Lyceum .NET DNS Backdoor
ID: 6d24972a-cb68-537b-9832-b078c6d3923b
STIX ID: report--6d24972a-cb68-537b-9832-b078c6d3923b
Feed Name: Zscaler Security Research Blog
Threat Score
**Zscaler ThreatLabz analyzed a Lyceum (Iranian APT) campaign delivering a customized .NET DNS backdoor (DnsSystem.exe) via a macro-enabled Word document that uses DNS hijacking and DNS TXT/A records for stealthy C2 and exfiltration; the report includes behavior analysis, persistence method, command/upload/download capabilities, MITRE ATT&CK mappings, and IOCs (file hashes, domains, URLs).**
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
