Hackers exploit a blind spot by hiding malware inside DNS records

Hackers exploit a blind spot by hiding malware inside DNS records

Cybercriminals are increasingly hiding malware in a surprising location—domain name system (DNS) records, which link domain names to their numerical IP addresses. This tactic allows them to deliver malicious scripts and early-stage malware without the need for downloads from questionable websites or email attachments, which are often flagged by antivirus programs. The reason this method is effective is that DNS traffic typically goes under the radar of many security measures. While web and email communications are closely monitored, DNS requests represent a significant vulnerability in cybersecurity defenses. Recent research by DomainTools has revealed that hackers have been using this method to host a malicious binary associated with Joke Screenmate, a type of disruptive malware that can interfere with a computer's operations. To evade detection, the malware was converted from binary format to hexadecimal—a compact encoding system using digits and letters. The hexadecimal data was then split into numerous segments, each embedded within the DNS records of various subdomains of whitetreecollective[.]com. Specifically, these segments were included in the TXT records, which are typically used for validating site ownership in services like Google Workspace. Once an attacker gains access to a secured network, they can easily retrieve these segments through seemingly harmless DNS queries. The pieces can then be reassembled and converted back into their original binary form. This technique not only facilitates the delivery of malware but also complicates detection efforts, especially as encrypted DNS protocols, such as DNS over HTTPS (DOH) and DNS over TLS (DOT), become more prevalent.

Sources : Ars Technica

Published On : Jul 16, 2025, 11:20

Computing
Why Public Speakerphone Conversations Are Sparking Outrage

In today’s tech-driven society, the norms of communication are evolving, often leading to discomfort among the public. A...

Ars Technica | Mar 11, 2026, 21:15
Why Public Speakerphone Conversations Are Sparking Outrage
AI
AI Chatbots Under Fire for Encouraging Violent Actions, New Study Reveals

A recent investigation by the Center for Countering Digital Hate (CCDH) has unveiled troubling findings regarding artifi...

Ars Technica | Mar 11, 2026, 20:50
AI Chatbots Under Fire for Encouraging Violent Actions, New Study Reveals
Computing
AI Boom Reshapes Memory Market: A New Era of Price Stability

The recent surge in artificial intelligence spending is transforming the memory industry in unprecedented ways. Over the...

CNBC | Mar 11, 2026, 21:15
AI Boom Reshapes Memory Market: A New Era of Price Stability
Gaming
Exciting Update: Xbox Mode Set to Transform Windows 11 PCs This April

Last summer, when Asus and Microsoft unveiled the ROG Xbox Ally X, it featured a unique, controller-friendly interface t...

Ars Technica | Mar 11, 2026, 21:00
Exciting Update: Xbox Mode Set to Transform Windows 11 PCs This April
Cybersecurity
Binance Takes Legal Action Against WSJ Amid Government Scrutiny

In a bold move to combat increasing scrutiny, Binance has initiated a defamation lawsuit against The Wall Street Journal...

Ars Technica | Mar 11, 2026, 18:05
Binance Takes Legal Action Against WSJ Amid Government Scrutiny
View All News