FORENSIA

ATT&CK · T1071.004 · sub-technique

DNS

Tactics: command-and-control

About

Adversaries may communicate using the Domain Name System (DNS) application layer protocol to avoid detection/network filtering by blending in with existing traffic. Commands to the remote system, and often the results of those commands, will be embedded within the protocol traffic between the client and server. The DNS protocol serves an administrative function in computer networking and thus may be very common in environments. DNS traffic may also be allowed even before network authentication is completed. DNS packets contain many fields and headers in which data can be concealed. Often known as DNS tunneling, adversaries may abuse DNS to communicate with systems under their control within a victim network while also mimicking normal, expected traffic. DNS beaconing may be used to send commands to remote systems via DNS queries. A DNS beacon is created by tunneling DNS traffic (i.e. Protocol Tunneling). The commands may be embedded into different DNS records, for example, TXT or A records. DNS beacons may be difficult to detect because the beacons infrequently communicate with infected devices. Infrequent communication conceals the malicious DNS traffic with normal DNS traffic.

Platforms: ESXi, Linux, macOS, Network Devices, WindowsParent: T1071 Application Layer ProtocolMITRE ATT&CK ↗

Used by actors

11 known groups

Software

43 malware/tools implement this

PlugXUroburosHTTPBrowserPisloaderRemsecPOWERSOURCETEXTMATECobalt StrikeSOUNDBITEMatryoshkaHelminthPOWRUNERNanHaiShuInvisiMoleQUADAGENTCobian RATDenisBONDUPDATEREburyGoopyRDATAnchorWellMessSUNBURSTShadowPadSombRATSliverSysUpdateGelsemiumGreen LambertMythicDanBotMilanSharkKevinDnsSystemHeyoka BackdoorMoriBrute Ratel C4NightClubDarkGateSystemBCBRICKSTORM

Corpus indicators tagged with this technique

582 indicators in the corpus carry T1071.004.

IndicatorTypeFamilySevSrc
cve-2017-18377cve851
cve-2025-34117cve851
cve-2021-25646cve851
cve-2025-34037cve851
cve-2014-2321cve851
cve-2021-4045cve851
cve-2020-17456cve851
cve-2013-7471cve851
cve-2007-5693cve851
cve-2026-5815cve851
d06b86da3777be0e2156c35f031f503d280a17ee3a1cc531f4c5fb806c0f749bhash802
ca5fd64932a82d3e24a19fe94d8b7636847f4335b8fd8795a63cfa0107e67048hash802
bf0b36dcbbc60dbf83ecac7c56534271e53a16817909306ecc6f15f7b6106730hash802
bbcc1a208b4bd0a9ffe8799158cd994d82e125acb30b630e774b242f11dd6985hash802
a29cdca72822c1f236c53c181d03f0c45907a45f2ef3c4c2da3ef839bfd3b7a6hash802
44f6101dd8171133f53317bfd752300ehash802
4c0d9b802c075be79e9edb52d88f8dd72e6904f5c58267213745818470945c78hashphishing802
fab69acd743f4111b749e3268690825c38822e62hash802
69f524815eeb3b2069ff41a8a12cae0537de8ad9bd856d694fa21bb2af8fada8hash802
51ead7f0490bfe6b432120bbbd63b807277d016911664fb264640bb8b007d756hash802
2e04dc8bee038a5771373fc4dbaa4e45f653cd649928199e9ce8098c8b27d64ehash802
22c860931f2ed22897b81ef8da16980fc24b2573ec884a153b3ff5df9e0f8cffhash802
7b7981c99d59595fe15377df84695bb72ce0b85560a3935f930657b2d162e5efsha256phishing801
79aec671ceb205db1769da6898c9659c7c8297b13929e593050523438c09a44fhash802
af93524fd0aac0a790734a0747fcf844ba5f0652b11a0f4a59bbe5aeace0fa75hash802
a806cece4a4fbbe502e6d76035681702d9adde1c6f74c9e1c0547d37d30ddfcfhash802
b8b8d41a8a7eccda90b366fb5a3d2c0f692504984429aaa19b0af0dcd81dec03hash802
2227df1207d2c90db46610bd98909032hash802
3a69aedb78677993384dfe9b476e3d26hash802
91e523a46f3bb860ac2e5800b7e1ec89d75a2408410b9cd25eebc17c8d7a92bchash802

Showing the top 30 by severity of 582.