Glossary

DNS beacons

DNS Beacons

DNS beaconing is a stealthy communication technique used by malware to maintain contact with attacker-controlled command-and-control (C2) infrastructure. Rather than relying solely on traditional network communications, attackers abuse DNS traffic to send instructions, maintain persistence, and regain access to compromised systems while avoiding detection.

Because DNS traffic is common in nearly every environment, DNS beacons can blend into legitimate network activity, making them difficult to identify without advanced monitoring and analysis.

{{anchor:How they work}}

How DNS beacons work

After a system is compromised, malware may establish communication with an attacker’s infrastructure through traditional channels such as HTTP or HTTPS. If those channels are disrupted or detected, the malware can fall back to DNS-based communications.

DNS beacons typically:

DNS beaconing often occurs infrequently, making it more difficult to identify through traditional security controls.

{{anchor:Why DNS beacons matter}}

Why DNS beacons matter

DNS beaconing is frequently associated with advanced malware campaigns, espionage operations, and long-term network compromises.

A successful DNS beacon can enable attackers to:

Because beaconing activity may remain undetected for extended periods, organizations face increased risks of data breaches, intellectual property theft, operational disruption, and reputational damage.

{{anchor:Reducing risk}}

Reducing DNS beacon risk

Organizations can improve their ability to detect and prevent DNS beaconing through a layered security approach that includes:

Continuous visibility into DNS activity is critical for identifying suspicious communications before they lead to broader compromise.

{{anchor:How DigiCert helps}}

How DigiCert can help

DigiCert UltraDDR helps organizations identify and block malicious DNS activity before threats can establish persistence within the environment. As a Protective DNS solution, UltraDDR uses continuously updated threat intelligence to prevent communications with known malicious domains and attacker infrastructure.

By providing real-time visibility into DNS activity, UltraDDR helps security teams detect suspicious communications, reduce exposure to malware command-and-control traffic, and strengthen overall cyber resilience. Its ability to identify and disrupt malicious DNS activity supports faster threat detection, improved security operations, and stronger protection against advanced attacks that rely on DNS-based communications.

Combined with a broader defense-in-depth strategy, DigiCert UltraDDR helps organizations protect users, systems, and data from evolving DNS-based threats while maintaining secure and reliable digital operations.