Infrastructure Unmasked: The Evolution of Emennet Pasargad
(ASA) In mid-2024, a joint advisory from the U.S. Department of Treasury, and the Israel National Cyber Directorate sounded a critical alarm.

In mid-2024, a joint advisory from the U.S. Department of Treasury, and the Israel National Cyber Directorate sounded a critical alarm. The Iranian cyber group Emennet Pasargad long known by aliases such as Cotton Sandstorm, Marnanbridge, and Haywire Kitten has undergone a strategic rebranding.
The group now operates under the corporate front Aria Sepehr Ayandehsazan (ASA). Their goal? To professionalize their interference and espionage operations under the guise of a legitimate IT services company.
The New Architecture of Interference
The group has shifted away from simple hacking, moving toward a “service provider” model. Their modern infrastructure is built on:
Fictitious Hosting Resellers: ASA has established its own hosting entities (like “Server-Speed” and “VPS-Agent”) to provision servers to their own actors and regional affiliates in Lebanon. This provides a layer of plausible deniability.
AI-Enabled Disinformation: The group is leveraging artificial intelligence to create highly convincing video and voice modulation for psychological operations.
IP Camera Harvesting: A disturbing new project involves mass-scanning for vulnerable IP cameras to harvest live content, particularly targeting infrastructure in Israel and Western media outlets.
Critical Indicators of Compromise (IOCs)
To protect your perimeter, our SOC team recommends immediately blacklisting the following assets associated with recent ASA campaigns.
| Type | Indicator |
|---|---|
| Domain | onlinelive[.]info, zeusistalking[.]io, zeusistalking[.]net, zeusistalking[.]com |
| Domain | rgud-group[.]net, rgud-group[.]com, cyberflood[.]io, cybercourt[.]io |
| Domain | pro-today[.]org, il-cert[.]net |
| Filename | First.exe |
| SHA256 | 4431b2a4d7758907f81fb1a0c1e36b2ce03e08d43123b1c398487770afd20727 |
| SHA256 | 6f765dda126e830c6cd2c7938dbb970d03be728e82c00388903a4ef3f9ecc853 |
| IPv4 | 5[.]230[.]56[.]148, 77[.]91[.]74[.]158, 195[.]26[.]87[.]80, 213[.]109[.]147[.]97 |
| IPv4 | 185[.]110[.]188[.]112, 45[.]140[.]146[.]139, 45[.]84[.]0[.]237, 45[.]140[.]146[.]197 |
| IPv4 | 45[.]140[.]146[.]137, 45[.]84[.]0[.]254, 45[.]142[.]212[.]21, 45[.]140[.]146[.]108 |
| IP Range | 85[.]206[.]170[.]160/27, 85[.]206[.]167[.]224/27 |
| IP Range | 85[.]206[.]169[.]64/28, 85[.]206[.]169[.]80/28 |
On VirusTotal, the connection between the onlinelive[.]info domain and the Bublik Trojan (often linked to Emennet Pasargad activity) is made visible through the platform’s Relations and Graph features. Specifically, when analyzing the domain, VirusTotal identifies it as a distribution point or Command and Control (C2) server for specific malicious files. Many of the PE (Portable Executable) files communicating with this URL are flagged by multiple antivirus engines with signatures such as Trojan.Win32.Bublik or Backdoor.Bublik. By pivoting through the Communicating Files section, researchers can see that these Bublik-infected samples consistently reach out to the onlinelive[.]info infrastructure to download secondary payloads or exfiltrate victim data, effectively mapping the domain as a core pillar of the Trojan’s operational lifecycle.
How VirusTotal visualizes this link:
Communicating Files: Shows a list of SHA-256 hashes (Bublik samples) that have been observed connecting to the domain.
Detection Labels: Displays the specific “Bublik” naming convention used by engines like Kaspersky, ESET, or Microsoft for the files associated with the URL.
Graph Visualizer: Creates a web showing the domain at the center, with spider-web lines connecting it to various malware samples that have been clustered by threat intelligence groups as part of the Emennet Pasargad toolkit.

Is Your Infrastructure a Target?
Recent Microsoft intelligence suggests this group is actively probing media outlets and election-related websites. Their tradecraft is no longer just about data theft it is about influence.
At Alpha Cyber, we specialize in mapping these hidden threats before they reach your firewall. We provide:
Active Threat Hunting targeting APT-specific TTPs.
Brand Protection to identify and take down fake news personas.
Infrastructure Audits to secure your IP camera and IoT fleet.



