Threats Feed|Greenbug|Last Updated 28/04/2026|AuthorCertfa Radar|Publish Date01/05/2017

Greenbug Group's Escalated Threat: Ismdoor RAT's Role in the Shamoon Attacks

  • Actor Motivations: Espionage,Exfiltration
  • Attack Vectors: RAT,Spyware
  • Attack Complexity: High
  • Threat Risk: High Impact/Low Probability

Threat Overview

NETSCOUT's ASERT team documents a significant evolution in Ismdoor, the custom remote access trojan used by the Iranian-linked Greenbug cyberespionage group. Where earlier versions used HTTP for command and control, the versions analyzed here replaced that entirely with a covert DNS-based C2 channel — communicating exclusively through AAAA DNS queries, encoding data as IPv6 addresses. The protocol is multi-layered: sessions are established via specially formatted query names containing a 32-character hex session ID, messages are base64-encoded and embedded in query subdomains, and responses are returned as static or data-carrying IPv6 addresses. File transfers use a separate session type with retransmission logic for missed packets. The malware supports over 20 C2 commands, including system information collection, self-update, credential dumping via Mimikatz (CreateMimi1Bat command invoking ccd61.ps1), keylogging (ExecuteKL), Powercat execution for network tunneling (ExecutePC), UAC bypass via RAAD, screenshot capture (PWS), and arbitrary command shell execution. Configuration is encrypted with a consistent substitution cipher and contains primary and secondary C2 domains, timeout values, and a unique bot identifier. NETSCOUT presents four indicators linking Ismdoor to the Shamoon/Disttrack campaigns against Saudi Arabia: Symantec observed an earlier Ismdoor variant on a Shamoon-targeted host shortly before Disttrack was deployed; all known DNS-variant samples were submitted to VirusTotal from Saudi Arabia; the CreateMimi1Bat command provides explicit credential-theft capability; and a McAfee blog on Shamoon traces a spearphishing email to the download and execution of an earlier Ismdoor variant. The link remains assessed as probable but unconfirmed at time of publication.

Detected Targets

TypeDescriptionConfidence
RegionSaudi Arabia
Verified

Extracted IOCs

  • dnslookupdater[.]com
  • winrepp[.]com
  • winsecupdater[.]com
  • 0.dr.237735c7dcf34de59f8e04cb852401b3.dnslookupdater[.]com
  • n.1.f.237735c7dcf34de59f8e04cb852401b3.dnslookupdater[.]com
  • n.n.c.237735c7dcf34de59f8e04cb852401b3.dnslookupdater[.]com
  • n.n.fc.237735c7dcf34de59f8e04cb852401b3.dnslookupdater[.]com
  • www.0.s.237735c7dcf34de59f8e04cb852401b3.dnslookupdater[.]com
  • 15b36b1e3a41ad80bbd363aea8f2d704
  • 237735c7dcf34de59f8e04cb852401b3
  • e01544bdab952f8b1fb4549021ecd728
  • 004f0519b69d9035034748d3fc4346e7b20fa102
  • e5e3d47a0395e2668e174713e8d3ef088c112eb7
  • 29c76f2115bcb3a92aeeedf3368f6ce94a420cd6d88fd5e4b7c37b51f2768c08
  • 5bc0a1f33c982916c8085076e8898ddbe8726249867b47df02e58ac3bf466b27
  • 3136:2c31:352c:392c:3520:2020:2020:2020
  • a67d:db8:85a3:4325:7654:8a2a:370:7334
  • a67d:db8:a2a1:7334:7654:4325:370:2aa3
download

Tip: 18 related IOCs (3 IP, 8 domain, 0 URL, 0 email, 7 file hash) to this threat have been found.

Overlaps

GreenbugDecoding Greenbug Group's Command and Control Communications via DNS Tunneling

Source: DomainTools - December 2019

Detection (three cases): a67d:db8:85a3:4325:7654:8a2a:370:7334, a67d:db8:a2a1:7334:7654:4325:370:2aa3, winrepp[.]com

GreenbugPotential Cyber Targets Revealed in Greenbug's Domain Registrations: Israeli and Saudi Firms in Focus

Source: ClearSky - October 2017

Detection (one case): winsecupdater[.]com

Hint: Overlaps are extracted automatically by examining the IOCs associated with all indexed threats and actors.

FAQs

Frequently Asked Questions: Greenbug's Ismdoor RAT and Its Possible Role in the Shamoon Attacks

NETSCOUT documented a major upgrade to Ismdoor, a custom spying tool used by the Iranian-linked Greenbug group to target Saudi Arabian companies. The newer versions of Ismdoor abandoned standard HTTP communications in favor of a hidden channel that tunnels all activity through normal-looking DNS queries — making it much harder to detect on the network. Separately, security researchers suspect Greenbug used Ismdoor to steal credentials from Saudi organizations before those credentials were used in the destructive Shamoon disk-wiping attacks, though a definitive link remains unconfirmed.

