Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Infoblox’s April 20, 2023 announcement described Decoy Dog as a remote-access-trojan toolkit using DNS for command and control, and urged companies to block six domains. The findings, dates and indicators below are claims made by Infoblox at that time—not an independent validation or a current blocklist.

What was Decoy Dog?

Infoblox called Decoy Dog a toolkit for remote access trojan (RAT) activity that communicated with its command-and-control infrastructure over the Domain Name System (DNS). In this arrangement, malware uses DNS traffic to communicate with an external controller. The announcement did not provide enough technical detail to establish the toolkit’s full capabilities or explain its specific DNS protocol behavior.

Infoblox said its Threat Intelligence Group identified the activity and was working with other vendors and customers. The company reported that it found Pupy activity in multiple enterprise networks in early April 2023, while the DNS command-and-control communications had gone undiscovered since April 2022. These are the dates Infoblox reported, not independently verified timelines.

What did Infoblox report finding?

In its April 20, 2023 release, Infoblox said it had observed anomalous DNS signatures in enterprise networks in the United States, Europe, South America and Asia. It described activity in technology, healthcare, energy, financial and other sectors, and said some communications went to a controller in Russia. The announcement did not provide a victim count or identify affected organizations.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Infoblox said it found activity on some network devices, including firewalls, rather than user devices such as laptops or mobile phones. It described the DNS footprint as difficult to identify from isolated observations: analysis over time and across its global cloud-based protective DNS system, it said, connected behavior and domains that initially appeared unrelated. The release does not independently establish how common this activity was across the named regions or industries.

Which six domains did Infoblox urge companies to block?

The April 2023 announcement listed these six indicators. They are reproduced in defanged form so they are not accidentally treated as clickable domains:

  • claudfront[.]net
  • allowlisted[.]net
  • atlas-upd[.]com
  • ads-tm-glb[.]click
  • cbox4[.]ignorelist[.]com
  • hsdps[.]cc

Infoblox said the domains were already in its BloxOne Threat Defense Advanced Suspicious Domains feed in fall 2022 and had been added to its anti-malware feed by the announcement date. That describes the vendor’s feeds and historical guidance. The list is dated April 2023; it does not establish that these indicators remain active or malicious now. Before blocking them, check current threat-intelligence sources and your organization’s own DNS records and allowlist requirements.

How can organizations respond to DNS command-and-control risks?

Protective DNS can apply threat-intelligence decisions to DNS requests, helping an organization block connections to domains it classifies as malicious. Infoblox described protective DNS as a mitigation and named its BloxOne Threat Defense service in that context; the announcement is not a comparative evaluation of security products or evidence of their present-day capabilities.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

For operational decisions, security teams can:

  • Review DNS logs for requests to the listed indicators and investigate relevant devices and time periods; do not assume a listed domain alone proves a device is compromised.
  • Validate indicators against current, trusted threat-intelligence sources before adding blocks, and assess possible business impact and false positives.
  • Check visibility across network infrastructure as well as user endpoints, since Infoblox said it observed activity on devices such as firewalls.
  • Use protective DNS or other existing controls to enforce vetted blocks, and retain logging so analysts can investigate blocked requests and adjust policy if needed.

Infoblox’s senior director of threat intelligence, Renée Burton, said the incident was “a stark reminder of the importance of having a strong, protective DNS strategy.” That is the company’s recommendation, rather than evidence that any one product or control alone prevents this type of activity.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What the announcement does—and does not—establish

The original source is Infoblox’s vendor announcement, published April 20, 2023: “Infoblox Uncovers DNS Malware Toolkit & Urges Companies to Block Malicious Domains.” It reports the company’s discovery, observations, dates, mitigation claims and indicators. It does not establish independent technical validation, victim counts, updated attribution, current indicator status or comparative product performance.

Best Value
WatchGuard Firebox T145 with 1 Year Standard Support - Tabletop Firewall, 2.5Gb, 1Gb & SFP Ports, Enterprise Security for Branch Locations (WGT145000+WGT1450061)
  • Watchguard T145 Firebox with 1 Year Standard Support License (WGT145001) - The Firebox T145 delivers enterprise-grade protection for branch offices and retail sites. With a blend of 2.5Gb, 1Gb, and SFP/SFP+ ports, it supports high throughput, AI-driven malware protection, and DNS filtering for robust network defense.
  • Standard Support covers software updates and round-the-clock emergency help. Add a Basic or Total Security Suite to activate IPS, gateway antivirus, and web filtering so threats are blocked before they reach users.
  • Standard Support provides reliable technical assistance and software updates for WatchGuard Firebox appliances. Offering 24x7 help for emergencies and business-hours support for routine needs, it ensures your network stays secure and operational.
  • Interfaces and deployment: 2.5Gb and 1Gb Ethernet with SFP or SFP+ fiber for clean aggregation and segmented backhaul at the edge.
  • Performance and scale: UTM up to 710 Mbps with inspection on; flexible VPN topologies for hub and spoke or mesh designs.
Rank #4
PUSR TCP232-302 TCP IP to Serial Support DNS DHCP Modbus Gateway Device Server RS232 to Ethernet Converter
  • ARM core, Cortex-M0 solution, equipped with deeply optimized TCP/IP protocol stack. It has low latency and strong scalability, stable and reliable
  • Supports custom webpage function to help users improve brand influence
  • Supports Modbus RTU to Modbus TCP protocol conversion and multi-host polling
  • Supports hardware and software watchdog, automatically restarts when the device goes down.
  • Versatile operation modes: TCP Server, TCP Client, UDP, HTTP client.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.