Skip to content

T1071.004 DNS

Adversaries may communicate using the Domain Name System (DNS) application layer protocol to avoid detection/network filtering by blending in with existing traffic. Commands to the remote system, and often the results of those commands, will be embedded within the protocol traffic between the client and server.

The DNS protocol serves an administrative function in computer networking and thus may be very common in environments. DNS traffic may also be allowed even before network authentication is completed. DNS packets contain many fields and headers in which data can be concealed. Often known as DNS tunneling, adversaries may abuse DNS to communicate with systems under their control within a victim network while also mimicking normal, expected traffic.41

DNS beaconing may be used to send commands to remote systems via DNS queries. A DNS beacon is created by tunneling DNS traffic (i.e. Protocol Tunneling). The commands may be embedded into different DNS records, for example, TXT or A records.3 DNS beacons may be difficult to detect because the beacons infrequently communicate with infected devices.5 Infrequent communication conceals the malicious DNS traffic with normal DNS traffic.

Item Value
ID T1071.004
Sub-techniques T1071.001, T1071.002, T1071.003, T1071.004, T1071.005
Tactics TA0011
Platforms ESXi, Linux, Network Devices, Windows, macOS
Version 1.4
Created 15 March 2020
Last Modified 24 October 2025

Procedure Examples

ID Name Description
S0504 Anchor Variants of Anchor can use DNS tunneling to communicate with C2.4748
G0026 APT18 APT18 uses DNS for C2 communications.78
G0087 APT39 APT39 has used remote access tools that leverage DNS in communications with C2.75
G0096 APT41 APT41 used DNS for C2 communications.6667
S0360 BONDUPDATER BONDUPDATER can use DNS and TXT records within its DNS tunneling protocol for command and control.40
S1063 Brute Ratel C4 Brute Ratel C4 can use DNS over HTTPS for C2.1213
G0114 Chimera Chimera has used Cobalt Strike to encapsulate C2 in DNS traffic.64
G0080 Cobalt Group Cobalt Group has used DNS tunneling for C2.686970
S0154 Cobalt Strike Cobalt Strike can use a custom command and control protocol that can be encapsulated in DNS. All protocols use their standard assigned ports.373638
S0338 Cobian RAT Cobian RAT uses DNS for C2.50
C0029 Cutting Edge During Cutting Edge, threat actors used DNS to tunnel IPv4 C2 traffic.80
S1014 DanBot DanBot can use use IPv4 A records and IPv6 AAAA DNS records in C2 communications.33
S1111 DarkGate DarkGate can cloak command and control traffic in DNS records from legitimate services to avoid reputation-based detection techniques. 19
S0354 Denis Denis has used DNS tunneling for C2 communications.161714
S1021 DnsSystem DnsSystem can direct queries to custom DNS servers and return C2 commands using TXT records.35
S0377 Ebury Ebury has used DNS requests over UDP port 53 for C2.24
G1003 Ember Bear Ember Bear has used DNS tunnelling tools, such as dnscat/2 and Iodine, for C2 purposes.76
G0046 FIN7 FIN7 has performed C2 using DNS via A, OPT, and TXT records.79
S0666 Gelsemium Gelsemium has the ability to use DNS in communication with C2.39
S0477 Goopy Goopy has the ability to communicate with its C2 over DNS.14
S0690 Green Lambert Green Lambert can use DNS for C2 communications.4142
S0170 Helminth Helminth can use DNS for C2.25
S1027 Heyoka Backdoor Heyoka Backdoor can use DNS tunneling for C2 communications.34
S0070 HTTPBrowser HTTPBrowser has used DNS for command and control.4344
S0260 InvisiMole InvisiMole has used a custom implementation of DNS tunneling to embed C2 communications in DNS requests and replies.53
G0004 Ke3chang Ke3chang malware RoyalDNS has used DNS for C2.74
S1020 Kevin Variants of Kevin can communicate over DNS through queries to the server for constructed domain names with embedded information.21
G0140 LazyScripter LazyScripter has leveraged dynamic DNS providers for C2 communications.65
S0167 Matryoshka Matryoshka uses DNS for C2.5758
S1015 Milan Milan has the ability to use DNS for C2 communications.232122
S1047 Mori Mori can use DNS tunneling to communicate with C2.4645
S0699 Mythic Mythic supports DNS-based C2 profiles.6
S0228 NanHaiShu NanHaiShu uses DNS for the C2 communications.55
S1090 NightClub NightClub can use a DNS tunneling plugin to exfiltrate data by adding it to the subdomain portion of a DNS request.31
G0049 OilRig OilRig has used DNS for C2 including the publicly available requestbin.net tunneling service.73287172
S0124 Pisloader Pisloader uses DNS as its C2 protocol.32
S0013 PlugX PlugX can be configured to use DNS for command and control.43
S0145 POWERSOURCE POWERSOURCE uses DNS TXT records for C2.2059
S0184 POWRUNER POWRUNER can use DNS for C2 communications.2728
S0269 QUADAGENT QUADAGENT uses DNS for C2 communications.15
S0495 RDAT RDAT has used DNS to communicate with the C2.26
S0125 Remsec Remsec is capable of using DNS for C2.606162
S0596 ShadowPad ShadowPad has used DNS tunneling for C2 communications.49
S1019 Shark Shark can use DNS in C2 communications.2322
S0633 Sliver Sliver can support C2 communications over DNS.1197810
S0615 SombRAT SombRAT can communicate over DNS with the C2 server.5152
S0157 SOUNDBITE SOUNDBITE communicates via DNS for C2.54
S0559 SUNBURST SUNBURST used DNS for C2 traffic designed to mimic normal SolarWinds API communications.56
S0663 SysUpdate SysUpdate has used DNS TXT requests as for its C2 communication.18
S0146 TEXTMATE TEXTMATE uses DNS TXT records for C2.20
G0081 Tropic Trooper Tropic Trooper’s backdoor has communicated to the C2 over the DNS protocol.77
S0022 Uroburos Uroburos has encoded outbound C2 communications in DNS requests consisting of character strings made to resemble standard domain names. The actual information transmitted by Uroburos is contained in the part of the character string prior to the first ‘.’ character.63
S0514 WellMess WellMess has the ability to use DNS tunneling for C2 communications.2930

