Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors DNSpionage

Also known as: COBALT EDGEWATER

Description

**Targets:** Lebanon, UAE

AI Analysis

· 1 week ago

Executive Summary

DNSpionage is a nation-state threat actor linked to espionage activities targeting Lebanon and the UAE. The actor leverages spear-phishing, custom malware, and DNS-based command-and-control (C2) techniques to exfiltrate sensitive information. Their operations are associated with the 'Karkoff' campaign, utilizing a mix of hashes, domains, and stealthy infrastructure to avoid detection.

Goals & Targeting

DNSpionage's primary objective is espionage, targeting Lebanon and the UAE to gather intelligence on political, military, or economic interests. The choice of these regions suggests strategic intent to monitor Middle Eastern affairs, conduct cyber reconnaissance, or undermine regional stability. Typical victims likely include government agencies, diplomatic institutions, security organizations, and private entities with ties to sensitive national infrastructure. The actor's activities are consistent with nation-state objectives, focusing on long-term persistence and data exfiltration rather than immediate financial gain.

Enhanced Description

DNSpionage, also known as COBALT and EDGEWATER, is a sophisticated state-sponsored group focused on espionage against Lebanese and UAE targets. Their operations typically involve tailored phishing campaigns using malicious documents, followed by the deployment of custom malware to establish persistent access. The group heavily relies on DNS tunneling for C2 communications, using domains like coldfart.com and kuternull.com to mask traffic. Linked to the 'Karkoff' campaign, DNSpionage demonstrates a preference for stealth and operational security, often leveraging bulletproof hosting and staged infrastructure to evade attribution. While no specific sectors are explicitly named in the provided data, the targeting of Lebanon and the UAE suggests a focus on government, military, or critical infrastructure entities. The actor's use of a wide range of cryptographic hashes (SHA-256, SHA-1, MD5) indicates efforts to obfuscate malicious payloads and infrastructure.

Key Capabilities

  • Spear-phishing with macro-laced Office documents
  • DNS tunneling for covert C2 communications
  • Custom malware deployment for persistence and data exfiltration
  • Use of bulletproof hosting and staging infrastructure
  • Leveraging cryptographic hash obfuscation (SHA-256, SHA-1, MD5) for payload delivery

MITRE ATT&CK Tactics

Initial Access
Execution
Persistence
Exfiltration
Command and Control

ATT&CK Techniques

T1059.003 (DNS Tunneling)
T1055 (Custom Command and Control)
T1204.001 (User Execution via Malicious Documents)
T1566.001 (Phishing)
T1040 (Exfiltration over Existing Communication Channels)

Software / Tooling

Karkoff (linked campaign malware)
Custom RAT (Remote Access Trojan)
Malicious Office documents with embedded macros

Campaigns & Victims

DNSpionage's 'Karkoff' campaign highlights a low-and-slow operational tempo, emphasizing stealth and long-term access. The actor frequently reuses infrastructure domains (e.g., rimrun.com, kuternull.com) and employs a variety of cryptographic hashes to avoid signature-based detection. Campaigns often target Lebanon and the UAE with no clear sector-specific focus, suggesting broad reconnaissance activities. The use of multiple hash types indicates a deliberate effort to evade analysis and attribution, pointing to a well-resourced, persistent threat actor.

IOC Patterns

  • Spear-phishing with macro-laced Office documents
  • C2 over DNS using fast-flux domains (e.g., coldfart.com, kuternull.com)
  • Staging infrastructure on bulletproof hosting
  • Cryptographic hash obfuscation (SHA-256, SHA-1, MD5) for payloads

Recommended Actions

  • Implement DNS monitoring and anomaly detection for tunneling activity
  • Conduct regular phishing simulations and employee training to mitigate document-based attacks
  • Analyze hash values (SHA-256, SHA-1, MD5) against threat intelligence feeds
  • Deploy network traffic analysis tools to detect encrypted C2 traffic
  • Block known malicious domains (e.g., coldfart.com, rimrun.com) at the perimeter

Suggested Tags

APT
espionage
nation-state
Middle East
DNS tunneling

Confidence Assessment

Confidence in the linked IOCs (hashes, domains) and campaign association ('Karkoff') is high due to the volume of attributed indicators. However, gaps exist in the actor's full TTPs, software tools, and sector-specific targeting details. The lack of explicit sector information and limited public attribution reduce certainty about the actor's complete operational scope.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

SHA-1 Hash 5 MD5 Hash 5 SHA-256 Hash 6 Domain 3

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

1

Campaigns

19

IOCs

0

Observed Data

0

Tactics

Tags

APT
espionage
nation-state
Middle East
DNS tunneling

Details

Type
Nation-State
Resource Level
Government
Primary Motivation
Espionage
Country of Origin
Iran (IR)
Confidence
70%
Added
May 4, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.