DNS

T1071.004

Sub-technique of T1071 Application Layer Protocol.View on attack.mitre.org

About this technique

Adversaries may communicate using the Domain Name System (DNS) application layer protocol to avoid detection/network filtering by blending in with existing traffic. Commands to the remote system, and often the results of those commands, will be embedded within the protocol traffic between the client and server.

The DNS protocol serves an administrative function in computer networking and thus may be very common in environments. DNS traffic may also be allowed even before network authentication is completed. DNS packets contain many fields and headers in which data can be concealed. Often known as DNS tunneling, adversaries may abuse DNS to communicate with systems under their control within a victim network while also mimicking normal, expected traffic.

DNS beaconing may be used to send commands to remote systems via DNS queries. A DNS beacon is created by tunneling DNS traffic (i.e. Protocol Tunneling). The commands may be embedded into different DNS records, for example, TXT or A records. DNS beacons may be difficult to detect because the beacons infrequently communicate with infected devices. Infrequent communication conceals the malicious DNS traffic with normal DNS traffic.

Detection rules22

Rules on DetectionCode tagged with T1071.004.

Sigma10

Splunk12

RuleTypeRiskData source
DNS Kerberos CoercionTTPNULLSuricata, Sysmon EventID 22
DNS Query Length Outliers - MLTKAnomalyNULL
DNS Query Requests Resolved by Unauthorized DNS ServersTTPNULL
DNS record changedTTPNULL
Excessive DNS FailuresAnomalyNULL
Windows AI Platform DNS QueryAnomalyNULLSysmon EventID 22
Windows Credential Target Information Structure in CommandlineTTPNULLSysmon EventID 1
Windows DNS Query Request by Telegram Bot APIAnomalyNULLSysmon EventID 22
Windows Kerberos Coercion via DNSTTPNULLWindows Event Log Security 4662, Windows Event Log Security 5136, Windows Event Log Security 5137
Windows Powershell Commands from DNS TXTAnomalyNULLPowershell Script Block Logging 4104
Windows Short Lived DNS RecordTTPNULLWindows Event Log Security 5136, Windows Event Log Security 5137
Windows Visual Basic Commandline Compiler DNSQueryTTPNULLSysmon EventID 22

Groups11

Software43

Show 19 more

Campaigns1

Procedure examples55

Groups11

Used byProcedure example
GroupAPT18

APT18 uses DNS for C2 communications.

GroupAPT39

APT39 has used remote access tools that leverage DNS in communications with C2.

GroupAPT41

APT41 used DNS for C2 communications.

GroupChimera

Chimera has used Cobalt Strike to encapsulate C2 in DNS traffic.

GroupCobalt Group

Cobalt Group has used DNS tunneling for C2.

GroupEmber Bear

Ember Bear has used DNS tunnelling tools, such as dnscat/2 and Iodine, for C2 purposes.

GroupFIN7

FIN7 has performed C2 using DNS via A, OPT, and TXT records.

GroupKe3chang

Ke3chang malware RoyalDNS has used DNS for C2.

View all 11 groups examples

Software43

Used byProcedure example
MalwareAnchor

Variants of Anchor can use DNS tunneling to communicate with C2.

MalwareBONDUPDATER

BONDUPDATER can use DNS and TXT records within its DNS tunneling protocol for command and control.

MalwareBRICKSTORM

BRICKSTORM has used DNS over HTTPS to resolve C2 infrastructure and obscure DNS traffic from inspection.

ToolBrute Ratel C4

Brute Ratel C4 can use DNS over HTTPS for C2.

MalwareCobalt Strike

Cobalt Strike can use a custom command and control protocol that can be encapsulated in DNS. All protocols use their standard assigned ports.

MalwareCobian RAT

Cobian RAT uses DNS for C2.

MalwareDanBot

DanBot can use use IPv4 A records and IPv6 AAAA DNS records in C2 communications.

MalwareDarkGate

DarkGate can cloak command and control traffic in DNS records from legitimate services to avoid reputation-based detection techniques.

View all 43 software examples

Campaigns1

Used byProcedure example
CampaignCutting Edge

During Cutting Edge, threat actors used DNS to tunnel IPv4 C2 traffic.

References4

  1. DNS Beacons Open source
    Vercara. (n.d.). Retrieved July 21, 2025.
  2. Medium DnsTunneling Open source
    Galobardes, R. (2018, October 30). Learn how easy is to bypass firewalls using DNS tunneling (and also how to block it). Retrieved March 15, 2020.
  3. OilRig Uses Updated BONDUPDATER to Target Middle Eastern Government Open source
    Kyle Wilhoit, Robert Falcone. (2018, September 12). OilRig Uses Updated BONDUPDATER to Target Middle Eastern Government. Retrieved July 21, 2025.
  4. PAN DNS Tunneling Open source
    Palo Alto Networks. (n.d.). What Is DNS Tunneling?. Retrieved March 15, 2020.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.