[![Logo](https://www.paloaltonetworks.com/wp-content/uploads/2021/07/PANW_Parent.png)](https://www.paloaltonetworks.com/)  
[![Unit42 Logo](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/unit42-logo-white.svg)](https://unit42.paloaltonetworks.com/)  
Menu

* [Tools](https://unit42.paloaltonetworks.com/tools/)
* [ATOMs](https://unit42.paloaltonetworks.com/atoms/)
* [Security Consulting](https://www.paloaltonetworks.com/unit42)
* [About Us](https://unit42.paloaltonetworks.com/about-unit-42/)
* [**Under Attack?**](https://start.paloaltonetworks.com/contact-unit42.html)  
  English
* [English](https://unit42.paloaltonetworks.com/unit42-dont-be-an-april-fool-inside-a-common-phone-scam/)
* [Japanese](https://unit42.paloaltonetworks.com/ja/unit42-dont-be-an-april-fool-inside-a-common-phone-scam/)
* [Threat Research Center](https://unit42.paloaltonetworks.com "Threat Research")
* [Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/ "Threat Research")
* [DNS](https://unit42.paloaltonetworks.com/category/dns/ "DNS")  
  [DNS](https://unit42.paloaltonetworks.com/category/dns/)

# Don't Be an April Fool: Inside a Common Phone Scam

![Clock Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-clock.svg) 8 min read

* ![Profile Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-profile-grey.svg)  
  By:
  
  * [Simon Conant](https://unit42.paloaltonetworks.com/author/simon-conant/)

* ![Published Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-calendar-grey.svg)  
  Published:April 1, 2016

* ![Tags Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-category.svg)  
  Categories:
  
  * [DNS](https://unit42.paloaltonetworks.com/category/dns/)
  * [Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/)

* ![Tags Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-tags-grey.svg)  
  Tags:
  
  * [Phone Scam](https://unit42.paloaltonetworks.com/tag/phone-scam/)
  * [Windows](https://unit42.paloaltonetworks.com/tag/windows/)

* [![Download Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-download.svg)](https://unit42.paloaltonetworks.com/unit42-dont-be-an-april-fool-inside-a-common-phone-scam/?pdf=download&lg=en&_wpnonce=0e33cfdd78 "Click here to download")

* [![Print Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-print.svg)](https://unit42.paloaltonetworks.com/unit42-dont-be-an-april-fool-inside-a-common-phone-scam/?pdf=print&lg=en&_wpnonce=0e33cfdd78 "Click here to print")

Share![Down arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/down-arrow.svg)

* ![Link Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-share-link.svg)
* [![Link Email](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-sms.svg)](mailto:?subject=Don’t%20Be%20an%20April%20Fool:%20Inside%20a%20Common%20Phone%20Scam&body=Check%20out%20this%20article%20https%3A%2F%2Funit42.paloaltonetworks.com%2Funit42-dont-be-an-april-fool-inside-a-common-phone-scam%2F "Share in email")
* [![Facebook Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-fb-share.svg)](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Funit42.paloaltonetworks.com%2Funit42-dont-be-an-april-fool-inside-a-common-phone-scam%2F "Share in Facebook")
* [![LinkedIn Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-linkedin-share.svg)](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Funit42-dont-be-an-april-fool-inside-a-common-phone-scam%2F&title=Don’t%20Be%20an%20April%20Fool:%20Inside%20a%20Common%20Phone%20Scam "Share in LinkedIn")
* [![Twitter Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-twitter-share.svg)](https://twitter.com/intent/tweet?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Funit42-dont-be-an-april-fool-inside-a-common-phone-scam%2F&text=Don’t%20Be%20an%20April%20Fool:%20Inside%20a%20Common%20Phone%20Scam "Share in Twitter")
* [![Reddit Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-reddit-share.svg)](https://www.paloaltonetworks.com//www.reddit.com/submit?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Funit42-dont-be-an-april-fool-inside-a-common-phone-scam%2F&ts=markdown "Share in Reddit")
* [![Mastodon Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-mastodon-share.svg)](https://mastodon.social/share?text=Don’t%20Be%20an%20April%20Fool:%20Inside%20a%20Common%20Phone%20Scam%20https%3A%2F%2Funit42.paloaltonetworks.com%2Funit42-dont-be-an-april-fool-inside-a-common-phone-scam%2F "Share in Mastodon")
  One of our team members on Unit 42 recently received a phone call from a scammer, and today being April Fool's Day we decided to write about how we played along with the scammer to learn about his operation.

