Leveraging DNS Tunneling for Tracking and Scanning
ID: 0ffc48ef-25fa-56bb-a2b4-9903eaa1152b
STIX ID: report--0ffc48ef-25fa-56bb-a2b4-9903eaa1152b
Feed Name: Palo Alto Networks Unit 42
Date Published: 2024-05-13
Date Updated: 2026-04-28
Author: Shu Wang, Ruian Duan and Daiping Liu
This Unit 42 report analyzes multiple active DNS tunneling campaigns that abuse DNS to perform tracking (email/open tracking via hashed identifiers) and network scanning (discovering open resolvers, testing delays, and preparing reflection/amplification or cache-poisoning attacks). The report documents campaign naming and timelines (TrkCdn, SpamTracker, SecShow), provides sample FQDN patterns, domain lifecycles, associated IP addresses and nameserver usage, and recommends detection/mitigation steps while listing IoCs for defensive action.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
