{"id":24292,"date":"2019-01-10T14:04:05","date_gmt":"2019-01-10T14:04:05","guid":{"rendered":"https:\/\/www.threatshub.org\/blog\/baddies-linked-to-iran-fingered-for-dns-hijacking-to-read-middle-eastern-regimes-emails\/"},"modified":"2019-01-10T14:04:05","modified_gmt":"2019-01-10T14:04:05","slug":"baddies-linked-to-iran-fingered-for-dns-hijacking-to-read-middle-eastern-regimes-emails","status":"publish","type":"post","link":"https:\/\/www.threatshub.org\/blog\/baddies-linked-to-iran-fingered-for-dns-hijacking-to-read-middle-eastern-regimes-emails\/","title":{"rendered":"Baddies linked to Iran fingered for DNS hijacking to read Middle Eastern regimes&#8217; emails"},"content":{"rendered":"<p>Infosec biz FireEye has suggested Iran may be responsible for what it claims are DNS hijacking attacks aimed at snooping on the contents of Middle Eastern governments&#8217; email inboxes.<\/p>\n<div class=\"promo_article\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/regmedia.co.uk\/2018\/04\/12\/shutterstock_vladimir_putin.jpg?x=174&amp;y=115&amp;crop=1\" width=\"174\" height=\"115\" alt=\"illustration showing russian president vladimir putin winking\"\/><\/p>\n<h2 title=\"FireEye reckons it's fingered the miscreants behind nasty cyber-infection at industrial complex\">That Saudi oil and gas plant that got hacked. You&#8217;ll never guess who could&#8230; OK, it&#8217;s Russia<\/h2>\n<p><a href=\"https:\/\/www.theregister.co.uk\/2018\/10\/24\/triton_malware_attack\/\"><span>READ MORE<\/span><\/a><\/div>\n<p>The firm&#8217;s incident response and intelligence teams said they had spotted miscreants logging into <code>pxy1<\/code>, described as &#8220;a proxy box used to conduct non-attributed browsing and as a jumpbox to other infrastructure&#8221;.<\/p>\n<p>From there they were seen to use previously stolen DNS admin creds to change basic DNS A records to point to IP addresses the bad actors controlled, establishing a man-in-the-middle setup. The researchers said the crew used a load balancer to ensure the technique passed through genuine web traffic, helping keep it invisible to users.<\/p>\n<p>A Let&#8217;s Encrypt free SSL certificate was used to get around any problems with mismatched certificates in the instances highlighted by FireEye. The company did point out that it had also seen &#8220;multiple Domain Control Validation providers being utilised as part of this campaign&#8221; so that particular part of the attack is not solely dependent upon Let&#8217;s Encrypt certs.<\/p>\n<p>Fireeye said it had also watched the manipulators using broadly similar techniques to fiddle with DNS nameservers, with the same ultimate aim of getting their hands on the contents of targets&#8217; email inboxes.<\/p>\n<p>&#8220;While we do not currently link this activity to any tracked group, initial research suggests the actor or actors responsible have a nexus to Iran,&#8221; mused FireEye in its <a target=\"_blank\" rel=\"nofollow\" href=\"https:\/\/www.fireeye.com\/blog\/threat-research\/2019\/01\/global-dns-hijacking-campaign-dns-record-manipulation-at-scale.html\">blog post<\/a> about the research.<\/p>\n<p>The firm said that while it &#8220;suggested&#8221; people in Iran were involved with &#8220;moderate confidence&#8221;, based on geolocation of IP addresses, the attack techniques &#8220;may not be exclusive to a single threat actor as the activity spans disparate timeframes, infrastructure, and service providers&#8221;.<\/p>\n<p>It also noted that &#8220;the activity aligns with Iranian government interests&#8221;.<\/p>\n<p>Those same IPs, however, &#8220;were previously observed during the response to an intrusion attributed to Iranian cyber espionage actors&#8221;.<\/p>\n<p>Iran, like other pariah states throughout the world, has some capable cyber-folk working for it. Back in August last year a potential BGP hack <a target=\"_blank\" href=\"https:\/\/www.theregister.co.uk\/2018\/08\/01\/bgp_route_leak_telegram_iran\/\">routed messages from chat app Telegram through Iran<\/a>, while a <a target=\"_blank\" href=\"https:\/\/www.theregister.co.uk\/2018\/11\/02\/iran_cracked_cia_google\/\">staggering failure of basic opsec techniques helped Iranian counter-espionage units round up and neutralise American spies<\/a> operating in their country \u2013 all thanks to a Google search. \u00ae<\/p>\n<p>READ MORE <a href=\"http:\/\/go.theregister.com\/feed\/www.theregister.co.uk\/2019\/01\/10\/fireeye_iran_dns_hijacking\/\">HERE<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>&#8216;Almost unprecedented&#8217; attacks use the old man-in-the-middle diddle \u2013 infoseccers Infosec biz FireEye has suggested Iran may be responsible for what it claims are DNS hijacking attacks aimed at snooping on the contents of Middle Eastern governments&#8217; email inboxes.