Hackers Exploit DNS Records to Hide Malware, Evade Defenses
Hackers Exploit DNS Records to Hide Malware, Evade Defenses

Hackers Exploit DNS Records to Hide Malware, Evade Defenses

News summary

Cybercriminals are increasingly exploiting the Domain Name System (DNS) to hide and deliver malware, leveraging its trusted but often overlooked infrastructure to bypass traditional security measures. Researchers at DomainTools and others have discovered that attackers encode malware, such as the Joke Screenmate strain, into hexadecimal chunks stored in DNS TXT records across subdomains, which can then be retrieved and reassembled via seemingly normal DNS queries without triggering alerts. This technique is further complicated by the adoption of encrypted DNS protocols like DNS-over-HTTPS (DoH) and DNS-over-TLS (DoT), which shield malicious DNS traffic from security monitoring tools. Attackers also use DNS tunneling to conduct command-and-control operations and data exfiltration by encoding instructions and stolen data within various DNS record types, including A, AAAA, TXT, and CNAME records. These methods enable malware communication to blend in with legitimate DNS traffic, making detection difficult even for organizations with internal DNS resolvers and advanced security setups. The misuse of DNS in this way represents a new frontier for cyber threats, with implications extending to malware delivery, AI-related prompt injections, and stealthy command execution.

Story Coverage
Bias Distribution
100% Left
Information Sources
de83a561-4c0e-4e9e-9a71-8ecf0da2dc5b
Left 100%
Coverage Details
Total News Sources
1
Left
1
Center
0
Right
0
Unrated
0
Last Updated
12 hours ago
Bias Distribution
100% Left
Related News
Daily Index

Negative

22Serious

Neutral

Optimistic

Positive

Ask VT AI
Story Coverage
Subscribe

Stay in the know

Get the latest news, exclusive insights, and curated content delivered straight to your inbox.

Present

Gift Subscriptions

The perfect gift for understanding
news from all angles.

Related News
Recommended News