A newly disclosed unprecedented surge in suspected Iranian VPN-over-DNS activity, with one domain generating 40 billion passive DNS observations within days.
Published October 9, 2026, the investigation documents infrastructure expanding across more than 100 domains during military conflict, while leaving its operators, transmitted content, and purpose unconfirmed.
The activity began around 07:00 UTC on March 1, 2026, and escalated sharply by noon. Engineers investigating congestion in DomainTools’ intake servers traced the processing backlog to supaghost[.]cc, which generated up to 500,000 observations per second.
Iranian VPN-over-DNS Activity Generates 40 Billion DNS Observations
DomainTools normally processes, deduplicates, and validates approximately one million observations per second. The single domain therefore increased intake by roughly 50%, eventually accumulating 40 billion observations before engineers began filtering its traffic.

Most observations involved TXT records containing payload structures consistent with VPN-over-DNS transport. This technique uses DNS queries and responses to carry bidirectional communications across network boundaries, repurposing name-resolution infrastructure as a data transport channel.
TXT responses can carry arbitrary data, while algorithmically generated subdomain labels provide another way to transport information.
Researcher Ian Campbell assessed that the observed TXT payloads likely contained multiple binary packets multiplexed together to improve efficiency. Under that interpretation, the exit node would decode and forward the encapsulated traffic.
However, DomainTools did not decode the observed data. The proposed packet handling remains a structural assessment rather than a verified reconstruction of the communications or their contents.
Delegation patterns supplied additional evidence of bidirectional tunneling. The third-level label slsa1.supaghost[.]cc delegated to sa1.supaghost[.]cc, with comparable mappings extending through slsa6.
Nameserver hosts often resolved to separate, inexpensive virtual private servers that DomainTools described as protected by Cloudflare, suggesting traffic distribution across multiple endpoints.
The activity subsequently spread to more than 100 domains, with Iran’s .ir country-code domain disproportionately represented.
Most were registered between September and November 2025 and remained dormant before exhibiting similar spikes during the March observation period. Several approached the original domain’s throughput, although none individually reached its peak.
Established DNS tunneling services in Eurasia and South Asia also experienced intensified activity. DomainTools said the escalation followed the opening of a U.S.-Israeli bombing campaign by approximately 24 hours, while external indicators suggested origins near or within Iran. Timing alone did not establish attribution.
Campbell proposed emergency offsite backup activity as one possible explanation. Suggestions involving Iranian regime operations or nuclear-program data transfers were explicitly speculation, not confirmed findings.
The 40 billion figure counts passive DNS observations not unique files, decoded packets, or measured stolen data. DomainTools began quietly disclosing the observations in March and published them to encourage corroboration from other organizations with visibility into similar activity.
Join 16,000+ SOC teams using ANY.RUN to streamline threat investigations and reduce manual effort. Explore for your team

