Widespread DNS Hijacking Campaign with Possible Iranian Nexus Targets Multiple Sectors
- Actor Motivations: Espionage,Exfiltration
- Attack Vectors: Vulnerability Exploitation
- Attack Complexity: High
- Threat Risk: High Impact/Low Probability
Threat Overview
CrowdStrike Intelligence's January 2019 report documents a widespread DNS hijacking campaign active from at least February 2017 through January 2019, affecting 28 organizations across 12 countries. The campaign primarily targeted entities in the Middle East and North Africa, with limited impact in Europe and the United States. Affected sectors included government (the dominant target across Jordan, Kuwait, UAE, Iraq, Egypt, Libya, Lebanon, Albania, Cyprus, and Saudi Arabia), law enforcement, civil aviation, insurance, telecommunications, and internet infrastructure providers including ISPs, internet exchange points, root DNS servers, and TLD operators. The attack method involved hijacking victim organizations' DNS records to redirect traffic to actor-controlled IP addresses. Fraudulent TLS certificates were then obtained — primarily through Let's Encrypt — enabling the actors to present trusted HTTPS connections to victims redirected to malicious infrastructure. Most hijacked domains remained redirected for very short windows (sometimes under 24 hours), though one domain was hijacked for over a month. Five actor-controlled name server domains were used as malicious authoritative DNS: cloudipnameserver.com, cloudnamedns.com, lcjcomputing.com, mmfasi.com, and interaland.com. CrowdStrike assessed that the likely objectives were direct traffic interception, credential collection, and potential malware delivery against targeted organizations. Public reporting at the time pointed to a possible Iranian nexus, though CrowdStrike stated definitive attribution was inconclusive at the time of publication.
Detected Targets
| Type | Description | Confidence |
|---|---|---|
| Sector | Government Agencies and Services | Verified |
| Sector | Information Technology | Verified |
| Sector | Insurance | Verified |
| Sector | Telecommunication | Verified |
| Sector | Transportation | Verified |
| Region | Albania | Verified |
| Region | Egypt | Verified |
| Region | Iraq | Verified |
| Region | Jordan | Verified |
| Region | Kuwait | Verified |
| Region | Lebanon | Verified |
| Region | Libya | Verified |
| Region | Saudi Arabia | Verified |
| Region | Sweden | Verified |
| Region | United States | Verified |
Extracted IOCs
- cloudipnameserver[.]com
- cloudnamedns[.]com
- interaland[.]com
- lcjcomputing[.]com
- mmfasi[.]com
- 128[.]199.50.175
- 139[.]162.144.139
- 139[.]59.134.216
- 142[.]54.179.69
- 146[.]185.143.158
- 178[.]62.218.244
- 185[.]15.247.140
- 185[.]161.209.147
- 185[.]20.187.8
- 188[.]166.119.57
- 199[.]247.3.191
- 206[.]221.184.133
- 37[.]139.11.155
- 46[.]101.250.202
- 82[.]196.11.127
- 82[.]196.8.43
- 89[.]163.206.26
Tip: 22 related IOCs (17 IP, 5 domain, 0 URL, 0 email, 0 file hash) to this threat have been found.
Overlaps
Source: Palo Alto Networks - January 2020
Detection (four cases): 185[.]15.247.140, 185[.]161.209.147, 199[.]247.3.191, cloudipnameserver[.]com
Source: Palo Alto Network - September 2019
Detection (one case): 185[.]15.247.140
Source: Cyware - August 2019
Detection (two cases): 185[.]15.247.140, 185[.]20.187.8
Source: Cisco Talos - November 2018
Detection (one case): 185[.]20.187.8
Hint: Overlaps are extracted automatically by examining the IOCs associated with all indexed threats and actors.
