Real-world descriptions of how a group, tool or campaign used a technique.
43 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1071.004 DNS |
MalwareBRICKSTORM | BRICKSTORM has used DNS over HTTPS to resolve C2 infrastructure and obscure DNS traffic from inspection. |
| T1071.004 DNS |
MalwarePOWRUNER | POWRUNER can use DNS for C2 communications. |
| T1071.004 DNS |
MalwarePOWERSOURCE | POWERSOURCE uses DNS TXT records for C2. |
| T1071.004 DNS |
MalwareMatryoshka | Matryoshka uses DNS for C2. |
| T1071.004 DNS |
MalwareSystemBC | SystemBC has used DNS servers to resolve .bit domains to C2 infrastructure. |
| T1071.004 DNS |
MalwareWellMess | WellMess has the ability to use DNS tunneling for C2 communications. |
| T1071.004 DNS |
MalwareSombRAT | SombRAT can communicate over DNS with the C2 server. |
| T1071.004 DNS |
MalwareInvisiMole | InvisiMole has used a custom implementation of DNS tunneling to embed C2 communications in DNS requests and replies. |
| T1071.004 DNS |
MalwareRDAT | RDAT has used DNS to communicate with the C2. |
| T1071.004 DNS |
MalwareTEXTMATE | TEXTMATE uses DNS TXT records for C2. |
| T1071.004 DNS |
MalwareGreen Lambert | Green Lambert can use DNS for C2 communications. |
| T1071.004 DNS |
MalwareAnchor | Variants of Anchor can use DNS tunneling to communicate with C2. |
| T1071.004 DNS |
MalwarePlugX | PlugX can be configured to use DNS for command and control. |
| T1071.004 DNS |
MalwareRemsec | Remsec is capable of using DNS for C2. |
| T1071.004 DNS |
MalwareDarkGate | DarkGate can cloak command and control traffic in DNS records from legitimate services to avoid reputation-based detection techniques. |
| T1071.004 DNS |
MalwareNanHaiShu | NanHaiShu uses DNS for the C2 communications. |
| T1071.004 DNS |
MalwareMori | Mori can use DNS tunneling to communicate with C2. |
| T1071.004 DNS |
MalwareQUADAGENT | QUADAGENT uses DNS for C2 communications. |
| T1071.004 DNS |
MalwareUroburos | Uroburos has encoded outbound C2 communications in DNS requests consisting of character strings made to resemble standard domain names. The actual information transmitted by Uroburos is contained in the part of the character string prior to the first ‘.’ character. |
| T1071.004 DNS |
MalwareDnsSystem | DnsSystem can direct queries to custom DNS servers and return C2 commands using TXT records. |
| T1071.004 DNS |
MalwareNightClub | NightClub can use a DNS tunneling plugin to exfiltrate data by adding it to the subdomain portion of a DNS request. |
| T1071.004 DNS |
MalwareShark | Shark can use DNS in C2 communications. |
| T1071.004 DNS |
MalwareSOUNDBITE | SOUNDBITE communicates via DNS for C2. |
| T1071.004 DNS |
MalwareCobalt Strike | Cobalt Strike can use a custom command and control protocol that can be encapsulated in DNS. All protocols use their standard assigned ports. |
| T1071.004 DNS |
MalwareSUNBURST | SUNBURST used DNS for C2 traffic designed to mimic normal SolarWinds API communications. |
| T1071.004 DNS |
MalwareCobian RAT | Cobian RAT uses DNS for C2. |
| T1071.004 DNS |
MalwareMilan | Milan has the ability to use DNS for C2 communications. |
| T1071.004 DNS |
MalwareDanBot | DanBot can use use IPv4 A records and IPv6 AAAA DNS records in C2 communications. |
| T1071.004 DNS |
MalwarePisloader | Pisloader uses DNS as its C2 protocol. |
| T1071.004 DNS |
MalwareSysUpdate | SysUpdate has used DNS TXT requests as for its C2 communication. |
| T1071.004 DNS |
MalwareBONDUPDATER | BONDUPDATER can use DNS and TXT records within its DNS tunneling protocol for command and control. |
| T1071.004 DNS |
MalwareEbury | Ebury has used DNS requests over UDP port 53 for C2. |
| T1071.004 DNS |
MalwareHeyoka Backdoor | Heyoka Backdoor can use DNS tunneling for C2 communications. |
| T1071.004 DNS |
MalwareHTTPBrowser | HTTPBrowser has used DNS for command and control. |
| T1071.004 DNS |
MalwareKevin | Variants of Kevin can communicate over DNS through queries to the server for constructed domain names with embedded information. |
| T1071.004 DNS |
MalwareGoopy | Goopy has the ability to communicate with its C2 over DNS. |
| T1071.004 DNS |
MalwareShadowPad | ShadowPad has used DNS tunneling for C2 communications. |
| T1071.004 DNS |
MalwareGelsemium | Gelsemium has the ability to use DNS in communication with C2. |
| T1071.004 DNS |
MalwareHelminth | Helminth can use DNS for C2. |
| T1071.004 DNS |
MalwareDenis | Denis has used DNS tunneling for C2 communications. |
| T1071.004 DNS |
ToolSliver | Sliver can support C2 communications over DNS. |
| T1071.004 DNS |
ToolBrute Ratel C4 | Brute Ratel C4 can use DNS over HTTPS for C2. |
| T1071.004 DNS |
ToolMythic | Mythic supports DNS-based C2 profiles. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.