Malicious DNS Query To fdmpkg C2 Domain via DNS Query

PremiumReviewedSigma · High · v1
Product
linux
Category
dns_query
Author
HuntRule
Published
2026-10-06
Updated
2026-10-06

ATT&CK techniques

C2
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Cred Access

  9. Discovery

  10. Lateral Movement

  11. Collection

  12. Exfiltration

  13. Impact

What it detects

This rule detects DNS resolution of subdomains under the fdmpkg C2 domain used by the backdoored Free Download Manager Linux package. The malware encodes a 20-byte hex value as a subdomain of u.fdmpkg[.]org for DNS-based command-and-control, so any query matching this structure indicates an infected host.

Related detections9 linkedT1071.004 — drag to rearrange
Malicious SUNBURST avsvmcloud.com C2 DNS Query
Suspicious Cobalt Strike DNS Beacon Default Subdomain Query Linked to Cozy Bear
Suspicious DNS Query to Interactsh OAST Callback Domains
Possible Out-of-Band OAST Callback Domain Resolution via DNS
Possible TrickBot Anchor DNS C2 Registration via HTTP URI (via proxy)
Possible TrickBot DNS Tunneling C2 to westurn.in (via dns_query)
Suspicious SlowStepper DNS TXT C2 Subdomain Lookup via DNS Query
Malicious PIPEDANCE Named Pipe Command and Control Channel via Pipe Created
Suspicious DNS Query for Tor Onion Domain
Malicious DNS Query To fdmpkg C2 Domain via DNS Query
Pivot detection · T1071.004 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.