Our (with @[email protected]) latest work on #DNSpionage is online: https://blog.talosintelligence.com/2019/04/dnspionage-brings-out-karkoff.html we analyzed a bizarre version of #DNSpionage and we identified a new malware named #Karkoff. We put a bonus: a small link between this campaigns and the alleged #Oilrig leak from last week...
DNSpionage: Massive Angriffe auf Mail- und VPN-User
Für Angriffe auf Firmen und Regierungsstellen im Nahen Osten haben Unbekannte die DNS-Infrastruktur einer deutschen Firma missbraucht. Der Ablauf der Attacke.
#DNSpionage #Angriffe #Mail #VPN #DNS #Infrastruktur #Internet #Hack
https://www.heise.de/ct/artikel/DNSpionage-Massive-Angriffe-auf-Mail-und-VPN-User-4333644.html
Rigolo, je découvre que l'Irak a un truc de sécurité nationale qui s'appelle NSA https://nsa.gov.iq/
(Je vois ça parce qu'il y a un IOC de #DNSpionage qui les désigne : ils ont été piratés le 2 octobre 2018.)
With @[email protected] we wrote an article about what we observed during an incident response few months ago performing by CERT-OPMD (@[email protected] ) . The malware used was #DNSPIONAGE.
https://blog-cert.opmd.fr/dnspionage-focus-on-internal-actions/
We hope it may help you to hunt some identical threats.
Interesting, @[email protected] published some details on the infrastructure used by the attacker for the DNS redirection mentioned in our #DNSpionage post: https://www.fireeye.com/blog/threat-research/2019/01/global-dns-hijacking-campaign-dns-record-manipulation-at-scale.html (our post for the context: https://blog.talosintelligence.com/2018/11/dnspionage-campaign-targets-middle-east.html)