HomeSecurityHackers exploit DNS queries to steal data

Hackers exploit DNS queries to steal data

Hackers are increasingly leveraging the DNS tunneling technique to create covert communication channels that bypass traditional network security measures.

See also: Hazy Hawk compromises trusted domains via DNS

DNS hacker

This sophisticated method exploits the trust placed in DNS traffic, which typically passes through corporate firewalls with minimal scrutiny due to its critical role in internet communication. According to Infoblox, DNS tunneling involves encoding malicious data inside legitimate DNS queries and responses, thereby creating an invisible communication channel between compromised systems and servers controlled by the attackers.

To create this infrastructure, cybercriminals must gain control of a domain, allowing malware on infected systems to perform periodic DNS lookups that trigger specific actions, depending on the responses received.

The process exploits the recursive nature of DNS resolution, in which queries pass through multiple servers before reaching their final destination. The response from the server may include a TXT record with encoded commands, such as ON2WI3ZAOJWSAL3FORRS643IMFSG65YK, which, when decoded, can instruct the compromised system to perform specific actions.

See also: CISA: DNS Fast Flux is used by cybercriminals

Security researchers have identified several DNS tunneling "families" that are often used in real-world attacks.

Hackers exploit DNS queries to steal data
Hackers exploit DNS queries to steal data

Cobalt Strike, a popular penetration testing tool often abused by malicious actors, was responsible for 26% of the detected DNS tunneling activity. The tool uses hex-encoded and customizable prefixes, such as “post” or “api.”

The tool performs beaconing via A records and performs command-and-control (C2) operations via TXT records. DNSCat2, which accounts for 13% of recorded DNS tunneling traffic, creates encrypted DNS tunnels using various query types, including A, TXT, CNAME , and MX.

See also: ZLoader malware uses DNS Tunneling technique

Traditional security measures have difficulty detecting DNS tunneling activity, as the traffic appears legitimate and relies on regular DNS protocols. However, advanced algorithms can detect these hidden communication channels by analyzing query patterns and response behavior.

Source: cybersecuritynews

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS