Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The SystemSyncs.exe file ... is a custom Trojan created by the OilRig group called “ALMA Communicator” ... The ALMA Communicator Trojan is a backdoor Trojan that uses DNS tunneling exclusively to receive commands from the adversary and to exfiltrate data.
6 distinct techniques documented for this family, organized by ATT&CK tactic.
ATT&CK Ⓡ does not have an explicit technique assigned for DNS Tunneling; instead, it identifies this technique as a sub-technique of Command and Control Over Application Layer Protocol, described as follows: “Adversaries may communicate using the Domain Name System (DNS) application layer protocol to avoid detection/network filtering by blending in with existing traffic. Commands to the remote system, and often the results of those commands, will be embedded within the protocol traffic between the client and server.”
4 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named as an example of a malicious tool that has leveraged DNS tunneling.
Custom OilRig backdoor trojan that relies exclusively on DNS tunneling for C2. It reads an external cfg file for configuration, stages batch files in Download and Upload folders, executes received batch scripts, and exfiltrates command output via specially crafted DNS requests.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.