Sunburst: connecting the dots in the DNS requests
SecureList
DECEMBER 18, 2020
Other advanced threat groups are also known to adopt similar strategies, for instance with hardware or firmware implants, which “sleep” for weeks or months before connecting to their C2 infrastructure. In the initial phases, the Sunburst malware talks to the C&C server by sending encoded DNS requests. Low-level details.
Let's personalize your content