Technique with 3 sub-techniques.View on attack.mitre.org
Adversaries may dynamically establish connections to command and control infrastructure to evade common detections and remediations. This may be achieved by using malware that shares a common algorithm with the infrastructure the adversary uses to receive the malware's communications. These calculations can be used to dynamically adjust parameters such as the domain name, IP address, or port number the malware uses for command and control.
Adversaries may use dynamic resolution for the purpose of Fallback Channels. When contact is lost with the primary command and control server malware may employ dynamic resolution as a means to reestablishing command and control.
Rules on DetectionCode tagged with T1568 or one of its sub-techniques.
| Rule | Level | Log source | Technique |
|---|---|---|---|
| Communication To Ngrok Tunneling Service - Linux | high | linux / network_connection | T1568.002 |
| Communication To Ngrok Tunneling Service Initiated | high | windows / network_connection | T1568.002 |
| Download from Suspicious Dyndns Hosts | medium | NULL / proxy | T1568 |
| Rule | Type | Risk | Data source | Technique |
|---|---|---|---|---|
| Detect DGA domains using pretrained model in DSDL | Anomaly | NULL | T1568.002 | |
| Detect suspicious DNS TXT records using pretrained model in DSDL | Anomaly | NULL | T1568.002 |
| Used by | Procedure example |
|---|---|
| GroupAPT-C-36 | APT-C-36 has used DDNS services such as DuckDNS, noip[.]com, and con-ip[.]com to redirect victims to sites or repositories hosting malware implants. |
| GroupAPT29 | APT29 has used Dynamic DNS providers for their malware C2 infrastructure. |
| GroupBITTER | BITTER has used DDNS for C2 communications. |
| GroupGamaredon Group | Gamaredon Group has incorporated dynamic DNS domains in its infrastructure. |
| GroupKimsuky | Kimsuky has used Dynamic DNS (DDNS) services, such as FreeDNS or No-IP DDNS, to include servers located in South Korea. |
| GroupRedEcho | RedEcho used dynamic DNS domains associated with malicious infrastructure. |
| GroupTA2541 | TA2541 has used dynamic DNS services for C2 infrastructure. |
| GroupTransparent Tribe | Transparent Tribe has used dynamic DNS services to set up C2. |
| Used by | Procedure example |
|---|---|
| ToolAsyncRAT | AsyncRAT can be configured to use dynamic DNS. |
| MalwareBisonal | Bisonal has used a dynamic DNS service for C2. |
| MalwareBRICKSTORM | BRICKSTORM has utilized DNS services sslip.io and nip.io to resolve C2 IP addresses. |
| MalwareGelsemium | Gelsemium can use dynamic DNS domain names in C2. |
| MalwareMaze | Maze has forged POST strings with a random choice from a list of possibilities including "forum", "php", "view", etc. while making connection with the C2, hindering detection efforts. |
| MalwareNETEAGLE | NETEAGLE can use HTTP to download resources that contain an IP address and port number pair to connect to for C2. |
| ToolRemcos | Remcos has used dynamic DNS domains in C2 communications. |
| MalwareRTM | RTM has resolved Pony C2 server IP addresses by either converting Bitcoin blockchain transaction data to specific octets, or accessing IP addresses directly within the Namecoin blockchain. |
| Used by | Procedure example |
|---|---|
| CampaignC0026 | During C0026, the threat actors re-registered a ClouDNS dynamic DNS subdomain which was previously used by ANDROMEDA. |
| CampaignIndian Critical Infrastructure Intrusions | During Indian Critical Infrastructure Intrusions, RedEcho used dynamic DNS domains associated with malicious infrastructure. |
| CampaignNight Dragon | During Night Dragon, threat actors used dynamic DNS services for C2. |
| CampaignOperation Dust Storm | For Operation Dust Storm, the threat actors used dynamic DNS domains from a variety of free providers, including No-IP, Oray, and 3322. |
| CampaignOperation Spalax | For Operation Spalax, the threat actors used dynamic DNS services, including Duck DNS and DNS Exit, as part of their C2 infrastructure. |
| CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 used dynamic DNS resolution to construct and resolve to randomly-generated subdomains for C2. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.