Unit 42 analyst Robert received a phone call from a Tech Support scammer who told him his system was compromised and was seen performing illegal activities. The scam relied solely on social engineering, which is a technique to manipulate a victim into doing something or to give up information, but in this case was intended to get Robert to pay the scammer for unneeded system protection services. Social engineering is used in a majority of cyber crime and espionage attacks, albeit in this scam it was conducted over the phone and not via e-mail or social networking.

This blog, in Robert's voice, recounts the story of this unsolicited call and provides a glimpse into this scam operation. We intend this story to be light reading for security professionals, but hope that it provides awareness for less technical folks into the social engineering techniques used in these types of scams.

*Note: We have redacted some portions of this blog, specifically the domain involved with this scam while law enforcement investigates.*

### The Scam

On March 30, 2016 at approximately 12:45 PM EST, I received a call on my house phone showing a caller I.D. of "1-161-565-4328". An individual greeted me and told me that a hacker had infected my Windows system. The individual told me that the hacker used my system to do illegal things, which is the reason they were calling me to help clean up my system. I feigned shock and surprise that someone had used my system to carry out illegal activities and responded that I was very grateful that they brought this to my attention. The individual told me he would transfer me to a technician to clean my computer.

The technician walked me through the various buttons on my keyboard, specifically focusing on the buttons on the bottom left corner of the keyboard. He asked me to read off the different keys, so I told him it was CTRL, ALT and Windows even though I do not run Windows as my operating system. Once he heard me say the Windows key, he instructed that I press and hold it while pushing the "R" key. The technician then had me type in a command to the Run window, specifically reading off each letter using acrophony (like "R" as in wrench) in the following command:

*eventvwr*

To stall him, I had him read it out several times while I set up my virtual machine and its network interfaces. With the event viewer open, I was instructed to click "Custom Views" and then "Administrative Events" and the operator asked what I saw. I saw the warning and error messages seen in Figure 1, which I was told was confirmation that my computer was compromised, even though all the displayed messages were caused by failed DNS lookups and DHCP requests.

![April Fools 1](http://blog.paloaltonetworks.com/wp-content/uploads/2016/04/April-Fools-1-500x151.png)

*Figure 1 Event viewer application showing DNS and DHCP errors, not a compromise*

I was then instructed to close the event viewer application and press the "Windows" key and "R" again to run another command. The technician told me to run another command that he read off, again using acrophony and again with me wasting his time by having him repeat the command several times:

*iexplore www.support.me*

The technician then asked me what I saw. My virtual machines' network interfaces were set up correctly but I had to fix my DNS settings, so I told the technician the page was unreachable and that he would have to help me fix my Internet connection before we could continue. The technician said he would transfer me to his supervisor who would be able to assist me in fixing my Internet connection. Meanwhile, I fixed my DNS settings while I was being transferred.

The individual I was transferred to again had me open the event viewer application. Again, I was told all of the warnings and errors are issues with my computer, which I needed to fix or else I could lose my computer. I responded by asking "*Where would my computer go if I lost it and how would I go about finding it?*" I chuckled to myself, but the supervisor then asked my age and if my parents or I owned the computer. I told him I was 28 years old and assured him I owned the computer.

I continued the conversation by telling him my Internet connection was fixed, so the supervisor told me to open my Google application and type in "www.support.me". I visited the URL and it redirected me to "secure.logmeinrescue.com", as seen in the following HTTP 301 redirection:

*HTTP/1.1 301 Moved Permanently*  
*Content-Type: text/html; charset=UTF-8*  
*Location: [https://secure.logmeinrescue.com/Customer/Code.aspx](https://secure.logmeinrescue.com/Customer/Code.aspx)*  
*Server: Microsoft-IIS/7.5*  
*X-Powered-By: ASP.NET*  
*Date: Wed, 30 Mar 2016 19:32:13 GMT*  
*Content-Length: 174*

The website displayed in the browser, seen in Figure 2, has a form that requires a six digit code to download a LogMeIn application that would allow the technician to interact with my system. The technician provided me a six-digit number of 242137 and instructed me to download the resulting application that had a filename of "Support-LogMeInRescue.exe" (SHA256: 3196ac75120fad5eed97801768d33e74f452194cf7ebd0dbf4775c53a052fe46) and run the application.

