typetechniqueconfidencehighcreated2026-08-15updated2026-08-15c2dnsdohfallbackexfiltration

DNS-over-HTTPS Fallback

Overview

Malware using DNS-over-HTTPS (DoH) as a fallback or primary resolution mechanism for C2 infrastructure. DoH tunnels DNS queries inside HTTPS, bypassing local DNS filtering and leaving only TLS traffic on port 443.

Observed In

  • afk-stealer — Hardcoded DoH endpoints: https://1.1.1.1/dns-query, https://dns.google/resolve, https://cloudflare-dns.com/dns-query. ^[/intel/analyses/0b6c65cde50cae62eb3e15a9857193abd2ed130f8d73de6afc3e58ac2397c49a.html]

Detection

  • Monitor for HTTPS requests to known DoH endpoints from non-browser processes.
  • NXLog/Sysmon Event ID 22 (DNS query) will show the HTTPS hostname, not the queried domain.
  • TLS SNI of cloudflare-dns.com or dns.google from unexpected processes.

ATT&CK Mapping

  • T1071.004 — Application Layer Protocol: DNS
  • T1572 — Protocol Tunneling

Related