- What: TrickBot uses DNS tunneling for command and control
- Impact: Malware evades traditional detection by hiding in DNS traffic
Malware TrickBot variant uses DNS tunneling for command and control July 22, 2026 Share By SC Staff (Adobe Stock) Per Infosecurity Magazine, a new variant of the TrickBot malware has been observed abandoning its traditional HTTP command-and-control (C2) channel for a custom DNS tunneling scheme, embedding malicious communications within seemingly normal DNS queries. This TrickBot variant, detailed in research by Fortinet's FortiGuard Labs, utilizes a modular architecture but features a redesigned transport layer. It disguises outbound C2 messages as domain-name lookups and reads responses from IP addresses. Commands are encrypted with a single-byte XOR key, hex-encoded, and broken into chunks to mimic valid domains. Inbound traffic exploits the DNS specification's allowance for multiple IPv4 addresses per reply, with TrickBot extracting payload data from these addresses. The malware achieves persistence through the Windows Task Scheduler, creating tasks that run every five minutes. Its modular execution capabilities, including downloading and executing modules, injecting into processes, and running shellcode, remain intact. This shift to DNS tunneling, which FortiGuard measured at approximately 30.7 KB per second throughput, allows TrickBot to evade detection and maintain its status as a persistent threat despite previous disruption efforts. Source: Infosecurity Magazine SC Staff Related Malware ACR Stealer exploits user interaction to steal sensitive data SC Staff July 17, 2026 Microsoft has detailed two primary intrusion chains used by ACR Stealer. Malware MacOS malware hijacks Telegram sessions, targets crypto wallets SC Staff July 17, 2026 The macOS malware targets information stored locally on infected devices, including passwords, browser cookies, Apple Notes and Telegram Desktop session files. Malware New macOS stealer uses social engineering and coercion SC Staff July 17, 2026 The attack chain begins when a victim pastes a command into their Terminal, often lured by a ClickFix page. Get daily email updates SC Media's daily must-read of the most current and pressing daily news Business Email By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy . Subscribe Related Terms Adware You can skip this ad in 5 seconds