HanifNet is a custom unsigned .NET backdoor used by the Iranian state-aligned threat actor commonly tracked as Lemon Sandstorm, also known as Parisite, Pioneer Kitten, Fox Kitten, Rubidium, and UNC757. It was deployed during a long-running intrusion against Middle Eastern critical infrastructure as part of a broader malware ecosystem that also included HXLibrary, NeoExpressRAT, Havoc, and multiple web shells.
HanifNet is designed to maintain persistent remote access by contacting command-and-control infrastructure, retrieving tasking, and executing commands on compromised systems. Reported functionality includes remote command execution through PowerShell, file operations, and system discovery, making it suitable for post-compromise control and operator-driven espionage activity. In the observed campaign, it was launched via masqueraded scheduled tasks to blend with legitimate administrative activity and support long-term access.
The malware was used after the adversary had already obtained access to the victim environment through stolen VPN credentials and subsequent internal compromise. Its deployment formed part of a sustained, multi-phase operation focused on persistence, credential access, lateral movement, and strategic prepositioning inside critical infrastructure networks. The broader campaign targeted Middle Eastern energy and infrastructure organizations and showed strong interest in restricted and operational-technology-adjacent environments, although no confirmed disruptive OT impact was established. HanifNet is best characterized as a bespoke backdoor supporting long-dwell espionage and infrastructure prepositioning by an Iranian threat actor.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Once inside, they installed multiple web shells on public-facing web servers and deployed three backdoors—Havoc, HanifNet, and HXLibrary—to maintain long-term access. | Scheduled task runs ‘masf.exe’ with ‘ml’ as sole command line argument. FortiGuard tracks this malware as HanifNet.
8 distinct techniques documented for this family, organized by ATT&CK tactic.
“Persistence was maintained through web shells and scheduled tasks …” / command lines show “schtasks /create …” and “Register-ScheduledTask …”
Table 11. Scheduled tasks created by the adversary throughout the reported intrusion... The heavy use of scheduled tasks to execute malware aligns with previous Lemon Sandstorm activity. | These backdoors were run using scheduled tasks.
“Persistence was maintained through web shells and scheduled tasks …” / command lines show “schtasks /create …” and “Register-ScheduledTask …”
“Persistence was maintained through web shells and scheduled tasks …” / command lines show “schtasks /create …” and “Register-ScheduledTask …”
8 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Part of Parisite’s custom malware ecosystem used in a multi-phase campaign against Middle Eastern energy and infrastructure targets.
Custom malware used by the Iran-linked Lemon Sandstorm intrusion set as part of a long-term persistence-focused campaign against a critical national infrastructure (CNI) target, supporting sustained access rather than immediate data theft.
Custom backdoor used to maintain long-term, stealthy access for espionage and suspected network prepositioning.
Unsigned .NET backdoor that retrieves and executes commands from a C2 server.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.