DNSpionage
Aliases: Agent Drable, AgentDrable, Webmask
- First seen
- 2018-11-26 00:00:00
- Malware type
- spyware, trojan
- Family
- Malware family
- Profile updated
- 2026-07-07 12:54:04
Targeted industries: government-and-public-sector energy-and-utilities
Targeted regions: country_code:lb country_code:ae
Context
DNSpionage is a cyber-espionage malware primarily used for conducting surveillance and exfiltrating data. It is known for abusing DNS communications to stealthily relay information while targeting government and energy sectors, particularly in the Middle East.
Detection coverage
- 1 YARA rules
Detection rules
- MALPEDIA_Win_Dnspionage_Auto (yara-rule)
Reports & references
- pwc.co.uk — Cyber Threats 2019 Retrospect (report)
- Cisco Talos — Dnspionage Campaign Targets Middle East (report)
- Cisco Talos — Dnspionage Brings Out Karkoff (report)
- Mandiant — Global Dns Hijacking Campaign Dns Record Manipulation At Scale (report)
- secureworks.com — Cobalt Edgewater (report)
- lastline.com — Threat Actor Cold River Network Traffic Analysis And A Deep Dive On Agent Drable (report)
- Mandiant — Global Dns Hijacking Campaign Dns Record Manipulation At Scale (report)
- virusbulletin.com — Vb2019 Mercer Rascagneres (report)
- youtube.com — Watch (report)
- research.checkpoint.com — Irans Apt34 Returns With An Updated Arsenal (report)
- ti.qianxin.com — Cb78386A082F465F259B37Dae5Df4884 (report)
- zdnet.com — Source Code Of Iranian Cyber Espionage Tools Leaked On Telegram (report)
- nsfocusglobal.com — Apt34 Event Analysis Report (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Dnspionage (report)
- blog-cert.opmd.fr — Dnspionage Focus On Internal Actions (report)
- us-cert.gov — Aa19 024A (report)
- marcoramilli.com — Apt34 Webmask Project (report)