Summary:
After analyzing unusual DNS traffic that differs from typical internet activity, a new malware toolkit targeting enterprises named "Decoy Dog" has been uncovered. The objective of Decoy Dog, a malware toolkit, is to assist threat actors in avoiding detection by utilizing strategic domain aging and DNS query dribbling. This approach enables them to establish a favorable reputation with security vendors before engaging in cybercrime operations. Decoy Dog's DNS fingerprint is distinct and uncommon among the 370 million active domains on the internet, allowing for easier identification and tracking. As a result, the investigation into the infrastructure of Decoy Dog promptly uncovered multiple C2 domains associated with the same operation, and the majority of communications from these servers were traced back to hosts in Russia.[/subscribe_to_unlock_form]
Summary:
After analyzing unusual DNS traffic that differs from typical internet activity, a new malware toolkit targeting enterprises named "Decoy Dog" has been uncovered. The objective of Decoy Dog, a malware toolkit, is to assist threat actors in avoiding detection by utilizing strategic domain aging and DNS query dribbling. This approach enables them to establish a favorable reputation with security vendors before engaging in cybercrime operations. Decoy Dog's DNS fingerprint is distinct and uncommon among the 370 million active domains on the internet, allowing for easier identification and tracking. As a result, the investigation into the infrastructure of Decoy Dog promptly uncovered multiple C2 domains associated with the same operation, and the majority of communications from these servers were traced back to hosts in Russia.[emaillocker id="1283"]
The Decoy Dog toolkit was found by researchers in early April 2023 as they analyzed more than 70 billion DNS records daily in search of indications of irregular or dubious behavior. After conducting additional research, it was discovered that the DNS tunnels on these domains possessed qualities that indicated the use of Pupy RAT, a remote access trojan deployed by the Decoy Dog toolkit. Pupy RAT is a modular open-source post-exploitation toolkit that is renowned among state-sponsored threat actors for its ability to operate stealthily without a file and support encrypted C2 communications. It is also helpful for blending their actions with those of other tool users. The Pupy RAT project provides payloads for all the major operating systems, such as Windows, macOS, Linux, and Android. Similar to other RATs, it enables threat actors to remotely execute commands, escalate privileges, pilfer credentials, and spread through a network laterally.
Pupy RAT is not used by less skilled actors because configuring the DNS server correctly for C2 communications requires expertise and knowledge. The distinct DNS signature spanning multiple parts provided researchers with a high level of certainty that the correlated domains were not only utilizing Pupy RAT but were all integral components of Decoy Dog, a significant and cohesive toolkit that specifically utilized Pupy RAT on enterprise or large organizational devices, as opposed to consumer devices. In addition, the analysts identified a unique DNS beaconing behavior across all Decoy Dog domains that follows a specific pattern of sporadic but regular DNS request generation.
The detection of Decoy Dog highlights the potential of employing big data analytics to identify abnormal behavior on the internet. The identification of this malware toolkit, along with the realization that several apparently unrelated domains were employing the same unique toolkit, is an outcome of the combination of automated and human methods.
Threat Profile:

References:
The following reports contain further technical details:
[/emaillocker]