logo

Hiding in Plain Sight: Part 2

ID: 83a247b6-36c3-5fea-80b8-323f73b00e22

STIX ID: report--83a247b6-36c3-5fea-80b8-323f73b00e22

Feed Name: Huntress Blog

Threat Score
75/100

Date Published: 2024-04-12

Date Updated: 2026-04-28

...
...

Analysts uncovered a multi-stage, multi-payload malware campaign that uses masqueraded Windows binaries and obfuscated PowerShell to fetch further payloads via DNS-over-HTTPS TXT records. The malware hides payloads inside a fake DKIM TXT response, uses nested Base64 and numeric-encoded IPs to resolve dynamic C2 servers, and employs scheduled tasks and decoy filenames to evade detection, with multiple observed variants and reusable infrastructure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.