Uptime Hamster: 10d 6h 38mDeploy: 14 Jul 2026 21:26Updated: 2026-07-21
Logo del actor de amenaza DNSpionage

DNSpionage

0 incidentes 0 paises 0 sectores apt IR Ultimo: -
Aliases: COBALT EDGEWATER, APT DNSPIONAGE
Ver en IntelTracker → APTTrail →
DNSpionage is a state-sponsored threat actor, assessed with high confidence to be of Iranian origin, that emerged in November 2018. The group's primary motivation is information theft and espionage, specifically targeting sensitive credentials and data from various government and private sector entities. What distinguishes DNSpionage is its extensive use of DNS hijacking at scale, where it manipulates DNS records to redirect victims to malicious sites, often employing valid Let's Encrypt certificates to evade detection. While DNSpionage is also known by the alias COBALT EDGEWATER, and has been associated with APT34 (OilRig) through infrastructure and malware overlaps, Cisco Talos has explicitly differentiated its campaigns from others like Sea Turtle.

Aliases del actor

COBALT EDGEWATERAPT DNSPIONAGE

Actores similares

apt-dnspionageactor · 1apt-45actor · 2apt-c-27actor · 2apt-c-01actor · 2apt-c-12actor · 1apt-18actor · 1apt-1877teamactor · 1apt-27actor · 1apt-30actor · 1apt-38actor · 1

Canales, DLS e infraestructura asociada

Clasificacion automatica desde IntelTracker/APTTrail/OSINT. Estado real solo si viene indicado por la fuente.

TipoEstadoHost / enlaceTitle / ultimo titulo
DLS / leak siteunknownblog.talosintelligence.comAPT DNSPIONAGE indicators and references
Repositoriounknowngithub.comAPT DNSPIONAGE indicators and references
DLS / leak siteunknownwww.virustotal.comAPT DNSPIONAGE indicators and references
DLS / leak siteunknownwww.virustotal.comAPT DNSPIONAGE indicators and references
Repositoriounknowngithub.comAPT DNSPIONAGE indicators and references
DLS / leak siteunknownraw.githubusercontent.comAPT DNSPIONAGE indicators and references
Repositoriounknownblog.talosintelligence.comAPT DNSPIONAGE indicators and references
Motivacion