Now They’re Hiding Malware in Hexadecimal Chunks Inside DNS Records

Source: Ars Technica Now They’re Hiding Malware in Hexadecimal Chunks Inside DNS Records

As If DNS Wasn’t Already Enough Of A Headache

Security researchers have found yet another way to brighten your day; you can blame Ian Campbell of DomainTools for this new ray of sunshine.  He has found hackers using DNS to infect machines in a new way, beyond the currently known DNS exploit of hiding PowerShell scripts in the TXT records on a site.  In this case malicious actors translate their code into hex, and then stash it in various TXT records of subdomains associated with a single domain.  With a bit of tweaking to the site to ensure your machine queries enough of those DNS records to get all the hex code, your computer could be infected without you ever doing anything other than visiting that site.

Antivirus and other protective software do not monitor DNS requests, and even something like a Pi-hole or DNSFilter might not protect you from this sort of attack.  Thankfully the complexity of the malware that can be spread this way is limited, you can only fit so much hex code in a TXT record before it would become obviously modified and as anyone who has to slap DNS around knows, there’s no guarantee that a machine won’t just ignore some DNS records.  It is still rather worrisome to see yet another attack surface appear and need to be defended against.

One of the uses that this attack has been used for suggests it might actually be something websites might adopt on purpose.  There was a site found with this hex code in it’s DNS and the code was specifically designed to feed AI bots prompt injections, with some amusing instructions.  This could, at least briefly, stop websites from being treated as free training data by the LLM bots plaguing the web.

Researchers from DomainTools on Tuesday said they recently spotted the trick being used to host a malicious binary for Joke Screenmate, a strain of nuisance malware that interferes with normal and safe functions of a computer.

Video News

About The Author

Jeremy Hellstrom

Call it K7M.com, AMDMB.com, or PC Perspective, Jeremy has been hanging out and then working with the gang here for years. Apart from the front page you might find him on the BOINC Forums or possibly the Fraggin' Frogs if he has the time.

Leave a reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Latest Podcasts

Archive & Timeline

Previous 12 months
Explore: All The Years!