{"id":470,"date":"2024-12-11T07:15:44","date_gmt":"2024-12-11T07:15:44","guid":{"rendered":"https:\/\/familiebuckens.nl\/?p=470"},"modified":"2025-02-24T08:08:01","modified_gmt":"2025-02-24T08:08:01","slug":"zloader-malware-returns-with-dns-tunneling-to-stealthily-mask-c2-comms","status":"publish","type":"post","link":"https:\/\/familiebuckens.nl\/index.php\/2024\/12\/11\/zloader-malware-returns-with-dns-tunneling-to-stealthily-mask-c2-comms\/","title":{"rendered":"ZLoader Malware Returns With DNS Tunneling to Stealthily Mask C2 Comms"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">Cybersecurity researchers have discovered a new version of the&nbsp;<strong>ZLoader<\/strong>&nbsp;malware that employs a Domain Name System (DNS) tunnel for command-and-control (C2) communications, indicating that the threat actors are continuing to refine the tool after&nbsp;<a href=\"https:\/\/thehackernews.com\/2024\/01\/new-zloader-malware-variant-surfaces.html\" rel=\"noreferrer noopener\" target=\"_blank\">resurfacing<\/a>&nbsp;a year ago.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">&#8220;Zloader 2.9.4.0 adds notable improvements including a custom DNS tunnel protocol for C2 communications and an interactive shell that supports more than a dozen commands, which may be valuable for ransomware attacks,&#8221; Zscaler ThreatLabz\u00a0<a href=\"https:\/\/www.zscaler.com\/blogs\/security-research\/inside-zloader-s-latest-trick-dns-tunneling\" target=\"_blank\" rel=\"noreferrer noopener\">said<\/a>\u00a0in a Tuesday report. &#8220;These modifications provide additional layers of resilience against detection and mitigation.&#8221;<\/p>\n\n\n<a class=\"wp-block-read-more\" href=\"https:\/\/familiebuckens.nl\/index.php\/2024\/12\/11\/zloader-malware-returns-with-dns-tunneling-to-stealthily-mask-c2-comms\/\" target=\"_self\"><a href=\"https:\/\/thehackernews.com\/2024\/12\/zloader-malware-returns-with-dns.html\">ZLoader Malware Returns With DNS Tunneling to Stealthily Mask C2 Comms<\/a><span class=\"screen-reader-text\">: ZLoader Malware Returns With DNS Tunneling to Stealthily Mask C2 Comms<\/span><\/a>","protected":false},"excerpt":{"rendered":"<p>Cybersecurity researchers have discovered a new version of the&nbsp;ZLoader&nbsp;malware that employs a Domain Name System (DNS) tunnel for command-and-control (C2) communications, indicating that the threat actors are continuing to refine the tool after&nbsp;resurfacing&nbsp;a year ago. &#8220;Zloader 2.9.4.0 adds notable improvements including a custom DNS tunnel protocol for C2 communications and&#8230;<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[3],"tags":[31,54],"class_list":["post-470","post","type-post","status-publish","format-standard","hentry","category-malware","tag-31","tag-command-and-control"],"_links":{"self":[{"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/posts\/470","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/comments?post=470"}],"version-history":[{"count":1,"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/posts\/470\/revisions"}],"predecessor-version":[{"id":471,"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/posts\/470\/revisions\/471"}],"wp:attachment":[{"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/media?parent=470"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/categories?post=470"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/tags?post=470"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}