Iran-Based Hackers Behind a Worldwide DNS Hijacking Campaign: FireEye

Advertisement
By Indo-Asian News Service | Updated: 11 January 2019 18:48 IST

Iran-based cyber criminals are likely behind a sophisticated "unprecedented" hacking campaign targeting entities across the Middle East and North Africa, Europe and North America, according to US cybersecurity firm FireEye.

The researchers at FireEye have identified a wave of DNS (Domain Name System) hijacking that has affected dozens of domains belonging to government, telecommunications and Internet infrastructure entities.

"While we do not currently link this activity to any tracked group, initial research suggests the actor or actors responsible have a nexus to Iran," FireEye said in a blog post on Thursday.

Advertisement

"Preliminary technical evidence allows us to assess with moderate confidence that this activity is conducted by persons based in Iran and that the activity aligns with Iranian government interests," researchers wrote in the blog.

Advertisement

The hacking campaign has targeted victims across the globe on an almost unprecedented scale, with a high degree of success.

The teams at FireEye tracked the activity for several months -- mapping and understanding the innovative tactics, techniques and procedures (TTPs) deployed by the attacker.

Advertisement

They also worked closely with victims, security organisations and law enforcement agencies where possible to reduce the impact of the attacks and/or prevent further compromises.

"While this campaign employs some traditional tactics, it is differentiated from other Iranian activity we have seen by leveraging DNS hijacking at scale. The attacker uses this technique for their initial foothold, which can then be exploited in a variety of ways," explained researchers.

Advertisement

A large number of organisations have been affected by this pattern of DNS record manipulation and fraudulent SSL (Secure Sockets Layer) certificates.

"They include telecoms and ISP providers, Internet infrastructure providers, government and sensitive commercial entities," said FireEye.

This type of attack is difficult to defend against, because valuable information can be stolen, even if an attacker is never able to get direct access to an organisation's network.

"Implement multi-factor authentication on your domain's administration portal, search for SSL certificates related to your domain and revoke any malicious certificates, conduct an internal investigation to assess if attackers gained access to your environment," suggested researchers.

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Further reading: Iran, FireEye
Advertisement

Related Stories

Popular Mobile Brands
  1. Realme Narzo 90 Series With 7,000mAh Battery Launched in India: See Pricing
  2. Lenovo Idea Tab Plus Launched in India With 10,200mah Battery: Details
  3. Pixel 10 Series Gets Price Cuts During Google's End of Year Sale: See Offers
  4. RAM Crisis 2026: 16GB Phones Out, 4GB Models Making a Comeback
  5. Redmi Note 15 5G Chipset Revealed Ahead of January 6 India Launch
  6. Mrs Deshpande OTT Release Date: Madhuri Dixit's Starrere to Premiere on This Date
  7. Vivo S50, S50 Pro Mini With Snapdragon Chips Launched at These Prices
  8. Motorola Edge 70 First Impressions
  9. Realme 16 Pro to Launch With Urban Wild Design in These Four Colourways
  10. SBI YONO 2.0 Launch: State Bank of India Reportedly Targets 20 Crore Users
  1. Dhruv64: India’s First Homegrown 64-Bit Dual-Core Microprocessor Unveiled
  2. Disney CEO Says AI Deal With OpenAI Is Exclusive For Just One Year: Report
  3. Arasayyana Prema Prasanga Streaming Online: Know Where to Watch This Kannada Film
  4. Filmfare OTT Awards 2025 Winners: Black Warrant, Paatal Lok Season 2, Girls Will Be Girls, and More
  5. Thamma Now Streaming on Amazon Prime Video: Watch Ayushmann Khurrana and Rashmika Mandanna in This Horrer Comedy
  6. Realme 16 Pro Series Colourways Revealed; Company Announces Design Collaboration With Naoto Fukasawa
  7. Samsung Galaxy A07 5G Key Specifications Spotted in Geekbench Listing, Could Launch Soon
  8. Bungie Shares New Vision for Marathon, Confirms New March 2026 Launch Window, $40 Pricing
  9. Google to Discontinue Dark Web Reports in February 2026, Directs Users to Existing Privacy and Security Tools
  10. Realme Narzo 90 5G, Narzo 90x 5G Launched in India With 7,000mAh Battery, 50-Megapixel Cameras: Price, Features
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.