Check TXT records to detect hidden signs of compromise. Threat actors have been found distributing malware through DNS by leveraging TXT records and other DNS tunneling techniques to hide commands, configurations, and fragments of malicious code that enable communication with command-and-control servers without going through conventional channels.
The technique involves using TXT records and DNS responses to transport encoded information. Attackers can insert instructions, keys, or fragmented payloads into TXT records of seemingly legitimate domains, or set up subdomains that act as command-and-control channels. This method makes detection difficult because DNS traffic is usually trusted and many organizations do not thoroughly inspect TXT records or the content of DNS responses.
Warning signs and detection steps: monitor unexpected changes in TXT records, analyze atypical DNS query patterns, review domains with low TTLs or recently created records, correlate DNS queries with unusual endpoint behavior, and apply content analysis to identify Base64 or hex encoded data. Implement DNSSEC records and integrity controls to reduce DNS response tampering, and use blocklists and DNS inspection solutions to filter malicious domains.
Recommended mitigation measures: network segmentation and least privilege principles to limit impact, continuous endpoint protection and patching, use of detection and response solutions, and DNS filtering policies. Leverage managed services and cloud capabilities for detection scalability, including AWS and Azure cloud services to deploy DNS inspection solutions, centralized logging, and real-time analysis.
At Q2BSTUDIO we combine cybersecurity expertise with custom solution development to address modern threats. We offer security audits, implementation of DNS detection mechanisms, development of custom applications and custom software to automate responses, and integration of artificial intelligence to identify anomalous patterns. Our AI for business and AI agents capabilities allow us to create autonomous agents that analyze DNS logs, prioritize alerts, and orchestrate containment actions.
We also provide AWS and Azure cloud services for secure and scalable deployment, and business intelligence services with Power BI integration to visualize threat trends and make data-driven decisions. With Q2BSTUDIO you get solutions that combine cybersecurity, artificial intelligence, and custom development to protect your assets and optimize operations.
If you need assistance reviewing TXT records, auditing your DNS infrastructure, or developing defense solutions based on AI agents and Power BI, contact Q2BSTUDIO for an assessment and a tailored plan that strengthens your security posture and leverages business intelligence and the cloud to mitigate risks.




