Skip to content
Threat Feed
medium advisory

Detection of Internal Host Connections to Dynamic DNS Providers

This detection identifies DNS queries from internal hosts to known dynamic domain providers, a technique frequently used by attackers to maintain flexible command-and-control infrastructure and host malicious payloads.

Attackers frequently leverage dynamic DNS (DDNS) services to facilitate command-and-control (C2) communication and host malicious content. By utilizing DDNS, adversaries can quickly update the IP addresses associated with a domain, allowing them to evade static firewall blocks and maintain persistent access even if their infrastructure is disrupted or migrated. This detection analytic monitors DNS query logs for connections to known DDNS providers. While the usage of dynamic DNS is not inherently malicious, as some legitimate applications rely on these services, the activity warrants investigation to distinguish between authorized traffic and potential adversarial staging or C2 callback behavior. Defenders should monitor for spikes in DDNS resolution requests, especially from endpoints that do not typically interact with these services.

Attack Chain

  1. Attacker registers a domain name through a free or low-cost Dynamic DNS service.
  2. Attacker deploys malicious infrastructure (e.g., C2 server or file server) and associates it with the DDNS domain.
  3. Victim system is compromised through initial access vector (e.g., drive-by compromise).
  4. Compromised endpoint performs a DNS lookup for the adversary-controlled DDNS domain.
  5. DNS resolver returns the current, attacker-controlled IP address.
  6. Endpoint initiates an outbound network connection to the resolved IP.
  7. Attacker gains control over the endpoint to execute commands, exfiltrate data, or deploy secondary payloads.

Impact

Successful exploitation allows attackers to bypass network-level security controls, evade domain-based blacklisting through rapid IP rotation, and maintain stable long-term C2 access to compromised corporate environments.

Recommendation

  • Deploy the provided DNS query detection logic to SIEM to identify connections to known dynamic DNS domains.
  • Establish a process to regularly update the local lookup file (dynamic_dns_providers_local.csv) with emerging DDNS providers identified in network traffic.
  • Implement DNS filtering to block known malicious or untrusted DDNS domains if they are not required for business operations.
  • Investigate anomalous outbound connections from internal endpoints that resolve to dynamic DNS domains using the drilldown search provided in the detection logic.

Immediate actions

Deploy DNS detection rules and integrate DDNS lookup files.

Detection Engineering 48h

Threat Hunt

Search for DNS resolution patterns to identify non-standard DDNS providers.

T1189 medium medium confidence hunt now

Data: DNS request logs

Detection coverage 1

Detect Hosts Connecting to Dynamic DNS Providers

medium

Detects DNS queries to known dynamic DNS domains which may indicate C2 activity or malicious staging.

sigma tactics: command_and_control techniques: T1189 sources: dns_query

Detection queries are available on the platform. Get full rules →