DNS Hijacking Campaign with Suspected Iranian Links Targets Global Domains
- Actor Motivations: Espionage,Exfiltration
- Attack Vectors: Compromised Credentials,DNS spoofing
- Attack Complexity: High
- Threat Risk: High Impact/Low Probability
Threat Overview
Mandiant's January 2019 report was the first public disclosure of a large-scale DNS hijacking campaign affecting domains across the Middle East and North Africa, Europe, and North America from January 2017 to January 2019. The attackers manipulated both DNS A records (changing the IP address a domain resolves to) and NS records (changing the authoritative name server for a domain), redirecting victim traffic through attacker-controlled infrastructure. SSL certificates were obtained for the hijacked domains to prevent browser warnings and make the interception transparent to victims. Credentials were harvested from the intercepted traffic. Targeted sectors included government, telecommunications, internet infrastructure providers, and other organizations across the MENA region. Mandiant noted that some techniques observed were previously associated with Iranian cyber espionage activity, leading to the assessment of a suspected Iranian nexus — though definitive attribution was not established. The campaign operated in waves, with multiple hijacking operations conducted at different times targeting organizations in different countries. Mandiant's analysis was published shortly before CrowdStrike's complementary report, prompting coordinated government-level advisories from CISA and other agencies urging immediate DNS record monitoring and registrar account security hardening.
Detected Targets
| Type | Description | Confidence |
|---|---|---|
| Sector | Government Agencies and Services | Verified |
| Sector | Information Technology | Verified |
| Sector | Telecommunication | Verified |
| Region | Middle East Countries | Verified |
| Region | European Countries | Verified |
FAQs
Frequently Asked Questions About Mandiant's Global DNS Hijacking Campaign Report
Mandiant published a report in January 2019 documenting a large-scale DNS hijacking campaign that had been operating since at least January 2017. Unknown attackers — with a suspected but unconfirmed Iranian connection — systematically modified the DNS records of government, telecom, and internet infrastructure organizations across the Middle East, North Africa, Europe, and North America. By redirecting victim domain traffic through their own servers and obtaining fraudulent SSL certificates, the attackers silently intercepted credentials and communications without any visible indication to the targeted users.
Attribution remains inconclusive. Mandiant assessed a suspected Iranian nexus based on some techniques previously associated with Iranian cyber espionage activity and the heavy focus on Middle Eastern government targets — a region of consistent strategic interest to Iran. However, definitive country or actor-level attribution was not established at the time of publication. CrowdStrike's concurrent report reached the same position. Subsequent analysis by other researchers and government agencies also pointed toward Iran without reaching certainty.
The primary goal was credential harvesting and intelligence collection. By routing victim organization traffic through attacker-controlled infrastructure, the attackers could passively intercept usernames, passwords, email communications, and other sensitive data from employees logging into their organization's web portals. The harvested credentials could then be used for follow-on access into victim networks. The targeting of ISPs and internet infrastructure operators also raised the possibility of passive surveillance against a much broader set of downstream users.
The campaign ran for at least two years — from January 2017 to January 2019 — and affected dozens of organizations across the Middle East and North Africa, Europe, and North America. CrowdStrike identified 28 victim organizations across 12 countries. The breadth of targeting was described by Mandiant as operating on an "almost unprecedented scale." ISPs, internet infrastructure providers, and government entities were all compromised, meaning the actual number of individuals whose credentials and communications were intercepted could extend well beyond the named organizational victims.
The campaign specifically targeted government agencies, telecommunications providers, internet infrastructure operators, and ISPs — primarily across the Middle East and North Africa, with secondary targeting in Europe and North America. Government organizations in the Middle East were the highest-priority victims, consistent with Iranian intelligence interests. Telecom and internet infrastructure operators were also prime targets because compromising them gives attackers access to the broader communications traffic of downstream customers.
The attackers used three related DNS manipulation techniques. In the first, they logged into a victim's DNS provider using stolen credentials and changed the IP address a domain points to — redirecting all traffic for that domain (for example, an email login page) through their own servers. In the second, they compromised a domain registrar or country-level domain authority and swapped the nameserver records, rerouting all of a domain's subdomains to attacker infrastructure. In both cases, they used a free certificate service (Let's Encrypt) to obtain valid SSL certificates for the victim domains so users would see no browser security warnings. All intercepted traffic was forwarded to the real servers, so victims noticed nothing unusual — except perhaps a slight delay. A third variant added a custom DNS redirector server that answered DNS requests selectively, routing only target domains through the attacker's infrastructure while passing all other traffic normally.
Government entities in the Middle East hold sensitive diplomatic, military, and economic communications of direct interest to Iranian intelligence services. Telecom and internet infrastructure operators are attractive because they sit at the center of national communications — compromising their infrastructure provides passive access to vast amounts of traffic without ever touching individual victim endpoints. ISPs in particular represent a high-value, low-detection-risk target: traffic through their networks appears entirely normal, making interception very difficult to detect at the individual organization level.
Enable DNS registry lock at your domain registrar — this is the single most effective control, as it requires out-of-band human verification for any DNS record changes. Enforce multi-factor authentication on all registrar and DNS management accounts. Monitor Certificate Transparency logs for any unexpected TLS certificates issued for your domains (tools like crt.sh provide free alerts). Regularly validate your A and NS records directly through your registrar portal and set up alerts for unexpected changes. Implement DNSSEC to cryptographically sign your DNS responses. Review OWA and Exchange server access logs for source IPs that don't match expected ranges, as redirected traffic would originate from attacker-controlled servers.