Glimpse malware uses alternative DNS to evade detection
#1
Quote:Security researchers have detailed how the Glimpse malware uses a text mode as an alternative DNS resource record type.
 
According to a blog post by security researchers Jon Perez and Jonathan Lepore at IronNet, the malware is written in PowerShell and associated with APT34. It is executed by Visual Basic script, yet how the script is initiated remains unclear, researchers said.
 
They added that the malware is similar to the PoisonFrog malware. Both use "A" resource records to communicate with their controller. Glimpse differs by its ability to use text mode as an alternative DNS resource record type. This allows it to provide tasking in fewer transactions. Additionally, instead of relying on existing .NET DNS libraries, it manually crafts its DNS queries and communicates directly with the controller.
Source(full read)- https://www.scmagazineuk.com/glimpse-mal...le/1665336
[-] The following 2 users say Thank You to dhruv2193 for this post:
  • harlan4096, silversurfer
Reply


Messages In This Thread
Glimpse malware uses alternative DNS to evade detection - by dhruv2193 - 11 November 19, 13:50

Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
Free Download Manager 6.33.1.6648
Changes in 6.33.1....harlan4096 — 08:33
Brave 1.87.190 (Chromium 145.0.7632.109)
Release v1.87.190 ...harlan4096 — 08:32
LibreOffice 25.8.5
Berlin, 19 Februar...harlan4096 — 08:30
Google Chrome 145.0.7632.109/110
Google Chrome 145....harlan4096 — 08:29
Internet Download Manager 6.32 Build 9
Internet Download ...Kool — 00:41

[-]
Birthdays
Today's Birthdays
No birthdays today.
Upcoming Birthdays
avatar (46)dimaWeami
avatar (38)Michaelaburi
avatar (46)dpascoal
avatar (44)Baihu

[-]
Online Staff
There are no staff members currently online.

>