In 2018, a sophisticated threat actor took control of the DNS records for entire countries and top level domains. The attacker succeeded in redirecting a nation state’s ministry of foreign affairs domain records to point to systems under the malicious control. In this presentation learn how Cisco Talos spotted the attack within their telemetry and discovered the expanse of the attacker’s campaign, and how Talos’ expertise can protect your networks.