Palo Alto Networks Unit 42 reported that the xHunt campaign deployed CASHY200, a PowerShell-based backdoor that used DNS tunneling for command-and-control and data exfiltration against organizations in Kuwait, including government entities. The malware communicated through DNS A queries and responses to infrastructure including windows64x[.]com, encoding commands and stolen data in subdomains with sequence numbers and command values such as 48, 92, and in older variants 200.
Investigators linked the activity to earlier xHunt infrastructure associated with Sakabota C2 operations and said the campaign ran from spring 2018 through 2019. Delivery methods included malicious Word documents and executable droppers using lures themed around Kuwait government organizations, and Unit 42 said a Kuwait-based victim’s malicious DNS tunneling traffic was blocked by DNS Security in September 2019, cutting off the attackers’ access to compromised systems.

Get the actors, campaigns, and ATT&CK mapping behind it.
7 events from the most recent confirmed update back to the earliest known activity.
On September 16, 2019, a Kuwait-based organization enabled DNS Security, which detected malicious DNS tunneling activity within minutes. Blocking access to windows64x[.]com disrupted the threat actor's communications with compromised systems.
In September 2019, a host in Kuwait was observed beaconing to windows64x[.]com using the same DNS tunneling protocol as CASHY200. The sample appeared tailored to the compromised host because its unique hostname value was hardcoded.
Researchers observed the domain windows64x[.]com being used in June 2019 as a command-and-control server for CASHY200. They also linked the domain to pasta58[.]com, which had been associated with Sakabota C2 activity.
On May 14, 2019, an individual posted on Microsoft TechNet about suspicious tunneling activity involving windows64x[.]com on two servers. The activity matched the same DNS tunneling protocol later seen in the Kuwait intrusion.
On June 3, 2018, researchers observed another executable that installed and executed CASHY200. This sample used firewallsupports[.]com for command-and-control communications.
On May 1, 2018, researchers observed an executable that installed and executed a CASHY200 PowerShell script. The malware communicated with the command-and-control domain windows-updates[.]com.
Researchers found evidence that the threat group used the CASHY200 PowerShell backdoor against Kuwait organizations, including government entities, starting in spring 2018. The campaign continued through 2019 and overlapped with prior xHunt activity.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 35 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
1 reference tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.