A new malware toolkit targeting businesses dubbed “Decoy Dog” was discovered after inspecting anomalous DNS traffic that was indistinguishable from normal Internet activity.
See also: Bumblebee malware: Distributed via Google Ads and used for ransomware attacks

Decoy Dog helps threat actors evade standard detection methods through domain aging and DNS query dribbling strategies, aiming to build a good reputation with security vendors before moving on to facilitate cybercrime operations.
Infoblox researchers discovered the toolkit in early April 2023 as part of their analysis of over 70 billion DNS records daily, looking for signs of abnormal or suspicious activity.
Infoblox reports that Decoy Dog's DNS fingerprint is extremely rare and unique among the 370 million active domains on the internet, making it easier to detect and track .
Therefore, research into Decoy Dog's infrastructure quickly led to the discovery of multiple C2 (command and control) domains associated with the same enterprise, with most communications from these servers originating from hosts in Russia.
Further investigation revealed that the DNS tunnels on these domains had characteristics that were consistent with the Pupy RAT, a remote access trojan deployed by the Decoy Dog toolkit.
See also: Hackers breach networks using data on corporate routers

PuppyRAT is a modular, open-source post-exploitation toolkit that is popular among state-sponsored threat actors due to its stealth (no logs), support for encrypted C2 communications , and ability to blend their activities with other users of the tool.
The PuPy RAT project supports payloads on all major operating systems, including Windows, macOS, Linux , and Android. As with other RATs, it enables threat actors to execute commands remotely, gain elevated privileges, steal credentials , and spread laterally across a network.
Less specialized actors do not use Puppy RAT, as deploying the tool with the correct DNS server configuration for C2 communications requires knowledge and experience.
Additionally, analysts discovered a distinct DNS beaconing behavior across all Decoy Dog domains that was configured to follow a specific pattern of periodic but infrequent DNS request generation.
See also: Yellow Pages Canada confirms cyberattack as BlackBasta leaks its data
Investigations of hosting and domain registration data revealed that the Decoy Dog operation had been ongoing since early April 2022, so it remained under the radar for over a year, despite the fact that the toolkit domains showed outliers in the analyses.
The discovery of Decoy Dog demonstrates the power of using large-scale data analytics to detect anomalous activity across the vastness of the Internet.
“Because the situation is complex and we have focused on the discovery of DNS, we expect more details from the industry, as well as from ourselves, in the future.”
The company has also shared indicators of compromise on its public GitHub, which can be used to manually add to block lists.
Information source: bleepingcomputer.com
