Threats Feed|Greenbug|Last Updated 28/04/2026|AuthorCertfa Radar|Publish Date12/12/2019

Decoding Greenbug Group's Command and Control Communications via DNS Tunneling

  • Actor Motivations: Espionage,Exfiltration
  • Attack Vectors: RAT,Spyware
  • Attack Complexity: High
  • Threat Risk: High Impact/Low Probability

Threat Overview

DomainTools demonstrates how passive DNS pivoting on ISMDoor's static IPv6 response fingerprints can be used to systematically discover Greenbug's C2 infrastructure — including domains not previously reported. The analysis confirms ISMDoor remained active as recently as November 2019, more than two years after the malware's initial public disclosure in 2017. By querying passive DNS for four known static IPv6 addresses returned during ISMDoor's session establishment protocol (a67d:db8:a2a1:7334:7654:4325:370:2aa3, a67d:db8:85a3:4325:7654:8a2a:370:7334, the all-spaces address 2020:2020:..., and the "Ok" response 4f6b:2020:...), DomainTools identified 19 C2 domains across old and current infrastructure. Most were already sinkholed, but winrepp[.]com was still active on Digital Ocean at the time of publication. Pivoting from that IP and then from outbrainsecupdater[.]com revealed an additional 37 associated domains, including microsoft-publisher[.]com confirmed as an ISMDoor C2 through captured AAAA query data. The report notes that Greenbug's use of DNS tunneling remains effective because many organizations do not monitor DNS traffic for behavioral anomalies. The static IPv6 fingerprints embedded in ISMDoor's session establishment provide a durable detection opportunity regardless of which C2 domain the malware uses — a technique DomainTools notes can be applied to hunt for other DNS-tunneling malware families as well.

Extracted IOCs

  • adobeproduct[.]com
  • basnevs[.]com
  • broadcaster[.]rocks
  • dunyanews[.]info
  • edarat-gruop[.]com
  • gaaranews[.]com
  • level3-resolvers[.]net
  • microsoft-publisher[.]com
  • microsoftupdated[.]net
  • msoffice365update[.]com
  • ntpupdateserver[.]com
  • opendns-server[.]com
  • osissoft[.]com
  • osupd[.]com
  • outbrainsecupdater[.]com
  • tessera[.]icu
  • thetaraysecurityupdate[.]com
  • winappupdater[.]com
  • winrepp[.]com
  • yaskawaelectriccorporation[.]com
  • yokogawaelectric[.]com
  • 165[.]227.50.73
  • 2020:2020:2020:2020:2020:2020:2020:2020
  • 4f6b:2020:2020:2020:2020:2020:2020:2020
  • a67d:db8:85a3:4325:7654:8a2a:0000:0001
  • a67d:db8:85a3:4325:7654:8a2a:370:7334
  • a67d:db8:85a3:4325:7654:8a2a:ffff
  • a67d:db8:a2a1:7334:7654:4325:370:2aa3
download

Tip: 28 related IOCs (7 IP, 21 domain, 0 URL, 0 email, 0 file hash) to this threat have been found.

Overlaps

UnclassifiedxHunt Campaign Targets Kuwait's Transportation and Shipping Sectors

Source: Palo Alto Network - September 2019

Detection (one case): microsoft-publisher[.]com

GreenbugHow the GreenBug Group Exploits DNS Tunneling with Ismdoor Malware

Source: Black Lotus Labs - September 2019

Detection (two cases): basnevs[.]com, gaaranews[.]com

OilRigAnalyzing OilRig's Use of DNS Tunneling in Cyber Espionage Campaigns

Source: Palo Alto Network - April 2019

Detection (one case): ntpupdateserver[.]com

GreenbugPotential Cyber Targets Revealed in Greenbug's Domain Registrations: Israeli and Saudi Firms in Focus

Source: ClearSky - October 2017

Detection (three cases): ntpupdateserver[.]com, outbrainsecupdater[.]com, thetaraysecurityupdate[.]com

OilRigInside OilRig's Attack on UAE Government: ISMInjector and CVE-2017-0199 Exploit in Play

Source: Palo Alto Networks - October 2017

Detection (three cases): microsoft-publisher[.]com, msoffice365update[.]com, ntpupdateserver[.]com

APT33Cyber Espionage on Aviation: APT33 Targets US, Saudi Arabia, and South Korea

Source: Mandiant - September 2017

Detection (two cases): microsoftupdated[.]net, osupd[.]com

OilRigOilRig and Greenbug Connection: Expanding Threats with Modified Trojans

Source: Palo Alto Network - July 2017

Detection (four cases): adobeproduct[.]com, level3-resolvers[.]net, microsoft-publisher[.]com, ntpupdateserver[.]com

GreenbugGreenbug Group's Escalated Threat: Ismdoor RAT's Role in the Shamoon Attacks

Source: NETSCOUT - May 2017

Detection (three cases): a67d:db8:85a3:4325:7654:8a2a:370:7334, a67d:db8:a2a1:7334:7654:4325:370:2aa3, winrepp[.]com

Hint: Overlaps are extracted automatically by examining the IOCs associated with all indexed threats and actors.

