Hackers Hide Malware in DNS Records: The Shocking Technique Evading Cybersecurity Tools

Listen to this Post

Featured Image
A New Breed of Cyber Threat Is Hiding in Plain Sight

Cybercriminals are becoming increasingly cunning, and their latest trick is both disturbing and brilliant. Instead of using conventional file-sharing or network-based methods to deliver malware, they’re now embedding it directly within DNS (Domain Name System) records — the very infrastructure that helps the internet function. A recent investigation uncovered how attackers are storing pieces of executable files inside DNS TXT records, effectively turning DNS servers into secret file lockers. These files are fragmented and cleverly disguised to evade detection, revealing a complex new frontier in cyber warfare.

DNS-Based Malware Distribution Exposed

Security analysts have stumbled upon a sophisticated malware delivery network that operates almost invisibly by exploiting DNS infrastructure. Using forensic tools like DNSDB Scout and advanced regular expressions, researchers detected file headers hidden within DNS TXT records — a type of DNS field typically used for text data. These headers matched known signatures for various file formats, including JPEG, PNG, PDF, ZIP, EXE, and ELF binaries. This finding led to the discovery of full files being fragmented across multiple DNS entries and stored in TXT fields that persist until DNS caches clear them.

Digging into passive DNS data from 2021 and 2022, the team unearthed a magic byte sequence linked to executable files, distributed over three domains with similar subdomain structures. One domain in particular, “.felix.stf.whitetreecollective[.]com,” contained an extensive list of subdomains with sequentially numbered TXT records. When pieced together, these records formed complete malicious files.

The result? Researchers found two distinct malware samples identified as Joke Screenmate — a type of nuisance malware that pretends to damage the system but actually just floods users with fake error messages, interferes with controls, and slows down operations. These files matched SHA256 hashes and demonstrated how the malware payload was stealthily constructed from DNS fragments.

But it doesn’t stop there. Analysts also discovered that the same method was being used for command-and-control (C2) communication. By embedding PowerShell scripts into TXT records under domains like drsmitty[.]com, hackers ensured that infected systems could retrieve instructions via DNS, bypassing traditional firewalls and endpoint protection tools. The malicious PowerShell stager reached out to a remote Covenant C2 server, highlighting how malware authors have weaponized DNS not only for delivery but also for persistence and control.

This strategy takes advantage of a fundamental trust in DNS, a core internet protocol rarely scrutinized for malware. Its stealthy nature and ability to bypass detection make it a dangerous tool in the hands of attackers — and a nightmare for cybersecurity professionals who may not even be looking there.

What Undercode Say:

The Weaponization of DNS Infrastructure

This report reveals a troubling evolution in cyberattacks — the shift toward misusing essential internet infrastructure to distribute and manage malware. DNS is a ubiquitous protocol that’s often taken for granted, making it an attractive vector for covert activities. By embedding executable fragments into DNS TXT records, attackers achieve both stealth and longevity, avoiding typical security triggers.

DNS TXT Records: The New Malware Storage Device

Traditionally used to store SPF and DMARC settings, DNS TXT records are now being transformed into repositories for malware. The forensic discovery of magic bytes that match file headers within these records demonstrates how creative and dangerous this vector can be. Because DNS records often go unmonitored and unfiltered, attackers can easily fly under the radar.

File Fragmentation Tactics

Splitting malware into hundreds of TXT fragments and reassembling them later is an effective way to avoid signature-based detection. It also creates challenges for incident responders, as the malware payload doesn’t exist in one location — it’s scattered and reconstructed on the fly. This method also adds resilience, as only partial removal or detection won’t neutralize the threat.

The ScreenMate Malware Twist

Although Joke Screenmate malware

Command-and-Control Over DNS

Embedding C2 communication into TXT records is particularly alarming. It bypasses most firewalls and intrusion detection systems, which typically allow DNS traffic by default. Using PowerShell scripts inside TXT records that fetch payloads from servers like Covenant C2 illustrates just how versatile this channel can be for ongoing compromise and control.

Persistent Threats That Evade Cleanup

Unlike typical infections that rely on installed files or registry keys, this method can restore malware even after system cleanup if the DNS source remains intact. Unless DNS records are flushed or altered, the payload may keep regenerating itself across compromised endpoints.

Implications for Security Professionals

This tactic challenges conventional detection methods. Most endpoint protection tools are not designed to inspect DNS TXT records for binary code fragments. Organizations now need to consider DNS monitoring and logging as essential parts of their defense strategy.

A New Front in the Cyber Arms Race

With the use of DNS as a covert storage medium, cybercriminals are showing a deep understanding of both internet architecture and human oversight. This method demonstrates a shift toward deeper, infrastructure-level attacks that will require equally sophisticated countermeasures.

🔍 Fact Checker Results:

✅ Malware was indeed discovered stored in DNS TXT records

✅ Confirmed SHA256 hashes matched known Joke Screenmate variants

✅ PowerShell stager script linked to Covenant C2 was verified in DNS logs

📊 Prediction:

Cybercriminals will continue to abuse DNS infrastructure in increasingly complex ways. As defenders catch up, attackers may evolve to use DNS-over-HTTPS (DoH) or other encrypted methods to conceal even more advanced malware. Expect a sharp rise in security tools that analyze DNS activity at a granular level to address this blind spot.

References:

Reported By: cyberpress.org
Extra Source Hub:
https://www.discord.com
Wikipedia
OpenAi & Undercode AI

Image Source:

Unsplash
Undercode AI DI v2

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow UndercodeNews & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin