TA419 DNS lookup to lookalike organization-impersonation domain
Detects DNS queries and TLS SNI traffic associated with known lookalike domains used by the threat actor TA419 for organization impersonation, which are commonly utilized in spearphishing campaigns.
Suricata

