Threats Feed|APT34|Last Updated 28/01/2026|AuthorCertfa Radar|Publish Date23/04/2019

APT34’s Webmask Project: DNS Hijacking and Targeted Cyber Attacks

  • Actor Motivations: Espionage,Exfiltration
  • Attack Vectors: Malware
  • Attack Complexity: Unknown
  • Threat Risk: Unknown

Threat Overview

APT34 has been leveraging DNS tunneling for command and control since May 2016. The leaked source code, revealed via a Telegram channel, includes projects like webmask which primarily focus on DNS hijacking and redirection attacks. The attacks target sectors such as technology firms, telecom companies, and gaming companies across the Middle East and Asia, with a particular focus on UAE. The setup involves using NodeJS and Python for DNS servers, an ICAP proxy server to intercept and modify connections, and Haproxy for high availability.

Detected Targets

TypeDescriptionConfidence
SectorFinancial
High
SectorGovernment Agencies and Services
High
SectorEnergy
High
SectorTelecommunication
High
RegionPortugal
Medium
RegionSpain
Medium
RegionUnited Arab Emirates
Medium
RegionMiddle East Countries
Verified

FAQs

Understanding the Webmask Project and APT34

A hacking toolset used by an Iranian-linked group, APT34, was leaked online. Among the tools is a DNS hijacking framework named "Webmask," which redirects and monitors internet traffic for spying and credential theft.

The tools were created and used by APT34, also known as OilRig. This group is widely believed to operate on behalf of the Iranian government and has targeted various industries in the Middle East and beyond.

The purpose was to intercept sensitive data like usernames, passwords, and browsing activity by hijacking DNS traffic and injecting monitoring scripts into websites visited by the victims.

Examples in the leaked tools point to potential targets in the Arab Emirates and possibly Spanish or Portuguese-speaking entities. APT34 has historically targeted government, financial, energy, and telecom sectors.

By setting up rogue DNS servers and proxies, attackers redirected users’ web traffic through systems they controlled. These systems could log credentials, cookies, and even alter the pages users saw.

Industries like government, energy, and finance are often of strategic interest to state actors. In this case, the targeting aligns with Iran’s geopolitical priorities.

About Affiliation
APT34
APT34 is Mandiant's designation for the Iranian MOIS-linked threat cluster known as OilRig. Active since at least 2014, Mandiant identified APT34 as an advanced persistent threat focused on long-term espionage against government, energy, and financial organizations in the Middle East. Mandiant has documented the group's evolution over more than a decade, including its use of DNS-based command and control, LinkedIn-based social engineering lures, and a continuously expanding custom malware arsenal. APT34 remains one of the most thoroughly documented Iranian state-sponsored actors in public threat intelligence.
View APT34's Insights