DNSpionage is malware associated with cyberespionage and DNS-hijacking operations targeting organizations in the Middle East. Publicly uncovered in 2018, associated campaigns compromised upstream service providers and altered DNS records to redirect legitimate traffic for interception and credential theft. Delivery has included spear-phishing with malicious documents. A similarly named tool for managing DNS hijacking and extracting authentication details through man-in-the-middle interception appeared in the 2019 OilRig tooling leak. That leaked tool was not established to be the malware used in the original DNSpionage campaign, and shared functionality and victim overlap do not establish a definitive OilRig attribution.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
These include Alma Communicator, BONDUPDATER, certutil, Clayslide, DistTrack, DNSExfiltrator, DNSpionage, Dustman, Fox Pane, GoogleDrive RAT, and Helminth.
2 distinct techniques documented for this family, organized by ATT&CK tactic.
Charming Kitten, Haywire Kitten, and Remix Kitten are described as “exploiting Microsoft Exchange vulnerabilities,” including “ProxyShell.”
Multiple Iran-nexus APT groups are described as using spear-phishing: e.g., Charming Kitten uses “spear-phishing with fake personas and compromised emails… phishing via benign PDFs for credential harvesting”; several others use “spear-phishing with malicious documents/attachments/links.”
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malware used in spear-phishing operations; associated with PowerShell scripting and Exchange exploitation as described.
Malware used by Haywire Kitten (Emennet Pasargad) for espionage, delivered via spear-phishing and exploiting Exchange vulnerabilities.
Named malware/campaign referenced with alias COBALT EDGEWATER.
Included in the article's list of APT34 malware and tools. Separately, the article describes possible overlap with DNSpionage campaigns as unattributed; no specific capabilities are provided.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.