T1071.004DNS
T1071.004 — DNS is a MITRE ATT&CK technique in the Command and Control tactic. Clankerusecase tracks 33 detection use cases covering it and 166 threat-intel articles citing it.
Command and Control
33Use cases
166Articles
0Sub-techniques
1Tactic
↑ Parent technique: T1071 · Application Layer Protocol
Use cases covering this technique (33)
Beaconing — periodic outbound to small set of destinations DNS tunneling / TXT-heavy domain queries Windows AI Platform DNS Query Windows Credential Target Information Structure in Commandline Windows Kerberos Coercion via DNS Windows Short Lived DNS Record Windows Visual Basic Commandline Compiler DNSQuery DNS Kerberos Coercion Excessive DNS Failures Windows DNS Query Request by Telegram Bot API DNS Query Length Outliers - MLTK DNS Query Requests Resolved by Unauthorized DNS Servers DNS record changed [LLM] OWAReaper C2 / exfiltration egress to TA488 CDN and DNS-tunnel domains [LLM] BINDCLOAK C2 beacon to cert.hypersnet.com / ssl.blsouqs.com [LLM] CAV3RN/HOLLOWGRAPH DNS AAAA config-recovery beaconing to cloudlanecdn[.]com [LLM] TuxBot fallback C2 via digikalas.online DGA subdomains and DNS TXT queries [LLM] Apache Camel DNS SSRF: inbound HTTP request carrying dns.server / dns.name control headers [LLM] Apache Camel DNS SSRF egress: app server (java) resolving via external / attacker DNS resolver [LLM] DNS resolution of TeamPCP typosquat exfil domain scan.aquasecurtiy.org [LLM] OceanLotus SPECTRALVIPER C2 communication to FireAnt-campaign domains/IPs [LLM] Nx Console / Shai-Hulud C2 connection (t.m-kosche.com, check.git-service.com, filev2.getsession.org, api.masscan.cloud, 83.142.209.194) [LLM] DNS / Network egress to TeamPCP Nx Console C2 domain check.git-service.com [LLM] DNS lookup for azurestaticprovider[.]net node-ipc exfil domain [LLM] Session/Oxen P2P exfil DNS or TCP to getsession.org from build/CI host [LLM] IoliteLabs IOC sweep: rraghh.com / oortt.com hostnames + campaign file hashes [LLM] bittensor-wallet 4.0.2 backdoor C2 domain contact (opentensor-* lookalikes) [LLM] DNS tunneling exfiltration pattern to *.t.opentensor-cdn.com (hex chunk/index/total/session) [LLM] DNS/HTTP egress to CanisterWorm ICP canister C2 (tdtqy-oyaaa-aaaae-af2dq-cai) [LLM] GhostChat C2/staging infrastructure contact (hitpak.org, buildthenations.info, fkclb.com) [LLM] Java process fetching first-seen external URL/DNS — Commons Config url/dns lookup (CVE-2022-33980) [LLM] npm dropper exfiltration to pkgio.com telemetry server [LLM] npm dropper DNS exfil to pkgio.com / game-note.com (gxm-reference campaign)Articles citing this technique (166)
crit Russian Hackers Exploit Microsoft OWA Flaw to Keep Mailbox Access After Credential Rotation art-01
crit Don’t swing at everything art-107
crit Begun, the Patch Wars have art-151
high GoSerpent: a persistent threat evolves with sophisticated data collection and exfiltration art-154
crit Winning 54% of the time art-215
crit 10 Layers Deep: How StepSecurity Stops TeamPCP's Trivy Supply Chain Attack on GitHub Actions art-254
high Node-gyp Supply Chain Compromise: A Self-Propagating npm Worm That Hides in binding.gyp art-362
high GitHub breached via a malicious VS Code extension: why developer devices are the real target art-412
high Microsoft's durabletask package on PyPi Compromised. Mini Shai Hulud attacks again... again! art-423
crit Malicious node-ipc versions published to npm in suspected maintainer account compromise art-431
high Malicious Release of elementary-data PyPI Package Steals Cloud Credentials from Data Engineers art-475
high CanisterWorm: How a Self-Propagating npm Worm Is Spreading Backdoors Across the Ecosystem art-551
crit Malicious Polymarket Bot Hides in Hijacked dev-protocol GitHub Org and Steals Wallet Keys art-555
crit ForceMemo: Hundreds of GitHub Python Repos Compromised via Account Takeover and Force-Push art-556
low Snyk @ RSAC 2025 art-971
crit CISA KEV: CVE-2019-11001 — Reolink Multiple IP Cameras OS Command Injection Vulnerability art-1118
high Ethical Hacking: Top Tools art-1702
med New IaC security workshop from Snyk, HashiCorp, and AWS at KubeCon Europe 2023 and on-demand art-1772
crit Snyk finds 200+ malicious npm packages, including Cobalt Strike dependency confusion attacks art-2203
crit CISA KEV: CVE-2021-45382 — D-Link Multiple Routers Remote Code Execution Vulnerability art-2340