Finding Additional Indicators With a SeaTurtle Deep Dive in Passive DNS Within DomainTools Iris
ID: f235b78e-63f4-556d-8981-6d71960ef140
STIX ID: report--f235b78e-63f4-556d-8981-6d71960ef140
Feed Name: DomainTools
This report examines the SeaTurtle DNS hijacking campaign, detailing how attackers compromised tertiary DNS vendors to steal signing certificates and flip NS/A records to actor-controlled nameservers and man-in-the-middle servers. Using passive DNS and DomainTools Iris data the authors expand Cisco Talos IoCs, listing additional malicious nameservers, domains, and IPs used across many governments and infrastructure providers, and recommend DNS monitoring, DNSSEC, and MFA to mitigate such attacks.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
