Skip to content

Malware

Royal DNS

RoyalDNS is a DNS based backdoor used by APT15 that persistences on a system through a service called 'Nwsapagent'.

Royal DNS is a Windows malware family operated by Mirage.

Background

RoyalDNS is a backdoor employed by APT15 that tunnels its operations over DNS and maintains persistence on the host by installing a service named 'Nwsapagent'.


Source: Malpedia (Fraunhofer FKIE).