/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Microsoft granted US court order to take control of 99 websites the company says are linked to Iranian hacking group Phosphorus and host them on its own servers

Microsoft has won a restraining order in a U.S. court in order to take control of domains used by an Iranian hacker group.

TechCrunch Zack Whittaker

Context & Ripple Effects

This seizure is an early rung in what becomes a repeatable Microsoft playbook: win a U.S. court order, take over attacker-controlled domains, and host them on Microsoft servers to monitor who connects. Months after this Phosphorus action, Microsoft applied the same tactic against North Korean espionage group Thallium — by then its fourth APT target — and the corpus shows the cadence continuing through a 42-domain seizure from a Chinese espionage group operating in 29 countries, a seven-domain takeover disrupting Strontium's attacks on Ukraine, and a Storm-1152 takedown that reached the fraudulent-account ecosystem itself.

The Phosphorus connection is direct rather than thematic: months after this court order, Microsoft disclosed that Phosphorus had attempted to hack 241 accounts tied to a 2020 presidential campaign and others, making the group one of the most closely tracked Iranian actors in Microsoft's threat reporting.

First-order effects

  • Phosphorus loses 99 domains of operational infrastructure at once, and because Microsoft hosts the seized sites, connections to them become telemetry the company can use to map victims and ongoing campaigns.
  • Microsoft gains a legal template — a restraining order against foreign state-linked hackers in U.S. civil court — that it reuses within months against Thallium's 50 domains.

Second-order effects

  • State-linked groups relying on U.S.-based registrars and hosting face a new failure mode: their infrastructure can be flipped by a private company's litigation, pushing rotation to non-U.S. providers.
  • The tactic shifts some counter-espionage workload from government agencies to Microsoft's legal and threat-intelligence teams, raising the bar for rivals without comparable court-access machinery.

Third-order effects

  • If the pattern holds — and the corpus shows it running from Phosphorus in 2019 through Storm-1152 in 2023 — large platform companies become standing cyber-enforcement actors whose civil court orders complement, and sometimes precede, government takedowns.
  • Adversary infrastructure migrates structurally away from jurisdictions where U.S. companies can seize it, fragmenting the hosting landscape along geopolitical lines.

The trend: Court-ordered domain seizures are hardening into a standard private-sector counter-APT instrument, with Microsoft running it repeatedly against Iranian, North Korean, Chinese, Russian, and cybercrime infrastructure between 2019 and 2023.