Mitigations

ID Mitigation Description
M1037 Filter Network Traffic Consider filtering DNS requests to unknown, untrusted, or known bad domains and resources. Resolving DNS requests with on-premise/proxy servers may also disrupt adversary attempts to conceal data within DNS packets.
M1031 Network Intrusion Prevention Network intrusion detection and prevention systems that use network signatures to identify traffic for specific adversary malware can be used to mitigate activity at the network level.

References


  1. Galobardes, R. (2018, October 30). Learn how easy is to bypass firewalls using DNS tunneling (and also how to block it). Retrieved March 15, 2020. 

  2. Gardiner, J., Cova, M., Nagaraja, S. (2014, February). Command & Control Understanding, Denying and Detecting. Retrieved April 20, 2016. 

  3. Kyle Wilhoit, Robert Falcone. (2018, September 12). OilRig Uses Updated BONDUPDATER to Target Middle Eastern Government. Retrieved July 21, 2025. 

  4. Palo Alto Networks. (n.d.). What Is DNS Tunneling?. Retrieved March 15, 2020. 

  5. Vercara. (n.d.). Retrieved July 21, 2025. 

  6. Thomas, C. (n.d.). Mythc Documentation. Retrieved March 25, 2022. 

  7. BishopFox. (n.d.). Sliver DNS C2 . Retrieved September 15, 2021. 

  8. Cybereason Global SOC and Incident Response Team. (n.d.). Sliver C2 Leveraged by Many Threat Actors. Retrieved March 24, 2025. 

