Royal DNS

First seen
2017-05-01 00:00:00
Malware type
backdoor
Family
Malware family
Profile updated
2026-07-07 12:39:43

Targeted industries: government-and-public-sector defense-and-aerospace

Targeted regions: country_code:cn country_code:us

Context

RoyalDNS is a DNS based backdoor used by APT15 that persistences on a system through a service called 'Nwsapagent'.

Reports & references

  • github.com — Royal Apt (report)
  • research.nccgroup.com — Apt15 Is Alive And Strong An Analysis Of Royalcli And Royaldns (report)
  • secureworks.com — Bronze Palace (report)
  • nccgroup.trust — Apt15 Is Alive And Strong An Analysis Of Royalcli And Royaldns (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Royal Dns (report)

External references