TGViewer
SITREP - Independent OSINT Channel SITREP - Independent OSINT Channel @sitreports · 23K subscribers
Post #39564 218
📡 Iran-linked DNS tunneling spike generated 40 billion passive DNS records

DomainTools disclosed a March 1 surge centered on supaghost.cc, which produced up to 500,000 observations per second and added roughly 50% to normal intake. The activity expanded to more than 100 domains, many registered in late 2025, with TXT records and delegated subdomains indicating suspected VPN-over-DNS transport. DomainTools said it did not decode the traffic or verify content in its investigation.

The key point is scale, not attribution certainty. The 40 billion figure reflects passive DNS observations rather than confirmed exfiltrated data, but the pattern shows DNS infrastructure being used as a high-volume transport layer under conflict conditions.

🛰️ Open sources - closed narratives
@sitreports
More from @sitreports
  1. Oct 11, 2026🔍 Cyber executive arrested in sealed US extortion case Canadian cybersecurity executive E…
  2. Oct 11, 2026🔍 Third-party AI agents widen enterprise blind spots A new analysis argues that AI securi…
  3. Oct 11, 2026🤖 Anthropic Restricts Live Web Access in Internal Claude Testing Anthropic has cut live i…
  4. Oct 11, 2026🤖 AI-assisted intrusion chain exposed in South Korean bank attacks A Chinese-speaking thr…
  5. Oct 11, 2026📡 DarkBlinders campaign uses fake meeting client and GitHub C2 DarkBlinders ran a cyberes…
  6. Oct 11, 2026🔍 AhsayCBS zero-days enable unauthenticated SYSTEM access on backup servers Threat actors…
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook →Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 →