Hackers are increasingly leveraging the DNS tunneling technique to create covert communication channels that bypass traditional network security measures.
See also: Hazy Hawk compromises trusted domains via DNS

This sophisticated method exploits the trust placed in DNS traffic, which typically passes through corporate firewalls with minimal scrutiny due to its critical role in internet communication. According to Infoblox, DNS tunneling involves encoding malicious data inside legitimate DNS queries and responses, thereby creating an invisible communication channel between compromised systems and servers controlled by the attackers.
To create this infrastructure, cybercriminals must gain control of a domain, allowing malware on infected systems to perform periodic DNS lookups that trigger specific actions, depending on the responses received.
The process exploits the recursive nature of DNS resolution, in which queries pass through multiple servers before reaching their final destination. The response from the server may include a TXT record with encoded commands, such as ON2WI3ZAOJWSAL3FORRS643IMFSG65YK, which, when decoded, can instruct the compromised system to perform specific actions.
See also: CISA: DNS Fast Flux is used by cybercriminals
Security researchers have identified several DNS tunneling "families" that are often used in real-world attacks.

Cobalt Strike, a popular penetration testing tool often abused by malicious actors, was responsible for 26% of the detected DNS tunneling activity. The tool uses hex-encoded and customizable prefixes, such as “post” or “api.”
The tool performs beaconing via A records and performs command-and-control (C2) operations via TXT records. DNSCat2, which accounts for 13% of recorded DNS tunneling traffic, creates encrypted DNS tunnels using various query types, including A, TXT, CNAME , and MX.
See also: ZLoader malware uses DNS Tunneling technique
Traditional security measures have difficulty detecting DNS tunneling activity, as the traffic appears legitimate and relies on regular DNS protocols. However, advanced algorithms can detect these hidden communication channels by analyzing query patterns and response behavior.
Source: cybersecuritynews
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
