Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

DNS TXT records can be abused to store encoded malware or scripts, but simply placing data in DNS does not infect a computer. In a case documented by DomainTools, researchers reconstructed files from TXT records and found a separate encoded PowerShell stager; another action would still have been needed to retrieve and execute that script.

What DomainTools found in DNS records

In a July 15, 2025 investigation, DomainTools said it searched passively collected DNS records for hexadecimal patterns resembling file headers. Under subdomains of whitetreecollective[.]com, researchers found TXT records holding pieces of binary data represented as hexadecimal. The subdomains had different TXT contents; researchers assembled the fragments into two files, both of which appeared to be Joke Screenmate malware. DomainTools’ investigation describes activity from 2021–2022.

DomainTools also identified a TXT record under drsmitty[.]com containing an encoded PowerShell script. The script functioned as a stager and connected to another domain at an endpoint the researchers identified as the default endpoint for a Covenant command-and-control (C2) server. DomainTools said the stager’s presence in a TXT record was not enough to run it: something else had to retrieve and execute it. The post also noted that the same C2 domain appeared in another TXT record in July 2017. The findings do not identify who was responsible or establish how any system was initially compromised.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Ars Technica’s July 16, 2025 report described the binary data as hexadecimal split into hundreds of chunks and placed in TXT records on different subdomains, where it could be retrieved through a series of DNS requests.

#1 Best Overall
FortiGate-40F Firewall Appliance - 5 Gigabit Ethernet RJ45 Ports, Ideal for Small Businesses (Appliance Only, No Subscription) (FG-40F)
  • Compact and Efficient Design: The FortiGate 40F is designed for small to mid-sized businesses and enterprise branch offices, featuring a compact, fanless desktop form factor that ensures quiet operation and minimizes space usage.
  • Robust Connectivity Options: Equipped with 5 GE RJ45 ports, including 1 WAN port and 4 internal ports, this model provides essential connectivity and flexibility for various network configurations in a small-scale environment.
  • High-Performance Security: Offers up to 1 Gbps IPS throughput and 600 Mbps threat protection throughput, using Fortinet’s purpose-built security processor technology to deliver industry-leading performance and protection for SSL encrypted traffic.
  • Advanced Threat Protection: Integrated with Fortinet’s AI-powered FortiGuard Labs, the FortiGate 40F offers comprehensive cybersecurity, identifying and mitigating both known and unknown threats to maintain robust security across your network.
  • Simplified Management and Deployment: Features a user-friendly management console that provides comprehensive network automation and visibility, coupled with Zero Touch Integration with Fortinet’s Security Fabric for easy deployment.

How malware data can be stored and retrieved through DNS

  1. Encode the content. Binary data can be represented as text; in DomainTools’ file example, it was represented in hexadecimal.

  2. Split it into pieces. The encoded data can be divided into chunks small enough to place in separate TXT records associated with subdomains.

  3. Request the records. A system must be induced or authorized to make the relevant DNS requests. DNS is the lookup system used to resolve names, and TXT records carry text associated with a name.

    Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  4. Reassemble or use the content. Retrieved pieces can be put back in order to reconstruct a file or provide script content. In the PowerShell example, a separate action was still required to retrieve and execute the stager.

The important distinction is between storage, delivery, execution, and initial access. The observed records show that DNS can hold and deliver encoded content; they do not show that publishing a record alone compromises a device. Nor do they establish how a machine would be made to request those records.

Why DNS can be a blind spot

DNS is essential network traffic and is often permitted, so suspicious requests can be harder to distinguish from routine name lookups than traffic that security teams already scrutinize closely. Ian Campbell, a DomainTools senior security operations engineer, told Ars Technica: “Even sophisticated organizations with their own in-network DNS resolvers have a hard time delineating authentic DNS traffic from anomalous requests, so it’s a route that’s been used before for malicious activity.”

Rank #2
FortiGate-60F Network Security Appliance Plus 1 Year FortiGuard Unified Threat Protection (UTP) and FortiCare Premium (FG-60F-BDL-950-12)
  • HARDWARE PLUS SECURITY SERVICES: FortiGate-60F Firewall Appliance bundled with 1 year of FortiCare Premium and FortiGuard Unified Threat Protection.
  • UNIFIED THREAT PROTECTION (UTP): Secures against advanced online threats with comprehensive web filtering and anti-botnet technologies.
  • OPTIMIZED FOR MEDIUM-SIZED BUSINESSES: Tailored for businesses needing robust security without the infrastructure of larger enterprises.
  • RELIABLE CUSTOMER SUPPORT: FortiCare Premium ensures high-quality support and service continuity.
  • EFFECTIVE PROTECTION: Employs advanced filtering technologies to safeguard against sophisticated threats.

Encrypted DNS adds a visibility challenge when the organization does not control the path. DNS over HTTPS (DoH) and DNS over TLS (DoT) encrypt requests between a client and resolver; a network observer who cannot see inside that connection may not see the queried name or record details before traffic reaches the resolver. Campbell told Ars Technica that DoH and DoT encrypt DNS traffic until it hits the resolver, limiting what organizations can inspect unless they operate in-network DNS resolution.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

TXT records also have legitimate uses, including service verification. Blocking every TXT lookup could disrupt ordinary services, while allowing DNS without inspecting its patterns can leave suspicious activity unnoticed.

