Iranian APT hackers from the group known as “Oilrig”are the first to incorporate the DNS-over-HTTPS (DoH) protocol into attacks . Vincente Diaz, a malware analyst at antivirus company Kaspersky, said in a webinar held last week that this change was observed in May, when Oilrig added the DNS-over-HTTPS (DoH) protocol to its arsenal to enhance its attacks.
According to Diaz, Iranian APT hackers from “Oilrig” have started using a new tool, DNSExfiltrator, in their intrusions into compromised networks. DNSExfiltrator is an open-source project available on GitHub that creates secret communication channels by routing data and hiding it in non-standard protocols. This tool can transfer data between two points using standard DNS requests, and it can also use the newer DoH protocol. Diaz also reported that the Oilrig group, also known as APT34, uses DNSExfiltrator to transfer data to internal networks and then transfer it to an external point.

Also, Oilrig is likely using DoH as an exfiltration channel to avoid detection or monitoring of its activities while transferring stolen data. This is because the DoH protocol is an ideal exfiltration channel for two reasons. First , it is a new protocol that not all security products can monitor . Second , it is encrypted by default, while DNS is clear text.
The fact that Oilrig was one of the first APT (Advanced Persistent Threats) groups – a term used to describe government hacking groups – to incorporate DoH into its attacks is not surprising. Historically, the group has dabbled in DNS-based exfiltration techniques. Before adopting the open-source DNSExfiltrator toolkit in May, the group had been using a custom tool called DNSpionage since at least 2018, as Talos, NSFOCUS, and Palo Alto Networks have all noted in related reports.

Additionally, in the May campaign, Kaspersky noted that Oilrig removed data via DoH on domains related to the COVID-19 pandemic . That same month, Reuters reported a phishing campaign orchestrated by unknown Iranian hackers that targeted employees of pharmaceutical giant Gilead , which had announced at the time that it had begun working on a treatment and vaccine for COVID-19. However, it is unclear whether these are the same incidents. Previous reports have linked most Iranian APT groups to the Islamic Revolutionary Guard Corps (IRGC) , Iran ’s top military entity .

Oilrig is not only the first APT group known to use DoH, but also the first to do so in general. Godlua, a Lua-based Linux malware strain, was the first to use DoH as part of its DDoS botnet in July 2019, according to a report by Netlab, a network threat intelligence firm for Chinese cybersecurity giant Qihoo 360.
