impact.

Goals & Targeting

Targeted Sectors

Financial services
Government
Critical infrastructure
Education
Telecommunications
Defense
Energy
Healthcare
Manufacturing
Media
Retail
Aviation
Non profit
Transportation
Maritime

Targeted Countries / Regions

IL
IR
US
AU
AE
TR
SA
EG
RU
IN
NG
PL

AI Analysis

Grounded in web research
· analyzed in 2 chunks · 2 days ago

Executive Summary

DieNet is an emergent hacktivist group that surfaced in early 2025 and has rapidly escalated from high‑volume DDoS campaigns to multi‑vector attacks targeting critical U.S., Israeli, Australian, and Middle Eastern infrastructure. The actors blend political disruption with sophisticated credential abuse—such as Kerberos golden/silver tickets—and exploit industrial control systems while also deploying ransomware families under the Dark Storm banner.

Goals & Targeting

DieNet’s strategic objectives revolve around political disruption and sectarian messaging. By targeting governments, financial services, energy, telecommunications, healthcare, critical infrastructure, and educational institutions across Israel, Iran, the U.S., Australia, UAE, Turkey, Saudi Arabia, Egypt, Russia, India, Nigeria, and Poland, the group seeks to destabilize state‑backed or politically associated networks while amplifying its ideological narrative. Its selection of high‑profile public services (e.g., national portals, universities) indicates a desire for visibility and propaganda dissemination rather than pure financial gain.

Enhanced Description

Key Capabilities

  • Backup software discovery via CLI, registry and process inspection
  • Data encoding using Base64, Hex, MIME and other non‑standard methods
  • Exploitation of external remote services across platforms
  • Access token manipulation (imitation, theft, creation with token, PID spoofing, SID‑history injection)
  • Infrastructure share discovery on Windows, Linux, macOS
  • Container deployment and abuse via Docker and Kubernetes
  • Trusted developer utilities proxy execution (MSBuild, ClickOnce, JamPlus)
  • System time discovery for precision adjustment
  • Video capture functionality
  • Shared module manipulation (DLL injection/overwrites)
  • System recovery inhibition techniques
  • High‑volume Network Denial of Service (reflection amplification, botnet attacks)
  • Audio capture capabilities
  • Use of alternate authentication materials (T1550 family)
  • Abuse of Component Object Model and Dynamic Data Exchange for lateral movement
  • Inter‑Process Communication via XPC services, DDE, COM
  • Data archiving & encryption through custom libraries/utilities
  • Kerberos security abuses: AS‑REP roasting, golden/silver ticket forging, Ccache theft
  • Certificate and registry attribute manipulation to subvert trust controls
  • Elevation control mechanism abuse (UAC bypass)
  • Debugger evasion tactics (anti‑debugging checks, trap execution)
  • MFA request generation exploitation
  • Plist file modifications for persistence on macOS
  • Serverless environment execution detection
  • SQL stored procedure abuse for persistence/exfiltration
  • Cloud account creation and abuse across IaaS IdP SaaS
  • Defacement operations exploiting weakened defenses
  • Exfiltration over command & control channels
  • Industrial control PLC exploitation (Rockwell/Allen‑Bradley)

MITRE ATT&CK Tactics

Discovery
Execution
Privilege Escalation
Lateral Movement
Credential Access
Defense Evasion
Impact
Collection

ATT&CK Techniques

T1518.002
T1132.001
T1132.002
T1133
T1134
T1134.001
T1134.002
T1134.003
T1134.004
T1134.005
T1135
T1610
T1127.001
T1127.002
T1127.003
T1124
T1125
T1129
T1490
T1498
T1123
T1550
T1550.001
T1059.013
T1559.001
T1559.002
T1559
T1559.003
T1560
T1560.001
T1560.002
T1560.003
T1558.004
T1558.001
T1558.002
T1558
T1548
T1622
T1546.005
T1621
T1647
T1648
T1505.001
T1505.002
T1505.004
T1505.005
T1525
T1528
T1542
T1542.001
T1542.002
T1542.004
T1542.005
T1546.016
T1546.017
T1547.009
T1547.010
T1136
T1136.003
T1218.011
T1218.012
T1497
T1505
T1547.015
T1548.002
T1550.002
T1550.003
T1548.005
T1189

Software / Tooling

DieNet
MSBuild
ClickOnce
JamPlus
Docker
Kubernetes
CL-STA-1128
Cyber Av3ngers
Storm-0784
Dark Storm Team
MRHELL112
Explosive
Epic
Skeleton Key
Qilin
Cobalt
Hook
Nexus
Rogue
Rhysida
Interception
Leverage
systemd
OilRig
Custom malware
DragonForce
Gentlemen
Global
Handala
SafePay
Stealc
STOP
Group Policy
Windows Command Shell
Telegram
GitHub
VBScript
Remote access tools
BITS
Rundll32
mshta
Rootkit
wmic
GitHub Actions workflows
WinRM
Infostealer
MuddyWater
PowerShell