How DNS storage differs from tunneling, command and control, and exfiltration

These terms describe related but distinct uses of DNS. In this case, researchers found data stored in TXT records and described how it could be retrieved in chunks. DNS tunneling more broadly embeds data in DNS queries and responses to move it through the protocol. Command and control (C2) uses a communication channel to send instructions to compromised systems or return results. Exfiltration is the unauthorized removal of data. A single operation might combine techniques, but the DomainTools findings do not establish that all of them occurred in this incident.

MITRE ATT&CK classifies DNS command and control as T1071.004, Application Layer Protocol: DNS. MITRE notes that DNS is common and often allowed, and that infrequent beaconing can blend into routine traffic. This broader classification provides context; it is not proof that every DNS TXT record—or every use of DNS in the DomainTools case—was command and control.

How to spot suspicious DNS TXT activity

Investigate patterns and context rather than treating a single record type or unfamiliar domain as proof of malware. MITRE’s DNS detection guidance highlights unusual processes generating DNS requests, long or frequent subdomains, encoded-looking content, and high query volumes. Palo Alto Networks also recommends examining unexpected or high-volume TXT traffic and other abnormal DNS behavior.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • Unusual TXT activity: Check whether a client is making unexpected TXT requests, especially at a high rate or to a domain it does not normally contact.

    Rank #3
    GL.iNet GL-MT5000 Brume 3 Wired VPN Security Gateway NO Wi-Fi
    • 【Up to 1100 Mbps VPN Speed 】 Hardware-accelerated WireGuard and OpenVPN-DCO deliver up to 1100 Mbps VPN throughput, over 3× faster than Brume 2 for smooth remote access and file transfers.
    • 【Three 2.5G Ports & Multi-WAN】Tri-port 2.5GbE design with flexible WAN LAN configuration supports multi-gigabit wired setups, dual-ISP Multi-WAN and failover to keep home and SOHO networks online.
    • 【Stealth VPN Obfuscation】VPN obfuscation disguises VPN traffic as regular HTTPS, helping you evade blocking, bypass restrictive networks and maintain stable, private connections.
    • 【DPI protection】Deep Packet Inspection with visual dashboards blocks adult/gambling/malicious sites, while SQM and QoS prioritize gaming, calls, and video when bandwidth is tight
    • 【OpenWrt & USB 3.0 Expansion】OpenWrt with 1GB DDR4 and 8GB eMMC lets you install plugins and build VPN, ad-blocking or NAS, while USB 3.0 Type‑C connects high-speed storage or 4G/5G dongles
  • Long or unusual subdomains: Look for long, random-looking labels or repeated requests to many distinct subdomains of one parent domain.

  • Volume and timing: Review bursts, frequent requests, or repeated low-frequency lookups that depart from the organization’s normal traffic.

  • Client process: Correlate DNS requests with the process that generated them. Queries from unexpected scripts or applications may matter more than the domain’s reputation alone.

    Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • Related activity: Compare DNS observations with endpoint and network events to determine whether a suspicious lookup is part of a larger sequence.

These are investigation signals, not a verdict. Legitimate services use TXT records, and a new or unfamiliar domain by itself does not demonstrate malicious activity.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Practical defenses for organizations

  1. Route client DNS through managed resolvers. Use resolvers the organization can monitor and apply policy to. MITRE recommends on-premises or proxy DNS resolution as a way to improve control over DNS traffic.

    Rank #4
    Ubiquiti Cloud Gateway Ultra (UCG-Ultra)
    • Runs UniFi Network for full-stack network management
    • Manages 30+ UniFi Network devices and 300+ clients
    • 1 Gbps routing with IDS/IPS
    • Multi-WAN load balancing
    • 0.96" LCM status display
  2. Inspect requests and responses. Record the query name, record type, response, client, and timing where feasible. Apply behavioral analysis to long or unusual subdomains, encoded-looking content, repeated TXT use, and volume anomalies.

    Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  3. Control unmanaged encrypted DNS paths. Manage or monitor DoH and DoT so clients do not silently bypass enterprise resolver policies. The goal is to preserve an appropriate inspection path, not to assume encryption itself is malicious.

  4. Correlate DNS with endpoint telemetry. Investigate which process made a query and whether the same endpoint shows suspicious script activity or related network connections.

  5. Use reputation as one signal, not the whole defense. Filtering known-bad or untrusted domains can help, but behavioral monitoring can surface suspicious activity involving domains not yet on a list.

  6. Set policy with legitimate TXT use in mind. Avoid indiscriminate TXT blocking. Palo Alto Networks cautions that blanket blocking may interrupt valid services; use context and behavior to decide what warrants restriction.

    Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

MITRE lists filtering requests to unknown, untrusted, or known-bad domains, routing DNS through managed infrastructure, and network intrusion prevention among its mitigations. These controls improve visibility and raise the cost of abuse, but no single DNS control proves a device is clean or prevents every path to compromise.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.