Not sleeping anymore: SOMNIRECORD's wake-up call
ID: e3edfae1-72a6-572e-bc24-cd8d40ea98fd
STIX ID: report--e3edfae1-72a6-572e-bc24-cd8d40ea98fd
Feed Name: Elastic Security Labs
**Executive summary:** Elastic Security Labs identified and analyzed SOMNIRECORD, a C++ backdoor used by REF2924 that uses DNS TXT records to poll for commands and exfiltrate hex-encoded results (via subdomains like XXX-DATA-...), supports commands for system enumeration, process listing, executing programs, changing beacon intervals, and deploying an ASPX webshell, and includes a hardcoded domain (dafadfweer.top) and a provided YARA signature; the malware appears adapted from the open-source DNS-Persist project.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
