The article details Kaspersky's Network Anomaly Detection (NAD) technology within the KATA platform, focusing on two detection scenarios: Kerberoasting and DNS tunneling via TXT records. NAD uses SQL-based behavioral analytics against network session data in ClickHouse to identify deviations from baseline host behavior, overcoming limitations of traditional signature-based IDS tools that cannot distinguish malicious Kerberos TGS requests or DNS tunneling from legitimate traffic. The approach correlates multiple indirect indicators — anomalous SPN request volume, unusual DNS query patterns, data transfer thresholds — into consolidated alerts with tunable infrastructure-specific variables.
DNS Tunneling
6 posts
Network Anomaly Detection in KATA Inside a TrickBot Variant Using DNS Tunneling for C2 FortiGuard Labs identified a TrickBot variant that uses DNS tunneling for C2 communication instead of HTTP, embedding XOR-encrypted data in DNS queries and encoding response payloads within IPv4 address octets. The malware establishes persistence via Windows Task Scheduler disguised as software updates, stores configuration in NTFS Alternate Data Streams, and employs runtime string decryption and hash-based API resolution to evade analysis. Its modular architecture supports process injection (hollowing, doppelgänging), DLL execution via rundll32, PowerShell execution, and raw shellcode execution, retaining the full capability set of the TrickBot family.
Pirates in the crosshairs: how one cybercrime gang has been infecting book, movie, and TV show fans for years A cybercrime campaign is targeting users of pirated media sites with a fake video player update that deploys a modified SilentCryptoMiner and a Remote Access Trojan (RAT). The malware utilizes DLL side-loading, DNS tunneling for initial check-ins, and a DGA for C2 communications, while employing a Watchdog component to ensure persistence via a rogue Google Update service.
Cracks in the Bedrock: Escaping the AWS AgentCore Sandbox Unit 42 researchers discovered a method to bypass the network isolation of Amazon Bedrock AgentCore's Code Interpreter sandbox using DNS tunneling. Combined with a legacy MMDSv1 configuration that lacked session token enforcement, attackers could potentially exploit SSRF to extract highly privileged IAM credentials and exfiltrate them via the DNS covert channel.
ChatGPT Data Leakage via a Hidden Outbound Channel in the Code Execution Runtime Check Point Research discovered a vulnerability in ChatGPT's code execution runtime that allowed silent data exfiltration and remote shell access via DNS tunneling. By using malicious prompts or custom GPTs, attackers could bypass outbound network restrictions to steal sensitive user data without triggering security warnings.
Silver Dragon Targets Organizations in Southeast Asia and Europe Check Point Research identified Silver Dragon, a Chinese-nexus APT group likely affiliated with APT41, targeting organizations in Southeast Asia and Europe. The group utilizes public-facing server exploits and phishing to deploy custom loaders that establish persistence via AppDomain hijacking and service manipulation. These loaders deliver Cobalt Strike and a novel Google Drive-based backdoor called GearDoor.