New TrickBot Variant Spotted Using DNS to Control Infected Windows PCs
Cybersecurity researchers at Fortinet’s FortiGuard Labs have identified a TrickBot variant that uses DNS tunneling to exchange commands with its operators. The Windows malware can download additional modules, run PowerShell code, inject code into other processes, and execute commands on an infected computer.
ComputerSecurity
The samples were identified after FortiGuard Labs noticed malformed DNS queries. Further analysis confirmed that the traffic belonged to TrickBot variants using DNS in place of the HTTP connections seen in earlier versions.
TrickBot Uses DNS to Contact Its Operators
For better understanding, DNS normally translates website names into IP addresses. On the other hand, DNS tunneling abuses that process by placing non-DNS data inside queries and responses, allowing malware to communicate through a service that most networks need to keep available.
In this case, the TrickBot variant disguises its communications as ordinary website lookups. It breaks commands into small pieces, inserts them into requests for...
Copyright of this story solely belongs to hackread.com. To see the full text click HERE