Campaigns & Victims

DieNet’s operational tempo has accelerated dramatically, particularly in March 2026 when it executed over 192 separate attacks—a yearly output compressed into a single month. The group has consistently paired large‑scale reflection amplification DDoS with opportunistic defacement campaigns against government ministries, university networks, and consumer brands, especially within Australia and the Middle East. In addition to denial‑of‑service, DieNet performed 12 exfiltration events using command‑and‑control channels, leveraged Pass‑the‑Hash/Ticket techniques for lateral movement, and exploited Rockwell Automation/Allen‑Bradley PLCs through affiliated actors (CL‑STA‑1128/Cyber Av3ngers/Storm‑0784). A ransomware component under the Dark Storm Team / MRHELL112 banner has also emerged, signaling a broadening threat spectrum beyond pure disruption. Victim types span national critical infrastructure, finance, defense, healthcare, and public sector portals in a geographically diverse footprint. Operations are coordinated via social media hashtags while using sophisticated credential abuse to facilitate persistence and exfiltration across cloud and on‑prem environments.

IOC Patterns

  • Domain-based indicators (suspicious commercial hosting domains, phishing URLs)
  • Executable file paths indicating payload deployment such as mavinject.exe or SyncAppvPublishingServer.vbs
  • Kerberos golden/silver ticket forging activity
  • AS‑REP roasting attempts targeting service accounts
  • Certificate/registry attribute manipulation indicative of trust subversion
  • Debugger evasion indicators (anti-debug checks and trap execution)

Recommended Actions

  • Deploy monitoring and alerting for MSBuild, ClickOnce, and JamPlus execution paths
  • Implement detection of container orchestration abuse in Docker/Kubernetes environments
  • Enable comprehensive logging of token creation, impersonation, PID spoofing, and related privilege changes
  • Establish Kerberos monitoring to detect golden/silver ticket forging, AS‑REP roasting, and Ccache theft attempts
  • Configure network traffic analysis for reflection amplification DoS and abnormal volumetric attack patterns
  • Apply best‑practice controls against elevation mechanisms, debugger evasion, and UAC bypass techniques (e.g., T1548.002)
  • Deploy detection rules for macOS login item persistence (T1547.015) and other platform persistence tactics
  • Enforce credential protection to mitigate Pass‑the‑Hash/Ticket reuse (T1550 family)
  • Implement behavior‑based, multi‑platform intrusion detection for Drive‑by Compromise (T1189)
  • Correlate web request anomalies with post‑exploit activity to detect exploitation events
  • Segment OT/ICS networks and harden firmware to defend against PLC exploitation
  • Use rate limiting, traffic scrubbing, and anti‑DDoS services to mitigate large‑scale DoS attacks

Suggested Tags

hacktivist
multi-vector attack
critical-infrastructure target
DDoS
Government Targeting
Industrial Control System Attack
Political Motivation
Defacement

Confidence Assessment

The available data provides a high‑level view of DieNet’s tactics, techniques, and objectives based largely on public reports and shared indicators. While the breadth of MITRE technique coverage suggests significant threat actor sophistication, there remain gaps regarding exact attribution timelines, in‑depth technical capabilities (e.g., specific ransomware payloads), and precise adversary infrastructure. The operational tempo and geographic reach are corroborated by multiple sources but the depth of evidence for certain techniques (e.g., Kerberos ticket forging) is largely inferred from associated tool usage rather than confirmed capture samples.

ATT&CK Techniques

Initial Access
1 technique
1 technique

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

References

  1. unit42.paloaltonetworks.com — Cited by web research for: Cyber Av3ngers
  2. attack.mitre.org — Cited by web research for: T1518.002
  3. www.group-ib.com — Cited by web research for: Telegram
  4. www.group-ib.com — Cited by web research for: Explosive
  5. attack.mitre.org — Cited by web research for: vnd.openxmlformats-officedocument.spreadsheetml.sheet

Intel Summary

74

Techniques

53

Tools

0

Campaigns

40

IOCs

0

Observed Data

14

Tactics

Tags

Critical Infrastructure
DDoS
Hacktivism
Hacktivist
APT
Political-Espionage
Sectarian-Conflict
Iraq-related
U.S.-related
hacktivist
multi-vector attack
critical-infrastructure target
Government Targeting
Industrial Control System Attack
Political Motivation
Defacement

Details

Type
Unknown
Primary Motivation
Disruption
Country of Origin
Israel (IL)
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.