Threats Feed|Unclassified|Last Updated 01/05/2026|AuthorCertfa Radar|Publish Date27/11/2018

DNSpionage Campaign Targets Lebanon and UAE Government Domains

  • Actor Motivations: Espionage,Exfiltration
  • Attack Vectors: DNS spoofing,Backdoor,Spear Phishing
  • Attack Complexity: Medium
  • Threat Risk: High Impact/Low Probability

Threat Overview

Cisco Talos discovered a targeted campaign in November 2018 affecting government domains in Lebanon and the UAE, as well as Middle East Airlines. The attackers operated on two tracks simultaneously. First, they delivered a custom backdoor called DNSpionage via malicious Word documents hosted on fake job listing websites (hr-wipro[.]com and hr-suncor[.]com), which used embedded macros to drop and execute a remote administration tool supporting both HTTP and DNS command-and-control. The malware stored commands in a fake Wikipedia page, used a custom per-target Base64 alphabet for obfuscation, and communicated over DNS by encoding data as Base32-encoded subdomain queries to 0ffice36o[.]com. Second, the same actor conducted parallel DNS redirection attacks against specific government and airline hostnames in Lebanon and the UAE between September and November 2018 — redirecting email and VPN domains to attacker-controlled IP 185.20.187.8 after pre-generating matching Let's Encrypt certificates, enabling silent interception of credentials and potentially MFA codes. Named redirected domains included the Lebanese Finance Ministry's webmail, Abu Dhabi Police VPN, UAE Ministry of Government Services mail, UAE Telecommunications Regulatory Authority mail, and multiple Middle East Airlines domains. Talos assessed both activities originated from the same actor and confirmed victims in Lebanon and the UAE via DNS telemetry data. No attribution to a specific group was established.

Detected Targets

TypeDescriptionConfidence
CaseAbu Dhabi Police
Abu Dhabi Police has been targeted by Unclassified as the main target.
Verified
CaseLebanese Ministry of Finance
Lebanese Ministry of Finance has been targeted by Unclassified as the main target.
Verified
CaseMiddle East Airlines
Middle East Airlines has been targeted by Unclassified as the main target.
Verified
CaseMinistry of education
Ministry of education has been targeted by Unclassified as the main target.
Verified
CaseSuncor
Suncor Energy is a Canadian integrated energy company based in Calgary, Alberta. It specializes in production of synthetic crude from oil sands. Suncor has been targeted by Unclassified with abusive purposes.
Verified
CaseTelecommunications and Digital Government Regulatory Authority
Telecommunications and Digital Government Regulatory Authority has been targeted by Unclassified as the main target.
Verified
CaseWipro
Wipro is an Indian multinational corporation that provides information technology, consultant and business process services. It is one of the leading Big Tech companies. Wipro has been targeted by Unclassified with abusive purposes.
Verified
SectorFinancial
Verified
SectorGovernment Agencies and Services
Verified
SectorTelecommunication
Verified
SectorTransportation
Verified
RegionLebanon
Verified
RegionLebanon
Lebanon explicitly named as a primary target. Lebanese Finance Ministry webmail and Middle East Airlines domains were DNS-redirected. Talos confirmed Lebanese victims via Umbrella telemetry.
Verified
RegionUnited Arab Emirates
UAE explicitly named as a primary target. Abu Dhabi Police VPN, UAE Ministry of Government Services mail, and UAE TRA mail all DNS-redirected to attacker infrastructure between September and November 2018.
Verified
RegionUnited Arab Emirates
Verified

Extracted IOCs

  • 0ffice36o[.]com
  • hr-suncor[.]com
  • hr-wipro[.]com
  • mea[.]aero
  • meacorp.com[.]lb
  • adpvpn.adpolice.gov[.]ae
  • autodiscover.mea[.]aero
  • autodiscover.mea.com[.]lb
  • autodiscover.meacorp.com[.]lb
  • mail.apc.gov[.]ae
  • mail.mgov[.]ae
  • memail.mea.com[.]lb
  • memailr.meacorp.com[.]lb
  • meoutlook.meacorp.com[.]lb
  • owa.mea.com[.]lb
  • tmec.mea.com[.]lb
  • webmail.finance.gov[.]lb
  • www.mea.com[.]lb
  • 15fe5dbcd31be15f98aa9ba18755ee6264a26f5ea0877730b00ca0646d0f25fa
  • 45a9edb24d4174592c69d9d37a534a518fbe2a88d3817fc0cc739e455883b8ff
  • 9ea577a4b3faaf04a3bddbfcb934c9752bed0d0fc579f2152751c5f6923f7e14
  • 2010f38ef300be4349e7bc287e720b1ecec678cacbf0ea0556bcf765f6e073ec82285b6743cc5e3545d8e67740a4d04c5aed138d9f31d7c16bd11188a2042969
  • 185[.]161.211.72
  • 185[.]20.184.138
  • 185[.]20.187.8
download

Tip: 25 related IOCs (3 IP, 18 domain, 0 URL, 0 email, 4 file hash) to this threat have been found.

