Suspicious DNS Exfiltration to azurestaticprovider Backdoor Domain

PremiumReviewedSigma · High · v1
Category
dns_query
Author
HuntRule
Published
2026-09-14
Updated
2026-09-14

ATT&CK techniques

Cred Access → Exfiltration
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Discovery

  9. Lateral Movement

  10. Collection

  11. Impact

What it detects

This rule detects DNS queries carrying the structured bt.node.js label suffix to the azurestaticprovider backdoor domain used by the trojanized node-ipc package. The backdoor encodes stolen developer credentials into subdomains resolved through the actor name server for covert exfiltration. DNS lookups matching this domain or the encoded node.js suffix indicate active credential theft over DNS.

Related detections9 linkedT1552.001 — drag to rearrange
Suspicious Azure Key Vault Access Policy Modification
Suspicious UAT-10608 Credential Harvesting C2 Beacon via HTTP
Suspicious UAT-10608 Hidden Credential Harvesting Script Execution via nohup
Suspicious Script Download via Curl and PowerShell by Dohdoor
DoT (DNS Over TLS) Activation - Command (via process_creation)
DoT (DNS Over TLS) Activation - PowerShell (via powershell)
Suspicious Access to Cloud and Database Credential Files via Process
Possible C2 Beacon with Fixed Authorization URI Parameter via proxy
Suspicious Credential Exfiltration to webhook.site (via dns_query)
Suspicious DNS Exfiltration to azurestaticprovider Backdoor Domain
Pivot detection · T1552.001 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.