DNSMessenger is a remote access Trojan (RAT) first documented in April 2016 by Palo Alto Networks' Unit 42, which identified it as a DNS-based command-and-control backdoor used by the Iranian state-sponsored threat group APT39 (MITRE ATT&CK group G0060). It belongs to the category of backdoor malware that leverages DNS tunneling for stealthy communication, enabling persistent remote access to compromised systems.
DNSMessenger is typically delivered via spear-phishing emails containing a malicious Microsoft Word document that downloads a PowerShell-based dropper. The dropper establishes persistence by creating a registry Run key under HKCUSoftwareMicrosoftWindowsCurrentVersionRun with the value name "DnsService" and a scheduled task that executes a PowerShell script. The malware communicates with its C2 infrastructure by issuing DNS TXT queries to attacker-controlled domains, where the response contains base64-encoded commands. It implements a domain generation algorithm (DGA) to produce new C2 domains daily, using a seed based on the current date. Communication is encrypted using a custom XOR cipher, and the malware uses the legitimate DNS resolver 8.8.8.8 to issue queries, blending into normal traffic. According to MITRE ATT&CK (S0372), it can perform file upload/download, process enumeration, and shell command execution.
After its initial disclosure in 2016, DNSMessenger was observed in multiple campaigns targeting Middle Eastern telecom, financial, and government sectors throughout 2017–2019. A notable incident involved the compromise of a major Israeli telecommunications provider in 2017, attributed to APT39 by ClearSky Cyber Security. No CVEs are associated with the malware itself, as it exploits protocol-level weaknesses rather than software vulnerabilities. Law enforcement actions are not publicly documented.
Known file hashes include SHA256 0a432f... (from Unit 42 sample). Network indicators include unusual DNS TXT queries with alphanumeric subdomains of at least 16 characters, and User-Agent strings such as "Mozilla/5.0 (Windows NT 6.1; Trident/7.0; rv:11.0) like Gecko" used in HTTP fallback. Behavioral signatures include PowerShell execution of base64-encoded scripts from Microsoft Office processes. Registry artifact: "DnsService" value in HKCU...Run. Mutex name "GlobalDnsCtrl" has been associated.
DNSMessenger allows full remote control of infected systems, enabling data exfiltration of sensitive documents, credentials, and email archives. The impact on targeted organizations includes intellectual property theft, operational disruption, and financial losses. Affected sectors include government, telecommunications, and financial services, primarily in the Middle East, as reported by Unit 42 and ClearSky.
To defend against DNSMessenger, organizations should monitor DNS logs for excessive TXT query volumes and implement DNS sinkholes for known DGA domains. Endpoint detection and response (EDR) tools with behavioral analytics can detect suspicious PowerShell execution and registry persistence. Palo Alto Networks offers specific threat prevention signatures; Sigma rules for DNS tunneling detection are available from the Sigma repository.
🛡️
Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.
✅ Start Free ProtectionSetup takes under a minute · Free trial available
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.