Saturday, May 31, 2025
HomeComputer SecurityDNS Hijacking Campaign Targeting Various Organizations Around the Globe

DNS Hijacking Campaign Targeting Various Organizations Around the Globe

Published on

SIEM as a Service

Follow Us on Google News

A new wave of DNS Hijacking campaign targeting various domains organizations belonging to various government, telecommunications and internet infrastructure entities.

The campaign has targeted victims across the globe at an unprecedented scale at a high degree of success rate. Security researchers from FireEye tracked the activity for several months and the attackers explotiting it with high degree of success.

DNS hijacking is a type of Malicious attack that used to redirect the users to the malicious website when they visit the website via compromised routers or attackers modifying a server’s settings.

- Advertisement - Google News

According to researchers the campaign is active from January 2017 to January 2019 and the attack not carried out by a single actor based on the timeframes, infrastructure, and service providers.

“Technical evidence shows that attack carried out by threat actors in Iran and the entities targeted and the activity aligns with Iranian government interests.”

DNS Hijacking Campaign

Threat actors followed multiple techniques to manipulate the DNS records.

With the first method attackers log in with the DNS provider’s administration panel and attackers points the A record IP of the domain top a different IP address. Then attackers uses Let’s Encrypt certificate to establish a secure connection without any certificate errors.

In the second method attackers gained access to the server and they will change the nameserver details and implement proxies to listen all the ports.

Third technique involves DNS Redirector which responds to DNS requests, with the previously modified A and NS records to redirect victim’s traffic to the servers controlled by attackers.

Researchers said a number of the organization affected with the patterns of DNS record manipulations and fraudulent SSL certificates.

You can follow us on LinkedinTwitterFacebook for daily Cybersecurity updates also you can take the Best Cybersecurity courses online to keep your self-updated.

Cloudflare Announced Internet’s Fastest DNS Service 1.1.1.1 that Extremely Focus on Consumer Privacy

New Phishing Attack Taking Advantages of Vulnerability in Office 365 to Bypass all of Microsoft’s Security

Gurubaran
Gurubaran
Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

Latest articles

Attackers Exploit Microsoft Entra Billing Roles to Escalate Privileges in Organizational Environments

A startling discovery by BeyondTrust researchers has unveiled a critical vulnerability in Microsoft Entra...

Threat Actors Exploit Google Apps Script to Host Phishing Sites

The Cofense Phishing Defense Center has uncovered a highly strategic phishing campaign that leverages...

Dadsec Hacker Group Uses Tycoon2FA Infrastructure to Steal Office365 Credentials

Cybersecurity researchers from Trustwave’s Threat Intelligence Team have uncovered a large-scale phishing campaign orchestrated...

Beware: Weaponized AI Tool Installers Infect Devices with Ransomware

Cisco Talos has uncovered a series of malicious threats masquerading as legitimate AI tool...

Resilience at Scale

Why Application Security is Non-Negotiable

The resilience of your digital infrastructure directly impacts your ability to scale. And yet, application security remains a critical weak link for most organizations.

Application Security is no longer just a defensive play—it’s the cornerstone of cyber resilience and sustainable growth. In this webinar, Karthik Krishnamoorthy (CTO of Indusface) and Phani Deepak Akella (VP of Marketing – Indusface), will share how AI-powered application security can help organizations build resilience by

Discussion points


Protecting at internet scale using AI and behavioral-based DDoS & bot mitigation.
Autonomously discovering external assets and remediating vulnerabilities within 72 hours, enabling secure, confident scaling.
Ensuring 100% application availability through platforms architected for failure resilience.
Eliminating silos with real-time correlation between attack surface and active threats for rapid, accurate mitigation

More like this

Attackers Exploit Microsoft Entra Billing Roles to Escalate Privileges in Organizational Environments

A startling discovery by BeyondTrust researchers has unveiled a critical vulnerability in Microsoft Entra...

Threat Actors Exploit Google Apps Script to Host Phishing Sites

The Cofense Phishing Defense Center has uncovered a highly strategic phishing campaign that leverages...

Dadsec Hacker Group Uses Tycoon2FA Infrastructure to Steal Office365 Credentials

Cybersecurity researchers from Trustwave’s Threat Intelligence Team have uncovered a large-scale phishing campaign orchestrated...