T1568Dynamic Resolution
T1568 — Dynamic Resolution is a MITRE ATT&CK technique in the Command and Control tactic. Clankerusecase tracks 19 detection use cases covering it and 19 threat-intel articles citing it.
Command and Control
19Use cases
19Articles
3Sub-techniques
1Tactic
Sub-techniques (3)
Use cases covering this technique (19)
[LLM] Sniper Dz seized phishing infrastructure callback (post-takedown beacons) [LLM] Connection to RoguePlanet PoC C2 Domain projectnightcrawler.dev [LLM] Outbound DNS / HTTP to Miasma C2 (git-service.com / m-kosche.com) [LLM] Miasma C2 / IOC domain resolution: check.git-service.com, t.m-kosche.com, git-service.com [LLM] Connection to AI-brand phishing / installer C2 infrastructure (MSTI June 2026 IOCs) [LLM] C2 beacon to audit.checkmarx[.]cx /v1/telemetry (TeamPCP Shai-Hulud Third Coming) [LLM] TamperedChef C2 / distribution callback to appsuites.ai and sibling domains [LLM] Mini Shai-Hulud / TeamPCP C2 beacon to api.masscan.cloud / git-tanstack.com / *.getsession.org [LLM] BadIIS C2 IP / domain beacon (lee.6686ty.vip, iis.01nmwe.xyz) [LLM] node-ipc C2 callback to sh.azurestaticprovider.net (May 2026 npm supply-chain) [LLM] Mini Shai-Hulud npm Worm C2 callback to Session Protocol CDN and masscan.cloud [LLM] axios Supply Chain RAT C2 Callback to sfrclak.com (Port 8000) [LLM] C2 beaconing to Vercel-hosted Cloudflare-impersonating domains (cloudflareguard / cloudflareinsights) [LLM] Egress to Qix npm phishing/exfil infrastructure (npmjs.help, publicvm.com, BunnyCDN buckets) [LLM] Scavenger npm malware C2 beacon to firebase.su / dieorsuffer.com / smartscreen-api.com [LLM] Beamglea mad-* dead-drop fetch from raw.githubusercontent.com/Abassdos2992 [LLM] Scavenger C2 callback: ifyouseethisyouareultragay[.]com / pokerainteasy[.]su [LLM] Scavenger Stealer C2 beacon to corroborated infrastructure (datahog.su / datalytica.su / smartscreen-api.com) [LLM] Egress to Solidity Language Cursor extension C2 infrastructure (angelic.su / lmfao.su / staketree.net / ab498.pythonanywhere.com / 144.172.1Articles citing this technique (19)
crit From PDB strings to MaaS: Tracking a commodity BadIIS ecosystem used by Chinese-speaking threat art-265
crit Malicious Polymarket Bot Hides in Hijacked dev-protocol GitHub Org and Steals Wallet Keys art-433