409. Adversaries Abuse Localhost[.]run for Tunneling
Hello everyone! Tunnels. Attackers are coming up with more and more ways to implement them. Today, we’ll take another look at the Protocol Tunneling technique (T1572) . There are plenty of free tunneling services that allow a local service to be exposed to the internet through a public URL. For example, attackers often use Cloudflare Tunnel. However, according to this report , threat actors also used localhost [.] run . You can detect traces of its use, for example, by monitoring communications with lhr [.] life subdomains: event_type: dnsreq* AND dns_rname: "lhr.life" See you soon!