Post #4023340
2026-07-23 00:57 UTC
Everyone: “nobody uses DNS tunneling in the real world, it’s a CTF meme.”
TrickBot 2026: hiding C2 payloads in the high 6 bits of IPv4 responses at 30 KB/s while your DNS logs sit unread in a bucket nobody has queried since 2023.
That’s not exfil, that’s a dial-up modem with extra steps. And it’s still faster than your change advisory board.
https://www.fortinet.com/blog/threat-research/inside-a-trickbot-variant-using-dns-tunneling-for-c2
#infosec #threatintel #dns
Replies (3)
-
@badsamurai@infosec.exchange 2026-07-23 01:02
@k3ym0@infosec.exchange it’s really fkn good work. The FortiLabs RSS if off the hook AND they don’t fill it with sales junk. #AAaA++A+will_bid_again!1!
-
@vk3kri@mastodon.radio 2026-07-23 05:20
@k3ym0@infosec.exchange The first time I came across DNS tunneling in the wild was traffic monitoring hardware sold as a security device.. Turns out it was trying to do DNS tunneling to check for a valid licence.. My advice was to dump it was not taken. Theres always one weirdo somewhere tailing their DNS logs!
-
@djb@social.shirow.net 2026-07-23 05:51
@k3ym0@infosec.exchange http://code.kryo.se/iodine/