Suspicious DNS Queries to Operation Triangulation-Like Domains for C2 Beaconing
Detects DNS queries to known Operation Triangulation-related domains that may indicate C2 beaconing.
FreeReviewedSigma · High · v5
- Category
- dns
- Author
- Florian Roth (Nextron Systems) (SigmaHQ), DRL 1.1
- Published
- 2023-06-01
- Updated
- 2026-07-31
What it detects
This rule flags DNS queries for a specific set of domains associated with potential Operation Triangulation-style command-and-control beaconing. Attackers can use recurring DNS lookups to reach C2 infrastructure while blending into normal network activity. Detection relies on DNS telemetry that records domain name queries matching the listed indicators.
Reporting behind it
- securelist.comhttps://securelist.com/operation-triangulation/109842/
- www-fsb-ru.translate.googhttps://www-fsb-ru.translate.goog/fsb/press/message/single.htm!id=10439739@fsbMessage.html?_x_tr_sch=http&_x_tr_sl=ru&_x_tr_tl=en&_x_tr_hl=de&_x_tr_pto=wapp
- github.comhttps://github.com/SigmaHQ/sigma/blob/master/rules-emerging-threats/2023/TA/EquationGroup/net_dns_apt_equation_group_triangulation_c2_coms.yml
Changelog
v5- v5Candidate ingested via manual entry.2026-07-31
- v4Candidate ingested via manual entry.2026-07-31
- v3Candidate ingested via manual entry.2026-07-31
- v2Candidate ingested via manual entry.2026-07-31
- v1No changelog recorded for this version.2026-07-30
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.
potential-operation-triangulation-dns-c2-beaconing-to-known-domains-7fc30d63
title: Suspicious DNS Queries to Operation Triangulation-Like Domains for C2 Beaconing
id: d900901b-59d6-473e-aaa7-7c5e5d4783c1
related:
- id: aa03c712-75c6-438b-8d42-de88f2427e09
type: similar
- id: 7fc30d63-728d-48d9-ad6f-14d14f4accf7
type: derived
status: test
description: This rule flags DNS queries for a specific set of domains associated with potential Operation Triangulation-style command-and-control beaconing. Attackers can use recurring DNS lookups to reach C2 infrastructure while blending into normal network activity. Detection relies on DNS telemetry that records domain name queries matching the listed indicators.
references:
- https://securelist.com/operation-triangulation/109842/
- https://www-fsb-ru.translate.goog/fsb/press/message/single.htm!id=10439739@fsbMessage.html?_x_tr_sch=http&_x_tr_sl=ru&_x_tr_tl=en&_x_tr_hl=de&_x_tr_pto=wapp
- https://github.com/SigmaHQ/sigma/blob/master/rules-emerging-threats/2023/TA/EquationGroup/net_dns_apt_equation_group_triangulation_c2_coms.yml
author: Florian Roth (Nextron Systems), Huntrule Team
date: 2023-06-01
tags:
- attack.command-and-control
- attack.g0020
- detection.emerging-threats
logsource:
category: dns
detection:
selection:
query:
- addatamarket.net
- ans7tv.net
- anstv.net
- backuprabbit.com
- businessvideonews.com
- cloudsponcer.com
- datamarketplace.net
- growthtransport.com
- mobilegamerstats.com
- snoweeanalytics.com
- tagclick-cdn.com
- topographyupdates.com
- unlimitedteacup.com
- virtuallaughing.com
- web-trackers.com
condition: selection
falsepositives:
- Unknown
level: high
license: DRL-1.1