The DNSMessenger remote access Trojan (RAT) was first detected by a security researcher, Simpo, in February 2017. It is a sophisticated RAT and is likely used in targeted attacks. According to further investigation conducted by Cisco Talos, DNSMessenger uses malicious macros in Word documents to infect victims. 

