Threat actors are using Domain Name System (DNS) tunneling to track when their targets open phishing emails and click on malicious links, and to scan networks for potential vulnerabilities.

https://www.bleepingcomputer.com/news/security/hackers-use-dns-tunneling-for-network-scanning-tracking-victims/

Hackers use DNS tunneling for network scanning, tracking victims

Threat actors are using Domain Name System (DNS) tunneling to track when their targets open phishing emails and click on malicious links, and to scan networks for potential vulnerabilities.

BleepingComputer
@BleepingComputer Anyone can use #DNS transport and it's trivial. https://dnskv.com is a free key value data store over dns which doesn't require any other protocols than pure DNS.
dnskv.com - DNS Key Value Storage

Store and retrieve data over raw DNS protocol and test for DNS leaks