A familiar Windows malware family is being linked to a persistence trick that blends into routine admin work, while its control traffic shifts into DNS and away from the more obvious web channels.