![April Fools 2](http://blog.paloaltonetworks.com/wp-content/uploads/2016/04/April-Fools-2-500x379.png)

*Figure 2 Support.me requires a 6-digit access code to download and install the LogMeIn Rescue Application*

After I executed the application, the technician told me to click "Ok" to all of the popups, which was Windows' UAC telling me that I should be careful about running such an application. The application is LogMeIn Rescue, which is a legitimate application that allows IT support to interact with remote systems. However, in this case, the scammer used the aptly titled HappyToAssist application to gain access to my virtual machine. As you can see in Figure 3, the technician used this application to transfer a file named "AA\_v3.exe" (SHA256: 1831806fc27d496f0f9dcfd8402724189deaeb5f8bcf0118f3d6484d0bdee9ed) to my system.

[![April Fools 3](http://blog.paloaltonetworks.com/wp-content/uploads/2016/04/April-Fools-3-500x462.png)](https://blog.paloaltonetworks.com/wp-content/uploads/2016/04/April-Fools-3.png)

*Figure 3 HappyToAssist application used to transfer AA\_v3.exe file*

The technician then ran the "AA\_v3.exe" executable, which is a variant of the Ammyy Admin tool seen in Figure 4.

![April Fools 4](http://blog.paloaltonetworks.com/wp-content/uploads/2016/04/April-Fools-4-500x297.png)

*Figure 4 Ammyy Admin tool used to transfer additional file*

The technician used this tool to transfer another file, specifically a batch script with a name of "Route Tracer.bat". The batch script was a further attempt to show me that my computer was compromised, as the technician told me that the application would show me the current activity on my system.[![April Fools 5](http://blog.paloaltonetworks.com/wp-content/uploads/2016/04/April-Fools-5-500x245.png)](https://blog.paloaltonetworks.com/wp-content/uploads/2016/04/April-Fools-5.png)

*Figure 5 Batch script printing fake hack attempts to the screen*

According to the output of this batch script, my virtual machine was hacked by China from an IP address currently belonging to a wireless provider in the United States. I asked the technician why China would be hacking my computer and he said to gain access to my banking information.

At this point, the technician changed hats from security expert to professional salesman, by opening the Notepad application and typing out the services they offer to clean the system. As you can see from Figure 6, the now salesman offered me three service plans to keep my system protected for 3 years, 5 years or a lifetime for prices ranging from $199 to $299.

![April Fools 6](http://blog.paloaltonetworks.com/wp-content/uploads/2016/04/April-Fools-6-500x446.png)

*Figure 6 Notepad document the technician used to show the services available for purchase*

I told the salesman that I never want this to happen again, so I wanted to purchase the lifetime plan, which he was generous enough to open an Internet Explorer window and navigate me to a billing page. The billing page, seen in Figure 7, is hosted at http:// \[redacted\] /billing\_us.php.

![April-Fools-7](http://blog.paloaltonetworks.com/wp-content/uploads/2016/04/April-Fools-7-1-500x355.png)

*Figure 7 Billing page for scam*

At this point, I disconnected the adapters to my virtual system, which effectively removed the technician/salesman's access to my system. I asked if he recognized any icons on my system, specifically the icons of malware analysis tools. I heard rustling on the other end of the phone and a click when the individual hung up the phone.

While this call was ongoing, I kept several of my team members amused with the progress in a separate chat window. As I was documenting the scammer's activity, my colleague Simon took a look at who might be behind the site.

### Attribution

The domain \[redacted\] hosting the billing page was created on February 28, 2014. It has resolved to the IP address \[redacted\], and used the DNS name server (NS) \[redacted\] consistently from when the domain was created, through to the present time.

The current WHOIS information for this domain is anonymized using a WHOIS protection service; however, up until July 2014 the WHOIS was not anonymized and gave us the information used during registration. The email address used to register the \[redacted\] domain is associated with two social networking accounts, both of which we have passed to law enforcement to provide further scrutiny of the individual's involvement in this scam operation.

Historic captures of the site at archive.org show fundamentally the same site content throughout the history of this domain. The website currently lists their contact phone number as "\[redacted\]" (Figure 8), however prior to 2016 it listed a different number "\[redacted\]" (Figure 9).

