HomeSecurityHackers use DNS tunneling to find victims

Hackers use DNS tunneling to find victims

Threat actors use the Domain Name System (DNS) tunneling to monitor when their victims open phishing and click on malicious links, and to scan networks for potential vulnerabilities.

See also: Hackers are forging emails from trusted sources

DNS tunneling

DNS tunneling is the encoding of data or commands sent and retrieved via DNS requests, essentially turning DNS, a fundamental element of network communication, into a hidden communication channel.

Malicious actors encode data in various ways, such as Base16 or Base64 , or custom text encoding algorithms, so that it can be returned when querying DNS records, such as TXT, MX, CNAME, and Address.

Hackers commonly use DNS tunneling to bypass firewalls and network filters, using the technique for command and control (C2) and virtual private network (VPN) functions. There are also legitimate applications of DNS tunneling, such as for circumventing censorship.

Palo Alto Networks' Unit 42 security research team discovered additional use of DNS tunneling in malicious campaigns involving victim tracking and network scanning.

See also: Goldoon Botnet targets D-Link Routers

TrkCdn Campaign

The first campaign, tracked as “TrkCdn,” focuses on monitoring victims’ interactions with phishing content.

Hackers use DNS tunneling to find victims

Attackers embed content in an email that, when opened, performs a DNS query to subdomains controlled by the attackers whose FQDN contains encoded content.

This approach allows attackers to evaluate their strategies, improve them, and confirm the delivery of malicious payloads to their victims.

SecShow Campaign

The second campaign that analysts identified, codenamed “SecShow,” uses DNS tunneling to scan network infrastructure.

See also: Cuttlefish Malware: Hacks routers for covert surveillance

Attackers embed IP addresses and timestamps in DNS queries to map network layouts and discover potential configuration flaws that can be exploited for intrusion, data theft, or denial of service.

The DNS queries used in this campaign were repeated periodically to allow for real-time data collection, detection of state changes, and testing the response of different network segments to unsolicited DNS requests.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Source: bleepingcomputer

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS