Threat Group Cards: A Threat Actor Encyclopedia Archived: 2026-04-05 21:38:04 UTC Home > List all groups > List all tools > List all groups using tool DNSRat Tool: DNSRat Names DNSRat DNSbot Category Malware Type Backdoor Description (Flashpoint) The second new malware sample discovered is a multiprotocol backdoor called DNSbot, which is used to exchange commands and push data to and from compromised machines. Primarily, it operates over DNS traffic, but can also switch to encrypted channels such as HTTPS or SSL, Flashpoint analysts discovered. Information Malpedia Last change to this tool card: 23 April 2020 Download this tool card in JSON format All groups using tool DNSRat Changed Name Country Observed APT groups Carbanak, Anunak 2013-Apr 2023 1 group listed (1 APT, 0 other, 0 unknown) Source: https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=6e09b135-4ac5-4b5a-92b8-a901ad6af1d5 https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=6e09b135-4ac5-4b5a-92b8-a901ad6af1d5 Page 1 of 1