\u2026 READ MORE HERE&#8230;<\/p>\n","protected":false},"author":2,"featured_media":24293,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"colormag_page_layout":"default_layout","footnotes":""},"categories":[63],"tags":[],"class_list":["post-24292","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-the-register"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.8 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Baddies linked to Iran fingered for DNS hijacking to read Middle Eastern regimes&#039; emails 2026 | ThreatsHub Cybersecurity News<\/title>\n<meta name=\"description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.threatshub.org\/blog\/baddies-linked-to-iran-fingered-for-dns-hijacking-to-read-middle-eastern-regimes-emails\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Baddies linked to Iran fingered for DNS hijacking to read Middle Eastern regimes&#039; emails 2026 | ThreatsHub Cybersecurity News\" \/>\n<meta property=\"og:description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.threatshub.org\/blog\/baddies-linked-to-iran-fingered-for-dns-hijacking-to-read-middle-eastern-regimes-emails\/\" \/>\n<meta property=\"og:site_name\" content=\"ThreatsHub Cybersecurity News\" \/>\n<meta property=\"article:published_time\" content=\"2019-01-10T14:04:05+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2019\/01\/baddies-linked-to-iran-fingered-for-dns-hijacking-to-read-middle-eastern-regimes-emails.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"174\" \/>\n\t<meta property=\"og:image:height\" content=\"115\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"TH Author\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@threatshub\" \/>\n<meta name=\"twitter:site\" content=\"@threatshub\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"TH Author\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"2 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/baddies-linked-to-iran-fingered-for-dns-hijacking-to-read-middle-eastern-regimes-emails\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/baddies-linked-to-iran-fingered-for-dns-hijacking-to-read-middle-eastern-regimes-emails\\\/\"},\"author\":{\"name\":\"TH Author\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\"},\"headline\":\"Baddies linked to Iran fingered for DNS hijacking to read Middle Eastern regimes&#8217; emails\",\"datePublished\":\"2019-01-10T14:04:05+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/baddies-linked-to-iran-fingered-for-dns-hijacking-to-read-middle-eastern-regimes-emails\\\/\"},\"wordCount\":415,\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/baddies-linked-to-iran-fingered-for-dns-hijacking-to-read-middle-eastern-regimes-emails\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2019\\\/01\\\/baddies-linked-to-iran-fingered-for-dns-hijacking-to-read-middle-eastern-regimes-emails.jpg\",\"articleSection\":[\"The Register\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/baddies-linked-to-iran-fingered-for-dns-hijacking-to-read-middle-eastern-regimes-emails\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/baddies-linked-to-iran-fingered-for-dns-hijacking-to-read-middle-eastern-regimes-emails\\\/\",\"name\":\"Baddies linked to Iran fingered for DNS hijacking to read Middle Eastern regimes' emails 2026 | ThreatsHub Cybersecurity News\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/baddies-linked-to-iran-fingered-for-dns-hijacking-to-read-middle-eastern-regimes-emails\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/baddies-linked-to-iran-fingered-for-dns-hijacking-to-read-middle-eastern-regimes-emails\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2019\\\/01\\\/baddies-linked-to-iran-fingered-for-dns-hijacking-to-read-middle-eastern-regimes-emails.jpg\",\"datePublished\":\"2019-01-10T14:04:05+00:00\",\"description\":\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/baddies-linked-to-iran-fingered-for-dns-hijacking-to-read-middle-eastern-regimes-emails\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/baddies-linked-to-iran-fingered-for-dns-hijacking-to-read-middle-eastern-regimes-emails\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/baddies-linked-to-iran-fingered-for-dns-hijacking-to-read-middle-eastern-regimes-emails\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2019\\\/01\\\/baddies-linked-to-iran-fingered-for-dns-hijacking-to-read-middle-eastern-regimes-emails.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2019\\\/01\\\/baddies-linked-to-iran-fingered-for-dns-hijacking-to-read-middle-eastern-regimes-emails.jpg\",\"width\":174,\"height\":115},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/baddies-linked-to-iran-fingered-for-dns-hijacking-to-read-middle-eastern-regimes-emails\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Baddies linked to Iran fingered for DNS hijacking to read Middle Eastern regimes&#8217; emails\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"name\":\"ThreatsHub Cybersecurity News\",\"description\":\"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"alternateName\":\"Threatshub.org\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\",\"name\":\"ThreatsHub.org\",\"alternateName\":\"Threatshub.org\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"width\":432,\"height\":435,\"caption\":\"ThreatsHub.org\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/threatshub\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\",\"name\":\"TH Author\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"caption\":\"TH Author\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Baddies linked to Iran fingered for DNS hijacking to read Middle Eastern regimes' emails 2026 | ThreatsHub Cybersecurity News","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.threatshub.org\/blog\/baddies-linked-to-iran-fingered-for-dns-hijacking-to-read-middle-eastern-regimes-emails\/","og_locale":"en_US","og_type":"article","og_title":"Baddies linked to Iran fingered for DNS hijacking to read Middle Eastern regimes' emails 2026 | ThreatsHub Cybersecurity