Iran-Based Hackers Behind a Worldwide DNS Hijacking Campaign: FireEye

Advertisement
By Indo-Asian News Service | Updated: 11 January 2019 18:48 IST
Iran-Based Hackers Behind a Worldwide DNS Hijacking Campaign: FireEye

Iran-based cyber criminals are likely behind a sophisticated "unprecedented" hacking campaign targeting entities across the Middle East and North Africa, Europe and North America, according to US cybersecurity firm FireEye.

The researchers at FireEye have identified a wave of DNS (Domain Name System) hijacking that has affected dozens of domains belonging to government, telecommunications and Internet infrastructure entities.

"While we do not currently link this activity to any tracked group, initial research suggests the actor or actors responsible have a nexus to Iran," FireEye said in a blog post on Thursday.

"Preliminary technical evidence allows us to assess with moderate confidence that this activity is conducted by persons based in Iran and that the activity aligns with Iranian government interests," researchers wrote in the blog.

Advertisement

The hacking campaign has targeted victims across the globe on an almost unprecedented scale, with a high degree of success.

The teams at FireEye tracked the activity for several months -- mapping and understanding the innovative tactics, techniques and procedures (TTPs) deployed by the attacker.

Advertisement

They also worked closely with victims, security organisations and law enforcement agencies where possible to reduce the impact of the attacks and/or prevent further compromises.

"While this campaign employs some traditional tactics, it is differentiated from other Iranian activity we have seen by leveraging DNS hijacking at scale. The attacker uses this technique for their initial foothold, which can then be exploited in a variety of ways," explained researchers.

Advertisement

A large number of organisations have been affected by this pattern of DNS record manipulation and fraudulent SSL (Secure Sockets Layer) certificates.

"They include telecoms and ISP providers, Internet infrastructure providers, government and sensitive commercial entities," said FireEye.

This type of attack is difficult to defend against, because valuable information can be stolen, even if an attacker is never able to get direct access to an organisation's network.

"Implement multi-factor authentication on your domain's administration portal, search for SSL certificates related to your domain and revoke any malicious certificates, conduct an internal investigation to assess if attackers gained access to your environment," suggested researchers.

 

For the latest tech news and reviews, follow Gadgets 360 on X, Facebook, WhatsApp, Threads and Google News. For the latest videos on gadgets and tech, subscribe to our YouTube channel. If you want to know everything about top influencers, follow our in-house Who'sThat360 on Instagram and YouTube.

Further reading: Iran, FireEye
Advertisement

Related Stories

Popular Mobile Brands
  1. Nothing Announces 'Now or Nothing' Sale in India: Check All Offers
  2. Vivo T4 Ultra Launched in India With 50-Megapixel Periscope Camera
  3. Google Releases Android 16 for Pixel Devices With These New Features
  4. Itel Zeno 5G With 50-Megapixel Rear Camera Launched in India: See Price
  5. Here's When the OnePlus Nord 5 and OnePlus Nord CE 5 Could Launch
  6. Android 16 Update Is Coming Soon - Here's What to Expect
  7. Eleven OTT Release Date Announced: Know Where to Watch This Tamil Crime Thriller
  8. Motorola Edge 60 With 5,500mAh Battery Launched in India: Price, Offers
  9. Nothing Phone 3 Leaked Render Suggests Design, Triple Rear Camera Unit
  1. OpenAI Releases o3-Pro Reasoning-Focused AI Model, Comes With Improved Capabilities and Tool Use
  2. Google's June 2025 Pixel Drop Brings AI Sticker Generation to Gboard, Pixel VIPs Widget and Camera Hints
  3. Nintendo Switch 2 Sets Record, Sells Over 3.5 Million Units in First Four Days of Launch
  4. Vivo T4 Ultra With MediaTek Dimensity 9300+ SoC, 50-Megapixel Periscope Camera Launched in India
  5. Android 16 QPR1 Beta 2 Update With Support for Connected Displays, Flexible Window Tiling Released
  6. Android 16 With Support for Live Activities, Advanced Protection Rolling Out for Pixel Devices
  7. Itel Zeno 5G With MediaTek Dimensity 6300 SoC, 50-Megapixel Rear Camera Launched in India
  8. OnePlus Nord 5, OnePlus Nord CE 5 Launch Date Leaked: Expected Specifications
  9. NASA Slightly Raises Odds of Asteroid Hitting the Moon in 2032 After Updated JWST Data
  10. James Webb Space Telescope Captures Stunning Near-Infrared View of Sombrero Galaxy
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.