DNSpionage Campaign Targets Middle East
ID: 42e9a7fb-2a42-4884-b163-82a54f680584
STIX ID: report--42e9a7fb-2a42-4884-b163-82a54f680584
Threat Score
78/100
Uploaded: 2026-08-14
Published Date: 2018-11-29
Last Modified Date: 2018-11-29
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Cisco Talos discovered the DNSpionage campaign targeting Lebanon and the UAE that distributed malicious Office documents with macros to install a remote administration tool capable of DNS tunneling and HTTP C2, and separately used DNS hijacking/redirection (with attacker-created Let's Encrypt certificates) against government and airline domains; the report includes malware analysis, IOCs (domains, IPs, hashes), victimology, and mitigation guidance.
