[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fH7dk-4lwxD7yMicABOlfPjrVqXfG9TJjese3vW7XpLE":3},{"article":4,"iocs":40,"watch_terms":48},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":23,"category":24,"article_tags":27},"121056bf-f502-4dfd-8171-0e5e85bf45e2","That PS code will get the TXT DNS record of sagi.chatcamic[.]com, write the content to a file and...","that-ps-code-will-get-the-txt-dns-record-of-sagi-chatcamic-com-write-the-content-c80dde","That PS code will get the TXT DNS record of sagi.chatcamic[.]com, write the content to a file and run it.\n(2\u002F3) https:\u002F\u002Ft.co\u002F7TwqdUGxhZ","A PowerShell-based attack vector uses DNS TXT records as a command-and-control mechanism to fetch and execute arbitrary code from the domain sagi.chatcamic[.]com. The technique leverages DNS queries to retrieve instructions, writing them to a file before execution—a method commonly used in fileless malware and living-off-the-land attacks to evade detection.","PowerShell script retrieves TXT DNS record from malicious domain and executes downloaded content.",null,"https:\u002F\u002Fx.com\u002Fmalwrhunterteam\u002Fstatus\u002F2049458257089978662","https:\u002F\u002Fpbs.twimg.com\u002Fmedia\u002FHHEhp93akAANQeO.jpg","2026-04-29T11:58:20+00:00","2026-04-29T12:00:04.5716+00:00",7,[18,21],{"name":19,"type":20},"PowerShell","technology",{"name":22,"type":20},"DNS TXT Records","89f78b1c-3503-45a1-9fc7-e23d2ce1c6d5",{"id":23,"icon":11,"name":25,"slug":26},"Malware","malware",[28,33,35],{"category":29},{"id":30,"icon":11,"name":31,"slug":32},"26b0b636-0e31-4db1-bffb-61bdf9f20a58","Supply Chain","supply-chain",{"category":34},{"id":23,"icon":11,"name":25,"slug":26},{"category":36},{"id":37,"icon":11,"name":38,"slug":39},"e7b231c8-5f79-4465-8d38-1ef13aea5a14","Threat Intelligence","threat-intelligence",[41,45],{"type":42,"value":43,"context":44},"domain","sagi.chatcamic[.]com","Malicious C2 domain used to deliver PowerShell payloads via DNS TXT records",{"type":26,"value":46,"context":47},"PowerShell DNS TXT record execution","Fileless malware technique using DNS exfiltration and command delivery",[]]