Overlaps

UnclassifiedShades of OilRig and Chafer in xHunt Campaign's Attack on Kuwaiti Government Sector

Source: Palo Alto Networks - January 2020

Detection (one case): 185[.]161.211.72

APT34Cyber-Espionage in the Middle East: A Deep Dive into APT34's Operations

Source: Cyware - August 2019

Detection (one case): 185[.]20.187.8

UnclassifiedWidespread DNS Hijacking Campaign with Possible Iranian Nexus Targets Multiple Sectors

Source: CrowdStrike - January 2019

Detection (one case): 185[.]20.187.8

UnclassifiedDNSPIONAGE: Unpacking Advanced Spear Phishing and Lateral Movement Techniques

Source: Openminded - January 2019

Detection (five cases): 185[.]161.211.72, 185[.]20.184.138, 0ffice36o[.]com, hr-suncor[.]com, hr-wipro[.]com

Hint: Overlaps are extracted automatically by examining the IOCs associated with all indexed threats and actors.

FAQs

DNSpionage Campaign — Frequently Asked Questions

In late 2018, Cisco Talos uncovered a two-part cyberattack targeting government organizations in Lebanon and the UAE, as well as Middle East Airlines. In the first part, attackers used fake job listing websites to deliver a custom backdoor called DNSpionage to victims' computers. In the second part, the same actor quietly redirected official government and airline domain names — email portals and VPN gateways — through their own servers, enabling silent interception of credentials and communications.

Cisco Talos did not attribute this campaign to a specific group. However, Mandiant subsequently linked the DNSpionage activity to APT34 (OilRig), an Iranian state-sponsored group, based on overlapping infrastructure and targeting patterns. The campaign's heavy focus on Lebanese and UAE government entities, as well as a private airline, is consistent with Iranian intelligence interests in the region. The Openminded incident response report on the same campaign also references the Mandiant APT34 link.

The campaign had two connected goals. The DNSpionage malware was designed to give attackers persistent remote access to infected systems for espionage and data collection. The parallel DNS redirection attacks were aimed at passively intercepting credentials, email communications, and potentially MFA codes from government employees and airline staff — without ever needing to compromise their devices directly. Together the two tracks suggest a broad intelligence collection operation targeting sensitive government communications.

The campaign was narrowly targeted but high-impact. Named DNS redirection victims included the Lebanese Finance Ministry, Abu Dhabi Police (VPN infrastructure), UAE Ministry of Government Services, the UAE Telecommunications Regulatory Authority, and Middle East Airlines — whose certificate covered 11 subdomains. Talos confirmed victims in both Lebanon and the UAE via DNS telemetry. The breadth of the DNS redirection across both the public and private sectors across two countries over two months indicates a well-resourced, deliberate operation rather than opportunistic attacks.

The campaign specifically targeted government agencies in Lebanon and the UAE, including finance, law enforcement, and telecommunications regulatory bodies. A private Lebanese airline (Middle East Airlines) was also targeted. The use of fake Wipro and Suncor Energy recruitment sites as lures suggests IT and energy sector employees were also in scope for the malware delivery track. The DNS redirection focused specifically on email and VPN infrastructure — services that carry high volumes of sensitive communications and credentials.

The attack used two methods simultaneously. For device compromise, attackers created fake job sites impersonating Wipro and Suncor Energy, hosting malicious Word documents. Opening the document triggered a macro that silently installed the DNSpionage backdoor — which communicated back to attackers either via HTTP requests to a fake Wikipedia page or via DNS queries with commands encoded in the subdomain names. For network-level interception, the attackers compromised DNS records of target government domains at the registrar or nameserver level, redirecting email and VPN traffic through their servers — after pre-generating matching SSL certificates so users would see no browser warnings. Anyone logging into their organization's email or VPN during the redirection period would have had their credentials captured.

Lebanese and UAE government ministries hold sensitive diplomatic, financial, and security communications that are directly valuable to Iranian state intelligence. Law enforcement and VPN infrastructure are particularly attractive because compromising them can expose both operational security details and employee identities. Middle East Airlines, as Lebanon's national carrier, handles travel records and communications that could assist in tracking individuals of intelligence interest. The targeting of email and MFA-protected systems specifically suggests the attackers wanted sustained, high-quality access to communications rather than one-off data theft.

Monitor Certificate Transparency logs for any unexpected TLS certificates issued for your domains — this provides early warning before a DNS redirect goes live. Enable DNS registry lock and enforce MFA on all registrar accounts. Monitor DNS records regularly for unauthorized changes to A and NS entries. Block outbound DNS to non-corporate resolvers and alert on high-entropy subdomain queries. Disable Office macros from external sources and block the disclosed IOCs: 0ffice36o[.]com, hr-wipro[.]com, hr-suncor[.]com, the three C2 IPs (185.20.184.138, 185.20.187.8, 185.161.211.72), and the four file hashes. Review OWA and VPN access logs for source IPs outside expected ranges during the September–November 2018 window if not already done.