Iranian Botnet Exposed via Open Directory: 15-Node Relay Network and Active C2
Reported 17 Mar 2026 by otx · Severity: medium
An Iranian threat actor's operational infrastructure was exposed through an open directory, revealing a 15-node relay network spanning Finland and Iran, an SSH-based botnet framework, and an active command and control server. The exposed bash history documented the full operation