commandandcontrol (2)

31269810271?profile=RESIZE_400xResearch published by Chainalysis shows that nation-state cyber actors are leading an unprecedented expansion in the use of public distributed ledgers to orchestrate cyberattacks.  Analysts recorded a 440% year-on-year surge in what the industry terms "blockchain dead drop" (BDD) techniques. In these schemes, threat actors insert malicious commands and routing instructions straight into public ledger records and automated smart contracts.[1]

Conventional attack infrastructure relies on centraliz

31204934889?profile=RESIZE_400xFortiGuard Labs recently captured several malicious samples that were sending malformed DNS queries.  After conducting an in-depth analysis, researchers determined that these samples are TrickBot variants that use DNS tunneling to communicate with their command-and-control (C2) servers.

TrickBot is a modular malware family that FortiGuard Labs has repeatedly captured over the past decade.  Its modular architecture enables it to extend its capabilities by downloading and executing additional modu