T1071.004 - DNS - MITRE ATT&CK

Threat entity extracted from intelligence sources

Frequency
37
occurrences
First Seen
January 19, 2026
Last Seen
July 23, 2026

T1071.004 - DNS is a mitre_attack tracked by ThreatCluster, appearing in 27 threat clusters built from 37 intelligence report mentions.

T1071.004 - DNS is a mitre_attack tracked across 27 threat clusters and 37 intelligence report mentions on ThreatCluster. First observed January 19, 2026; most recent activity July 23, 2026.

Related Threat Clusters

Recent Intelligence Reports

  • T1102 — attack.mitre.org · July 23, 2026
  • TrickBot Ditches HTTP for DNS Tunneling in Latest Variant — Infosecurity-Magazine · July 22, 2026
  • New TELEPUZ malware spreads via ClickFix lures — Feeds.Feedburner · July 16, 2026
  • New Rust — Feeds.Feedburner · July 14, 2026
  • Russia's FSB attacks critical infrastructure, says 12 Western nations | news — Scworld · July 13, 2026
  • Tenda Firmware Backdoor Lets Anyone Log In as Admin Regardless of Password — Techtimes · July 7, 2026
  • Lyceum — malpedia.caad.fkie.fraunhofer.de · July 7, 2026
  • New APT Group Hits Power Grids in Three Countries with AI-Crafted Malware — Techtimes · July 4, 2026

Frequently asked questions

What is T1071.004 - DNS?

T1071.004 - DNS is a mitre_attack tracked by ThreatCluster, appearing in 27 threat clusters built from 37 intelligence report mentions.

Is T1071.004 - DNS still active?

The most recent intelligence report mentioning T1071.004 - DNS on ThreatCluster is dated July 23, 2026. Activity was first observed January 19, 2026, giving a tracked span from then to July 23, 2026.

What is T1071.004 - DNS associated with?

Across ThreatCluster reporting, T1071.004 - DNS most frequently co-occurs with Apt28, Apt32, Apt34, Apt36, APT41, among 12 tracked related entities.

What are the latest developments involving T1071.004 - DNS?

The most significant recent cluster is “Russian FSB Exploits Vulnerable Routers to Target Critical Infrastructure” (76 articles · Updated July 13, 2026). T1071.004 - DNS appears across 27 threat clusters in total, listed above with sources.

How much reporting does ThreatCluster have on T1071.004 - DNS?

T1071.004 - DNS appears in 37 intelligence report mentions across 27 deduplicated threat clusters, aggregated from 17,000+ monitored sources.

CVSS v3.1 Breakdown