Palo Alto Networks' Unit 42 reported that multiple malware families, including Dyreza, abused the Session Traversal Utilities for NAT (STUN) protocol to discover public IP addresses and blend malicious traffic into communications commonly permitted for VoIP, messaging, and video services. The researchers said the investigation was prompted by earlier reporting on Dyreza and expanded through WildFire telemetry, which showed that STUN misuse was not isolated to a single threat family.
The analysis found notable spikes in malicious STUN activity across 2014 and identified two non-Dyreza-associated servers—stun.qvod.com and stun.qq.com—as the dominant destinations, with stun.qvod.com accounting for 4,705 samples, or about 75% of the extended-list total. Unit 42 also observed a sharp drop in QVOD-related STUN traffic around April that likely aligned with the service's shutdown, followed by a later increase in Dyreza-linked STUN use as the banking trojan incorporated the capability, underscoring how attackers were adopting legitimate network protocols to conceal command-and-control activity.

Get the actors, campaigns, and ATT&CK mapping behind it.
3 events from the most recent confirmed update back to the earliest known activity.
Palo Alto Networks' WildFire telemetry showed notable spikes in malware using the STUN protocol in January, March, and again from July through September 2014, depending on the server set analyzed. The activity involved multiple malware families rather than Dyreza alone.
The analysis notes a sharp decline in malware STUN traffic tied to QVOD-related servers around April 2014, which it says likely correlates with the shutdown of the Qvod service. This marked a reduction in abuse involving stun.qvod.com.
After a Stop Malvertising report on Dyreza prompted further investigation, Palo Alto Networks analyzed WildFire telemetry and found several malware families abusing STUN. The report highlighted stun.qvod.com and stun.qq.com as the dominant servers in observed malicious STUN traffic, with stun.qvod.com accounting for 4,705 samples.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 40 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
1 reference tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.