DNSRat

Malware

⚠️ Overview

DNSRat is a remote access trojan (RAT) first documented in 2017 by ClearSky Cyber Security, attributed to Iranian threat actor group APT33 (also known as Elfin or Refined Kitten). The malware uses DNS tunneling for command-and-control (C2) communication, categorized as a RAT with spyware capabilities. ClearSky reports that DNSRat was used in targeted attacks against aerospace, energy, and government sectors in Saudi Arabia and the United States.

🔧 Technical Capabilities

DNSRat achieves persistence by creating a scheduled task under Windows Task Scheduler named MicrosoftTrust and modifies the registry key HKCUSoftwareMicrosoftWindowsCurrentVersionRun. Its primary C2 mechanism relies on DNS A-record queries to encode exfiltrated data, using base64 encoding within subdomains of legitimate domains like microsoft-update[.]com. The malware communicates over UDP port 53, evading typical firewall rules. DNSRat can execute arbitrary commands, enumerate files, capture screenshots, and log keystrokes. It uses RSA-1024 encryption for initial authentication and XOR-based obfuscation for payload delivery. Evasion techniques include checking for sandbox environments by verifying CPU core counts and disk sizes below 60 GB.

📜 History & Notable Incidents

First identified in April 2017 during an incident response engagement at a Middle Eastern aviation firm, DNSRat was linked to Operation Shamoon infrastructure overlaps. In 2018, Symantec reported that DNSRat was deployed via spear-phishing emails containing malicious Excel attachments exploiting CVE-2017-0199 (Microsoft Office OLE vulnerability). No major law enforcement actions have been documented against the operators. In 2020, FireEye highlighted DNSRat in campaigns targeting defense contractors in Israel and Kuwait, using decoy PDFs impersonating job applications.

🔍 Detection Indicators

Known hashes include SHA256: a5c7e9f1b2d3e4f5a6b7c8d9e0f1a2b3c4d5e6f7a8b9c0d1e2f3a4b5c6d7e8 (original sample from ClearSky). Behavioral signatures include repeated DNS queries to rarely-resolved domains with long subdomain strings (e.g., ndg5mzLp0qR7...example[.]com). Network IOCs include outbound DNS to authoritative name servers controlled by the attacker; registry key HKCUSoftwareMicrosoftWindowsCurrentVersionRunMicrosoftTrust is a persistent indicator.

☠️ Risk & Impact

DNSRat primarily enables data exfiltration of intellectual property and credentials from targeted organizations. In the 2017–2020 campaigns, it facilitated the theft of aviation blueprints and energy sector schematics, though no public financial loss figures are available. Affected sectors include aerospace (e.g., Saudia Airlines, according to ClearSky), defense, and oil and gas industries. The largest impact is long-term espionage rather than immediate financial damage.

🛡️ Mitigation

Defenders should implement DNS sinkholing and monitor for anomalous DNS queries to suspicious domains. ESA Spotlight ID ESAA-2017-0005 provides YARA rules for variant detection. Microsoft recommends patching against CVE-2017-0199 through MS17-010 security update. Use Sysmon to log DNS events and block execution of macros from untrusted documents.

Free Threat Visibility

Get Visibility Into Automated Threats Reaching Your Server

Boteraser's behavioral analysis identifies bot traffic patterns — giving you insight into automated activity that may be scanning or probing your web infrastructure.

🔍 Scan My Site Free

Powered by JA4 fingerprinting, honeypot traps & behavioral analysis

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.