DNSPIONAGE: Unpacking Advanced Spear Phishing and Lateral Movement Techniques
- Actor Motivations: Espionage,Exfiltration
- Attack Vectors: Backdoor,Spear Phishing
- Attack Complexity: Medium
- Threat Risk: High Impact/Low Probability
Threat Overview
CERT-OPMD (Openminded) published a detailed incident response analysis of a live DNSpionage intrusion in January 2019, focusing on post-compromise internal actions not visible to Cisco Talos from their telemetry. The attackers conducted advanced LinkedIn-based spearphishing, impersonating a Wipro HR recruiter for several days before delivering a malicious document (using the hr-wipro[.]com and hr-suncor[.]com domains observed by Talos). After initial compromise via the DNSpionage backdoor, attackers used batch scripts to perform full recursive directory listings across all drives and exfiltrated results via HTTP to the C2 at 0ffice36o[.]com. They conducted extensive discovery using native Windows tools including WMIC, net, ping, ipconfig, and reg query, identified domain admins, and scanned for antivirus. Credential dumping was performed via Mimikatz (sekurlsa::logonpasswords) invoked through PowerShell with execution bypass. Lateral movement used Plink (plink32.exe) to create SSH tunnels on port 443 to attacker-controlled IP 185.236.78.63, enabling RDP access to internal servers. Files including PowerShell scripts and tools were copied via Windows Admin Shares (net use). The C2 communicated over both HTTP (port 80) and DNS (Base32-encoded queries to 0ffice36o[.]com subdomains), with the malware switching between modes. Openminded confirmed Bitvise WinSSHD was installed for remote access, and Veil-Pillage was used alongside Mimikatz for credential operations.
Detected Targets
| Type | Description | Confidence |
|---|---|---|
| Case | Suncor Suncor Energy is a Canadian integrated energy company based in Calgary, Alberta. It specializes in production of synthetic crude from oil sands. Suncor has been targeted by Unclassified with abusive purposes. | Verified |
| Case | Wipro Wipro is an Indian multinational corporation that provides information technology, consultant and business process services. It is one of the leading Big Tech companies. Wipro has been targeted by Unclassified with abusive purposes. | Verified |
| Sector | Information Technology | High |
| Sector | Energy | Medium |
| Region | Lebanon Lebanon explicitly named in the Cisco Talos DNSpionage report as a primary target. IOC overlap with this threat confirmed (hr-wipro.com, 0ffice36o.com). | Verified |
| Region | United Arab Emirates UAE explicitly named in the Cisco Talos DNSpionage report as a primary target alongside Lebanon. | Verified |
Extracted IOCs
- 0ffice36o[.]com
- hr-suncor[.]com
- hr-wipro[.]com
- 3984ae8dd6df1196211232eb56393a4ce3a330508c5862c38ea3b8faf8048072
- 107[.]161.23.204
- 185[.]161.211.72
- 185[.]161.211.79
- 185[.]174.101.168
- 185[.]20.184.138
- 185[.]236.78.63
- 192[.]161.187.200
- 209[.]141.38.71
Tip: 12 related IOCs (8 IP, 3 domain, 0 URL, 0 email, 1 file hash) to this threat have been found.
Overlaps
Source: Palo Alto Networks - January 2020
Detection (two cases): 185[.]161.211.72, 185[.]161.211.79
Source: Cyware - August 2019
Detection (one case): 185[.]236.78.63
Source: Cisco Talos - November 2018
Detection (five cases): 185[.]161.211.72, 185[.]20.184.138, 0ffice36o[.]com, hr-suncor[.]com, hr-wipro[.]com
Hint: Overlaps are extracted automatically by examining the IOCs associated with all indexed threats and actors.
FAQs
DNSpionage Internal Actions — Frequently Asked Questions
In late 2018, CERT-OPMD responded to a live intrusion involving the DNSpionage malware — a backdoor previously documented by Cisco Talos as targeting organizations in Lebanon and the UAE. Their report focused on what happened after the initial infection: how the attackers moved through the network, stole credentials, and exfiltrated data. The attackers used a multi-week LinkedIn social engineering campaign to trick employees into opening a malicious document, then used the resulting access to systematically map and compromise internal systems.
Definitive attribution was not established in this report. Cisco Talos, who originally documented the DNSpionage campaign, did not attribute it to a specific group. However, Mandiant subsequently linked the broader DNSpionage activity to APT34 — an Iranian state-sponsored group — based on overlapping infrastructure and targeting patterns. The heavy focus on Lebanon, the UAE, and energy sector companies is consistent with Iranian intelligence interests in the region.
The campaign was a cyberespionage and data exfiltration operation. The attackers' goal was to gain deep, persistent access to target networks and steal sensitive data — including file system contents, credentials, and network configuration information. The dual-mode command-and-control design (HTTP and DNS tunneling) and the careful use of legitimate-looking tools suggest the operation was intended to remain undetected for as long as possible while maximizing intelligence collection.
The broader DNSpionage campaign targeted organizations in Lebanon and the UAE, with two fake recruitment domains — hr-wipro[.]com and hr-suncor[.]com — used to impersonate real companies (Wipro, an IT services giant, and Suncor Energy). This specific incident involved a confirmed victim organization where CERT-OPMD performed the response. The attackers demonstrated the intent and capability to move laterally across an entire internal network, accessing multiple servers including database systems, suggesting the goal was broad network compromise rather than a single target.
The lure documents impersonated two major companies: Wipro (a global IT services firm) and Suncor Energy (a major Canadian oil and gas company), suggesting the attackers targeted employees in IT and energy sectors. The Cisco Talos report identified government entities in Lebanon and the UAE as primary targets of the broader campaign. This matches APT34's known targeting pattern — government agencies, energy companies, and IT service providers across the Middle East.
The attack began with a LinkedIn social engineering campaign: an attacker posing as a Wipro HR recruiter engaged target employees for several days before sending a malicious Word document link. Opening the document triggered a macro that installed the DNSpionage backdoor as a scheduled task. Once inside, the attackers ran batch scripts to map all drives and directories, used WMIC to execute Mimikatz remotely for credential dumping, and copied Plink (a command-line SSH client) to multiple machines to create encrypted tunnels back to their servers — giving them hidden RDP access to internal systems. All stolen data was sent back through either HTTP requests or covert DNS queries encoded in Base32, disguised as normal traffic.
IT service providers like Wipro are attractive targets because compromising them can give attackers access to the networks of all their customers — a supply-chain style leverage point. Energy companies like Suncor hold commercially and strategically sensitive data. Government entities in Lebanon and the UAE possess diplomatic and intelligence information of direct value to Iranian state interests. Using these company names as lures also increases the chance that employees in relevant roles will trust and open the malicious documents.
Train employees to recognize social engineering through professional networks like LinkedIn — attackers may spend days building rapport before delivering a malicious link. Block macros in Office documents from external sources and monitor for scheduled tasks created by Office processes. Implement DNS monitoring to detect high-entropy or high-volume subdomain queries that indicate DNS tunneling. Restrict PowerShell with "-exec bypass" and monitor WMIC remote process creation events. Block the disclosed IOCs: 0ffice36o[.]com, hr-wipro[.]com, hr-suncor[.]com, and the eight attacker IPs. Alert on Plink usage on non-admin workstations and block outbound SSH to unauthorized destinations.