APT35 Infrastructure Analysis Exposes Phishing Campaign Targeting Egyptian Shipping and Israeli Pipeline Interests

Researchers at SecurityScorecard's STRIKE Team have uncovered APT35 (Charming Kitten) infrastructure being used to stage phishing campaigns against Egypt-based shipping and marine services companies — with additional targeting indicators pointing toward Israeli pipeline investment firms and UAE legal entities, revealing the Iran-linked group's expansive regional intelligence appetite.

From Google TAG to Rogue Mail Subdomains

The investigation was triggered by a Google Threat Analysis Group (TAG) disclosure on August 23 describing a new Iranian APT data-extraction tool that required check-ins with two C2 servers: 136.243.108[.]14 (Germany) and 173.209.51[.]54 (Canada). Pivoting on the first IP, STRIKE researchers discovered it was hosting a cluster of imposter mail subdomains — each carrying a CNAME record redirecting to smtp11.smtplab[.]com, which itself presents a Kerio Connect webmail login interface. The setup is a textbook credential-harvesting configuration, designed to intercept email authentication attempts from targets deceived by lookalike domain names.

Targeting Profile: Egyptian Shipping as the Primary Focus

The majority of identified imposter domains impersonate Egypt-based shipping and marine services companies, with a notable concentration in Port Said — a major shipping hub whose professional services firms handle logistics, legal, and financial data directly relevant to the maritime industry. The researchers assess that even non-shipping Egyptian firms in the cluster are likely targeted for their proximity to the port's primary industries.

One concrete example: the legitimate domain elephantmarine[.]com (active since 2011, hosted at 207.180.247[.]135) had a rogue subdomain — mail.elephantmarine[.]com — pointing to the threat actor's C2 IP. Similar rogue subdomains were identified for mail.hhfis[.]com and mail.etisalategypt[.]com. Creating these subdomains would require access to the domains' DNS configuration or CPanel, indicating the threat actors likely achieved unauthorized access to the registrar accounts of at least three legitimate organizations.

Israeli Pipeline and UAE Legal Targeting

Beyond the Egyptian maritime focus, STRIKE identified a set of typo-squatted domains targeting investment entities in the Eilat region of southern Israel — substituting an "L" for a "T" in domain names (e.g., eilatinvest[.]comeitatinvest[.]com). Eilat is home to the southern terminal of the Trans-Israel pipeline, originally constructed as an Iran-Israel joint venture prior to the 1979 revolution. Iran was awarded $1.1 billion in compensation in a 2016 arbitration ruling against the Eilat Ashkelon Pipeline Company (EAPC) — an entity subject to Israeli state secrecy decrees on national security grounds. The targeting suggests ongoing Iranian interest in EAPC affairs. Additional domains impersonated a prominent UAE law firm whose client list includes members of the Al Maktoum royal family.

Infrastructure Registration and EgWan Hosting

All typo-squatted top-level domains were registered with identical registration details through Wild West Domains resold by EgWan, a small Egyptian hosting provider that also offers Office 365 email services. The uniform registration pattern across domains is a strong indicator of common actor ownership and provides a pivot point for further infrastructure tracking.

Attribution Assessment

While Google's TAG report on the HYPERSCRAPE tool did not address the subdomain hijacking activity, SecurityScorecard assesses with high confidence that the infrastructure cluster supports Iran-linked APT35 phishing campaigns. The targeting pattern — focusing on U.S.-aligned regional states, critical maritime infrastructure, and entities with direct financial disputes with Iran — is consistent with the strategic intelligence collection priorities observed across Iranian APT operations historically.

Read the full analysis on IntelFusions