logo

Hackers use DNS tunneling for network scanning, tracking victims

ID: 50289147-8131-5f88-b239-435916416628

STIX ID: report--50289147-8131-5f88-b239-435916416628

Feed Name: Bleeping Computer

Threat Score
60/100

Date Published: 2024-05-13

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

**Unit 42** uncovered active DNS tunneling campaigns—'TrkCdn' used to track phishing email interactions and 'SecShow' used to scan networks—where attackers encode identifiers and data into DNS queries and leverage DNS records (CNAME, TXT, etc.) as a covert channel for tracking, reconnaissance, and potential C2/data exfiltration; defensive recommendations include DNS traffic monitoring, anomaly detection, and restricting resolvers.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.