FAQs
Frequently Asked Questions About the Widespread DNS Hijacking Campaign
A threat actor — with a possible but unconfirmed Iranian nexus — conducted a two-year DNS hijacking campaign targeting 28 organizations across 12 countries. By modifying victims' DNS records, the attackers silently redirected internet traffic destined for legitimate government, ISP, and aviation domains to their own infrastructure, where they could intercept data and credentials. CrowdStrike published its analysis on January 25, 2019, identifying 18 malicious IP addresses and 5 actor-controlled name server domains used across the campaign.
Attribution remains inconclusive. CrowdStrike noted that the heavy targeting of Middle Eastern government entities aligns with Iran's traditional intelligence collection interests, and public reporting at the time pointed to a possible Iranian nexus. However, the extended timeframe of the campaign and variance in infrastructure led CrowdStrike to note it was unclear whether one or multiple actors were involved. FireEye's concurrent reporting also suggested possible Iranian connections but stopped short of definitive attribution.
The likely objectives were direct interception of web traffic, credential theft from captured traffic, and potential malware delivery against victims routed to malicious infrastructure. Government domain hijackings suggest intelligence collection was the primary mission — capturing login credentials, email communications, and web traffic from employees of targeted ministries and agencies. The targeting of ISPs and core internet infrastructure operators also raised concern about potential downstream collection against a much wider set of unidentified organizations using those services.
The campaign hit 28 organizations in 12 countries across a two-year period. The primary focus was the Middle East and North Africa — Jordan, Kuwait, UAE, Iraq, Egypt, Libya, Lebanon, Saudi Arabia, and Albania were all affected, predominantly in the government sector. Sweden and the United States were also impacted, specifically in internet infrastructure. The broad geographic and sectoral reach, combined with targeting of ISPs and root internet infrastructure, suggests the actors were casting a wide net to support intelligence collection across the region.
Government entities across the Middle East were the dominant targets — consistent with intelligence collection interests focused on regional geopolitics, foreign policy communications, and government operations. ISPs and internet infrastructure operators were particularly significant targets because compromising them could enable passive surveillance of a far wider range of organizations using their services, without needing to target each downstream customer individually. Civil aviation, insurance, and law enforcement entities were also hit, broadening the intelligence value of the intercepted traffic.
The attackers modified the DNS records of victim organizations — either by compromising the domain registrar accounts or the authoritative DNS servers themselves — so that the domains resolved to attacker-controlled IP addresses instead of the legitimate servers. Users visiting those domains were silently redirected without any visible warning. To make the interception completely transparent, the attackers obtained fraudulent TLS certificates for the hijacked domains through Let's Encrypt, a free certificate authority. This meant browsers showed a valid padlock icon, and users had no indication they were connected to malicious infrastructure. The hijacking windows were typically very short — often under 24 hours — suggesting rapid credential harvesting operations.
The use of fraudulent TLS certificates obtained through Let's Encrypt is the most technically significant aspect of this campaign. By presenting a valid certificate for the hijacked domain, the attackers ensured that victim browsers showed a secure padlock icon and did not generate any certificate warnings. This completely neutralized one of the main security indicators users rely on to detect impersonation attacks. It exploited a legitimate feature of the internet's certificate infrastructure — domain-validated certificates require only proof of DNS control, which the attackers had already obtained through hijacking.
Enable DNS registry lock at your domain registrar to prevent unauthorized record changes without out-of-band verification. Enforce MFA on all domain registrar and DNS management accounts. Implement DNSSEC on all public-facing domains to cryptographically sign DNS responses and detect unauthorized modifications. Monitor Certificate Transparency logs (e.g. via crt.sh) for unauthorized TLS certificates issued for your domains — all Let's Encrypt certificates are logged publicly and detectable. Set up passive DNS monitoring to alert on unexpected changes to your authoritative name servers or A/AAAA records. Block the five actor-controlled name server domains at your DNS resolver: cloudipnameserver.com, cloudnamedns.com, lcjcomputing.com, mmfasi.com, and interaland.com.