Also known as: COBALT EDGEWATER
**Targets:** Lebanon, UAE
Executive Summary
DNSpionage is a nation-state threat actor linked to espionage activities targeting Lebanon and the UAE. The actor leverages spear-phishing, custom malware, and DNS-based command-and-control (C2) techniques to exfiltrate sensitive information. Their operations are associated with the 'Karkoff' campaign, utilizing a mix of hashes, domains, and stealthy infrastructure to avoid detection.
Goals & Targeting
DNSpionage's primary objective is espionage, targeting Lebanon and the UAE to gather intelligence on political, military, or economic interests. The choice of these regions suggests strategic intent to monitor Middle Eastern affairs, conduct cyber reconnaissance, or undermine regional stability. Typical victims likely include government agencies, diplomatic institutions, security organizations, and private entities with ties to sensitive national infrastructure. The actor's activities are consistent with nation-state objectives, focusing on long-term persistence and data exfiltration rather than immediate financial gain.
Enhanced Description
DNSpionage, also known as COBALT and EDGEWATER, is a sophisticated state-sponsored group focused on espionage against Lebanese and UAE targets. Their operations typically involve tailored phishing campaigns using malicious documents, followed by the deployment of custom malware to establish persistent access. The group heavily relies on DNS tunneling for C2 communications, using domains like coldfart.com and kuternull.com to mask traffic. Linked to the 'Karkoff' campaign, DNSpionage demonstrates a preference for stealth and operational security, often leveraging bulletproof hosting and staged infrastructure to evade attribution. While no specific sectors are explicitly named in the provided data, the targeting of Lebanon and the UAE suggests a focus on government, military, or critical infrastructure entities. The actor's use of a wide range of cryptographic hashes (SHA-256, SHA-1, MD5) indicates efforts to obfuscate malicious payloads and infrastructure.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
DNSpionage's 'Karkoff' campaign highlights a low-and-slow operational tempo, emphasizing stealth and long-term access. The actor frequently reuses infrastructure domains (e.g., rimrun.com, kuternull.com) and employs a variety of cryptographic hashes to avoid signature-based detection. Campaigns often target Lebanon and the UAE with no clear sector-specific focus, suggesting broad reconnaissance activities. The use of multiple hash types indicates a deliberate effort to evade analysis and attribution, pointing to a well-resourced, persistent threat actor.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Confidence in the linked IOCs (hashes, domains) and campaign association ('Karkoff') is high due to the volume of attributed indicators. However, gaps exist in the actor's full TTPs, software tools, and sector-specific targeting details. The lack of explicit sector information and limited public attribution reduce certainty about the actor's complete operational scope.
No techniques linked yet.
No tools linked yet.
No observed data linked yet.
No references recorded yet.
0
Techniques
0
Tools
1
Campaigns
19
IOCs
0
Observed Data
0
Tactics