logo

New Wekby Attacks Use DNS Requests As Command and Control Mechanism - Palo Alto Networks BlogPalo Alto Networks Blog

ID: a8721941-fff9-4d6b-984c-f4045d1183e2

STIX ID: report--a8721941-fff9-4d6b-984c-f4045d1183e2

Threat Score

75/100

Uploaded: 2026-08-07

Published Date: 2016-07-05

Last Modified Date: 2016-07-05

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
This Unit 42 technical blog post documents Wekby APT activity targeting a U.S. organization using a malware family dubbed "pisloader" — a heavily obfuscated payload delivered via an HTTP dropper that establishes persistence and uses DNS TXT queries for C2 (with base32-encoded payloads and strict DNS flag checks); the report includes dynamic and static analysis details, supported commands, ROP-based obfuscation, associated domains/IPs and file hashes, and recommended protections (WildFire detection, AutoFocus tagging, IPS rules).