Disguising Exfiltrated Data

Current Berkman People and Projects 2014-08-21

Summary:

There's an interesting article on a data exfiltration technique. What was unique about the attackers was how they disguised traffic between the malware and command-and-control servers using Google Developers and the public Domain Name System (DNS) service of Hurricane Electric, based in Fremont, Calif. In both cases, the services were used as a kind of switching station to redirect traffic...

Link:

https://www.schneier.com/blog/archives/2014/08/disguising_exfi.html

From feeds:

Gudgeon and gist » Schneier on Security
Fair Use Tracker » Current Berkman People and Projects

Tags:

disguise dns google malware trafficanalysis

Authors:

schneier

Date tagged:

08/21/2014, 10:30

Date published:

08/21/2014, 07:08