Palo Alto Networks' Unit 42 reported that the OilRig threat group deployed ALMA Communicator, a malware family designed to use DNS tunneling for command-and-control communications. The activity links OilRig to a covert channel that can blend malicious traffic into normal DNS requests, helping operators maintain access and exchange data while reducing the chance of detection by traditional network monitoring.
The report identifies ALMA Communicator as part of OilRig's broader intrusion toolkit and highlights DNS-based communications as a key tradecraft element in the group's operations. For defenders, the findings underscore the need to inspect anomalous DNS behavior, hunt for suspicious beaconing patterns, and review endpoint activity associated with malware that abuses DNS for persistence and remote control.

Get the actors, campaigns, and ATT&CK mapping behind it.
1 event from the most recent confirmed update back to the earliest known activity.
Palo Alto Networks Unit 42 published a report describing OilRig's use of the 'ALMA Communicator' DNS tunneling trojan. The reference indicates public disclosure of technical details about the malware and its deployment.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
1 reference tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.