![April-Fools-8](http://blog.paloaltonetworks.com/wp-content/uploads/2016/04/April-Fools-8-1.png)

*Figure 8 Website March 2016*

![April-Fools-9](http://blog.paloaltonetworks.com/wp-content/uploads/2016/04/April-Fools-9-1.png)

*Figure 9 Website September 2014*

### Victims

Searches on the domain \[redacted\] and on both of these numbers finds multiple reports of support scam calls, referring to the site or referencing these as call-back numbers (Figure 10).

![April Fools 10\_1](http://blog.paloaltonetworks.com/wp-content/uploads/2016/04/April-Fools-10_1-500x137.png)

![April-Fools-10\_2](http://blog.paloaltonetworks.com/wp-content/uploads/2016/04/April-Fools-10_2-1-500x90.png)

![April-Fools-10\_3](http://blog.paloaltonetworks.com/wp-content/uploads/2016/04/April-Fools-10_3-1-500x193.png)

*Figure 10 Examples of complaints linked to this operation*

Although this call instructed the victim to supply a merchant reference code "my computer" during payment, which might be used as an affiliate code, the reports offering a call-back number suggest it's unlikely that this is using an affiliate model.

### Hanging Up

It is unlikely that readers of this blog would fall for a tech support scam like the one discussed in this blog. Security minded individuals would likely notice the absurdity in the tricks used by the scammers to confirm that the system is compromised, and even more likely to forbid the installation of a remote administration application on their system. Sadly, these scammers prey on less technically knowledgeable individuals, who are often tricked out of hundreds of dollars if they fall victim to these types of scams.

While it is unlikely that these scammers would call a business, we suggest that organizations consider putting controls in place to limit only authorized remote administration applications from running on their network. Palo Alto Networks identifies 93 different remote access applications with App-ID, including Ammyy-admin and LogMeIn Rescue that were used in this scam. We suggest that organizations should use the remote access App-ID's to block these tools from running on their networks to protect their user base in the event they fall victim to such a scam.

Additionally, for individuals not protected by the Palo Alto Networks platform, the FTC offers [consumer guidance](https://www.consumer.ftc.gov/articles/0346-tech-support-scams) that can help detect this type of tech support scam and how to file a complaint with the FTC. We have notified the FTC of this scam and handed over all pertinent information. Who's the April Fool now, scammer?
Back to top

### Tags

* [Phone Scam](https://unit42.paloaltonetworks.com/tag/phone-scam/ "Phone Scam")
* [Windows](https://unit42.paloaltonetworks.com/tag/windows/ "Windows")  
  [Threat Research Center](https://unit42.paloaltonetworks.com "Threat Research") [Next: How the EITest Campaign's Path to Angler EK Evolved Over Time](https://unit42.paloaltonetworks.com/unit42-how-the-eltest-campaigns-path-to-angler-ek-evolved-over-time/ "How the EITest Campaign's Path to Angler EK Evolved Over Time")

### Related Articles

* [01flip: Multi-Platform Ransomware Written in Rust](https://unit42.paloaltonetworks.com/new-ransomware-01flip-written-in-rust/ "article - table of contents")
* [You Thought It Was Over? Authentication Coercion Keeps Evolving](https://unit42.paloaltonetworks.com/authentication-coercion/ "article - table of contents")
* [Suspected Nation-State Threat Actor Uses New Airstalk Malware in a Supply Chain Attack](https://unit42.paloaltonetworks.com/new-windows-based-malware-family-airstalk/ "article - table of contents")

## Related DNS Resources

![Pictorial representation of Azure OpenAI DNS resolution issue. Futuristic cityscape illustration with luminous structures and floating cloud elements, showcasing advanced technology and a dynamic, digitally enhanced environment.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/06/02_DNS_Overview_1920x900-786x368.jpg)  
[![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) January 20, 2026 [#### DNS OverDoS: Are Private Endpoints Too Private?](https://unit42.paloaltonetworks.com/dos-attacks-and-azure-private-endpoint/)

* [Microsoft Azure](https://unit42.paloaltonetworks.com/tag/microsoft-azure/ "Microsoft Azure")

