Cisco Talos reported a targeted phishing campaign that impersonated U.S. Securities and Exchange Commission EDGAR notifications to deliver DNSMessenger, a multi-stage malware family that used malicious Microsoft Word documents for initial access. Instead of relying on macros, the lure documents abused Dynamic Data Exchange (DDE) to trigger obfuscated PowerShell, reflecting the broader macro-less code execution technique documented by SensePost for Microsoft Word. Talos said the campaign selectively targeted organizations and staged payload delivery through attacker-controlled infrastructure, including a compromised Louisiana state government server.
Once executed, DNSMessenger established persistence through multiple mechanisms, including registry Run keys, scheduled tasks, alternate data streams, and WMI event consumers, before shifting command-and-control traffic into DNS. Talos said the malware used DNS A and TXT record queries as a covert bidirectional channel to retrieve later-stage payloads, launch cmd.exe, and exchange commands and output using structured SYN, MSG, and FIN-style messages. Researchers linked the activity to earlier DNSMessenger operations seen in 2017 and highlighted its obfuscation, fileless PowerShell execution, and selective payloading as signs of a sophisticated intrusion set.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
Talos reported that some DNSMessenger command-and-control domains had registration dates in February 2017, with some tied to the email address valeriy.pagosyan@yandex.com. This anchored infrastructure associated with the malware campaign before Talos published its analysis.
Cisco Talos later reported additional targeted attacks using DNSMessenger in a campaign that sent spear-phishing emails spoofed as U.S. SEC EDGAR messages to selected organizations. The malicious Word attachments abused DDE rather than macros and fetched PowerShell payloads from attacker-controlled infrastructure, including a compromised Louisiana state government server.
Cisco Talos published analysis of a multi-stage malware infection chain it dubbed DNSMessenger, describing its phishing-delivered Word document, PowerShell stages, persistence mechanisms, and DNS TXT-based bidirectional command-and-control. The report also included indicators of compromise and explained how the malware tunneled commands and output over DNS.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
5 references tracked. Mallory keeps watching after this page renders.
bleepingcomputer.com
Open sourceblog.talosintelligence.com
Open sourceblog.talosintelligence.com
Open sourcesensepost.com
Open sourcemsdn.microsoft.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.