  9. Kervella, R. (2019, August 4). Cross-platform General Purpose Implant Framework Written in Golang. Retrieved July 30, 2021. 

  10. Microsoft Security Experts. (2022, August 24). Looking for the ‘Sliver’ lining: Hunting for emerging command-and-control frameworks. Retrieved March 24, 2025. 

  11. NCSC, CISA, FBI, NSA. (2021, May 7). Further TTPs associated with SVR cyber actors. Retrieved July 29, 2021. 

  12. Harbison, M. and Renals, P. (2022, July 5). When Pentest Tools Go Brutal: Red-Teaming Tool Being Abused by Malicious Actors. Retrieved February 1, 2023. 

  13. Kenefick, I. et al. (2022, October 12). Black Basta Ransomware Gang Infiltrates Networks via QAKBOT, Brute Ratel, and Cobalt Strike. Retrieved February 6, 2023. 

  14. Dahan, A. (2017). Operation Cobalt Kitty. Retrieved December 27, 2018. 

  15. Lee, B., Falcone, R. (2018, July 25). OilRig Targets Technology Service Provider and Government Agency with QUADAGENT. Retrieved August 9, 2018. 

  16. Dahan, A. (2017, May 24). OPERATION COBALT KITTY: A LARGE-SCALE APT IN ASIA CARRIED OUT BY THE OCEANLOTUS GROUP. Retrieved November 5, 2018. 

  17. Shulmin, A., Yunakovsky, S. (2017, April 28). Use of DNS Tunneling for C&C Communications. Retrieved November 5, 2018. 

  18. Daniel Lunghi. (2023, March 1). Iron Tiger’s SysUpdate Reappears, Adds Linux Targeting. Retrieved March 20, 2023. 

  19. Adi Zeligson & Rotem Kerner. (2018, November 13). Enter The DarkGate - New Cryptocurrency Mining and Ransomware Campaign. Retrieved February 9, 2024. 

  20. Miller, S., et al. (2017, March 7). FIN7 Spear Phishing Campaign Targets Personnel Involved in SEC Filings. Retrieved March 8, 2017. 

  21. Kayal, A. et al. (2021, October). LYCEUM REBORN: COUNTERINTELLIGENCE IN THE MIDDLE EAST. Retrieved June 14, 2022. 

  22. Accenture. (2021, November 9). Who are latest targets of cyber group Lyceum?. Retrieved June 16, 2022. 

  23. ClearSky Cyber Security . (2021, August). New Iranian Espionage Campaign By “Siamesekitten” - Lyceum. Retrieved June 6, 2022. 

  24. M.Léveillé, M.. (2014, February 21). An In-depth Analysis of Linux/Ebury. Retrieved April 19, 2019. 

  25. Falcone, R. and Lee, B.. (2016, May 26). The OilRig Campaign: Attacks on Saudi Arabian Organizations Deliver Helminth Backdoor. Retrieved May 3, 2017. 

  26. Falcone, R. (2020, July 22). OilRig Targets Middle Eastern Telecommunications Organization and Adds Novel C2 Channel with Steganography to Its Inventory. Retrieved July 28, 2020. 

  27. Sardiwal, M, et al. (2017, December 7). New Targeted Attack in the Middle East by APT34, a Suspected Iranian Threat Group, Using CVE-2017-11882 Exploit. Retrieved December 20, 2017. 

  28. Davis, S. and Caban, D. (2017, December 19). APT34 - New Targeted Attack in the Middle East. Retrieved December 20, 2017. 

  29. PWC. (2020, July 16). How WellMess malware has been used to target COVID-19 vaccines. Retrieved September 24, 2020. 

  30. National Cyber Security Centre. (2020, July 16). Advisory: APT29 targets COVID-19 vaccine development. Retrieved September 29, 2020. 

  31. Faou, M. (2023, August 10). MoustachedBouncer: Espionage against foreign diplomats in Belarus. Retrieved September 25, 2023. 

