DNSpionage Campaign Targets Lebanon and UAE Government Domains
- Actor Motivations: Espionage,Exfiltration
- Attack Vectors: DNS spoofing,Backdoor,Spear Phishing
- Attack Complexity: Medium
- Threat Risk: High Impact/Low Probability
Threat Overview
Cisco Talos discovered a targeted campaign in November 2018 affecting government domains in Lebanon and the UAE, as well as Middle East Airlines. The attackers operated on two tracks simultaneously. First, they delivered a custom backdoor called DNSpionage via malicious Word documents hosted on fake job listing websites (hr-wipro[.]com and hr-suncor[.]com), which used embedded macros to drop and execute a remote administration tool supporting both HTTP and DNS command-and-control. The malware stored commands in a fake Wikipedia page, used a custom per-target Base64 alphabet for obfuscation, and communicated over DNS by encoding data as Base32-encoded subdomain queries to 0ffice36o[.]com. Second, the same actor conducted parallel DNS redirection attacks against specific government and airline hostnames in Lebanon and the UAE between September and November 2018 — redirecting email and VPN domains to attacker-controlled IP 185.20.187.8 after pre-generating matching Let's Encrypt certificates, enabling silent interception of credentials and potentially MFA codes. Named redirected domains included the Lebanese Finance Ministry's webmail, Abu Dhabi Police VPN, UAE Ministry of Government Services mail, UAE Telecommunications Regulatory Authority mail, and multiple Middle East Airlines domains. Talos assessed both activities originated from the same actor and confirmed victims in Lebanon and the UAE via DNS telemetry data. No attribution to a specific group was established.
Detected Targets
| Type | Description | Confidence |
|---|---|---|
| Case | Abu Dhabi Police Abu Dhabi Police has been targeted by Unclassified as the main target. | Verified |
| Case | Lebanese Ministry of Finance Lebanese Ministry of Finance has been targeted by Unclassified as the main target. | Verified |
| Case | Middle East Airlines Middle East Airlines has been targeted by Unclassified as the main target. | Verified |
| Case | Ministry of education Ministry of education has been targeted by Unclassified as the main target. | Verified |
| Case | Suncor Suncor Energy is a Canadian integrated energy company based in Calgary, Alberta. It specializes in production of synthetic crude from oil sands. Suncor has been targeted by Unclassified with abusive purposes. | Verified |
| Case | Telecommunications and Digital Government Regulatory Authority Telecommunications and Digital Government Regulatory Authority has been targeted by Unclassified as the main target. | Verified |
| Case | Wipro Wipro is an Indian multinational corporation that provides information technology, consultant and business process services. It is one of the leading Big Tech companies. Wipro has been targeted by Unclassified with abusive purposes. | Verified |
| Sector | Financial | Verified |
| Sector | Government Agencies and Services | Verified |
| Sector | Telecommunication | Verified |
| Sector | Transportation | Verified |
| Region | Lebanon | Verified |
| Region | Lebanon Lebanon explicitly named as a primary target. Lebanese Finance Ministry webmail and Middle East Airlines domains were DNS-redirected. Talos confirmed Lebanese victims via Umbrella telemetry. | Verified |
| Region | United Arab Emirates UAE explicitly named as a primary target. Abu Dhabi Police VPN, UAE Ministry of Government Services mail, and UAE TRA mail all DNS-redirected to attacker infrastructure between September and November 2018. | Verified |
| Region | United Arab Emirates | Verified |
Extracted IOCs
- 0ffice36o[.]com
- hr-suncor[.]com
- hr-wipro[.]com
- mea[.]aero
- meacorp.com[.]lb
- adpvpn.adpolice.gov[.]ae
- autodiscover.mea[.]aero
- autodiscover.mea.com[.]lb
- autodiscover.meacorp.com[.]lb
- mail.apc.gov[.]ae
- mail.mgov[.]ae
- memail.mea.com[.]lb
- memailr.meacorp.com[.]lb
- meoutlook.meacorp.com[.]lb
- owa.mea.com[.]lb
- tmec.mea.com[.]lb
- webmail.finance.gov[.]lb
- www.mea.com[.]lb
- 15fe5dbcd31be15f98aa9ba18755ee6264a26f5ea0877730b00ca0646d0f25fa
- 45a9edb24d4174592c69d9d37a534a518fbe2a88d3817fc0cc739e455883b8ff
- 9ea577a4b3faaf04a3bddbfcb934c9752bed0d0fc579f2152751c5f6923f7e14
- 2010f38ef300be4349e7bc287e720b1ecec678cacbf0ea0556bcf765f6e073ec82285b6743cc5e3545d8e67740a4d04c5aed138d9f31d7c16bd11188a2042969
- 185[.]161.211.72
- 185[.]20.184.138
- 185[.]20.187.8
Tip: 25 related IOCs (3 IP, 18 domain, 0 URL, 0 email, 4 file hash) to this threat have been found.
