
DNS Tunneling
DNS tunneling is an attack technique in which data packets are covertly transmitted over a protocol that is actually only intended for name resolution on the internet. Attackers exploit this to bypass security controls or to smuggle data out of a network unnoticed.
Every device on the internet needs an address to be reachable — a so-called IP address, a sequence of numbers like 142.250.185.46. So that no one has to memorize every number, there is the DNS system: it automatically translates readable names like “google.com” into such addresses. This happens in the background, with every page load, without anyone noticing. DNS tunneling abuses exactly this translation process: attackers hide arbitrary data in the requests and responses that the DNS system sends back and forth. The protocol thus becomes a disguise for communication it was never intended for.
DNS requests as a blind spot in firewalls
Firewalls — that is, programs or devices that monitor traffic in a network — block suspicious traffic. Many types of connections can be blocked. DNS requests, on the other hand, are almost never blocked, because the internet simply doesn’t work without them. Every device, every server, every app is constantly making DNS requests. This makes DNS a tempting hiding place for attackers.
This is the core reason why DNS tunneling is so dangerous in practice. An attacker who has already placed malware on a computer in a corporate network can use DNS tunneling to receive commands or send stolen data outward unnoticed — even if all other communication channels are blocked. Security experts call this process “data exfiltration,” meaning the covert smuggling out of data.
How data disappears inside a name request
A normal DNS request asks: “Which IP address belongs to google.com?” The domain name google.com is the visible part of the request. In DNS tunneling, this domain name is repurposed. The attacker embeds the actual payload — that is, the data to be transmitted — into the domain name. A request might then look like this: “dGhpcyBpcyBzZWNyZXQ.attacker.com”. The cryptic-looking part before the dot is not a real subdomain, but encoded data.
On the other end is a DNS server controlled by the attacker themselves. This server receives the request, extracts the hidden data, and responds — likewise with hidden data in the response field. This creates a covert two-way communication channel. The transmission is slow, because a DNS request can only hold a few hundred characters. But that is completely sufficient for stolen passwords, credentials, or short commands.
DNS tunneling can be detected through unusual patterns: a machine that suddenly sends thousands of DNS requests per minute to the same unknown domain stands out. Modern security systems therefore analyze not just whether DNS requests are being made, but also how many, how often, and to which domains.
DNS tunneling in real attacks and security news
DNS tunneling is not a theoretical threat. Well-known malware families such as the spyware tool “FrameworkPOS” or the malware “Feederbot” have actively used DNS tunneling to steal credit card data from point-of-sale systems. The technique is well documented in the hacker community, and ready-made tools like “iodine” or “dnscat2” are freely available — originally developed for security researchers, they are also used by attackers.
In corporate reports and security news, the term often appears in connection with so-called APT activity — that is, attacks carried out by state-sponsored groups or highly professional criminal organizations. These groups need long-term, undetected access to a network. DNS tunneling provides exactly that: a quiet, persistent connection that blends into normal operations.
Those who browse the internet privately are hardly directly affected by DNS tunneling. The term becomes relevant for anyone administering corporate or school networks, pursuing security careers, or wanting to read news about cyberattacks on companies and government agencies. There, it regularly appears as part of complex attack chains.