ZeroSecurity - Information Security News
  • Home
  • Security
    • Exploits
    • Mobile Security
  • Malware
  • Breaches
  • Crypto
  • Privacy
  • Tech
    • AI
    • Downloads
      • Malwarebytes
      • Exploits
      • Paper Downloads
    • Reviews
No Result
View All Result
SUBSCRIBE
ZeroSecurity - Information Security News
  • Home
  • Security
    • Exploits
    • Mobile Security
  • Malware
  • Breaches
  • Crypto
  • Privacy
  • Tech
    • AI
    • Downloads
      • Malwarebytes
      • Exploits
      • Paper Downloads
    • Reviews
No Result
View All Result
ZeroSecurity - Information Security News
No Result
View All Result
Home Malware

State-sponsored Iranian Hackers utilize .NET DNS Backdoor in new Attack

Kyle by Kyle
June 12, 2022
in Malware, Security
Reading Time: 3 mins read
Lycaeum APT DNS hijacking backdoor
Share on FacebookShare on Twitter

An Advanced Persistent Threat (APT) hacking group based out of Iran going by the name Lycaeum has been seen using a .NET-based DNS backdoor to target organizations within the telecommunication and energy sectors Zscaler released in their report.

The APT group has been active since 2017 and has been known for targeting middle eastern organizations. But this group is now utilizing customized .NET-based malware, written in C#,  which utilizes copied code from a popular open-source tool.

The code was ripped from DIG.net which is a tool made for carrying out DNS hijacking attacks, as well as executing commands, dropping payloads, and snooping on data.

Key attack features:

  1. The new malware is a .NET-based DNS Backdoor which is basically a customized version of the open-source tool “DIG.net”.
  2. The malware leverages a DNS attack technique known as “DNS Hijacking” in which an attacker-controlled DNS server manipulates the response of DNS queries and resolves them as per their malicious requirements.
  3. The malware employs the DNS protocol for command and control (C2) communication which increases stealth and keeps the malware communication probes under the radar to evade detection.
  4. The technique allows for Uploading/Downloading files and execution of system commands on the infected machine by abusing DNS records, including TXT records for incoming commands and A records for data exfiltration.

Basically, the threat actors are able to manipulate DNS queries to redirect users to a clone of a website under the assailant’s control. Any info entered on this cloned site such as usernames and passwords will then be shown to the attackers.

One Word doc

The attack begins, like many we see today, with a malicious Microsoft Word doc containing a macro downloaded from a fake news website “http[:]//news-spot.live”.

Lycaeum .NET DNS backdoor
Malicious Microsoft Word macro, source – Zscaler

When the user enables the macro, the DNS backdoor is dropped to the user’s startup folder which is a technique utilized to start the malicious backdoor on every system startup.

.NET DNS backdoor startup folder
.NET DNS backdoor dropped to the startup folder, source Zscaler

A look at the new DNS Backdoor

The DNS backdoor is believed to be developed by the Lyceum Group. It has been widely used in their recent attack campaigns. As mentioned above, the backdoor is dropped and lives in the Startup folder of the infected system.

The backdoor’s executable name is set to “DnsSystem.exe” and the MD5 hash: 8199f14502e80581000bd5b3bda250ee.

You might also like

Hackers Exploit Maximum-Severity Cisco Zero-Day Bug Since 2023 (CVE-2026-20127)

How Hackers Still Manage to Compromise MFA

Anthropic Unveils Claude Code Security to Detect and Fix Critical Vulnerabilities

“The threat actors have customized and appended code that allows them to perform DNS queries for various records onto the custom DNS Server, parse the response of the query to execute system commands remotely, and upload/download files from the Command & Control server by leveraging the DNS protocol.” – Zscaler

The malware begins the DNS hijacking process by grabbing the IP address from a DNS site “http://cyberclub[.]one” and then generates a unique victim ID based on an MD5 hash generated from the victim’s Windows username.

DNS Malware Unique ID
How the malware generates a unique ID and resolves the DNS of cyberclub[.]one, source – Zscaler
The backdoor is also able to receive commands from the command and control server (C2) to execute on the victim’s computer. The responses from these commands are generated as TXT records and run through the Windows command prompt which is sent back to the attackers as a DNS A Record.

Backdoor command execution routine
The backdoor’s command execution routine, source – Zscaler

Who is the Lyceum APT group?

Lyceum is a team of hackers working on cyber espionage, and this new unique backdoor technique certainly is the mark of their progression in this field.

The Iranian hackers are anticipated to carry on engaging in these types of attack campaigns and are often involved with numerous threat groups from the country.

These APT threat actors are making a constant effort to evolve their tactics and strive to stay under the radar as long as possible. Despite how revolutionary this new backdoor technique is, there is still a need to enable macros within Word itself, which is an action that should rarely be taken.

Source: Zscaler Insights and Research
Tags: backdoordnshackersIranState-Sponsored
Previous Post

WatchDog’s new multi-stage cryptojacking attack unsurfaced

Next Post

$6 million Rewarded by Aurora Labs to Hacker who saved 70,000 ETH

Kyle

Kyle

Writer, and editor at ZeroSecurity. Interested in Information Security, the Blockchain, and an overall tech enthusiast. "Formal education will make you a living; self-education will make you a fortune." Contact me here: [email protected]

Recommended For You

Photo of the CISCO logo and text saying "You have been hacked!"

Hackers Exploit Maximum-Severity Cisco Zero-Day Bug Since 2023 (CVE-2026-20127)

March 6, 2026
How Hackers Still Manage to Compromise MFA

How Hackers Still Manage to Compromise MFA

March 6, 2026

Anthropic Unveils Claude Code Security to Detect and Fix Critical Vulnerabilities

February 22, 2026

Chinese Hackers Hijack Notepad++ Updates in 6-Month Supply Chain Campaign

February 6, 2026

Malicious Chrome Extensions Steal AI Data and Hijack Revenue in DarkSpectre Campaign

January 30, 2026

Phishing 2.0: How AI is Turning Cyber Attacks into a Science

January 7, 2025 - Updated on January 9, 2025

Related News

Malicious Chrome Extensions Steal AI Data and Hijack Revenue in DarkSpectre Campaign

Malicious Chrome Extensions Steal AI Data and Hijack Revenue in DarkSpectre Campaign

January 30, 2026
KPMG Netherlands Listed as Victim by Nova Ransomware Group

KPMG Netherlands Listed as Victim by Nova Ransomware Group

January 24, 2026
RansomHouse Claims Breach of Key Apple Assembler Luxshare

RansomHouse Claims Breach of Key Apple Assembler Luxshare

January 20, 2026
ZeroSecurity - Information Security News

We cover the latest in technology news, Crypto, Artificial Intelligence, and the threat trends impacting these sectors.

Categories

Piracy

Tutorials

Programming

Malware Analysis

Downloads

  • Contact us
  • Press
  • Writers
  • Privacy Policy
  • Terms of Service

© 2026 ZeroSecurity, All Rights Reserved.

No Result
View All Result
  • Home
  • Security
    • Tools
  • Exploits
  • Data Breaches
  • Malware
  • Privacy
  • Mobile Security
  • Contact Us
    • Press
  • Privacy Policy

© 2026 ZeroSecurity, All Rights Reserved.

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.