No Way to Hide: Uncovering New Campaigns from Daily Tunneling Detection
ID: cf46de6a-9d1e-5900-ad33-db01a7910e83
STIX ID: report--cf46de6a-9d1e-5900-ad33-db01a7910e83
Feed Name: Palo Alto Networks Unit 42
Date Published: 2024-10-04
Date Updated: 2026-04-28
Author: Shu Wang, Ruian Duan, Chao Lei and Qi Deng
**Executive Summary:** This Unit 42 report analyzes four previously undisclosed DNS tunneling campaigns—FinHealthXDS, RussianSite, 8NS, and NSfinder—describing shared infrastructure and encoding attributes used to cluster domains, linking campaigns to malware families (Hiloti, IcedID, RedLine), providing examples of tunneling formats, passive DNS observations, IoCs (domains, IPs, sample hashes), targeted sectors (finance, healthcare, education, government), and recommended protections via Palo Alto Networks products and signatures.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
