Malware
Lyceum .NET DNS Backdoor
This .NET written malware is used as backdoor using the dns protocol by a state sponsored threat actor.
Lyceum .NET DNS Backdoor is a Windows malware family operated by LYCEUM.
Background
A state-sponsored threat actor deploys this .NET-based malware as a backdoor that communicates over the DNS protocol. Beyond that, it offers further functions such as running commands, capturing screenshots, enumerating files/directories/installed applications, and uploading, downloading, and executing files. Related variants exist that use HTTP (.Net), as well as one written in Golang.
Source: Malpedia (Fraunhofer FKIE).