DNS EXIT - Tool

Threat entity extracted from intelligence sources

Frequency
1
occurrences
First Seen
December 17, 2025
Last Seen
December 17, 2025

DNS EXIT is a tool tracked across 1 threat cluster and 1 intelligence report mention on ThreatCluster. First observed December 17, 2025; most recent activity December 17, 2025.

Overview

DNS EXIT is a cybersecurity tool associated with threat actor BlueDelta, described in connection with a persistent campaign against UKR.NET. It appears to function as a DNS-based command-and-control and data-exfiltration mechanism, enabling stealthy, long-term presence by leveraging DNS tunneling techniques to evade traditional network defenses.

Related Threat Clusters

  • BlueDelta's Credential-Harvesting Campaigns Targeting Ukraine

    Between February and September 2025, BlueDelta, a Russian state-sponsored group, conducted multiple credential-harvesting campaigns. These operations targeted users of UKR.NET, a popular Ukrainian webmail and news…

    4 articles · Updated January 7, 2026

Recent Intelligence Reports

  • BlueDelta’s Persistent Campaign Against UKR.NET — Recordedfuture · December 17, 2025

CVSS v3.1 Breakdown