Researchers uncover PowerShell Trojan that uses DNS queries to get its orders
Delivered by “secure” Word doc, pure PowerShell malware fetches commands from DNS TXT records. — Researchers at Cisco's Talos threat research group are publishing research today on a targeted attack delivered …
Context & Ripple Effects
This Talos disclosure extends a pattern Cisco's researchers had already documented in 2016, when Word documents were used to deliver BlackEnergy malware tied to attacks on Ukraine's critical infrastructure — the trusted-document lure is the constant, but the payload here goes further by running entirely in PowerShell rather than dropping a traditional binary.
What makes this one analytically notable is the command-and-control channel: instead of beaconing to attacker-owned servers, the Trojan reads instructions from DNS TXT records, hiding its traffic inside queries every network already makes constantly. The disclosure landed months before Microsoft's Lee Holmes laid out the company's efforts to harden the PowerShell framework, which has long been a high-profile target precisely because attackers abuse a legitimate administrative tool.
First-order effects
- Defenders at organizations receiving targeted Word documents can no longer treat 'no binary dropped' as benign — Talos' findings mean security teams must inspect PowerShell activity and DNS query patterns, not just file attachments.
- The operators behind this campaign lose their infrastructure once the specific domains serving TXT-record commands are identified and sinkholed or blocked, forcing them to rebuild on new nameservers.
Second-order effects
- Microsoft faces pressure to keep tightening PowerShell — logging, script blocking, and constrained language modes become selling points for Windows security, a push the company itself later articulated through its own framework-hardening effort.
- DNS becomes a monitoring surface: enterprises that treated resolver traffic as plumbing now have reason to log and anomaly-detect TXT record lookups, shifting spend toward DNS-layer security tooling.
Third-order effects
- If living-off-the-land techniques like pure-PowerShell payloads plus covert DNS channels keep spreading, the industry moves from signature-based detection toward behavioral analytics over legitimate tools — a shift visible later in Microsoft's own forensics work, such as its detailed teardown of the Solorigate DLL used to backdoor SolarWinds Orion, where understanding abuse of trusted software was central.
- Talos' subsequent reporting that state-backed hackers were brazenly hijacking domains in a months-long DNS campaign suggests DNS abuse scales from a clever C2 trick into strategic terrain worth policing — pushing registrars and DNS operators toward greater accountability for how their infrastructure gets weaponized.
The trend: Malware is migrating from dropped binaries into trusted system tools and legitimate protocols like PowerShell and DNS, forcing the security industry to police behavior on networks rather than files.