  32. Grunzweig, J., et al. (2016, May 24). New Wekby Attacks Use DNS Requests As Command and Control Mechanism. Retrieved August 17, 2016. 

  33. SecureWorks 2019, August 27 LYCEUM Takes Center Stage in Middle East Campaign Retrieved. 2019/11/19  

  34. Chen, Joey. (2022, June 9). Aoqin Dragon | Newly-Discovered Chinese-linked APT Has Been Quietly Spying On Organizations For 10 Years. Retrieved July 14, 2022. 

  35. Shivtarkar, N. and Kumar, A. (2022, June 9). Lyceum .NET DNS Backdoor. Retrieved June 23, 2022. 

  36. Mavis, N. (2020, September 21). The Art and Science of Detecting Cobalt Strike. Retrieved September 12, 2024. 

  37. Strategic Cyber LLC. (2017, March 14). Cobalt Strike Manual. Retrieved May 24, 2017. 

  38. Strategic Cyber LLC. (2020, November 5). Cobalt Strike: Advanced Threat Tactics for Penetration Testers. Retrieved April 13, 2021. 

  39. Dupuy, T. and Faou, M. (2021, June). Gelsemium. Retrieved November 30, 2021. 

  40. Wilhoit, K. and Falcone, R. (2018, September 12). OilRig Uses Updated BONDUPDATER to Target Middle Eastern Government. Retrieved February 18, 2019. 

  41. Sandvik, Runa. (2021, October 1). Made In America: Green Lambert for OS X. Retrieved March 21, 2022. 

  42. Sandvik, Runa. (2021, October 18). Green Lambert and ATT&CK. Retrieved November 17, 2024. 

  43. Dell SecureWorks Counter Threat Unit Threat Intelligence. (2015, August 5). Threat Group-3390 Targets Organizations for Cyberespionage. Retrieved August 18, 2018. 

  44. Shelmire, A.. (2015, July 6). Evasive Maneuvers. Retrieved January 22, 2016. 

  45. Cyber National Mission Force. (2022, January 12). Iranian intel cyber suite of malware uses open source tools. Retrieved September 30, 2022. 

  46. FBI, CISA, CNMF, NCSC-UK. (2022, February 24). Iranian Government-Sponsored Actors Conduct Cyber Operations Against Global Government and Commercial Networks. Retrieved September 27, 2022. 

  47. Dahan, A. et al. (2019, December 11). DROPPING ANCHOR: FROM A TRICKBOT INFECTION TO THE DISCOVERY OF THE ANCHOR MALWARE. Retrieved September 10, 2020. 

  48. Grange, W. (2020, July 13). Anchor_dns malware goes cross platform. Retrieved September 10, 2020. 

  49. Kaspersky Lab. (2017, August). ShadowPad: popular server management software hit in supply chain attack. Retrieved March 22, 2021. 

  50. Yadav, A., et al. (2017, August 31). Cobian RAT – A backdoored RAT. Retrieved November 13, 2018. 

  51. The BlackBerry Research and Intelligence Team. (2020, November 12). The CostaRicto Campaign: Cyber-Espionage Outsourced. Retrieved May 24, 2021. 

  52. McLellan, T. and Moore, J. et al. (2021, April 29). UNC2447 SOMBRAT and FIVEHANDS Ransomware: A Sophisticated Financial Threat. Retrieved June 2, 2021. 

  53. Hromcova, Z. and Cherpanov, A. (2020, June). INVISIMOLE: THE HIDDEN PART OF THE STORY. Retrieved July 16, 2020. 

  54. Carr, N.. (2017, May 14). Cyber Espionage is Alive and Well: APT32 and the Threat to Global Corporations. Retrieved June 18, 2017. 

