Decoding Greenbug Group's Command and Control Communications via DNS Tunneling
- Actor Motivations: Espionage,Exfiltration
- Attack Vectors: RAT,Spyware
- Attack Complexity: High
- Threat Risk: High Impact/Low Probability
Threat Overview
DomainTools demonstrates how passive DNS pivoting on ISMDoor's static IPv6 response fingerprints can be used to systematically discover Greenbug's C2 infrastructure — including domains not previously reported. The analysis confirms ISMDoor remained active as recently as November 2019, more than two years after the malware's initial public disclosure in 2017. By querying passive DNS for four known static IPv6 addresses returned during ISMDoor's session establishment protocol (a67d:db8:a2a1:7334:7654:4325:370:2aa3, a67d:db8:85a3:4325:7654:8a2a:370:7334, the all-spaces address 2020:2020:..., and the "Ok" response 4f6b:2020:...), DomainTools identified 19 C2 domains across old and current infrastructure. Most were already sinkholed, but winrepp[.]com was still active on Digital Ocean at the time of publication. Pivoting from that IP and then from outbrainsecupdater[.]com revealed an additional 37 associated domains, including microsoft-publisher[.]com confirmed as an ISMDoor C2 through captured AAAA query data. The report notes that Greenbug's use of DNS tunneling remains effective because many organizations do not monitor DNS traffic for behavioral anomalies. The static IPv6 fingerprints embedded in ISMDoor's session establishment provide a durable detection opportunity regardless of which C2 domain the malware uses — a technique DomainTools notes can be applied to hunt for other DNS-tunneling malware families as well.
Extracted IOCs
- adobeproduct[.]com
- basnevs[.]com
- broadcaster[.]rocks
- dunyanews[.]info
- edarat-gruop[.]com
- gaaranews[.]com
- level3-resolvers[.]net
- microsoft-publisher[.]com
- microsoftupdated[.]net
- msoffice365update[.]com
- ntpupdateserver[.]com
- opendns-server[.]com
- osissoft[.]com
- osupd[.]com
- outbrainsecupdater[.]com
- tessera[.]icu
- thetaraysecurityupdate[.]com
- winappupdater[.]com
- winrepp[.]com
- yaskawaelectriccorporation[.]com
- yokogawaelectric[.]com
- 165[.]227.50.73
- 2020:2020:2020:2020:2020:2020:2020:2020
- 4f6b:2020:2020:2020:2020:2020:2020:2020
- a67d:db8:85a3:4325:7654:8a2a:0000:0001
- a67d:db8:85a3:4325:7654:8a2a:370:7334
- a67d:db8:85a3:4325:7654:8a2a:ffff
- a67d:db8:a2a1:7334:7654:4325:370:2aa3
Tip: 28 related IOCs (7 IP, 21 domain, 0 URL, 0 email, 0 file hash) to this threat have been found.
Overlaps
Source: Palo Alto Network - September 2019
Detection (one case): microsoft-publisher[.]com
Source: Black Lotus Labs - September 2019
Detection (two cases): basnevs[.]com, gaaranews[.]com
Source: Palo Alto Network - April 2019
Detection (one case): ntpupdateserver[.]com
Source: ClearSky - October 2017
Detection (three cases): ntpupdateserver[.]com, outbrainsecupdater[.]com, thetaraysecurityupdate[.]com
Source: Palo Alto Networks - October 2017
Detection (three cases): microsoft-publisher[.]com, msoffice365update[.]com, ntpupdateserver[.]com
Source: Mandiant - September 2017
Detection (two cases): microsoftupdated[.]net, osupd[.]com
Source: Palo Alto Network - July 2017
Detection (four cases): adobeproduct[.]com, level3-resolvers[.]net, microsoft-publisher[.]com, ntpupdateserver[.]com
Source: NETSCOUT - May 2017
Detection (three cases): a67d:db8:85a3:4325:7654:8a2a:370:7334, a67d:db8:a2a1:7334:7654:4325:370:2aa3, winrepp[.]com
Hint: Overlaps are extracted automatically by examining the IOCs associated with all indexed threats and actors.
FAQs
Frequently Asked Questions: Tracking Greenbug's ISMDoor DNS Tunneling Infrastructure
DomainTools used passive DNS data to show that Greenbug's ISMDoor malware was still actively using its DNS tunneling infrastructure as late as November 2019 — more than two years after the malware was first publicly documented. By searching for the unique, static IPv6 addresses that ISMDoor's C2 protocol always returns during session setup, DomainTools identified 19 C2 domains, then pivoted to uncover 37 more associated domains. The report maps the breadth of Greenbug's infrastructure and provides a repeatable method for defenders to hunt for new domains as Greenbug rotates them.
The infrastructure belongs to Greenbug, an Iranian-linked cyberespionage group active since at least 2016. The group is believed to be associated with Iranian state interests and has consistently targeted organizations in the Middle East. Despite years of public reporting on their tools and techniques, Greenbug continued operating ISMDoor with the same DNS tunneling approach through at least late 2019, showing little concern about being identified.
ISMDoor's DNS tunneling C2 is used for espionage — covertly issuing commands to compromised systems, stealing data, and maintaining persistent access. The DNS channel is deliberately chosen because most organizations do not monitor DNS traffic for anomalies, making it harder to detect than HTTP-based C2. The infrastructure DomainTools maps represents the backbone of Greenbug's long-running access operations against Middle Eastern targets.
DomainTools identified 19 C2 domains through passive DNS pivoting on ISMDoor's static fingerprints. Pivoting further from two of those domains uncovered an additional 37 associated domains. Most were sinkholed by December 2019, but at least two — winrepp[.]com and microsoft-publisher[.]com — were confirmed as recently active or live. The full domain list in this report's IOC bundle covers the complete known set across multiple years of Greenbug infrastructure activity.
The IOC overlap data shows that several ISMDoor C2 domains appear in infrastructure tracked across multiple Iranian-linked threat actor reports — including OilRig, APT33, and the xHunt campaign targeting Kuwait. This suggests either shared infrastructure registration practices, overlapping operations, or deliberate reuse of C2 hosting across different Iranian-aligned groups. It is a useful pivot point for defenders tracking multiple threat actors in the region.
ISMDoor communicates entirely through DNS. Infected machines generate a unique session ID and send it to the C2 domain as part of a DNS query. The C2 nameserver responds with a static IPv6 address to acknowledge the session. Messages and data are encoded in DNS query subdomains, and responses are carried back as IPv6 addresses — sometimes static acknowledgments, sometimes addresses where specific bytes encode message counts or content. This cycle repeats for each command and each data transfer, keeping all traffic inside normal-looking DNS resolution.
Greenbug registers domains designed to look like legitimate software and network services — names like ntpupdateserver[.]com, adobeproduct[.]com, microsoft-publisher[.]com, and winappupdater[.]com. This makes the C2 domains blend in with normal enterprise traffic at the domain name level. Combined with the DNS-only communication channel, the infrastructure is designed to avoid detection in environments that do not perform deep DNS inspection.
Monitor DNS traffic for AAAA queries returning IPv6 addresses outside the global unicast scope — the four static fingerprints documented by DomainTools and NETSCOUT are durable detection indicators regardless of which C2 domain is in use. Block all known ISMDoor domains from the IOC set. Deploy DNS anomaly detection to flag high-frequency AAAA queries with structured subdomain patterns. Organizations can also proactively hunt for new C2 domains by querying any passive DNS platform for the static IPv6 fingerprints — this technique will surface newly registered infrastructure before it appears in public threat intel feeds.