FAQs

Frequently Asked Questions: Tracking Greenbug's ISMDoor DNS Tunneling Infrastructure

DomainTools used passive DNS data to show that Greenbug's ISMDoor malware was still actively using its DNS tunneling infrastructure as late as November 2019 — more than two years after the malware was first publicly documented. By searching for the unique, static IPv6 addresses that ISMDoor's C2 protocol always returns during session setup, DomainTools identified 19 C2 domains, then pivoted to uncover 37 more associated domains. The report maps the breadth of Greenbug's infrastructure and provides a repeatable method for defenders to hunt for new domains as Greenbug rotates them.

The infrastructure belongs to Greenbug, an Iranian-linked cyberespionage group active since at least 2016. The group is believed to be associated with Iranian state interests and has consistently targeted organizations in the Middle East. Despite years of public reporting on their tools and techniques, Greenbug continued operating ISMDoor with the same DNS tunneling approach through at least late 2019, showing little concern about being identified.

ISMDoor's DNS tunneling C2 is used for espionage — covertly issuing commands to compromised systems, stealing data, and maintaining persistent access. The DNS channel is deliberately chosen because most organizations do not monitor DNS traffic for anomalies, making it harder to detect than HTTP-based C2. The infrastructure DomainTools maps represents the backbone of Greenbug's long-running access operations against Middle Eastern targets.

DomainTools identified 19 C2 domains through passive DNS pivoting on ISMDoor's static fingerprints. Pivoting further from two of those domains uncovered an additional 37 associated domains. Most were sinkholed by December 2019, but at least two — winrepp[.]com and microsoft-publisher[.]com — were confirmed as recently active or live. The full domain list in this report's IOC bundle covers the complete known set across multiple years of Greenbug infrastructure activity.

The IOC overlap data shows that several ISMDoor C2 domains appear in infrastructure tracked across multiple Iranian-linked threat actor reports — including OilRig, APT33, and the xHunt campaign targeting Kuwait. This suggests either shared infrastructure registration practices, overlapping operations, or deliberate reuse of C2 hosting across different Iranian-aligned groups. It is a useful pivot point for defenders tracking multiple threat actors in the region.

ISMDoor communicates entirely through DNS. Infected machines generate a unique session ID and send it to the C2 domain as part of a DNS query. The C2 nameserver responds with a static IPv6 address to acknowledge the session. Messages and data are encoded in DNS query subdomains, and responses are carried back as IPv6 addresses — sometimes static acknowledgments, sometimes addresses where specific bytes encode message counts or content. This cycle repeats for each command and each data transfer, keeping all traffic inside normal-looking DNS resolution.

Greenbug registers domains designed to look like legitimate software and network services — names like ntpupdateserver[.]com, adobeproduct[.]com, microsoft-publisher[.]com, and winappupdater[.]com. This makes the C2 domains blend in with normal enterprise traffic at the domain name level. Combined with the DNS-only communication channel, the infrastructure is designed to avoid detection in environments that do not perform deep DNS inspection.

Monitor DNS traffic for AAAA queries returning IPv6 addresses outside the global unicast scope — the four static fingerprints documented by DomainTools and NETSCOUT are durable detection indicators regardless of which C2 domain is in use. Block all known ISMDoor domains from the IOC set. Deploy DNS anomaly detection to flag high-frequency AAAA queries with structured subdomain patterns. Organizations can also proactively hunt for new C2 domains by querying any passive DNS platform for the static IPv6 fingerprints — this technique will surface newly registered infrastructure before it appears in public threat intel feeds.

About Affiliation
Greenbug
Greenbug is an Iranian state-linked cyber espionage cluster active since at least 2016, first documented by Symantec. The group specializes in targeting telecommunications, internet service providers, aviation, and energy companies across Saudi Arabia, Iraq, Bahrain, Qatar, Kuwait, and Turkey using spear phishing with fake business proposals to deliver its custom Ismdoor remote access trojan. Ismdoor uses DNS tunneling — and later DNS TXT record-based command and control — enabling covert credential theft and keylogging while blending into normal DNS traffic. Symantec assessed that Greenbug likely provided the credentials used by the Shamoon operators in the November 2016 Disttrack attacks, after detecting an Ismdoor infection on an administrator machine at a Shamoon-targeted organization days before the wiper deployment. Unit 42 identified a modified ISMDoor variant called ISMAgent deployed by OilRig operators in 2017, establishing shared tooling between Greenbug and OilRig and suggesting the groups are closely linked or overlapping within the same Iranian state espionage infrastructure.
View Greenbug's Insights