DNS Tunneling Abuse Expands to Tracking & Scanning Victims
ID: e096bf76-5cb2-5699-a0e8-3d823c151d1f
STIX ID: report--e096bf76-5cb2-5699-a0e8-3d823c151d1f
Feed Name: Dark Reading
Date Published: 2024-05-14
Date Updated: 2026-04-21
Author: Elizabeth Montalbano, Contributing Writer
Unit 42 researchers describe multiple recent campaigns that extend DNS tunneling beyond C2 and exfiltration to include user tracking and infrastructure scanning: TRkCdn tracked email interactions across ~731 potential victims, SpamTracker used tunneling to monitor spam/phishing delivery, and SecShow scanned for open resolvers and exploited resolver behaviors to enable reflection and other DNS-based attacks; defenders are advised to restrict resolver query scope, patch resolvers, and prioritize phishing prevention.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
