logo

DNSpionage Campaign Targets Middle East

ID: 42e9a7fb-2a42-4884-b163-82a54f680584

STIX ID: report--42e9a7fb-2a42-4884-b163-82a54f680584

Threat Score

78/100

Uploaded: 2026-08-14

Published Date: 2018-11-29

Last Modified Date: 2018-11-29

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Cisco Talos discovered the DNSpionage campaign targeting Lebanon and the UAE that distributed malicious Office documents with macros to install a remote administration tool capable of DNS tunneling and HTTP C2, and separately used DNS hijacking/redirection (with attacker-created Let's Encrypt certificates) against government and airline domains; the report includes malware analysis, IOCs (domains, IPs, hashes), victimology, and mitigation guidance.