Hackers use DNS tunneling for network scanning, tracking victims
ID: 50289147-8131-5f88-b239-435916416628
STIX ID: report--50289147-8131-5f88-b239-435916416628
Feed Name: Bleeping Computer
Threat Score
**Unit 42** uncovered active DNS tunneling campaigns—'TrkCdn' used to track phishing email interactions and 'SecShow' used to scan networks—where attackers encode identifiers and data into DNS queries and leverage DNS records (CNAME, TXT, etc.) as a covert channel for tracking, reconnaissance, and potential C2/data exfiltration; defensive recommendations include DNS traffic monitoring, anomaly detection, and restricting resolvers.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
