Threat actors use the Domain Name System (DNS) tunneling to monitor when their victims open phishing and click on malicious links, and to scan networks for potential vulnerabilities.
See also: Hackers are forging emails from trusted sources

DNS tunneling is the encoding of data or commands sent and retrieved via DNS requests, essentially turning DNS, a fundamental element of network communication, into a hidden communication channel.
Malicious actors encode data in various ways, such as Base16 or Base64 , or custom text encoding algorithms, so that it can be returned when querying DNS records, such as TXT, MX, CNAME, and Address.
Hackers commonly use DNS tunneling to bypass firewalls and network filters, using the technique for command and control (C2) and virtual private network (VPN) functions. There are also legitimate applications of DNS tunneling, such as for circumventing censorship.
Palo Alto Networks' Unit 42 security research team discovered additional use of DNS tunneling in malicious campaigns involving victim tracking and network scanning.
See also: Goldoon Botnet targets D-Link Routers
TrkCdn Campaign
The first campaign, tracked as “TrkCdn,” focuses on monitoring victims’ interactions with phishing content.

Attackers embed content in an email that, when opened, performs a DNS query to subdomains controlled by the attackers whose FQDN contains encoded content.
This approach allows attackers to evaluate their strategies, improve them, and confirm the delivery of malicious payloads to their victims.
SecShow Campaign
The second campaign that analysts identified, codenamed “SecShow,” uses DNS tunneling to scan network infrastructure.
See also: Cuttlefish Malware: Hacks routers for covert surveillance
Attackers embed IP addresses and timestamps in DNS queries to map network layouts and discover potential configuration flaws that can be exploited for intrusion, data theft, or denial of service.
The DNS queries used in this campaign were repeated periodically to allow for real-time data collection, detection of state changes, and testing the response of different network segments to unsolicited DNS requests.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Source: bleepingcomputer
