DnsSystem is a Windows malware family associated with command-and-control communications, host identification, and data theft. It has been observed using the current Windows username to derive a unique identifier for infected users and systems, indicating victim profiling and host tracking functionality. The malware can exfiltrate collected data to its command-and-control infrastructure and supports file upload from compromised machines on operator command. Its network communications may include Base64 encoding of data sent to command and control, consistent with basic traffic obfuscation. DnsSystem has also been delivered through social-engineering lures involving macro-enabled Microsoft Word documents, requiring user interaction to trigger execution. The documented behavior supports classification as a backdoor-oriented malware family used for post-compromise collection and remote tasking on Windows hosts.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
12 distinct techniques documented for this family, organized by ATT&CK tactic.
During the 2016 Ukraine Electric Power Attack, Sandworm Team used the xp_cmdshell command in MS-SQL. During the 2025 Poland Wiper Attacks, the adversaries leveraged PsExec to run cmd.exe commands on multiple victim machines. Numerous malware families and groups are described as using cmd.exe, cmd /c, Windows command shell, or command-line interfaces to execute commands, payloads, reconnaissance, persistence, cleanup, and ransomware actions.
The content repeatedly mentions malicious macros in Word/Excel documents, such as "enable macros," "embedded macros," and "macro-enabled documents."
The content repeatedly describes victims being lured into opening malicious attachments, enabling macros, launching installers, clicking embedded files/links, or otherwise directly executing malicious content.
Sandworm Team leveraged Microsoft Office attachments which contained malicious macros that were automatically executed once the user permitted them... APT29 has used various forms of spearphishing attempting to get a user to open attachments... DarkGate is distributed through phishing links to VBS or MSI objects requiring user interaction for execution.
12 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Backdoor that uses the Windows username to create a unique identifier for infected users and systems.
Malware executed through macro-enabled Word documents.
Malware that can Base64-encode data sent to command-and-control infrastructure.
Malware that can Base64-encode data sent to command-and-control infrastructure.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.