SOMNIRECORD is a C++ Windows backdoor associated with the REF2924 intrusion set, a state-sponsored, espionage-motivated cluster assessed as China-nexus. It uses DNS as its command-and-control transport, retrieving queued commands from DNS TXT records and returning hex-encoded command output through DNS queries, allowing its traffic to blend with DNS and potentially bypass egress filtering and network monitoring controls. SOMNIRECORD generates a per-instance identifier, supports host discovery and running-process enumeration, executes programs already present on the compromised host, and permits operators to adjust its beacon interval. It can also write a hard-coded ASPX web shell to an operator-selected location. Its implementation has been assessed as adapted from logic resembling the open-source DNS-Persist project. SOMNIRECORD has been observed alongside SIESTAGRAPH, NAPLISTENER, and DOORME in REF2924 operations affecting government environments.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
This environment has already seen the emergence of the REF2924 intrusion set (SIESTAGRAPH, NAPLISTENER, SOMNIRECORD, and DOORME).
7 distinct techniques documented for this family, organized by ATT&CK tactic.
2 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A named implant/tool previously observed in the REF2924 intrusion set.
Previously observed malware in the same government victim environment; no functionality is described here.
Referenced as a previously analyzed malware family whose payload was likely inspired by open-source code.
A C++ DNS-tunneling backdoor attributed to REF2924 activity. It uses DNS TXT-record queries for C2 tasking and DNS subdomains to send hex-encoded command output. Supported functions include host reconnaissance, process listing via tasklist, execution of locally available software such as cmd.exe, beacon-interval changes, and deployment of a hardcoded ASPX webshell.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.