* [Networking](https://unit42.paloaltonetworks.com/tag/networking/ "networking")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/dos-attacks-and-azure-private-endpoint/ "DNS OverDoS: Are Private Endpoints Too Private?")  
  ![Pictorial representation of Azure OpenAI DNS resolution issue. Futuristic cityscape illustration with luminous structures and floating cloud elements, showcasing advanced technology and a dynamic, digitally enhanced environment.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/06/02_DNS_Overview_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) June 3, 2025 [#### Lost in Resolution: Azure OpenAI's DNS Resolution Issue](https://unit42.paloaltonetworks.com/azure-openai-dns-resolution/)

* [Endpoint](https://unit42.paloaltonetworks.com/tag/endpoint/ "endpoint")

* [Microsoft Azure](https://unit42.paloaltonetworks.com/tag/microsoft-azure/ "Microsoft Azure")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/azure-openai-dns-resolution/ "Lost in Resolution: Azure OpenAI's DNS Resolution Issue")  
  ![Pictorial representation of domain registrations with typos. Illustration of a futuristic city with transparent, holographic buildings and glowing blue and orange lights.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/03/07_DNS_Overview_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) March 6, 2025 [#### The Next Level: Typo DGAs Used in Malicious Redirection Chains](https://unit42.paloaltonetworks.com/typo-domain-generation-algorithms/)

* [Domain Generation Algorithms](https://unit42.paloaltonetworks.com/tag/domain-generation-algorithms/ "Domain Generation Algorithms")

* [Malicious Domains](https://unit42.paloaltonetworks.com/tag/malicious-domains/ "Malicious Domains")

* [Newly Registered Domain](https://unit42.paloaltonetworks.com/tag/newly-registered-domain/ "Newly Registered Domain")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/typo-domain-generation-algorithms/ "The Next Level: Typo DGAs Used in Malicious Redirection Chains")  
  ![Pictorial representation of detecting and blocking malicious traffic distribution systems. A digital illustration of a glowing globe centered on North America, surrounded by multiple smaller globes, all connected with lines on a dark blue high-tech background, representing global connectivity and network technology.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/03/03_DNS_Overview_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) March 5, 2025 [#### Beneath the Surface: Detecting and Blocking Hidden Malicious Traffic Distribution Systems](https://unit42.paloaltonetworks.com/detect-block-malicious-traffic-distribution-systems/)

* [Phishing](https://unit42.paloaltonetworks.com/tag/phishing/ "phishing")

* [Redirection](https://unit42.paloaltonetworks.com/tag/redirection/ "Redirection")

* [Web attacks](https://unit42.paloaltonetworks.com/tag/web-attacks/ "web attacks")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/detect-block-malicious-traffic-distribution-systems/ "Beneath the Surface: Detecting and Blocking Hidden Malicious Traffic Distribution Systems")  
  ![Pictorial representation of detecting DNS hijacking. Digital illustration of a futuristic data center with glowing blue server racks connected by light beams, surrounded by cloud computing icons, set against a dark background.](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/11/02_DNS_Overview_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) November 4, 2024 [#### Automatically Detecting DNS Hijacking in Passive DNS](https://unit42.paloaltonetworks.com/detect-dns-hijacking-passive-dns/)

* [Domain hijacking](https://unit42.paloaltonetworks.com/tag/domain-hijacking/ "domain hijacking")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/detect-dns-hijacking-passive-dns/ "Automatically Detecting DNS Hijacking in Passive DNS")  
  ![Pictorial representation of DNS tunneling detection. Digital illustration of a padlock icon symbolizing cybersecurity, superimposed on a grid comprised of interconnected glowing lines and dots, depicting a global network.](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/10/08_DNS_Overview_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) October 4, 2024 [#### No Way to Hide: Uncovering New Campaigns from Daily Tunneling Detection](https://unit42.paloaltonetworks.com/detecting-dns-tunneling-campaigns/)

* [C2](https://unit42.paloaltonetworks.com/tag/c2/ "C2")

* [DNS tunneling](https://unit42.paloaltonetworks.com/tag/dns-tunneling/ "DNS tunneling")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/detecting-dns-tunneling-campaigns/ "No Way to Hide: Uncovering New Campaigns from Daily Tunneling Detection")  
  ![A visual representation of top level domain tracking. Close-up view of a modern data center with rows of illuminated server racks.](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/08/10_DNS_Category_1505x922-718x440.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 30, 2024 [#### TLD Tracker: Exploring Newly Released Top-Level Domains](https://unit42.paloaltonetworks.com/tracking-newly-released-top-level-domains/)

