APTTrail: MarkiRAT indicators and references

Fecha
18 Jun 2026
Actor
markirat
Tipo
Ioc
Pais
Iran
Sector
-
Confianza
high
100
Prioridad analitica
Alta

Basado en actor, pais, IOCs, TTPs, filtracion y calidad de contexto.

30IOCs
0TTPs
markiratActor
IranPais
Executive Summary
APTTrail mantiene indicadores publicos asociados a MarkiRAT. Aliases observados: MarkiRAT. Conteo por tipo: domain: 32, file_path: 4.

Key Points

  • https://securelist.com/ferocious-kitten-6-years-of-covert-surveillance-in-iran/102806/
  • https://twitter.com/360CoreSec/status/1407604585896632323
  • https://twitter.com/360CoreSec/status/1407653661816201226
  • https://twitter.com/360CoreSec/status/1435077875703562242
  • https://www.virustotal.com/gui/file/361524fb3d40dd2f275ee7aa4f40fccfe21f0552cd36ec38f48fbf7e50e66810/detection

Resumen APTTrail

APTTrail mantiene indicadores publicos asociados a MarkiRAT. Aliases observados: MarkiRAT. Conteo por tipo: domain: 32, file_path: 4.

Indicadores de Compromiso (IOCs)

TipoValorContexto
Domainaccountes.google.comesignt.websiteAPTTrail
Domainaccounts.google.comisignin.onlineAPTTrail
Domainaparat.com-view.spaceAPTTrail
Domaincom-accounts.websiteAPTTrail
Domaincom-signin.siteAPTTrail
Domaincom-view.orgAPTTrail
Domaincom-view.spaceAPTTrail
Domaincome-signin.questAPTTrail
Domaincomesignt.websiteAPTTrail
Domaincomi-site.websiteAPTTrail
Domaincomisignin.onlineAPTTrail
Domaincomuk.spaceAPTTrail
Domaingoogle.comisignin.onlineAPTTrail
Domainkhabarfarsi.com-view.orgAPTTrail
Domainmicrocaft.xyzAPTTrail
Domainmicrosoft.com-view.spaceAPTTrail
Domainmicrosoft.come-site.websiteAPTTrail
Domainmicrosoft.comi-site.websiteAPTTrail
Domainmicrosoft.comuk.spaceAPTTrail
Domainmicrosoft.microcaft.xyzAPTTrail
Domainmicrosoft.unupdate.mlAPTTrail
Domainmicrosoft.unupload.xyzAPTTrail
Domainmicrosoft.updatei.comAPTTrail
Domainmin.come-site.websiteAPTTrail
Domainmin.comi-site.websiteAPTTrail
Domainns1.com-accounts.websiteAPTTrail
Domainns1.com-signin.siteAPTTrail
Domainns2.com-accounts.websiteAPTTrail
Domainns2.com-signin.siteAPTTrail
Domainunupdate.mlAPTTrail

Referencias

Diamond Model

Adversary
markirat
Ver perfil →
Victim
APTTrail: MarkiRAT indicators and references
Iran
Capability
Ioc
Infrastructure
accountes.google.comesignt.website
accounts.google.comisignin.online
aparat.com-view.space
com-accounts.website

Indicadores de Compromiso (IOCs)

TipoValorContextoOSINT
Domain accountes.google.comesignt.website APTTrail VT OffSec SOCRadar
Domain accounts.google.comisignin.online APTTrail VT OffSec SOCRadar
Domain aparat.com-view.space APTTrail VT OffSec SOCRadar
Domain com-accounts.website APTTrail VT OffSec SOCRadar
Domain com-signin.site APTTrail VT OffSec SOCRadar
Domain com-view.org APTTrail VT OffSec SOCRadar
Domain com-view.space APTTrail VT OffSec SOCRadar
Domain come-signin.quest APTTrail VT OffSec SOCRadar
Domain comesignt.website APTTrail VT OffSec SOCRadar
Domain comi-site.website APTTrail VT OffSec SOCRadar
Domain comisignin.online APTTrail VT OffSec SOCRadar
Domain comuk.space APTTrail VT OffSec SOCRadar
Domain google.comisignin.online APTTrail VT OffSec SOCRadar
Domain khabarfarsi.com-view.org APTTrail VT OffSec SOCRadar
Domain microcaft.xyz APTTrail VT OffSec SOCRadar
Domain microsoft.com-view.space APTTrail VT OffSec SOCRadar
Domain microsoft.come-site.website APTTrail VT OffSec SOCRadar
Domain microsoft.comi-site.website APTTrail VT OffSec SOCRadar
Domain microsoft.comuk.space APTTrail VT OffSec SOCRadar
Domain microsoft.microcaft.xyz APTTrail VT OffSec SOCRadar
Domain microsoft.unupdate.ml APTTrail VT OffSec SOCRadar
Domain microsoft.unupload.xyz APTTrail VT OffSec SOCRadar
Domain microsoft.updatei.com APTTrail VT OffSec SOCRadar
Domain min.come-site.website APTTrail VT OffSec SOCRadar
Domain min.comi-site.website APTTrail VT OffSec SOCRadar
Domain ns1.com-accounts.website APTTrail VT OffSec SOCRadar
Domain ns1.com-signin.site APTTrail VT OffSec SOCRadar
Domain ns2.com-accounts.website APTTrail VT OffSec SOCRadar
Domain ns2.com-signin.site APTTrail VT OffSec SOCRadar
Domain unupdate.ml APTTrail VT OffSec SOCRadar

Referencias y enlaces

→ Perfil del actor markirat en el blog → Ver markirat en IntelTracker → URL IntelTracker: securelist.com→ URL IntelTracker: twitter.com→ URL IntelTracker: twitter.com→ URL IntelTracker: twitter.com→ URL IntelTracker: www.virustotal.com→ URL IntelTracker: www.virustotal.com → Fuente OSINT: github.com→ Fuente OSINT: raw.githubusercontent.com→ Fuente OSINT: securelist.com→ Fuente OSINT: twitter.com→ Fuente OSINT: twitter.com→ Fuente OSINT: twitter.com → Buscar markirat en APTTrail → Repositorio APTTrail → Mas incidentes en Iran → Buscar en Google News → Analizar en VirusTotal → Feed RSS del blog
← Volver al panel de inteligencia

Incidentes recientes