Unmasking Rana (APT‑39) Infrastructure Map Centered on the redjewelry.biz Malicious Domain
APT‑39, also known as “Chafer” or “Remix Kitten”, is a sophisticated Iranian cyber espionage group primarily associated with Iran’s Islamic Revolutionary Guard Corps (IRGC) and its intelligence agencies.

Title: Unmasking Rana (APT‑39) Infrastructure Map Centered on the redjewelry.biz Malicious Domain
APT‑39, also known as “Chafer” or “Remix Kitten”, is a sophisticated Iranian cyber espionage group primarily associated with Iran’s Islamic Revolutionary Guard Corps (IRGC) and its intelligence agencies. This group is primarily focused on espionage and intelligence gathering, often targeting organizations in telecommunications, energy, aerospace, and IT sectors worldwide.
Key Characteristics of APT‑39:
Tactics: APT‑39’s operations are highly targeted, with a focus on credential theft, email compromise, and data exfiltration. They often use spear-phishing and watering-hole attacks to gain initial access to networks.
Tools & Techniques: The group is known for using customized malware, often relying on web shells and backdoors to maintain long-term access. They employ credential harvesting tools, keyloggers, and web-based exploits.
Infrastructure: APT‑39 has a history of using custom domains (like redjewelry.biz) to serve malware and maintain C2 (Command & Control) communication, often leveraging encrypted channels to remain undetected.
Goals: The group’s operations are not financially motivated; instead, they focus on surveillance and intelligence collection to support Iran’s geopolitical objectives.
APT‑39’s activities suggest a high degree of sophistication and long-term planning, with a clear interest in political, economic, and military intelligence. Their ability to blend into legitimate network traffic and maintain persistence for extended periods makes them a significant threat to national security and private sector interests alike.
Observed IOC (ingest this into your telemetry)Domain: redjewelry.biz
(Treat any connection to this domain as high priority for investigation and containment.)
Infrastructure map, high level

1. Reconnaissance & Target Selection
Open‑source research, social profiling, credential harvesting, and targeted spear‑phishing lists.
2. Initial Access
Spear‑phishing emails, credential stuffing, watering‑hole compromises, and malicious attachments/links that redirect to asset‑hosted payloads or credential collection pages (e.g., redjewelry.biz).
3. Delivery & Execution
Web‑based implants, staged payloads, or custom tooling delivered via compromised web pages or email attachments.
4. Command & Control (C2)
Encrypted C2 channels using legitimate protocols over obfuscated domains and proxy infrastructure; periodic beaconing to domains like redjewelry.biz or related names.
5. Credential Harvesting & Lateral Movement
Use of harvested credentials to access internal resources, establish persistence, and escalate privileges.
6. Data Collection & Exfiltration
Selective exfiltration of emails, documents, telemetry and session cookies, often via covert, low‑volume channels to avoid detection.
7. Infrastructure Reuse & Layering
Use of multiple domain aliases, fast‑flux hosting, bulletproof providers, and sometimes shared infrastructure across campaigns to obfuscate attribution.
Technical indicators & defensive signals to monitor
Network: DNS queries or HTTP/S connections to redjewelry.biz or newly registered, similar domains; unusual POSTs with small, frequent payloads; anomalous SNI values or TLS fingerprints.
Email: Incoming emails with links redirecting to unusual domains, attachments with odd macro behavior, or sender addresses that impersonate trusted partners.
Endpoints: New or unexpected service processes, unusual scheduled tasks, presence of unknown web shells or reverse‑proxy tools, and logins from atypical geolocations or after hours.
Identity: Multiple failed logins followed by a successful access, unusual token exchanges, and MFA bypass attempts.
| IOC Type | Indicator | First Observed (UTC) | Count | Notes |
|---|---|---|---|---|
| FileHash-SHA256 | 7d6941590e5a405d412c577da3ccea56c8ace91222fed4c822e7d2b4ab3eb51b | Dec 8, 2020, 17:23:51 | 1 | – |
| FileHash-SHA1 | 28fa9354be6ce503ee7c1f7615a26cdd99d7b801 | Dec 8, 2020, 17:23:51 | 1 | – |
| FileHash-SHA1 | c2694dae46fd2846368731d92e810f32c2c9a2f9 | Dec 8, 2020, 17:23:51 | 1 | – |
| FileHash-SHA1 | c552f74bf23211428b7fab141a72db9073a98729 | Dec 8, 2020, 17:23:51 | 1 | – |
| domain | fullplayersoftware.com | Dec 8, 2020, 17:23:51 | 59 | Observed high frequency (block/monitor) |
| domain | softwareplayertop.com | Unknown | Unknown | No timestamp/count provided, recommend investigation |
Example non‑actionable hunt queries
DNS logs: dns.question.name == “redjewelry.biz” OR dns.question.name : “redjewelry”
Web proxy: http.request.method == “POST” && http.host : “redjewelry.biz”
Authentication logs: event.action == “login_success” AND src.geoip.country != expected_country AND user NOT in exception_list
Rapid containment checklist
1. Block redjewelry.biz at DNS and web gateway layers.
2. Isolate hosts that resolved or connected to the domain; collect full disk, memory, and network captures.
3. Force password resets and re‑issue credentials for impacted accounts; enforce MFA where not already in place.
4. Hunt for lateral movement using harvested credentials and review logs for additional domain/IP correlations.
5. Update detection rules with telemetry signatures and share phishing samples with mail filtering teams.
Why this matters
APT‑39 campaigns are often targeted, patient, and focused on intelligence collection. Early detection of infrastructure artifacts like redjewelry.biz significantly reduces dwell time and limits data loss. Mapping the attacker’s infrastructure from initial phish to C2 lets defenders prioritize controls, harden identity, and stop intrusions before they escalate.
How we help
We produce prioritized, operational infrastructure maps and correlate IOCs across network, email, and identity telemetry then deliver playbooks your SOC can apply immediately. Want a tailored investigation or a full infrastructure map for your environment?
Request a custom analysis



