DNSpionage Campaign Targets Middle East

No ratings

Presented at CopenhagenCyberCrime 2019 by

Cisco Talos identified an espionage campaign that mainly targeted Middle East that we named "DNSpionage". First, we will describe a malware targeting several government agencies in the Middle East, as well as a airline. During the research process for DNSpionage, we also discovered an effort to redirect DNSs from the targets and registered SSL certificates for them. We identified a dozen of countires targeted by this redirection. The January 22nd, U.S. DHS published a directive concerning this attack vector. In this presentation, we will present the timeline for these events and their technical details.