DNSpionage

Aliases: Agent Drable, AgentDrable, Webmask

First seen
2018-11-26 00:00:00
Malware type
spyware, trojan
Family
Malware family
Profile updated
2026-07-07 12:54:04

Targeted industries: government-and-public-sector energy-and-utilities

Targeted regions: country_code:lb country_code:ae

Context

DNSpionage is a cyber-espionage malware primarily used for conducting surveillance and exfiltrating data. It is known for abusing DNS communications to stealthily relay information while targeting government and energy sectors, particularly in the Middle East.

Detection coverage

  • 1 YARA rules

Detection rules

  • MALPEDIA_Win_Dnspionage_Auto (yara-rule)

Reports & references

  • pwc.co.uk — Cyber Threats 2019 Retrospect (report)
  • Cisco Talos — Dnspionage Campaign Targets Middle East (report)
  • Cisco Talos — Dnspionage Brings Out Karkoff (report)
  • Mandiant — Global Dns Hijacking Campaign Dns Record Manipulation At Scale (report)
  • secureworks.com — Cobalt Edgewater (report)
  • lastline.com — Threat Actor Cold River Network Traffic Analysis And A Deep Dive On Agent Drable (report)
  • Mandiant — Global Dns Hijacking Campaign Dns Record Manipulation At Scale (report)
  • virusbulletin.com — Vb2019 Mercer Rascagneres (report)
  • youtube.com — Watch (report)
  • research.checkpoint.com — Irans Apt34 Returns With An Updated Arsenal (report)
  • ti.qianxin.com — Cb78386A082F465F259B37Dae5Df4884 (report)
  • zdnet.com — Source Code Of Iranian Cyber Espionage Tools Leaked On Telegram (report)
  • nsfocusglobal.com — Apt34 Event Analysis Report (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Dnspionage (report)
  • blog-cert.opmd.fr — Dnspionage Focus On Internal Actions (report)
  • us-cert.gov — Aa19 024A (report)
  • marcoramilli.com — Apt34 Webmask Project (report)

External references