First-ever malware strain spotted abusing new DoH (DNS over HTTPS) protocol

Discussion in 'malware problems & news' started by guest, Jul 3, 2019.

  1. guest

    guest Guest

    First-ever malware strain spotted abusing new DoH (DNS over HTTPS) protocol
    Godlua, a Linux DDoS bot, is the first-ever malware strain seen using DoH to hide its DNS traffic
    July 3, 2019

    https://www.zdnet.com/article/first...tted-abusing-new-doh-dns-over-https-protocol/
     
  2. itman

    itman Registered Member

    Joined:
    Jun 22, 2010
    Posts:
    8,649
    Location:
    U.S.A.
    Dang! I just enabled DoH in FireFox.
     
  3. guest

    guest Guest

    Iranian hacker group becomes first known APT to weaponize DNS-over-HTTPS (DoH)
    Kaspersky says Oilrig (APT34) group has been using DoH to silently exfiltrate data from hacked networks
    August 4, 2020

    https://www.zdnet.com/article/irani...st-known-apt-to-weaponize-dns-over-https-doh/
     
  4. xxJackxx

    xxJackxx Registered Member

    Joined:
    Oct 23, 2008
    Posts:
    9,187
    Location:
    USA
    Seems like an exaggerated situation to me. Words like weaponizing and abusing seem over the top. They are taking advantage of the technology for sure. It seems like the lesser of your problems at the point at which it would matter.
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.
    Dismiss Notice