* [Malicious Domains](https://unit42.paloaltonetworks.com/tag/malicious-domains/ "Malicious Domains")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/tracking-newly-released-top-level-domains/ "TLD Tracker: Exploring Newly Released Top-Level Domains")  
  ![A pictorial representation of deepfake scams. A digital fingerprint integrated into a blue circuit board with glowing lights, illustrating concepts of cybersecurity and technology.](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/08/11_DNS_Overview_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 29, 2024 [#### The Emerging Dynamics of Deepfake Scam Campaigns on the Web](https://unit42.paloaltonetworks.com/dynamics-of-deepfake-scams/)

* [GenAI](https://unit42.paloaltonetworks.com/tag/genai/ "GenAI")

* [Scams](https://unit42.paloaltonetworks.com/tag/scams/ "Scams")

* [Phishing](https://unit42.paloaltonetworks.com/tag/phishing/ "phishing")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/dynamics-of-deepfake-scams/ "The Emerging Dynamics of Deepfake Scam Campaigns on the Web")  
  ![A pictorial representation of using autoencoders to detect malicious DNS traffic. Three transparent blocks with glowing letters "D," "N," and "S" on a circuit board background with blue and purple lighting.](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/08/01_DNS_Overview_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 21, 2024 [#### Autoencoder Is All You Need: Profiling and Detecting Malicious DNS Traffic](https://unit42.paloaltonetworks.com/profiling-detecting-malicious-dns-traffic/)

* [Malicious Domains](https://unit42.paloaltonetworks.com/tag/malicious-domains/ "Malicious Domains")

* [C2](https://unit42.paloaltonetworks.com/tag/c2/ "C2")

* [Machine Learning](https://unit42.paloaltonetworks.com/tag/machine-learning/ "Machine Learning")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/profiling-detecting-malicious-dns-traffic/ "Autoencoder Is All You Need: Profiling and Detecting Malicious DNS Traffic")  
  ![Conceptual illustration of a digital data center with glowing blue networks and holographic clouds above server racks, representing cloud computing infrastructure and data storage.](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/02_DNS_Overview_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) May 13, 2024 [#### Leveraging DNS Tunneling for Tracking and Scanning](https://unit42.paloaltonetworks.com/three-dns-tunneling-campaigns/)

* [DNS tunneling](https://unit42.paloaltonetworks.com/tag/dns-tunneling/ "DNS tunneling")

* [Scanning](https://unit42.paloaltonetworks.com/tag/scanning/ "scanning")

* [Tracking](https://unit42.paloaltonetworks.com/tag/tracking/ "tracking")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/three-dns-tunneling-campaigns/ "Leveraging DNS Tunneling for Tracking and Scanning")

* ![Slider arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/slider-arrow-left.svg)

* ![Slider arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/slider-arrow-left.svg)  
  ![Close button](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/close-modal.svg) ![Enlarged Image]()  
  ![Newsletter](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/03/unit42-footer-subscribe-desktop.png)  
  ![UNIT 42 Small Logo](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/palo-alto-logo-small.svg) Get updates from Unit 42

## Peace of mind comes from staying ahead of threats. Subscribe today.

Your Email

Subscribe for email updates to all Unit 42 threat research.  
By submitting this form, you agree to our [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use "Terms of Use") and acknowledge our [Privacy Statement.](https://www.paloaltonetworks.com/legal-notices/privacy "Privacy Statement")

This site is protected by reCAPTCHA and the Google [Privacy Policy](https://policies.google.com/privacy) and [Terms of Service](https://policies.google.com/terms) apply.

