Netskope Threat Labs

DnsSystem

ATP Sandbox Adv. HeuristicsAV

DnsSystem is a .NET based DNS backdoor, a customized version of the open source DIG.net tool, that the HEXANE threat actor has used since at least June 2022. Its DNS based channel hides command and control traffic inside ordinary name resolution.

First seen
April 2023
Last seen
October 2026

9 techniques across 6 tactics.

TA0002 Execution

TA0003 Persistence

  • T1547Boot or Logon Autostart Execution

TA0007 Discovery

  • T1033System Owner/User Discovery

TA0009 Collection

  • T1005Data from Local System

TA0011 Command and Control

TA0010 Exfiltration

  • T1041Exfiltration Over C2 Channel
Alert Name
ByteCode-MSIL.Trojan.DnsSystem
Generic.DnsSystem.A.37211CA2