Overview
Episode 4 exposed the unified infrastructure Excel spreadsheet maintained by Charming Kitten to document all operational servers. These spreadsheets were maintained by:- MOHAMMAD NAJAFLOO (National ID:
4270878835) - Former senior employee who maintained the infrastructure documentation for years - MOHAMMADERFAN HAMIDIAREF (National ID:
0023199709) - Current maintainer who took over after Najafloo’s departure
Excel Spreadsheet Files
The leaked infrastructure is documented across multiple CSV files:| File | Description | Purpose |
|---|---|---|
0-SERVICE-Service.csv | Primary infrastructure registry | Documents hosting services, domains, VPS, SSL certificates, and access credentials |
1-NET-Sheet1.csv | Network infrastructure | Internal network topology and connectivity |
0-SERVICE-payment BTC.csv | Payment records | Bitcoin payment transactions for infrastructure services |
Attack Server Infrastructure
Tunnel Servers
Charming Kitten deployed multiple tunnel servers for maintaining persistent access to compromised networks:Web Hosting Infrastructure
The group maintained various web hosting accounts for malicious operations:| Operation | Provider | Domain | Cost | Credentials |
|---|---|---|---|---|
| BBM Movement | bill.pq.hosting | bbmovements.com | €21 (3 months) | [email protected]:5U5v6L0s |
| SecNetDC | modernizmir.net | secnetdc.com | $10 | [email protected]:MXQ8GLX5qg3yEUV |
| Tecret | theonionhost.com | tecret.com | $3 | [email protected]:RN8OiQ6Y(%H0 |
| Dreamy Jobs | theonionhost.com | dreamy-jobs.com | $15 | [email protected]:15aB@gd52$kD# |
| Wazayif Halima | theonionhost.com | wazayif-halima.org | N/A | [email protected]:n!hnuec?‘9*Pb2D |
Abrahams Ax Infrastructure
Dedicated infrastructure for the Abrahams Ax operation:Server Access Details
Server Access Details
File Storage Servers
The group utilized multiple storage solutions:Cavinet Infrastructure
ProtonMail Storage Accounts
Multiple ProtonMail accounts were used for data exfiltration:- Moses Staff: recivestaff:CxZZspFuUfZF3m3-G (€5, Ticket #2041)
- Israel Talent: Maintained for data collection from compromised targets
SSL Certificate Infrastructure
The group purchased SSL certificates to legitimize phishing infrastructure:| Certificate Type | Provider | Cost | Account |
|---|---|---|---|
| Comodo PositiveSSL | superbithhost.com | $11 | [email protected]:JHGF&(^T&OYGI |
DNS and Domain Management
CloudDNS Infrastructure
Domain Registrars Used
NameCheap
Primary registrar for moses-staff domains (.io, .to)
PRQ.se
Used for .se and .nu domains (Termite.nu, moses-staff.se)
NameSilo
Used for bbmovements.com, dreamy-jobs.com, wazayif-halima.org
ModernizMir.net
Reseller for secnetdc.com and tecret.com domains
WhatsApp and SMS Services
Infrastructure Timeline
| Date | Action | Infrastructure |
|---|---|---|
| 1/12/2022 | Registration | cavinet.org domain |
| 25/8/2022 | SMS Service | WhatsApp verification for Termite.nu |
| 17/9/2023 | Email Setup | ProtonMail for moses-staff |
| 20/11/2023 | Hosting | Moses-staff new host on impreza.host |
| 25/2/2024 | Server Setup | Israel-talent hosting on theonionhost.com |
| 20/8/2024 | Deployment | Wazayif-halima.org hosting |
| 1/9/2024 | Registration | Moses-staff domains (.io, .to, .se) |
| 25/8/2024 | Infrastructure | Abrahams Ax hosting setup |
Internal Network Credentials
Turkish Foreign Ministry (MFA) Compromised Network
From theeposta.txt file found with BellaCiao source code:
Internal Network Topology
Compromised internal networks documented in eposta.txt:Tunnel and Reverse Proxy Configuration
From BellaCiao Variant 2 (iis.ps1):Operational Security Failures
Credential Reuse Patterns
The infrastructure spreadsheets reveal multiple operational security failures:- Pattern-based passwords: Many credentials follow observable patterns (e.g.,
KazimAtes1977+-*/!!) - Credential documentation: All infrastructure credentials stored in plaintext Excel files
- Email account reuse: Same ProtonMail accounts used across multiple operations
- Predictable ticket numbering: Sequential ticket IDs expose operational timeline
Cost Analysis
Total documented infrastructure spending:- Hosting Services: ~$500-700 over documented period
- Domain Registrations: ~$200-300 annually
- SSL Certificates: ~$50-100
- SMS Services: ~$10-20
- Total Estimated: $750-1,000+ for documented infrastructure
Detection Opportunities
Related Infrastructure
See also:- Domain Infrastructure - DNS domains used in BellaCiao malware
- Exposed Credentials - Communication platforms and internal access details
References
- Episode 4 leak:
0-SERVICE-Service.csv- Primary infrastructure documentation - Episode 3 leak:
eposta.txt- Turkish Foreign Ministry compromise details - Episode 3 leak: BellaCiao source code with embedded infrastructure