Underminr Vulnerability Hides C2 Behind Trusted Domains
A new DNS technique lets attackers tunnel command and control traffic through legitimate domains that security tools already trust.
Underminr abuses shared CDN routing so a connection can appear to go to a trusted domain while actually reaching another hosted domain.
Environments that rely on DNS allowlists without checking DNS, SNI, Host headers, and CDN routing together may be exposed. This includes enterprise proxies, endpoint agents, and cloud security stacks that skip subdomain checks.
Researchers say the method has already been abused in real-world attacks.
