216.73.217.98

No Way to Hide: Uncovering New Campaigns from Daily Tunneling Detection

· Published 05/10/2024 08:33 · Modified 07/10/2024 09:03

Export JSON

Essential information

Published
05/10/2024 08:33
Modified
07/10/2024 09:03
Tags
2024-10-05 8ns cobalt strike covert communications data exfiltration dns tunneling finhealthxds hiloti icedid nsfinder redline stealer russiansite
Related entities
9 techniques (mitre), 4 malware, 7 others

Description

This article analyzes four previously undisclosed campaigns identified through a new campaign monitoring system. The system detects tunneling domains based on common techniques and attributes used in malicious campaigns. Four new campaigns were uncovered: (targeting finance and healthcare), (over 100 domains sharing a Russian nameserver), (domains with 8 NS records), and (domains combining words ending in 'finder'). The campaigns exploit DNS protocol vulnerabilities to establish covert communication channels for and infiltration. Common attributes within campaigns include shared infrastructure, DNS configurations, payload encoding methods, domain registration patterns, and attack targets. The monitoring system has been implemented in Palo Alto Networks' Advanced DNS Security service to provide enhanced protection against emerging threats.

External references