TrickBot Replaces HTTP With DNS Tunneling for Stealthier C2
A new TrickBot variant replaces its traditional HTTP-based command-and-control channel with custom DNS tunneling, concealing encrypted commands and payloads inside DNS traffic. The malware uses encoded, fragmented DNS queries and manipulated IPv4 responses to transfer data through a public resolver at approximately 30.7 KB per second. It maintains persistence through Windows Task Scheduler and NTFS Alternate Data Streams, while supporting module downloads, PowerShell execution, process injection, and in-memory shellcode. Organizations should control DNS resolution and monitor for malformed queries, unusual domain patterns, and suspicious scheduled tasks.
Reference: infosecurity-magazine.com