Overlaps
Source: Palo Alto Networks - January 2020
Detection (one case): 185[.]161.211.72
Source: Cyware - August 2019
Detection (one case): 185[.]20.187.8
Source: CrowdStrike - January 2019
Detection (one case): 185[.]20.187.8
Source: Openminded - January 2019
Detection (five cases): 185[.]161.211.72, 185[.]20.184.138, 0ffice36o[.]com, hr-suncor[.]com, hr-wipro[.]com
Hint: Overlaps are extracted automatically by examining the IOCs associated with all indexed threats and actors.
FAQs
DNSpionage Campaign — Frequently Asked Questions
In late 2018, Cisco Talos uncovered a two-part cyberattack targeting government organizations in Lebanon and the UAE, as well as Middle East Airlines. In the first part, attackers used fake job listing websites to deliver a custom backdoor called DNSpionage to victims' computers. In the second part, the same actor quietly redirected official government and airline domain names — email portals and VPN gateways — through their own servers, enabling silent interception of credentials and communications.
Cisco Talos did not attribute this campaign to a specific group. However, Mandiant subsequently linked the DNSpionage activity to APT34 (OilRig), an Iranian state-sponsored group, based on overlapping infrastructure and targeting patterns. The campaign's heavy focus on Lebanese and UAE government entities, as well as a private airline, is consistent with Iranian intelligence interests in the region. The Openminded incident response report on the same campaign also references the Mandiant APT34 link.
The campaign had two connected goals. The DNSpionage malware was designed to give attackers persistent remote access to infected systems for espionage and data collection. The parallel DNS redirection attacks were aimed at passively intercepting credentials, email communications, and potentially MFA codes from government employees and airline staff — without ever needing to compromise their devices directly. Together the two tracks suggest a broad intelligence collection operation targeting sensitive government communications.
The campaign was narrowly targeted but high-impact. Named DNS redirection victims included the Lebanese Finance Ministry, Abu Dhabi Police (VPN infrastructure), UAE Ministry of Government Services, the UAE Telecommunications Regulatory Authority, and Middle East Airlines — whose certificate covered 11 subdomains. Talos confirmed victims in both Lebanon and the UAE via DNS telemetry. The breadth of the DNS redirection across both the public and private sectors across two countries over two months indicates a well-resourced, deliberate operation rather than opportunistic attacks.
The campaign specifically targeted government agencies in Lebanon and the UAE, including finance, law enforcement, and telecommunications regulatory bodies. A private Lebanese airline (Middle East Airlines) was also targeted. The use of fake Wipro and Suncor Energy recruitment sites as lures suggests IT and energy sector employees were also in scope for the malware delivery track. The DNS redirection focused specifically on email and VPN infrastructure — services that carry high volumes of sensitive communications and credentials.
The attack used two methods simultaneously. For device compromise, attackers created fake job sites impersonating Wipro and Suncor Energy, hosting malicious Word documents. Opening the document triggered a macro that silently installed the DNSpionage backdoor — which communicated back to attackers either via HTTP requests to a fake Wikipedia page or via DNS queries with commands encoded in the subdomain names. For network-level interception, the attackers compromised DNS records of target government domains at the registrar or nameserver level, redirecting email and VPN traffic through their servers — after pre-generating matching SSL certificates so users would see no browser warnings. Anyone logging into their organization's email or VPN during the redirection period would have had their credentials captured.
Lebanese and UAE government ministries hold sensitive diplomatic, financial, and security communications that are directly valuable to Iranian state intelligence. Law enforcement and VPN infrastructure are particularly attractive because compromising them can expose both operational security details and employee identities. Middle East Airlines, as Lebanon's national carrier, handles travel records and communications that could assist in tracking individuals of intelligence interest. The targeting of email and MFA-protected systems specifically suggests the attackers wanted sustained, high-quality access to communications rather than one-off data theft.
Monitor Certificate Transparency logs for any unexpected TLS certificates issued for your domains — this provides early warning before a DNS redirect goes live. Enable DNS registry lock and enforce MFA on all registrar accounts. Monitor DNS records regularly for unauthorized changes to A and NS entries. Block outbound DNS to non-corporate resolvers and alert on high-entropy subdomain queries. Disable Office macros from external sources and block the disclosed IOCs: 0ffice36o[.]com, hr-wipro[.]com, hr-suncor[.]com, the three C2 IPs (185.20.184.138, 185.20.187.8, 185.161.211.72), and the four file hashes. Review OWA and VPN access logs for source IPs outside expected ranges during the September–November 2018 window if not already done.