Threats Feed|Unclassified|Last Updated 30/04/2026|AuthorCertfa Radar|Publish Date25/01/2019

Widespread DNS Hijacking Campaign with Possible Iranian Nexus Targets Multiple Sectors

  • Actor Motivations: Espionage,Exfiltration
  • Attack Vectors: Vulnerability Exploitation
  • Attack Complexity: High
  • Threat Risk: High Impact/Low Probability

Threat Overview

CrowdStrike Intelligence's January 2019 report documents a widespread DNS hijacking campaign active from at least February 2017 through January 2019, affecting 28 organizations across 12 countries. The campaign primarily targeted entities in the Middle East and North Africa, with limited impact in Europe and the United States. Affected sectors included government (the dominant target across Jordan, Kuwait, UAE, Iraq, Egypt, Libya, Lebanon, Albania, Cyprus, and Saudi Arabia), law enforcement, civil aviation, insurance, telecommunications, and internet infrastructure providers including ISPs, internet exchange points, root DNS servers, and TLD operators. The attack method involved hijacking victim organizations' DNS records to redirect traffic to actor-controlled IP addresses. Fraudulent TLS certificates were then obtained — primarily through Let's Encrypt — enabling the actors to present trusted HTTPS connections to victims redirected to malicious infrastructure. Most hijacked domains remained redirected for very short windows (sometimes under 24 hours), though one domain was hijacked for over a month. Five actor-controlled name server domains were used as malicious authoritative DNS: cloudipnameserver.com, cloudnamedns.com, lcjcomputing.com, mmfasi.com, and interaland.com. CrowdStrike assessed that the likely objectives were direct traffic interception, credential collection, and potential malware delivery against targeted organizations. Public reporting at the time pointed to a possible Iranian nexus, though CrowdStrike stated definitive attribution was inconclusive at the time of publication.

Detected Targets

TypeDescriptionConfidence
SectorGovernment Agencies and Services
Verified
SectorInformation Technology
Verified
SectorInsurance
Verified
SectorTelecommunication
Verified
SectorTransportation
Verified
RegionAlbania
Verified
RegionEgypt
Verified
RegionIraq
Verified
RegionJordan
Verified
RegionKuwait
Verified
RegionLebanon
Verified
RegionLibya
Verified
RegionSaudi Arabia
Verified
RegionSweden
Verified
RegionUnited States
Verified

Extracted IOCs

  • cloudipnameserver[.]com
  • cloudnamedns[.]com
  • interaland[.]com
  • lcjcomputing[.]com
  • mmfasi[.]com
  • 128[.]199.50.175
  • 139[.]162.144.139
  • 139[.]59.134.216
  • 142[.]54.179.69
  • 146[.]185.143.158
  • 178[.]62.218.244
  • 185[.]15.247.140
  • 185[.]161.209.147
  • 185[.]20.187.8
  • 188[.]166.119.57
  • 199[.]247.3.191
  • 206[.]221.184.133
  • 37[.]139.11.155
  • 46[.]101.250.202
  • 82[.]196.11.127
  • 82[.]196.8.43
  • 89[.]163.206.26
download

Tip: 22 related IOCs (17 IP, 5 domain, 0 URL, 0 email, 0 file hash) to this threat have been found.

Overlaps

UnclassifiedShades of OilRig and Chafer in xHunt Campaign's Attack on Kuwaiti Government Sector

Source: Palo Alto Networks - January 2020

Detection (four cases): 185[.]15.247.140, 185[.]161.209.147, 199[.]247.3.191, cloudipnameserver[.]com

UnclassifiedxHunt Campaign Targets Kuwait's Transportation and Shipping Sectors

Source: Palo Alto Network - September 2019

Detection (one case): 185[.]15.247.140

APT34Cyber-Espionage in the Middle East: A Deep Dive into APT34's Operations

Source: Cyware - August 2019

Detection (two cases): 185[.]15.247.140, 185[.]20.187.8

UnclassifiedDNSpionage Campaign Targets Lebanon and UAE Government Domains

Source: Cisco Talos - November 2018

Detection (one case): 185[.]20.187.8

Hint: Overlaps are extracted automatically by examining the IOCs associated with all indexed threats and actors.