The attacks are attributed to Greenbug, a cyberespionage group assessed to be linked to the Iranian state. Greenbug has been active since at least 2016 and focuses on targets in the Middle East, particularly Saudi Arabia. The group is notable for developing its own custom malware rather than relying on off-the-shelf tools, and for continuously updating Ismdoor with new capabilities — including the DNS tunneling channel documented in this report.

Greenbug's primary goal with Ismdoor is espionage and credential theft. The RAT gives operators full remote access to compromised systems — they can steal files, capture screenshots, log keystrokes, dump Windows credentials using Mimikatz, and run arbitrary commands. The suspected downstream goal of this credential theft is to enable the Shamoon/Disttrack destructive attacks: the stolen credentials are believed to have been used to spread Disttrack across Saudi networks and trigger disk-wiping operations. If confirmed, Ismdoor functioned as the reconnaissance and access phase before a destructive payload was deployed.

All known DNS-variant Ismdoor samples were submitted to VirusTotal from Saudi Arabia, and the Shamoon campaigns it is suspected of enabling exclusively targeted Saudi Arabian companies. The campaign spans from at least mid-2016 through early 2017, with Ismdoor actively developed and updated throughout that period. Symantec confirmed Ismdoor's presence on at least one Shamoon-targeted organization's network prior to the November 2016 Disttrack deployment.

Greenbug targets Saudi Arabian organizations, with a particular focus on companies and sectors that were also targeted by the Shamoon attacks — including energy and critical infrastructure. The source does not identify specific victim organizations, but the targeting pattern is consistent with Iranian state interest in disrupting Saudi economic infrastructure and gathering intelligence on high-value Saudi entities.

Ismdoor gains a foothold on target systems and then communicates with attacker-controlled servers entirely through DNS — specifically through lookup requests for IPv6 addresses. Commands and data are encoded in the subdomain portion of these requests, and responses are embedded in the IPv6 addresses returned. This makes the traffic blend in with normal DNS activity on the network. Once connected, operators can execute over 20 commands: stealing credentials with Mimikatz, logging keystrokes, capturing screenshots, opening network tunnels with Powercat, bypassing Windows security controls, and uploading or downloading files. The malware updates its own configuration and code remotely and can remove itself when instructed.

Saudi Arabian organizations — particularly in energy and critical infrastructure — are high-value targets for Iran. Iran and Saudi Arabia have longstanding geopolitical and sectarian tensions, and disrupting Saudi industry serves Iranian strategic interests. The suspected link to Shamoon suggests Greenbug's espionage phase was not just about intelligence collection but about enabling follow-on destructive attacks designed to cause significant operational damage to the Saudi economy.

Monitor DNS traffic for unusual patterns of AAAA queries — particularly queries with long structured subdomains containing hex session IDs and message numbers, which are the behavioral fingerprint of Ismdoor's C2 channel. Block DNS resolution for the known Ismdoor domains: dnslookupdater[.]com, dnssecupdater[.]com, winrepp[.]com, and winsecupdater[.]com. Alert on PowerShell execution of ccd61.ps1 or Invoke-EventVwrBypass, both of which are invoked by specific Ismdoor commands. Enforce strict credential hygiene and monitor for Mimikatz usage — credential theft is the highest-risk downstream consequence of an Ismdoor infection given the suspected Shamoon connection. Use the published file hashes to scan endpoints for known Ismdoor samples.

About Affiliation
Greenbug
Greenbug is an Iranian state-linked cyber espionage cluster active since at least 2016, first documented by Symantec. The group specializes in targeting telecommunications, internet service providers, aviation, and energy companies across Saudi Arabia, Iraq, Bahrain, Qatar, Kuwait, and Turkey using spear phishing with fake business proposals to deliver its custom Ismdoor remote access trojan. Ismdoor uses DNS tunneling — and later DNS TXT record-based command and control — enabling covert credential theft and keylogging while blending into normal DNS traffic. Symantec assessed that Greenbug likely provided the credentials used by the Shamoon operators in the November 2016 Disttrack attacks, after detecting an Ismdoor infection on an administrator machine at a Shamoon-targeted organization days before the wiper deployment. Unit 42 identified a modified ISMDoor variant called ISMAgent deployed by OilRig operators in 2017, establishing shared tooling between Greenbug and OilRig and suggesting the groups are closely linked or overlapping within the same Iranian state espionage infrastructure.
View Greenbug's Insights