Description
DnsSystem is a .NET based DNS backdoor, a customized version of the open source DIG.net tool, that the HEXANE threat actor has used since at least June 2022. Its DNS based channel hides command and control traffic inside ordinary name resolution.
Stats
- First seen
- April 2023
- Last seen
- October 2026
MITRE ATT&CK techniques
9 techniques across 6 tactics.
Associated groups
Alert name variants
| Alert Name |
|---|
| ByteCode-MSIL.Trojan.DnsSystem |
| Generic.DnsSystem.A.37211CA2 |