Skip to main content
Mallory
MalwareUsed by 1 actor

NoDepDNS

NoDepDNS is a custom Golang backdoor used in 2024 intrusions against telecommunications providers in Southeast Asia/Southwest Asia that Palo Alto Networks Unit 42 tracks as CL-STA-0969, an activity cluster assessed to heavily overlap with CrowdStrike’s Liminal Panda and linked by Unit 42 to Beijing with high confidence. The malware was deployed after initial access that was likely obtained through SSH brute-force attacks using telecommunications-focused credential dictionaries. NoDepDNS is described as a stealthy DNS-tunneling backdoor that uses port 53 for malicious communications. It passively listens for UDP traffic on port 53, parses DNS messages, and decodes commands embedded in DNS response IP addresses using XOR encoding/encryption, then executes those commands locally. Available reporting states it does not return command output. The implant was internally named "MyDns" in debug symbols and was monitored and maintained by shell scripts. In the broader campaign, operators used NoDepDNS alongside other custom implants and tools such as AuthDoor, GTPDoor, ChronosRAT, EchoBackdoor, CordScan, FRP, Microsocks, FScan, and Responder to maintain persistent, stealthy access in mobile telecom environments. The threat actors used multiple defense-evasion measures in conjunction with this malware, including process-name masquerading, timestomping, weakening or disabling SELinux by setting permissive mode, and removing traces from authentication logs. The campaign targeted mobile telecom infrastructure and was assessed as likely intended to support location-tracking or other espionage objectives, although Unit 42 reported no clear evidence of data theft or direct communication with mobile devices in the investigated cases. High-confidence host/network characteristics directly mentioned for NoDepDNS include Golang implementation, passive listening on UDP/53, DNS-message parsing, command delivery via DNS/IP-address-based XOR decoding, and use of port 53 for covert command-and-control.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

THREAT ACTORS

Groups observed using it

1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.

View more details
Liminal Panda

NoDepDNS: A stealthy Go-based backdoor using DNS tunneling over port 53. It decodes commands embedded in DNS response IP addresses using XOR encryption and executes them, but does not return output. Monitored and maintained by shell scripts.

via securityaffairssecurityaffairs.com
INDICATORS OF COMPROMISE

IOCs tracked for this family

3 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.

View more in app
Hashes
3 tracked

File hashes (MD5, SHA-1, SHA-256) from samples and reports.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching3

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution1

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.