Almost Half of Malware Samples Communicate Direct to IP
Unit 42 data shows roughly half of C2 malware now skips DNS entirely, undermining organisations that rely primarily on DNS-layer visibility for threat detection.
Summary written by editorial AI · Source link below
Nearly half of C2 malware bypasses DNS by connecting directly to IP addresses. Zero trust IP enforcement secures networks against these threats. The post Almost Half of Malware Samples Communicate Direct to IP appeared first on Unit 42 .
Editorial Analysis
Enterprises heavily invested in DNS filtering and monitoring may have a significant blind spot; direct-to-IP C2 requires complementary network-layer controls such as IP reputation enforcement and zero-trust segmentation.
Review firewall egress rules and NDR policies to detect and block outbound traffic to raw IP addresses that bypass DNS resolution.
Nearly half of command-and-control malware evades DNS-based defences, requiring investment in IP-layer network controls.
Forward-looking interpretation drafted by editorial AI under human review — not a reproduction of the source. See methodology.
External link — opens at Unit 42 (Palo Alto) in a new tab.
More from the Threat Intel Desk
- Attackers conceal phishing lures using invisible Unicode characters1d
- Attackers Hijack MikroTik Routers Through Internet-Exposed SSH Without Authentication1d
- Four REVSTEALER-Linked Modules Disable Windows Update and Defender to Run a Crypto Miner2d
- Attackers Breached JetBrains Cadence via Unpatched TeamCity, Extracting AWS Credentials2d
- Over 5,400 hacked sites serve ClickFix payloads stored on the blockchain2d