Fast Flux DNS

T1568.001

Sub-technique of T1568 Dynamic Resolution.View on attack.mitre.org

About this technique

Adversaries may use Fast Flux DNS to hide a command and control channel behind an array of rapidly changing IP addresses linked to a single domain resolution. This technique uses a fully qualified domain name, with multiple IP addresses assigned to it which are swapped with high frequency, using a combination of round robin IP addressing and short Time-To-Live (TTL) for a DNS resource record.

The simplest, "single-flux" method, involves registering and de-registering an addresses as part of the DNS A (address) record list for a single DNS name. These registrations have a five-minute average lifespan, resulting in a constant shuffle of IP address resolution.

In contrast, the "double-flux" method registers and de-registers an address as part of the DNS Name Server record list for the DNS zone, providing additional resilience for the connection. With double-flux additional hosts can act as a proxy to the C2 host, further insulating the true source of the C2 channel.

Detection rules0

Rules on DetectionCode tagged with T1568.001.

Sigma0

No Sigma rules are mapped to this technique yet.

Splunk0

No Splunk rules are mapped to this technique yet.

Groups3

Software3

Campaigns0

None recorded.

Procedure examples6

Groups3

Used byProcedure example
GroupGamaredon Group

Gamaredon Group has used fast flux DNS to mask their command and control channel behind rotating IP addresses. Additionally, Gamaredon Group has used a low-frequency variant of the single-flux method.

GroupmenuPass

menuPass has used dynamic DNS service providers to host malicious domains.

GroupTA505

TA505 has used fast flux to mask botnets by distributing payloads across multiple IPs.

Software3

Used byProcedure example
MalwareAmadey

Amadey has used fast flux DNS for its C2.

Malwaregh0st RAT

gh0st RAT operators have used dynamic DNS to mask the true location of their C2 behind rapidly changing IP addresses.

MalwarenjRAT

njRAT has used a fast flux DNS for C2 IP resolution.

References3

  1. Fast Flux - Welivesecurity Open source
    Albors, Josep. (2017, January 12). Fast Flux networks: What are they and how do they work?. Retrieved March 11, 2020.
  2. MehtaFastFluxPt1 Open source
    Mehta, L. (2014, December 17). Fast Flux Networks Working and Detection, Part 1. Retrieved March 6, 2017.
  3. MehtaFastFluxPt2 Open source
    Mehta, L. (2014, December 23). Fast Flux Networks Working and Detection, Part 2. Retrieved March 6, 2017.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.