Established 2026Sunday, 6 September 2026
presents

The CloudySec Digest

The wires, edited.
← Front PageThreat Intel Desk
Threat Intel

Almost Half of Malware Samples Communicate Direct to IP

Unit 42 data shows roughly half of C2 malware now skips DNS entirely, undermining organisations that rely primarily on DNS-layer visibility for threat detection.

Summary written by editorial AI · Source link below

Filed by Unit 42 (Palo Alto)1 min readRead at source ↗

Nearly half of C2 malware bypasses DNS by connecting directly to IP addresses. Zero trust IP enforcement secures networks against these threats. The post Almost Half of Malware Samples Communicate Direct to IP appeared first on Unit 42 .

Editorial Analysis

Why it matters

Enterprises heavily invested in DNS filtering and monitoring may have a significant blind spot; direct-to-IP C2 requires complementary network-layer controls such as IP reputation enforcement and zero-trust segmentation.

What to do

Review firewall egress rules and NDR policies to detect and block outbound traffic to raw IP addresses that bypass DNS resolution.

Board brief

Nearly half of command-and-control malware evades DNS-based defences, requiring investment in IP-layer network controls.

Forward-looking interpretation drafted by editorial AI under human review — not a reproduction of the source. See methodology.

Continue at the source
Read the full report at Unit 42 (Palo Alto)

External link — opens at Unit 42 (Palo Alto) in a new tab.

§
Continue with

More from the Threat Intel Desk