New Wekby Attacks Use DNS Requests As Command and Control Mechanism - Palo Alto Networks BlogPalo Alto Networks Blog
ID: a8721941-fff9-4d6b-984c-f4045d1183e2
STIX ID: report--a8721941-fff9-4d6b-984c-f4045d1183e2
Threat Score
75/100
Uploaded: 2026-08-07
Published Date: 2016-07-05
Last Modified Date: 2016-07-05
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
This Unit 42 technical blog post documents Wekby APT activity targeting a U.S. organization using a malware family dubbed "pisloader" — a heavily obfuscated payload delivered via an HTTP dropper that establishes persistence and uses DNS TXT queries for C2 (with base32-encoded payloads and strict DNS flag checks); the report includes dynamic and static analysis details, supported commands, ROP-based obfuscation, associated domains/IPs and file hashes, and recommended protections (WildFire detection, AutoFocus tagging, IPS rules).
