Security News > 2023 > June > Chinese hackers use DNS-over-HTTPS for Linux malware communication

Chinese hackers use DNS-over-HTTPS for Linux malware communication
2023-06-14 17:01

The Chinese threat group 'ChamelGang' infects Linux devices with a previously unknown implant named 'ChamelDoH,' allowing DNS-over-HTTPS communications with attackers' servers.

The link between ChamelGang and the new Linux malware is based on a domain previously associated with the threat actor and a custom privilege elevation tool observed by Positive Technologies in past ChamelGang campaigns.

DNS queries are sent as unencrypted, plain text, allowing organizations, ISPs, and others to monitor the DNS requests.

This is a double-edged sword, as malware can use it as an effective encrypted communication channel, making it harder for security software to monitor for malicious network communication.

In the case of ChamelDoH, DNS-over-HTTPS provides encrypted communication between an infected device and the command and control server, making malicious queries indistinguishable from regular HTTPS traffic.

DoH can help bypass local DNS servers by using DoH-compatible servers provided by reputable organizations, which was not seen in this case.


News URL

https://www.bleepingcomputer.com/news/security/chinese-hackers-use-dns-over-https-for-linux-malware-communication/

Related vendor

VENDOR LAST 12M #/PRODUCTS LOW MEDIUM HIGH CRITICAL TOTAL VULNS
Linux 11 64 2337 1502 67 3970