ZLoader Malware Returns With DNS Tunneling to Stealthily Mask C2 Comms post, december 11, 2024februari 24, 2025 Cybersecurity researchers have discovered a new version of the ZLoader malware that employs a Domain Name System (DNS) tunnel for command-and-control (C2) communications, indicating that the threat actors are continuing to refine the tool after resurfacing a year ago. “Zloader 2.9.4.0 adds notable improvements including a custom DNS tunnel protocol for C2 communications and an interactive shell that supports more than a dozen commands, which may be valuable for ransomware attacks,” Zscaler ThreatLabz said in a Tuesday report. “These modifications provide additional layers of resilience against detection and mitigation.” ZLoader Malware Returns With DNS Tunneling to Stealthily Mask C2 Comms: ZLoader Malware Returns With DNS Tunneling to Stealthily Mask C2 Comms malware 2024Command and Control