CyberSecurity SEE

Iranian VPN-over-DNS Activity Produces 40 Billion DNS Observations Amid Military Conflict

Iranian VPN-over-DNS Activity Produces 40 Billion DNS Observations Amid Military Conflict

Surge in Suspected Iranian VPN-over-DNS Activity Generates Unprecedented Data Observations

A recent investigation has revealed an alarming spike in suspected Iranian VPN-over-DNS activity, marked by a single domain that amassed a staggering 40 billion passive DNS observations in just a matter of days. This discovery, made public on October 9, 2026, highlights a considerable extension of digital infrastructure, involving more than 100 different domains amid ongoing military tensions. However, the exact nature of the operators, the content involved, and the overall intent behind this activity remain unverified.

The surge in this VPN-over-DNS activity commenced around 07:00 UTC on March 1, 2026, quickly accelerating by midday. Engineers from DomainTools, a company specializing in domain intelligence and monitoring, stumbled upon this extraordinary increase while investigating congestion within their intake servers. They traced the source of the processing backlog to a specific domain, named supaghost[.]cc, which generated up to 500,000 observations every second.

Typically, DomainTools processes and validates roughly one million DNS observations per second. The activity linked to this single domain thus led to an intake increase of nearly 50%, ultimately resulting in an accumulation of 40 billion observations. To manage the overwhelming traffic, engineers at DomainTools commenced filtering efforts to sift through this immense overload of data.

Most of the reported observations were associated with TXT records, which contained payload structures consistent with VPN-over-DNS transport mechanisms. This sophisticated technique leverages DNS queries and responses to facilitate bidirectional communications that cross network boundaries, allowing the repurposing of name-resolution systems to serve as a covert data transportation channel.

TXT records can transmit arbitrary data, a feature that, when coupled with algorithmically generated subdomain labels, provides an additional avenue for information exchange. Ian Campbell, a researcher in the field, indicated that the observed TXT payloads likely encapsulated multiple binary packets that were multiplexed together for enhanced operational efficiency. In this scenario, the exit node would decode the traffic and redirect it accordingly. However, it is important to note that DomainTools did not decrypt the observed data, making such interpretations of packet handling speculative rather than definitive insights into the content or communications.

Further investigation into delegation patterns provided additional insights into bidirectional tunneling capabilities. A noteworthy third-level label, slsa1.supaghost[.]cc, delegated traffic to sa1.supaghost[.]cc, and this delegation pattern extended through slsa6. The nameservers typically resolved to a series of inexpensive virtual private servers, a fact that DomainTools noted were often shielded by Cloudflare, indicating that the traffic was likely distributed across multiple endpoints.

In the following period, this VPN-over-DNS activity proliferated across over 100 different domains, with Iran’s country-code domain, .ir, notably overrepresented. Most of these domains had been registered between September and November 2025 but had remained inactive until showcasing similar spikes in activity during the observed period in March. While several of these domains came close to matching the throughput of the original domain, none could individually replicate its peak performance.

The surge in activity didn’t just stop at these newly registered domains; established DNS tunneling services across Eurasia and South Asia also experienced intensified movements. DomainTools noted that this escalation closely followed the commencement of a U.S.-Israeli bombing campaign, occurring roughly 24 hours after the military operations began. However, external indicators suggesting the origins of this traffic seemed to point towards locations within or near Iran, although timing alone could not confirm attribution.

Campbell suggested several potential explanations for this surge, including the possibility of emergency offsite backup activities. Nevertheless, he cautioned that any assertions linking this activity to operations of the Iranian regime or nuclear program data transfers were unsubstantiated, existing purely in the realm of speculation.

It’s crucial to understand that the reported figure of 40 billion refers to passive DNS observations and does not reflect unique files, decoded packets, or any quantified stolen data. DomainTools began sharing these observations discreetly in March, aiming to prompt corroboration from other organizations possessing visibility into similar activities, thereby promoting a collaborative effort to analyze and understand the implications of this alarming trend in cybersecurity.

Source link

Exit mobile version