logo

Leveraging DNS Tunneling for Tracking and Scanning

ID: 0ffc48ef-25fa-56bb-a2b4-9903eaa1152b

STIX ID: report--0ffc48ef-25fa-56bb-a2b4-9903eaa1152b

Feed Name: Palo Alto Networks Unit 42

Threat Score
65/100

Date Published: 2024-05-13

Date Updated: 2026-04-28

Author: Shu Wang, Ruian Duan and Daiping Liu

...
...

This Unit 42 report analyzes multiple active DNS tunneling campaigns that abuse DNS to perform tracking (email/open tracking via hashed identifiers) and network scanning (discovering open resolvers, testing delays, and preparing reflection/amplification or cache-poisoning attacks). The report documents campaign naming and timelines (TrkCdn, SpamTracker, SecShow), provides sample FQDN patterns, domain lifecycles, associated IP addresses and nameserver usage, and recommends detection/mitigation steps while listing IoCs for defensive action.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.