DnsSystem

S1021

Malware.View on attack.mitre.org

About this malware

DnsSystem is a .NET based DNS backdoor, which is a customized version of the open source tool DIG.net, that has been used by HEXANE since at least June 2022.

Techniques used9

Procedure examples9

TechniqueProcedure example
T1005
Data from Local System

DnsSystem can upload files from infected machines after receiving a command with `uploaddd` in the string.

T1033
System Owner/User Discovery

DnsSystem can use the Windows user name to create a unique identification for infected users and systems.

T1041
Exfiltration Over C2 Channel

DnsSystem can exfiltrate collected data to its C2 server.

T1059.003
Windows Command Shell

DnsSystem can use `cmd.exe` for execution.

T1071.004
DNS

DnsSystem can direct queries to custom DNS servers and return C2 commands using TXT records.

T1105
Ingress Tool Transfer

DnsSystem can download files to compromised systems after receiving a command with the string `downloaddd`.

T1132.001
Standard Encoding

DnsSystem can Base64 encode data sent to C2.

T1204.002
Malicious File

DnsSystem has lured victims into opening macro-enabled Word documents for execution.

T1547.001
Registry Run Keys / Startup Folder

DnsSystem can write itself to the Startup folder to gain persistence.

Groups that use it1

Campaigns0

None recorded.

References1

  1. Zscaler Lyceum DnsSystem June 2022 Open source
    Shivtarkar, N. and Kumar, A. (2022, June 9). Lyceum .NET DNS Backdoor. Retrieved June 23, 2022.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.