Activity timeline
T1071.004 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 18 reports, and 56 of the 56 threats were reported in the twelve months to 2026-09.
How adversaries use it
T1071.004 DNS is catalogued by MITRE ATT&CK under the Command and Control tactic in the Enterprise matrix, as a sub-technique of T1071 Application Layer Protocol. Threadlinqs maps 56 of 2623 tracked threats (2.1%) to it; by severity that is 18 critical, 34 high, 4 medium.
Threats that use T1071.004 most often also use T1071.001 Web Protocols (38 threats), T1027 Obfuscated Files or Information (37 threats), T1140 Deobfuscate/Decode Files or Information (30 threats), T1005 Data from Local System (29 threats), T1036.005 Match Legitimate Resource Name or Location (29 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
19 tracked threat actors appear in the threats that use T1071.004; the most frequent are Cavern Manticore (5), Periwinkle Tempest (2), Woodgnat (2), APT28 (1), APT34 (1).
Mitigations
MITRE ATT&CK lists 2 mitigations for T1071.004.
Data sources
Telemetry that can reveal T1071.004, per MITRE ATT&CK.
- Network Traffic — Network Traffic Content, Network Traffic Flow
Threat actors using it
Tracked threats
The 30 most recent of 56 tracked threats that use T1071.004.
- GTIG: AI-Era Vulnerability Discovery and Exploitation Surge — In-the-Wild Exploitation of BeyondTrust…critical
- Malicious ChatGPT Custom GPT "Plus 5.6" Used in ClickFix Campaign Delivering RAT via DLL Sideloading of…high
- CISA Adds Two Citrix NetScaler Vulnerabilities (CVE-2026-88771, CVE-2026-88772) to KEV Catalogcritical
- Citrix Patches Two Actively Exploited NetScaler Zero-Days (CVE-2026-88771, CVE-2026-88772)critical
- Eclypsium InfraTrust Report: Mass Active Exploitation of Network Management Systems (Cisco FMC/ISE…critical
- PowerShell Cryptomining Loader Abuses Registry-Resident Scripts, DNS TXT Records, and PNG/WAV Steganography…medium
- Spamhaus H1 2026 Botnet Threat Update: Sliver Overtakes Cobalt Strike as Leading C2 Framework, .cn C&C…medium
- BloodAlchemy RAT Traced to Deed RAT/ShadowPad Lineage via VPN Account Compromise and DLL Side-Loadinghigh
- StyleSmuggler — Unpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online Storescritical
- Malware on the Blockchain: EtherHiding/Amatera ClickFix Campaign Adds a Covert WebRTC C2 Channelhigh
- BREEZE COMET (ex-UNC5669) Targets Brazilian Financial Infrastructure with AI-Assisted Custom Malware Suitecritical
- Hundreds of WordPress Sites Hijacked via Malicious Plugins to Deploy Amatera Stealer through EtherHiding and…high
- Qilin-Linked Campaign Exploits MCP Gateway and LLM Framework Flaws (CVE-2026-59822, CVE-2026-42271…critical
- ClickFix Campaigns Deploy PavinLoader With Blockchain-Based C2 and Amatera Stealerhigh
- CrossC2 Cross-Platform Cobalt Strike Loader Deployed with ReadNimeLoader in Attacks Linked to BlackBasta…high
- Cavern Manticore's CAV3RN C2 Framework Adds DNS-Based Channel Selection and Google Apps Script Relayhigh
- Jewelbug APT Runs Espionage and Crypto Fraud Operations Side by Sidehigh
- Suspected Russian Actor Uses AI Slopsquatting to Publish 1,000+ Malicious npm Packages (WEL1DROPPER /…high
- Nearly 800 Malicious npm Packages Deliver Cross-Platform WEL1DROPPER RAT and Infostealer ('Flooding Dropper'…high
- Microsoft shortens NuGet.org API key lifetimes to 30 days for supply-chain hardening (effective Aug 17, 2026)medium
- DOUBLECUP ClickFix Loader-as-a-Service Hides Malware in Browser Cache Images via Steganographyhigh
- CVE-2026-20316: Cisco Secure Firewall Management Center Hard-coded Password Vulnerability Added to CISA KEVcritical
- OpenAI Models Chain Eight JFrog Artifactory Zero-Days to Escape Sandbox and Breach Hugging Facecritical
- TrickBot Malware Variant Adopts DNS Tunneling for C2 Communications (westurn.in)high
- HollowGraph Malware Abuses Microsoft 365 Calendar as Covert C2 Channel (Cavern Framework, Suspected Cavern…high
- Project CAV3RN / Cavern Manticore: Iran-Linked Modular Cyberespionage Framework Abuses Outlook Calendar…high
- HollowGraph Malware Abuses Microsoft Graph API and M365 Calendar Events (Future-Dated 2050) for Stealthy…high
- HOLLOWGRAPH: .NET NativeAOT Malware Abusing Microsoft Graph API and M365 Calendar Events for C2, Linked to…high
- ClickLock Stealer: ClickFix-Delivered macOS Infostealer with GSocket Reverse-Shell Backdoorhigh
- LabubaRAT: Rust-Based Windows Implant Masquerading as NVIDIA Container Runtimehigh
Detection coverage
Threadlinqs maintains 172 detection rules mapped to T1071.004 (SPL 63, KQL 53, Sigma 56). Rule content is available to Blue tier accounts and above; this page shows counts only.
Parent technique
T1071 Application Layer Protocol — 859 tracked threats at the technique level.