/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

← → days · ↑ ↓ browse · Enter similar · o open

Researchers uncover PowerShell Trojan that uses DNS queries to get its orders

Delivered by “secure” Word doc, pure PowerShell malware fetches commands from DNS TXT records.  —  Researchers at Cisco's Talos threat research group are publishing research today on a targeted attack delivered …

Ars Technica Sean Gallagher

Context & Ripple Effects

This Talos disclosure extends a pattern Cisco's researchers had already documented in 2016, when Word documents were used to deliver BlackEnergy malware tied to attacks on Ukraine's critical infrastructure — the trusted-document lure is the constant, but the payload here goes further by running entirely in PowerShell rather than dropping a traditional binary.

What makes this one analytically notable is the command-and-control channel: instead of beaconing to attacker-owned servers, the Trojan reads instructions from DNS TXT records, hiding its traffic inside queries every network already makes constantly. The disclosure landed months before Microsoft's Lee Holmes laid out the company's efforts to harden the PowerShell framework, which has long been a high-profile target precisely because attackers abuse a legitimate administrative tool.

First-order effects

  • Defenders at organizations receiving targeted Word documents can no longer treat 'no binary dropped' as benign — Talos' findings mean security teams must inspect PowerShell activity and DNS query patterns, not just file attachments.
  • The operators behind this campaign lose their infrastructure once the specific domains serving TXT-record commands are identified and sinkholed or blocked, forcing them to rebuild on new nameservers.

Second-order effects

  • Microsoft faces pressure to keep tightening PowerShell — logging, script blocking, and constrained language modes become selling points for Windows security, a push the company itself later articulated through its own framework-hardening effort.
  • DNS becomes a monitoring surface: enterprises that treated resolver traffic as plumbing now have reason to log and anomaly-detect TXT record lookups, shifting spend toward DNS-layer security tooling.

Third-order effects

  • If living-off-the-land techniques like pure-PowerShell payloads plus covert DNS channels keep spreading, the industry moves from signature-based detection toward behavioral analytics over legitimate tools — a shift visible later in Microsoft's own forensics work, such as its detailed teardown of the Solorigate DLL used to backdoor SolarWinds Orion, where understanding abuse of trusted software was central.
  • Talos' subsequent reporting that state-backed hackers were brazenly hijacking domains in a months-long DNS campaign suggests DNS abuse scales from a clever C2 trick into strategic terrain worth policing — pushing registrars and DNS operators toward greater accountability for how their infrastructure gets weaponized.

The trend: Malware is migrating from dropped binaries into trusted system tools and legitimate protocols like PowerShell and DNS, forcing the security industry to police behavior on networks rather than files.