Post #4024703
2026-07-22 23:02 UTC
*REALLY NEAT* work by Fortinet here decrypting DNS C2 commands.
https://www.fortinet.com/blog/threat-research/inside-a-trickbot-variant-using-dns-tunneling-for-c2
Replies (2)
-
@Viss@mastodon.social 2026-07-23 02:23
@neurovagrant@masto.deoan.org its very weird to read "neat" and "fortinet" in the same post :D
-
@netresec@infosec.exchange 2026-07-23 17:56
@neurovagrant@masto.deoan.org They analyzed 6 year old TrickBot samples. The anchor_dns campaign was studied and reported on to great length back in 2019/2020. I can recommend reading CISA's AA20-302A report from October 2020 for more details. https://www.cisa.gov/sites/default/files/publications/AA20-302A_Ransomware%20_Activity_Targeting_the_Healthcare_and_Public_Health_Sector.pdf