Threat Intelligence Tarot
Vol. II · 123
Iran-suspected
G0079★★★★★
risk 3/5
✦ The Many-Headed Whisper ✦
DarkHydrus
LazyMeerkat-adjacent
Middle East governmentEducational institutionsEnergy sector
Active since ~2016 · Espionage, Regional surveillance
The Many-Headed Whisper does not hiss in private — it whispers through public DNS, the most-watched and least-suspected channel. Severing one head only reveals two more.
Tactics & Techniques
RCN
RDV
INI
EXC
PRS
PRV
EVA
CRD
DSC
LAT
COL
C2
EXF
IMP
Notable Operations
- ◆RogueRobin DNS-based PowerShell trojan
- ◆Phishery toolkit-based credential harvesting
- ◆Middle East government targeting via document lures
- ◆Educational institution spear-phishing campaigns (Palo Alto Unit 42 disclosure)
Defenses
- ▸DNS traffic analysis with anomaly detection on TXT and lengthy subdomainsNIST CSF: DE.CM ↗
- ▸Internal DNS resolvers with external query blockingCIS Control 9 ↗
- ▸Phishing-resistant MFA for academic and government usersNIST SP 800-63B ↗
- ▸PowerShell constrained language mode for non-admin usersCIS Control 8 ↗
Reversed: Their Weakness
DNS-layer detection and corporate DNS filtering remove this operator's preferred carrier. A whisper without a channel is just silence.
Share this adversary profile
Compare →swipe to browse
Related Adversaries
Data sourced from MITRE ATT&CK. For educational purposes.