logo

Injecting Rogue DNS Records Using DHCP

ID: d207754d-13e7-51ef-b79a-528f9a8bf037

STIX ID: report--d207754d-13e7-51ef-b79a-528f9a8bf037

Feed Name: TrustedSec blog

Threat Score
60/100

Date Published: 2025-03-19

Date Updated: 2026-05-01

...
...

**Executive Summary:** This report demonstrates a proof-of-concept attack in which an adversary deploys a rogue Linux networking device on a target LAN and uses spoofed DHCP transactions to inject dynamic DNS records (including WPAD or wildcard names) into Windows and some third-party DHCP/DNS setups; the attacker then claims the assigned IP on a virtual interface so the network routes traffic to their device, enabling credential capture or NTLM relay attacks. The write-up includes a step-by-step PoC using dhtest, observations about DHCP/DNS behaviors, and recommends mitigations such as switch port security, reserving key DNS names, and applying Microsoft’s DNS Server Global Query Blocklist.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.