Skip to content

Malware

Lyceum .NET DNS Backdoor

This .NET written malware is used as backdoor using the dns protocol by a state sponsored threat actor.

Lyceum .NET DNS Backdoor is a Windows malware family operated by LYCEUM.

Background

A state-sponsored threat actor deploys this .NET-based malware as a backdoor that communicates over the DNS protocol. Beyond that, it offers further functions such as running commands, capturing screenshots, enumerating files/directories/installed applications, and uploading, downloading, and executing files. Related variants exist that use HTTP (.Net), as well as one written in Golang.


Source: Malpedia (Fraunhofer FKIE).