Domain Generation Techniques - MITRE ATT&CK

Threat entity extracted from intelligence sources

Frequency
1
occurrences
First Seen
December 24, 2025
Last Seen
December 24, 2025

Domain Generation Techniques (DGA) are a MITRE ATT&CK capability where adversaries algorithmically generate large sets of domain names to use as command-and-control (C2) endpoints.

Overview

Domain Generation Techniques (DGA) are a MITRE ATT&CK capability where adversaries algorithmically generate large sets of domain names to use as command-and-control (C2) endpoints. This technique helps malware blend with regular DNS traffic, evade static domain blocklists, and survive takedowns by frequently changing the C2 domains. DGAs are a common, resilient tactic in botnets, ransomware, and other persistent campaigns, making network detection and DNS-based defenses challenging but feasible through behavior and entropy analysis.

Related Threat Clusters

Recent Intelligence Reports

  • Indian Vehicle Owners Warned as Browser-Based e — Thecyberexpress · December 24, 2025

CVSS v3.1 Breakdown