  55. F-Secure Labs. (2016, July). NANHAISHU RATing the South China Sea. Retrieved July 6, 2018. 

  56. FireEye. (2020, December 13). Highly Evasive Attacker Leverages SolarWinds Supply Chain to Compromise Multiple Global Victims With SUNBURST Backdoor. Retrieved January 4, 2021. 

  57. ClearSky Cyber Security and Trend Micro. (2017, July). Operation Wilted Tulip: Exposing a cyber espionage apparatus. Retrieved August 21, 2017. 

  58. Minerva Labs LTD and ClearSky Cyber Security. (2015, November 23). CopyKittens Attack Group. Retrieved November 17, 2024. 

  59. Brumaghin, E. and Grady, C.. (2017, March 2). Covert Channels and Poor Decisions: The Tale of DNSMessenger. Retrieved March 8, 2017. 

  60. Symantec Security Response. (2016, August 8). Backdoor.Remsec indicators of compromise. Retrieved August 17, 2016. 

  61. Kaspersky Lab’s Global Research & Analysis Team. (2016, August 9). The ProjectSauron APT. Retrieved August 17, 2016. 

  62. Kaspersky Lab’s Global Research & Analysis Team. (2016, August 9). The ProjectSauron APT. Technical Analysis. Retrieved August 17, 2016. 

  63. FBI et al. (2023, May 9). Hunting Russian Intelligence “Snake” Malware. Retrieved June 8, 2023. 

  64. Jansen, W . (2021, January 12). Abusing cloud services to fly under the radar. Retrieved September 12, 2024. 

  65. Jazi, H. (2021, February). LazyScripter: From Empire to double RAT. Retrieved November 17, 2024. 

  66. Fraser, N., et al. (2019, August 7). Double DragonAPT41, a dual espionage and cyber crime operation APT41. Retrieved September 23, 2019. 

  67. Rostovcev, N. (2021, June 10). Big airline heist APT41 likely behind a third-party attack on Air India. Retrieved August 26, 2021. 

  68. Svajcer, V. (2018, July 31). Multiple Cobalt Personality Disorder. Retrieved September 5, 2018. 

  69. Positive Technologies. (2016, December 16). Cobalt Snatch. Retrieved October 9, 2018. 

  70. Matveeva, V. (2017, August 15). Secrets of Cobalt. Retrieved October 10, 2018. 

  71. Bromiley, M., et al.. (2019, July 18). Hard Pass: Declining APT34’s Invite to Join Their Professional Network. Retrieved August 26, 2019. 

  72. Check Point. (2021, April 8). Iran’s APT34 Returns with an Updated Arsenal. Retrieved May 5, 2021. 

  73. Unit42. (2016, May 1). Evasive Serpens Unit 42 Playbook Viewer. Retrieved February 6, 2023. 

  74. Smallridge, R. (2018, March 10). APT15 is alive and strong: An analysis of RoyalCli and RoyalDNS. Retrieved April 4, 2018. 

  75. Rusu, B. (2020, May 21). Iranian Chafer APT Targeted Air Transportation and Government in Kuwait and Saudi Arabia. Retrieved May 22, 2020. 

  76. US Cybersecurity & Infrastructure Security Agency et al. (2024, September 5). Russian Military Cyber Actors Target U.S. and Global Critical Infrastructure. Retrieved September 6, 2024. 

  77. Chen, J.. (2020, May 12). Tropic Trooper’s Back: USBferry Attack Targets Air gapped Environments. Retrieved May 20, 2020. 

  78. Grunzweig, J., et al. (2016, May 24). New Wekby Attacks Use DNS Requests As Command and Control Mechanism. Retrieved November 15, 2018. 

  79. Carr, N., et al. (2018, August 01). On the Hunt for FIN7: Pursuing an Enigmatic and Evasive Global Criminal Operation. Retrieved August 23, 2018. 

  80. Lin, M. et al. (2024, January 31). Cutting Edge, Part 2: Investigating Ivanti Connect Secure VPN Zero-Day Exploitation. Retrieved February 27, 2024.