T1071.004DNS
T1071.004 — DNS is a MITRE ATT&CK technique in the Command and Control tactic. Clankerusecase tracks 33 detection use cases covering it and 169 threat-intel articles citing it.
Command and Control
33Use cases
169Articles
0Sub-techniques
1Tactic
↑ Parent technique: T1071 · Application Layer Protocol
Use cases covering this technique (33)
Beaconing — periodic outbound to small set of destinations DNS tunneling / TXT-heavy domain queries Windows AI Platform DNS Query Windows Credential Target Information Structure in Commandline Windows Kerberos Coercion via DNS Windows Powershell Commands from DNS TXT Windows Short Lived DNS Record Windows Visual Basic Commandline Compiler DNSQuery DNS Kerberos Coercion Excessive DNS Failures Windows DNS Query Request by Telegram Bot API DNS Query Length Outliers - MLTK DNS Query Requests Resolved by Unauthorized DNS Servers DNS record changed [LLM] Node.js process direct DNS egress to external resolver (vm2 dns.setServers host hijack) [LLM] Jewelbug XG-Web C2 beacon to Google-Fonts-mimicking domains and IPs [LLM] DNS tunneling: high-volume long/high-entropy subdomain queries to a single parent domain [LLM] Endpoint issuing DNS directly to unauthorised/external resolvers (resolver bypass) [LLM] DNS TXT/NULL record C2 & exfiltration: high-volume rare-record-type queries from one host [LLM] TuxBot fallback C2 via digikalas.online DGA subdomains and DNS TXT queries [LLM] DNS resolution of TeamPCP typosquat exfil domain scan.aquasecurtiy.org [LLM] OceanLotus SPECTRALVIPER C2 communication to FireAnt-campaign domains/IPs [LLM] Nx Console / Shai-Hulud C2 connection (t.m-kosche.com, check.git-service.com, filev2.getsession.org, api.masscan.cloud, 83.142.209.194) [LLM] DNS / Network egress to TeamPCP Nx Console C2 domain check.git-service.com [LLM] DNS lookup for azurestaticprovider[.]net node-ipc exfil domain [LLM] Session/Oxen P2P exfil DNS or TCP to getsession.org from build/CI host [LLM] IoliteLabs IOC sweep: rraghh.com / oortt.com hostnames + campaign file hashes [LLM] bittensor-wallet 4.0.2 backdoor C2 domain contact (opentensor-* lookalikes) [LLM] DNS tunneling exfiltration pattern to *.t.opentensor-cdn.com (hex chunk/index/total/session) [LLM] GhostChat C2/staging infrastructure contact (hitpak.org, buildthenations.info, fkclb.com) [LLM] Java process fetching first-seen external URL/DNS — Commons Config url/dns lookup (CVE-2022-33980) [LLM] npm dropper exfiltration to pkgio.com telemetry server [LLM] npm dropper DNS exfil to pkgio.com / game-note.com (gxm-reference campaign)Articles citing this technique (169)
crit Suspected China-Nexus Actor Exploits VMware vCenter Flaw, Deploys Babuk-Derived Ransomware art-28
crit Team PCP Stole 78,330 Secrets From 2,186 Organizations. CloudSEK Just Published the List. art-35
high Hackers Spend Nearly $7 Million on Expired Domains to Redirect Traffic to Scams and Malware art-40
high Chrome DevTools Technique Enables Authenticated Session Hijacking in Live Windows Browsers art-44
crit APT group HoneyMyte upgrades CoolClient: the backdoor gets a kernel-level Windows rootkit art-48
crit ThreatsDay: GhostJacking AI Attacks, EtherHiding ClickFix, Cursor CLI Flaw + 17 More Stories art-51
crit AmnesiaStealer Hijacks Chromium Sessions to Give Attackers Live Browser Control on macOS art-55
high Project CAV3RN continues: Google Apps Script as C2 relay and DNS-based C2 channel selection art-91
crit The Permanent Threat: Analyzing Aeternum’s Blockchain-Based C2 Operations and Communications art-96
crit Compromised PyPI Package: mrmustard 0.7.4 Steals SSH, Cloud, and Kubernetes Credentials art-193
crit Don’t swing at everything art-213
crit Begun, the Patch Wars have art-253
crit 10 Layers Deep: How StepSecurity Stops TeamPCP's Trivy Supply Chain Attack on GitHub Actions art-324
high Node-gyp Supply Chain Compromise: A Self-Propagating npm Worm That Hides in binding.gyp art-408
high GitHub breached via a malicious VS Code extension: why developer devices are the real target art-458
high Microsoft's durabletask package on PyPi Compromised. Mini Shai Hulud attacks again... again! art-469
crit Malicious node-ipc versions published to npm in suspected maintainer account compromise art-477
high Malicious Release of elementary-data PyPI Package Steals Cloud Credentials from Data Engineers art-520
high CanisterWorm: How a Self-Propagating npm Worm Is Spreading Backdoors Across the Ecosystem art-592
crit Malicious Polymarket Bot Hides in Hijacked dev-protocol GitHub Org and Steals Wallet Keys art-596
crit ForceMemo: Hundreds of GitHub Python Repos Compromised via Account Takeover and Force-Push art-597
low Snyk @ RSAC 2025 art-994
crit CISA KEV: CVE-2019-11001 — Reolink Multiple IP Cameras OS Command Injection Vulnerability art-1141
high Ethical Hacking: Top Tools art-1725
med New IaC security workshop from Snyk, HashiCorp, and AWS at KubeCon Europe 2023 and on-demand art-1795
crit Snyk finds 200+ malicious npm packages, including Cobalt Strike dependency confusion attacks art-2226
crit CISA KEV: CVE-2021-45382 — D-Link Multiple Routers Remote Code Execution Vulnerability art-2363