Threat actors continuously search for new techniques to compromise their victims. Recently, Cisco Talos identified a new malicious campaign named “DNSpionage”. This attack comprises three components: information stealing malware, tampering with organisations’ DNS records, and using the compromised DNS to register valid TLS certificates. Together these components allow the threat actor to perform man-in-the-middle attacks and to harvest further credentials.In addition to presenting what this attack reveals about the capabilities and aspirations of threat actors, Martin will review how organisations can protect themselves against similar attacks in the future.Learning Outcomes:Learn about a highly strategic cyber attackLearn how to protect against information stealing malwareLearn how TLS certificates were compromised from the DNSLearn how to prevent man-in-the-middle type attacksLearn what DNSpionage reveals about the new capabilities and aspirations of threat actors