DNSpionage: When the registrar becomes the attack path
Summary
Brian Krebs reconstructs an espionage campaign that manipulated registrar accounts and DNS records to intercept the email and VPN access of numerous organisations. Netnod confirmed that its registrar account had been compromised. The attackers obtained certificates for manipulated mail destinations.
Ideas
- Stolen registrar credentials can bypass all downstream security controls.
- Manipulated DNS records quietly redirect mail and VPN traffic to attackers.
- Control of a domain gives attackers seemingly valid TLS certificates.
- Short redirections are enough to collect many valuable credentials.
- DNSSEC only limits manipulation if name resolution validates trust without gaps.
- Captive portals can push devices out of a protected DNS configuration.
Insights
- Domain management is part of every organisation’s security boundary.
- Valid encryption does not prove that the endpoint reached is legitimate.
- Exceptional mobile situations can undermine otherwise strong infrastructure controls.
Quotes
The two people who did get popped, both were traveling.
– Bill Woodcock
Habits
- Krebs correlates public attack indicators with interviews with affected infrastructure operators.
Facts
- At PCH, DNSSEC blocked most of the attack described.
References
- Brian Krebs: A Deep Dive on the Recent Widespread DNS Hijacking Attacks
- Cisco Talos: DNSpionage.
- FireEye and CrowdStrike: technical indicators of the campaign.
- Netnod and Packet Clearing House: affected infrastructure operators.
Critique
- The attribution at the time was based on indicators and remained politically disputed.
- DNSSEC helped in the case described but does not prevent a compromised authoritative operator.
Remarks
- The article treats domains as critical infrastructure rather than mere marketing addresses.
- Certificate transparency provides an additional layer for detecting unwanted issuances.
Recommendations
- Secure registrar access with a hardware factor and separate administrator accounts.
- Monitor DNS changes and Certificate Transparency logs continuously.
- Test mobile clients behind captive portals for DNS and certificate deviations.
Links to the original source and the Web Archive open in a new tab.