Microsoft granted US court order to take control of 99 websites the company says are linked to Iranian hacking group Phosphorus and host them on its own servers
Microsoft has won a restraining order in a U.S. court in order to take control of domains used by an Iranian hacker group.
Context & Ripple Effects
This seizure is an early rung in what becomes a repeatable Microsoft playbook: win a U.S. court order, take over attacker-controlled domains, and host them on Microsoft servers to monitor who connects. Months after this Phosphorus action, Microsoft applied the same tactic against North Korean espionage group Thallium — by then its fourth APT target — and the corpus shows the cadence continuing through a 42-domain seizure from a Chinese espionage group operating in 29 countries, a seven-domain takeover disrupting Strontium's attacks on Ukraine, and a Storm-1152 takedown that reached the fraudulent-account ecosystem itself.
The Phosphorus connection is direct rather than thematic: months after this court order, Microsoft disclosed that Phosphorus had attempted to hack 241 accounts tied to a 2020 presidential campaign and others, making the group one of the most closely tracked Iranian actors in Microsoft's threat reporting.
First-order effects
- Phosphorus loses 99 domains of operational infrastructure at once, and because Microsoft hosts the seized sites, connections to them become telemetry the company can use to map victims and ongoing campaigns.
- Microsoft gains a legal template — a restraining order against foreign state-linked hackers in U.S. civil court — that it reuses within months against Thallium's 50 domains.
Second-order effects
- State-linked groups relying on U.S.-based registrars and hosting face a new failure mode: their infrastructure can be flipped by a private company's litigation, pushing rotation to non-U.S. providers.
- The tactic shifts some counter-espionage workload from government agencies to Microsoft's legal and threat-intelligence teams, raising the bar for rivals without comparable court-access machinery.
Third-order effects
- If the pattern holds — and the corpus shows it running from Phosphorus in 2019 through Storm-1152 in 2023 — large platform companies become standing cyber-enforcement actors whose civil court orders complement, and sometimes precede, government takedowns.
- Adversary infrastructure migrates structurally away from jurisdictions where U.S. companies can seize it, fragmenting the hosting landscape along geopolitical lines.
The trend: Court-ordered domain seizures are hardening into a standard private-sector counter-APT instrument, with Microsoft running it repeatedly against Iranian, North Korean, Chinese, Russian, and cybercrime infrastructure between 2019 and 2023.