This post was authored by Edmund Brumaghin, Colin Grady, with contributions from Dave Maynor and @Simpo13. We have observed additional attacks leveraging this type of malware attempting to infect several target organizations. These attacks began with a targeted spear phishing email to initiate the malware infections and also leveraged compromised U.S. state government servers to host malicious code used in later stages of the infection chain. The use of obfuscation as well as the presence of a complex multi-stage infection process indicates that this is a sophisticated and highly motivated threat actor that is continuing to operate.”]
Source: https://blog.talosintelligence.com/2017/10/dnsmessenger-sec-campaign.html