T1071.004DNS
T1071.004 — DNS is a MITRE ATT&CK technique in the Command and Control tactic. Clankerusecase tracks 29 detection use cases covering it and 126 threat-intel articles citing it.
Command and Control
29Use cases
126Articles
0Sub-techniques
1Tactic
↑ Parent technique: T1071 · Application Layer Protocol
Use cases covering this technique (29)
Beaconing — periodic outbound to small set of destinations DNS tunneling / TXT-heavy domain queries Windows AI Platform DNS Query Windows Credential Target Information Structure in Commandline Windows Kerberos Coercion via DNS Windows Short Lived DNS Record Windows Visual Basic Commandline Compiler DNSQuery DNS Kerberos Coercion Excessive DNS Failures Windows DNS Query Request by Telegram Bot API DNS Query Length Outliers - MLTK DNS Query Requests Resolved by Unauthorized DNS Servers DNS record changed [LLM] SPECTRALVIPER C2 callout to OceanLotus FireAnt infrastructure [LLM] DNS resolution for OceanLotus SPECTRALVIPER C2 domains [LLM] FlutterShell macOS C2 contact (atsheisdomestic / etoftheappyrince / healightejustb) [LLM] SilentCryptoMiner DNS tunneling to *.microsoft.com lookalike and known C2 .space domains [LLM] Screening Serpens C2 — DNS/network to UNC1549 infrastructure (Feb-Apr 2026) [LLM] Nx Console / Shai-Hulud C2 connection (t.m-kosche.com, check.git-service.com, filev2.getsession.org, api.masscan.cloud, 83.142.209.194) [LLM] Mini Shai-Hulud C2 callback to zero.masscan.cloud / 94.154.172.43 [LLM] DNS / Network egress to TeamPCP Nx Console C2 domain check.git-service.com [LLM] DNS lookup for git-tanstack.com TeamPCP C2 staging domain [LLM] DNS lookup for azurestaticprovider[.]net node-ipc exfil domain [LLM] Session/Oxen P2P exfil DNS or TCP to getsession.org from build/CI host [LLM] IoliteLabs IOC sweep: rraghh.com / oortt.com hostnames + campaign file hashes [LLM] bittensor-wallet 4.0.2 backdoor C2 domain contact (opentensor-* lookalikes) [LLM] DNS tunneling exfiltration pattern to *.t.opentensor-cdn.com (hex chunk/index/total/session) [LLM] DNS/HTTP egress to CanisterWorm ICP canister C2 (tdtqy-oyaaa-aaaae-af2dq-cai) [LLM] GhostChat C2/staging infrastructure contact (hitpak.org, buildthenations.info, fkclb.com)Articles citing this technique (126)
crit ShinyHunters Exploits Oracle PeopleSoft Zero-Day (CVE-2026-35273) to Breach Universities art-37
high Node-gyp Supply Chain Compromise: A Self-Propagating npm Worm That Hides in binding.gyp art-130
crit Cloud Atlas activity in the second half of 2025 and early 2026: new tools and a new payload art-219
high GitHub breached via a malicious VS Code extension: why developer devices are the real target art-238
high Microsoft's durabletask package on PyPi Compromised. Mini Shai Hulud attacks again... again! art-254
crit From PDB strings to MaaS: Tracking a commodity BadIIS ecosystem used by Chinese-speaking threat art-265
crit Malicious node-ipc versions published to npm in suspected maintainer account compromise art-284
high Malicious Release of elementary-data PyPI Package Steals Cloud Credentials from Data Engineers art-352
high CanisterWorm: How a Self-Propagating npm Worm Is Spreading Backdoors Across the Ecosystem art-429
crit Malicious Polymarket Bot Hides in Hijacked dev-protocol GitHub Org and Steals Wallet Keys art-433
crit ForceMemo: Hundreds of GitHub Python Repos Compromised via Account Takeover and Force-Push art-434
low Snyk @ RSAC 2025 art-911