Invalid captcha!
Subscribe ![Right Arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/right-arrow.svg) ![loader](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-loader.svg)  
{#footer} Products and Services

* [AI-Powered Network Security Platform](https://www.paloaltonetworks.com/network-security)

* [Secure AI by Design](https://www.paloaltonetworks.com/ai-security)

* [Prisma AIRS](https://www.paloaltonetworks.com/ai-security/prisma-airs)

* [AI Access Security](https://www.paloaltonetworks.com/sase/ai-access-security)

* [Cloud Delivered Security Services](https://www.paloaltonetworks.com/network-security/security-subscriptions)

* [Advanced Threat Prevention](https://www.paloaltonetworks.com/network-security/advanced-threat-prevention)

* [Advanced URL Filtering](https://www.paloaltonetworks.com/network-security/advanced-url-filtering)

* [Advanced WildFire](https://www.paloaltonetworks.com/network-security/advanced-wildfire)

* [Advanced DNS Security](https://www.paloaltonetworks.com/network-security/advanced-dns-security)

* [Enterprise Data Loss Prevention](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention)

* [Enterprise IoT Security](https://www.paloaltonetworks.com/network-security/enterprise-device-security)

* [Medical IoT Security](https://www.paloaltonetworks.com/network-security/medical-device-security)

* [Industrial OT Security](https://www.paloaltonetworks.com/network-security/ot-security-solution)

* [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security)

* [Next-Generation Firewalls](https://www.paloaltonetworks.com/network-security/next-generation-firewall)

* [Hardware Firewalls](https://www.paloaltonetworks.com/network-security/hardware-firewall-innovations)

* [Software Firewalls](https://www.paloaltonetworks.com/network-security/software-firewalls)

* [Strata Cloud Manager](https://www.paloaltonetworks.com/network-security/strata-cloud-manager)

* [SD-WAN for NGFW](https://www.paloaltonetworks.com/network-security/sd-wan-subscription)

* [PAN-OS](https://www.paloaltonetworks.com/network-security/pan-os)

* [Panorama](https://www.paloaltonetworks.com/network-security/panorama)

* [Secure Access Service Edge](https://www.paloaltonetworks.com/sase)

* [Prisma SASE](https://www.paloaltonetworks.com/sase)

* [Application Acceleration](https://www.paloaltonetworks.com/sase/app-acceleration)

* [Autonomous Digital Experience Management](https://www.paloaltonetworks.com/sase/adem)

* [Enterprise DLP](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention)

* [Prisma Access](https://www.paloaltonetworks.com/sase/access)

* [Prisma Browser](https://www.paloaltonetworks.com/sase/prisma-browser)

* [Prisma SD-WAN](https://www.paloaltonetworks.com/sase/sd-wan)

* [Remote Browser Isolation](https://www.paloaltonetworks.com/sase/remote-browser-isolation)

* [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security)

* [AI-Driven Security Operations Platform](https://www.paloaltonetworks.com/cortex)

* [Cloud Security](https://www.paloaltonetworks.com/cortex/cloud)

* [Cortex Cloud](https://www.paloaltonetworks.com/cortex/cloud)

* [Application Security](https://www.paloaltonetworks.com/cortex/cloud/application-security)

* [Cloud Posture Security](https://www.paloaltonetworks.com/cortex/cloud/cloud-posture-security)

* [Cloud Runtime Security](https://www.paloaltonetworks.com/cortex/cloud/runtime-security)

* [Prisma Cloud](https://www.paloaltonetworks.com/prisma/cloud)

* [AI-Driven SOC](https://www.paloaltonetworks.com/cortex)

* [Cortex XSIAM](https://www.paloaltonetworks.com/cortex/cortex-xsiam)

* [Cortex XDR](https://www.paloaltonetworks.com/cortex/cortex-xdr)

* [Cortex XSOAR](https://www.paloaltonetworks.com/cortex/cortex-xsoar)

* [Cortex Xpanse](https://www.paloaltonetworks.com/cortex/cortex-xpanse)

* [Unit 42 Managed Detection \& Response](https://www.paloaltonetworks.com/cortex/managed-detection-and-response)

* [Managed XSIAM](https://www.paloaltonetworks.com/cortex/managed-xsiam)

* [Next-Generation Identity Security](https://www.paloaltonetworks.com/idira)

* [Privileged Access Management](https://www.paloaltonetworks.com/idira/human/privileged-access-management)

* [Identity and Access Management](https://www.paloaltonetworks.com/idira/human/identity-and-access-management)

* [Endpoint Privilege Manager](https://www.paloaltonetworks.com/idira/human/endpoint-privilege-manager)

* [Identity Governance](https://www.paloaltonetworks.com/idira/human/identity-governance)

