216.73.216.6

DNS: A Small but Effective C2 system

· Published 17/07/2025 13:13 · Modified 17/07/2025 19:47

Export JSON

Essential information

Published
17/07/2025 13:13
Modified
17/07/2025 19:47
Tags
2025-07-17 cobalt strike command and control dns exfiltrator dns tunneling dnscat2 iodine sliver weasel
Related entities
1 techniques (mitre)

Description

This analysis explores the exploitation of DNS for command-and-control operations and data exfiltration. It details how cybercriminals leverage to create covert communication channels, bypassing traditional security measures. The article examines various families, including , , and , discussing their prevalence and unique characteristics. It also highlights Infoblox's Threat Insight machine learning algorithms, which can detect and block tunneling domains within minutes. The study provides insights into the detection rates of different tunneling families and discusses the challenges in differentiating between legitimate and malicious DNS traffic.

External references