Sub-technique of T1071 Application Layer Protocol.View on attack.mitre.org
Adversaries may communicate using the Domain Name System (DNS) application layer protocol to avoid detection/network filtering by blending in with existing traffic. Commands to the remote system, and often the results of those commands, will be embedded within the protocol traffic between the client and server.
The DNS protocol serves an administrative function in computer networking and thus may be very common in environments. DNS traffic may also be allowed even before network authentication is completed. DNS packets contain many fields and headers in which data can be concealed. Often known as DNS tunneling, adversaries may abuse DNS to communicate with systems under their control within a victim network while also mimicking normal, expected traffic.
DNS beaconing may be used to send commands to remote systems via DNS queries. A DNS beacon is created by tunneling DNS traffic (i.e. Protocol Tunneling). The commands may be embedded into different DNS records, for example, TXT or A records. DNS beacons may be difficult to detect because the beacons infrequently communicate with infected devices. Infrequent communication conceals the malicious DNS traffic with normal DNS traffic.
Rules on DetectionCode tagged with T1071.004.
| Rule | Level | Log source |
|---|---|---|
| Cobalt Strike DNS Beaconing | critical | NULL / dns |
| Silence.EDA Detection | critical | windows / ps_script |
| Suspicious Cobalt Strike DNS Beaconing - DNS Client | critical | windows / NULL |
| Suspicious Cobalt Strike DNS Beaconing - Sysmon | critical | windows / dns_query |
| DNS Exfiltration and Tunneling Tools Execution | high | windows / process_creation |
| DNS Query by Finger Utility | high | windows / dns_query |
| DNS TXT Answer with Possible Execution Strings | high | NULL / dns |
| Network Connection Initiated via Finger.EXE | high | windows / network_connection |
| DNS Query To Common Malware Hosting and Shortener Services | medium | windows / dns_query |
| Suspicious DNS Query with B64 Encoded String | medium | NULL / dns |
| Rule | Type | Risk | Data source |
|---|---|---|---|
| DNS Kerberos Coercion | TTP | NULL | Suricata, Sysmon EventID 22 |
| DNS Query Length Outliers - MLTK | Anomaly | NULL | |
| DNS Query Requests Resolved by Unauthorized DNS Servers | TTP | NULL | |
| DNS record changed | TTP | NULL | |
| Excessive DNS Failures | Anomaly | NULL | |
| Windows AI Platform DNS Query | Anomaly | NULL | Sysmon EventID 22 |
| Windows Credential Target Information Structure in Commandline | TTP | NULL | Sysmon EventID 1 |
| Windows DNS Query Request by Telegram Bot API | Anomaly | NULL | Sysmon EventID 22 |
| Windows Kerberos Coercion via DNS | TTP | NULL | Windows Event Log Security 4662, Windows Event Log Security 5136, Windows Event Log Security 5137 |
| Windows Powershell Commands from DNS TXT | Anomaly | NULL | Powershell Script Block Logging 4104 |
| Windows Short Lived DNS Record | TTP | NULL | Windows Event Log Security 5136, Windows Event Log Security 5137 |
| Windows Visual Basic Commandline Compiler DNSQuery | TTP | NULL | Sysmon EventID 22 |
| Used by | Procedure example |
|---|---|
| GroupAPT18 | APT18 uses DNS for C2 communications. |
| GroupAPT39 | APT39 has used remote access tools that leverage DNS in communications with C2. |
| GroupAPT41 | APT41 used DNS for C2 communications. |
| GroupChimera | Chimera has used Cobalt Strike to encapsulate C2 in DNS traffic. |
| GroupCobalt Group | Cobalt Group has used DNS tunneling for C2. |
| GroupEmber Bear | Ember Bear has used DNS tunnelling tools, such as dnscat/2 and Iodine, for C2 purposes. |
| GroupFIN7 | FIN7 has performed C2 using DNS via A, OPT, and TXT records. |
| GroupKe3chang | Ke3chang malware RoyalDNS has used DNS for C2. |
| Used by | Procedure example |
|---|---|
| MalwareAnchor | Variants of Anchor can use DNS tunneling to communicate with C2. |
| MalwareBONDUPDATER | BONDUPDATER can use DNS and TXT records within its DNS tunneling protocol for command and control. |
| MalwareBRICKSTORM | BRICKSTORM has used DNS over HTTPS to resolve C2 infrastructure and obscure DNS traffic from inspection. |
| ToolBrute Ratel C4 | Brute Ratel C4 can use DNS over HTTPS for C2. |
| MalwareCobalt Strike | Cobalt Strike can use a custom command and control protocol that can be encapsulated in DNS. All protocols use their standard assigned ports. |
| MalwareCobian RAT | Cobian RAT uses DNS for C2. |
| MalwareDanBot | DanBot can use use IPv4 A records and IPv6 AAAA DNS records in C2 communications. |
| MalwareDarkGate | DarkGate can cloak command and control traffic in DNS records from legitimate services to avoid reputation-based detection techniques. |
| Used by | Procedure example |
|---|---|
| CampaignCutting Edge | During Cutting Edge, threat actors used DNS to tunnel IPv4 C2 traffic. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.