Domain Generation Techniques (DGA) are a MITRE ATT&CK capability where adversaries algorithmically generate large sets of domain names to use as command-and-control (C2) endpoints.
Overview
Domain Generation Techniques (DGA) are a MITRE ATT&CK capability where adversaries algorithmically generate large sets of domain names to use as command-and-control (C2) endpoints. This technique helps malware blend with regular DNS traffic, evade static domain blocklists, and survive takedowns by frequently changing the C2 domains. DGAs are a common, resilient tactic in botnets, ransomware, and other persistent campaigns, making network detection and DNS-based defenses challenging but feasible through behavior and entropy analysis.
Related Threat Clusters
-
Over 36 Fake e-Challan Websites Target Indian Drivers in Phishing Scam
A large-scale phishing scam has emerged, targeting Indian vehicle owners through fake e-Challan websites. Cybercriminals are exploiting trust in India's traffic enforcement systems to steal sensitive financial…
4 articles · Updated December 26, 2025
Recent Intelligence Reports
- Indian Vehicle Owners Warned as Browser-Based e — Thecyberexpress · December 24, 2025