DNS EXIT is a tool tracked across 1 threat cluster and 1 intelligence report mention on ThreatCluster. First observed December 17, 2025; most recent activity December 17, 2025.
DNS EXIT is a cybersecurity tool associated with threat actor BlueDelta, described in connection with a persistent campaign against UKR.NET. It appears to function as a DNS-based command-and-control and data-exfiltration mechanism, enabling stealthy, long-term presence by leveraging DNS tunneling techniques to evade traditional network defenses.
Between February and September 2025, BlueDelta, a Russian state-sponsored group, conducted multiple credential-harvesting campaigns. These operations targeted users of UKR.NET, a popular Ukrainian webmail and news…