[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f95Ce_G3aNxbCekNnSRya0IkPyhkWLOajDWfNk_R4E20":3},{"article":4,"iocs":40,"watch_terms":45},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":23,"category":24,"article_tags":27},"99a59a72-7d78-46bc-8385-4ba456bf6abd","In the TXT DNS record of sagiw.chatcamic[.]com, there is some PS code...\n(1\u002F2) https:\u002F\u002Ft.co\u002FOa1gJ...","in-the-txt-dns-record-of-sagiw-chatcamic-com-there-is-some-ps-code-1-2-https-t-c-e5e849","In the TXT DNS record of sagiw.chatcamic[.]com, there is some PS code...\n(1\u002F2) https:\u002F\u002Ft.co\u002FOa1gJh37Mk","Security researchers identified PowerShell code embedded in the TXT DNS record of sagiw.chatcamic[.]com, suggesting use of DNS as a command-and-control or data exfiltration channel. This technique, known as DNS tunneling or DNS data exfiltration, is commonly employed by malware operators to evade detection and maintain persistence.","Malicious PowerShell code discovered in DNS TXT record of suspicious domain.",null,"https:\u002F\u002Fx.com\u002Fmalwrhunterteam\u002Fstatus\u002F2049458253243810069","https:\u002F\u002Fpbs.twimg.com\u002Fmedia\u002FHHEgzuWbsAAQFOm.jpg","2026-04-29T11:58:19+00:00","2026-04-29T12:00:04.5716+00:00",7,[18,21],{"name":19,"type":20},"PowerShell","technology",{"name":22,"type":20},"DNS TXT records","89f78b1c-3503-45a1-9fc7-e23d2ce1c6d5",{"id":23,"icon":11,"name":25,"slug":26},"Malware","malware",[28,33,35],{"category":29},{"id":30,"icon":11,"name":31,"slug":32},"02371804-cf6d-4449-98de-f1a2d4d9b266","Tools","tools",{"category":34},{"id":23,"icon":11,"name":25,"slug":26},{"category":36},{"id":37,"icon":11,"name":38,"slug":39},"e7b231c8-5f79-4465-8d38-1ef13aea5a14","Threat Intelligence","threat-intelligence",[41],{"type":42,"value":43,"context":44},"domain","sagiw.chatcamic.com","Domain containing malicious PowerShell code in TXT DNS record",[]]