It seems even DNS records can be infected with malware now – here’s why that’s a major worry
- Researchers found evidence of Joke Screenmate malware hiding on DNS servers
- Joke Screenmate is a harmless, prank malware
- There are ways to defend against it
Hackers found a way to hide malware in the Domain Name System (DNS), cleverly evading detection and flying under the radar. This is according to security researchers from Domain Tools who, in a recent blog, detailed how they discovered the Joke Screenmate malware hiding on DNS servers.
DNS is essentially the internet’s address book, turning readable domain names (such as techradar.com) into IP addresses that computers use to locate services. DNS records come in various types, including TXT records, which are usually used to store descriptive text.
However, as Domain Tools explained, cybercriminals found a way to slice up malware into small encoded fragments, and place them into a DNS TXT record under different subdomains. It’s essentially a digital jigsaw puzzle scattered across different addresses. On its own, each part is harmless, but when reassembled, it forms a malicious file.
Joke Screenmate
By using scripting tools, threat actors query the DNS records and reconstruct the malware without triggering the usual security alarms, and since DNS traffic is typically trusted, it doesn’t raise any suspicions.
In their writeup, Domain Tools researchers described finding Joke Screenmate, a program that triggers fake system errors and causes erratic cursor behaviors. But perhaps more alarmingly, they found a PowerShell stager, a script that can download and execute more destructive malware.
While the attack technique is perfidious, there are ways to defend. Cybersecurity teams should implement DNS traffic monitoring, looking for unusual patterns and repeated TXT queries. They can also use tools that inspect DNS records beyond simple resolution functions, and should maintain threat intelligence feeds that include malicious domains and subdomains.
So far, there were very few examples of in-the-wild abuse, apparently, but since the technique seems to be rather simple to pull off, it wouldn’t be too surprising to see it become more popular in the coming months.
Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!
Via Tom’s Hardware
You might also like
Researchers found evidence of Joke Screenmate malware hiding on DNS servers Joke Screenmate is a harmless, prank malware There are ways to defend against it Hackers found a way to hide malware in the Domain Name System (DNS), cleverly evading detection and flying under the radar. This is according to…
Recent Posts
- Amazon’s new plan for games: James Bond and AI Snoop Dogg
- How to watch France vs Ivory Coast: FREE streams, TV channels for World Cup 2026 warm-up
- Marshall Milton ANC review: Making the rare case for premium on-ear headphones
- Belkin’s new Joy-Con grips also boost the Switch 2’s battery life
- How to watch Spain vs Iraq: Free Streams & TV Channels for World Cup 2026 warm-up match
Archives
- June 2026
- May 2026
- April 2026
- March 2026
- February 2026
- January 2026
- December 2025
- November 2025
- October 2025
- September 2025
- August 2025
- July 2025
- June 2025
- May 2025
- April 2025
- March 2025
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023