* [Workforce Password Management](https://www.paloaltonetworks.com/idira/human/workforce-password-management)

* [Agentic Identities](https://www.paloaltonetworks.com/idira/agentic)

* [Secrets Management](https://www.paloaltonetworks.com/idira/machine/secrets-management)

* [Unified Secrets Governance](https://www.paloaltonetworks.com/idira/machine/unified-secrets-governance)

* [Application Credentials Delivery](https://www.paloaltonetworks.com/idira/machine/application-credentials-delivery)

* [Vendor Privileged Access](https://www.paloaltonetworks.com/idira/human/vendor-privileged-access)

* [Threat Intel and Incident Response Services](https://www.paloaltonetworks.com/unit42)

* [Prepare for Emerging Risks](https://www.paloaltonetworks.com/unit42/frontier-ai-defense)

* [Strengthen Your Defenses](https://www.paloaltonetworks.com/unit42/strengthen-your-defenses)

* [Build Your Security Strategy](https://www.paloaltonetworks.com/unit42/build-your-security-strategy)

* [Understand the Adversary](https://www.paloaltonetworks.com/unit42/threat-intelligence)

* [Respond to a Cyber Attack](https://www.paloaltonetworks.com/unit42/respond)  
  Company

* [About Us](https://www.paloaltonetworks.com/about-us)

* [Careers](https://jobs.paloaltonetworks.com/en/)

* [Contact Us](https://www.paloaltonetworks.com/company/contact-sales)

* [Corporate Responsibility](https://www.paloaltonetworks.com/about-us/corporate-responsibility)

* [Customers](https://www.paloaltonetworks.com/customers)

* [Investor Relations](https://investors.paloaltonetworks.com/)

* [Location](https://www.paloaltonetworks.com/about-us/locations)

* [Newsroom](https://www.paloaltonetworks.com/company/newsroom)  
  Popular Links

* [Blog](https://www.paloaltonetworks.com/blog/)

* [Communities](https://www.paloaltonetworks.com/communities)

* [Content Library](https://www.paloaltonetworks.com/resources)

* [Cyberpedia](https://www.paloaltonetworks.com/cyberpedia)

* [Event Center](https://events.paloaltonetworks.com/)

* [Manage Email Preferences](https://start.paloaltonetworks.com/preference-center)

* [Products A-Z](https://www.paloaltonetworks.com/products/products-a-z)

* [Product Certifications](https://www.paloaltonetworks.com/legal-notices/trust-center/certifications)

* [Report a Vulnerability](https://www.paloaltonetworks.com/security-disclosure)

* [Sitemap](https://www.paloaltonetworks.com/sitemap)

* [Tech Docs](https://docs.paloaltonetworks.com/)

* [Unit 42](https://unit42.paloaltonetworks.com/)

* [Do Not Sell or Share My Personal Information](https://panwedd.exterro.net/portal/dsar.htm?target=panwedd)
  ![Palo Alto Networks Logo](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/pan-logo-dark.svg)

* [Privacy](https://www.paloaltonetworks.com/legal-notices/privacy)

* [Trust Center](https://www.paloaltonetworks.com/legal-notices/trust-center)

* [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use)

* [Documents](https://www.paloaltonetworks.com/legal)

Copyright © 2026 Palo Alto Networks. All Rights Reserved

* [![Youtube](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/youtube-black.svg)](https://www.youtube.com/user/paloaltonetworks)
* [![Podcast](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/icons/podcast.svg)](https://www.paloaltonetworks.com/podcasts/threat-vector)
* [![Facebook](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/facebook-black.svg)](https://www.facebook.com/PaloAltoNetworks/)
* [![LinkedIn](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/linkedin-black.svg)](https://www.linkedin.com/company/palo-alto-networks)
* [![Twitter](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/twitter-x-black.svg)](https://twitter.com/PaloAltoNtwks)
* EN  
  Select your language  
  ![Play](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-play-icon.svg) ![Pause](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-pause-icon1.svg) ![Minimize](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-minimize.svg) ![Close button](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/close-modal.svg)

### Default Heading

Read the article ![Right Arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/right-arrow.svg)  
Seekbar

![Play](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-play-icon.svg) ![Pause](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-pause-icon1.svg)  
![Volume](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-volume.svg)  
Volume
![Minimize](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-minimize.svg)