FAQs

Frequently Asked Questions About the Widespread DNS Hijacking Campaign

A threat actor — with a possible but unconfirmed Iranian nexus — conducted a two-year DNS hijacking campaign targeting 28 organizations across 12 countries. By modifying victims' DNS records, the attackers silently redirected internet traffic destined for legitimate government, ISP, and aviation domains to their own infrastructure, where they could intercept data and credentials. CrowdStrike published its analysis on January 25, 2019, identifying 18 malicious IP addresses and 5 actor-controlled name server domains used across the campaign.

Attribution remains inconclusive. CrowdStrike noted that the heavy targeting of Middle Eastern government entities aligns with Iran's traditional intelligence collection interests, and public reporting at the time pointed to a possible Iranian nexus. However, the extended timeframe of the campaign and variance in infrastructure led CrowdStrike to note it was unclear whether one or multiple actors were involved. FireEye's concurrent reporting also suggested possible Iranian connections but stopped short of definitive attribution.

The likely objectives were direct interception of web traffic, credential theft from captured traffic, and potential malware delivery against victims routed to malicious infrastructure. Government domain hijackings suggest intelligence collection was the primary mission — capturing login credentials, email communications, and web traffic from employees of targeted ministries and agencies. The targeting of ISPs and core internet infrastructure operators also raised concern about potential downstream collection against a much wider set of unidentified organizations using those services.

The campaign hit 28 organizations in 12 countries across a two-year period. The primary focus was the Middle East and North Africa — Jordan, Kuwait, UAE, Iraq, Egypt, Libya, Lebanon, Saudi Arabia, and Albania were all affected, predominantly in the government sector. Sweden and the United States were also impacted, specifically in internet infrastructure. The broad geographic and sectoral reach, combined with targeting of ISPs and root internet infrastructure, suggests the actors were casting a wide net to support intelligence collection across the region.

Government entities across the Middle East were the dominant targets — consistent with intelligence collection interests focused on regional geopolitics, foreign policy communications, and government operations. ISPs and internet infrastructure operators were particularly significant targets because compromising them could enable passive surveillance of a far wider range of organizations using their services, without needing to target each downstream customer individually. Civil aviation, insurance, and law enforcement entities were also hit, broadening the intelligence value of the intercepted traffic.

The attackers modified the DNS records of victim organizations — either by compromising the domain registrar accounts or the authoritative DNS servers themselves — so that the domains resolved to attacker-controlled IP addresses instead of the legitimate servers. Users visiting those domains were silently redirected without any visible warning. To make the interception completely transparent, the attackers obtained fraudulent TLS certificates for the hijacked domains through Let's Encrypt, a free certificate authority. This meant browsers showed a valid padlock icon, and users had no indication they were connected to malicious infrastructure. The hijacking windows were typically very short — often under 24 hours — suggesting rapid credential harvesting operations.

The use of fraudulent TLS certificates obtained through Let's Encrypt is the most technically significant aspect of this campaign. By presenting a valid certificate for the hijacked domain, the attackers ensured that victim browsers showed a secure padlock icon and did not generate any certificate warnings. This completely neutralized one of the main security indicators users rely on to detect impersonation attacks. It exploited a legitimate feature of the internet's certificate infrastructure — domain-validated certificates require only proof of DNS control, which the attackers had already obtained through hijacking.

Enable DNS registry lock at your domain registrar to prevent unauthorized record changes without out-of-band verification. Enforce MFA on all domain registrar and DNS management accounts. Implement DNSSEC on all public-facing domains to cryptographically sign DNS responses and detect unauthorized modifications. Monitor Certificate Transparency logs (e.g. via crt.sh) for unauthorized TLS certificates issued for your domains — all Let's Encrypt certificates are logged publicly and detectable. Set up passive DNS monitoring to alert on unexpected changes to your authoritative name servers or A/AAAA records. Block the five actor-controlled name server domains at your DNS resolver: cloudipnameserver.com, cloudnamedns.com, lcjcomputing.com, mmfasi.com, and interaland.com.