News","og_description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","og_url":"https:\/\/www.threatshub.org\/blog\/baddies-linked-to-iran-fingered-for-dns-hijacking-to-read-middle-eastern-regimes-emails\/","og_site_name":"ThreatsHub Cybersecurity News","article_published_time":"2019-01-10T14:04:05+00:00","og_image":[{"width":174,"height":115,"url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2019\/01\/baddies-linked-to-iran-fingered-for-dns-hijacking-to-read-middle-eastern-regimes-emails.jpg","type":"image\/jpeg"}],"author":"TH Author","twitter_card":"summary_large_image","twitter_creator":"@threatshub","twitter_site":"@threatshub","twitter_misc":{"Written by":"TH Author","Est. reading time":"2 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.threatshub.org\/blog\/baddies-linked-to-iran-fingered-for-dns-hijacking-to-read-middle-eastern-regimes-emails\/#article","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/baddies-linked-to-iran-fingered-for-dns-hijacking-to-read-middle-eastern-regimes-emails\/"},"author":{"name":"TH Author","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476"},"headline":"Baddies linked to Iran fingered for DNS hijacking to read Middle Eastern regimes&#8217; emails","datePublished":"2019-01-10T14:04:05+00:00","mainEntityOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/baddies-linked-to-iran-fingered-for-dns-hijacking-to-read-middle-eastern-regimes-emails\/"},"wordCount":415,"publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/baddies-linked-to-iran-fingered-for-dns-hijacking-to-read-middle-eastern-regimes-emails\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2019\/01\/baddies-linked-to-iran-fingered-for-dns-hijacking-to-read-middle-eastern-regimes-emails.jpg","articleSection":["The Register"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.threatshub.org\/blog\/baddies-linked-to-iran-fingered-for-dns-hijacking-to-read-middle-eastern-regimes-emails\/","url":"https:\/\/www.threatshub.org\/blog\/baddies-linked-to-iran-fingered-for-dns-hijacking-to-read-middle-eastern-regimes-emails\/","name":"Baddies linked to Iran fingered for DNS hijacking to read Middle Eastern regimes' emails 2026 | ThreatsHub Cybersecurity News","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/baddies-linked-to-iran-fingered-for-dns-hijacking-to-read-middle-eastern-regimes-emails\/#primaryimage"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/baddies-linked-to-iran-fingered-for-dns-hijacking-to-read-middle-eastern-regimes-emails\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2019\/01\/baddies-linked-to-iran-fingered-for-dns-hijacking-to-read-middle-eastern-regimes-emails.jpg","datePublished":"2019-01-10T14:04:05+00:00","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","breadcrumb":{"@id":"https:\/\/www.threatshub.org\/blog\/baddies-linked-to-iran-fingered-for-dns-hijacking-to-read-middle-eastern-regimes-emails\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.threatshub.org\/blog\/baddies-linked-to-iran-fingered-for-dns-hijacking-to-read-middle-eastern-regimes-emails\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/baddies-linked-to-iran-fingered-for-dns-hijacking-to-read-middle-eastern-regimes-emails\/#primaryimage","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2019\/01\/baddies-linked-to-iran-fingered-for-dns-hijacking-to-read-middle-eastern-regimes-emails.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2019\/01\/baddies-linked-to-iran-fingered-for-dns-hijacking-to-read-middle-eastern-regimes-emails.jpg","width":174,"height":115},{"@type":"BreadcrumbList","@id":"https:\/\/www.threatshub.org\/blog\/baddies-linked-to-iran-fingered-for-dns-hijacking-to-read-middle-eastern-regimes-emails\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.threatshub.org\/blog\/"},{"@type":"ListItem","position":2,"name":"Baddies linked to Iran fingered for DNS hijacking to read Middle Eastern regimes&#8217; emails"}]},{"@type":"WebSite","@id":"https:\/\/www.threatshub.org\/blog\/#website","url":"https:\/\/www.threatshub.org\/blog\/","name":"ThreatsHub Cybersecurity News","description":"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform","publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"alternateName":"Threatshub.org","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.threatshub.org\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.threatshub.org\/blog\/#organization","name":"ThreatsHub.org","alternateName":"Threatshub.org","url":"https:\/\/www.threatshub.org\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","width":432,"height":435,"caption":"ThreatsHub.org"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/threatshub"]},{"@type":"Person","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476","name":"TH Author","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","caption":"TH Author"}}]}},"_links":{"self":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/24292","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/comments?post=24292"}],"version-history":[{"count":0,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/24292\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media\/24293"}],"wp:attachment":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media?parent=24292"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/categories?post=24292"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/tags?post=24292"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}