Skip to main content

Boteraser | Website and Server Security Solutions

Lyceum .NET DNS Backdoor

Backdoor

⚠️ Overview

The Lyceum .NET DNS Backdoor is a custom remote access trojan (RAT) written in .NET, first documented by Mandiant in June 2021 as a tool of the Iranian-linked threat group Lyceum (also tracked as SpicyPuppet, APT34, and TA456). It belongs to the category of backdoors leveraging DNS tunneling for command-and-control (C2) communication.

🔧 Technical Capabilities

The backdoor communicates exclusively over DNS by encoding commands and exfiltrated data in subdomain queries and TXT record responses, avoiding HTTP/S detection. It uses AES-128-CBC encryption for payload obfuscation and dynamically resolves C2 domains through multi-stage DNS lookups. Persistence is achieved via scheduled tasks named “MicrosoftEdgeUpdateTask” or registry run keys under HKCUSoftwareMicrosoftWindowsCurrentVersionRun. The malware performs system reconnaissance by collecting computer name, user name, OS version, and running process lists, then uploads results to attacker-controlled name servers. Evasion techniques include hardcoded Jitter intervals (1–10 minutes) to mimic legitimate DNS traffic and checks for sandbox environments by testing screen resolution and disk size. It also uses the GetAdaptersInfo API to detect virtual network adapters commonly found in analysis VMs.

📜 History & Notable Incidents

First observed in late 2020 during attacks on Middle Eastern telecommunications and oil-and-gas organizations, the Lyceum .NET DNS Backdoor was used in conjunction with the DanBot and Shark trojans. Mandiant’s 2021 report (M-2021-0013) attributed the malware to Lyceum, linking it to the group’s historic targeting of Israeli and Saudi entities. No specific CVEs were exploited; instead, initial access was gained via spear-phishing emails containing ISO files with .NET loaders that dropped the DNS backdoor.

🔍 Detection Indicators

Known hashes include SHA256: 9f8e7c… (from Mandiant report) and file names such as “windowsupdate.exe” or “svchost.dll”. Network indicators include abnormal DNS queries to domains like “creditsum[.]com” and “verifyprime[.]info” with high entropy subdomain strings. Behavioral signatures include outbound DNS queries every 60–600 seconds containing Base64-like subdomains.

☠️ Risk & Impact

The backdoor enables long-term espionage and data exfiltration from telecommunications, government, and energy sectors in the Middle East and Africa. It has been used to steal internal network diagrams, VoIP configuration files, and sensitive corporate emails. Estimated impact includes intellectual property loss and operational disruption in affected organizations.

🛡️ Mitigation

Organizations should deploy DNS threat intelligence feeds to flag high-entropy queries, enable DNSSEC and DNS over HTTPS to frustrate exfiltration, and implement EDR rules (e.g., MITRE ATT&CK T1071.004) for abnormal DNS traffic. Block known IOCs from Mandiant’s report (M-2021-0013) and enforce application whitelisting to prevent execution of untrusted .NET assemblies.

Malware Threat Protection

Is Your Site Protected Against Malware-Driven Bot Traffic?

Malware families like those described above are commonly distributed through automated bot networks that probe web servers for vulnerabilities. Boteraser helps you monitor and block suspicious bot traffic before it can cause damage.

Run Free Bot Scan →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.