news.mlab.sh
Back to the feed
threat-intel

Almost Half of Malware Samples Communicate Direct to IP

High
Image: Palo Alto Unit 42
Summary

Almost half (45.32%) of malware samples with Command & Control (C2) activity bypass DNS entirely, communicating directly to IP addresses. This behavior, known as D2IP, is prevalent across various threat types, including ransomware droppers, P2P botnets, and data exfiltration campaigns. Researchers at Palo Alto Unit 42 highlight this gap in DNS-based security, introducing Zero Trust IP (ZT-IP) as a network-level enforcement mechanism to block these direct IP connections. The findings reveal a significant number of attacks originating from malicious IP addresses and demonstrate the effectiveness of ZT-IP in uncovering threats that traditional DNS security measures miss.

Read the full article at Palo Alto Unit 42

Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data

Report an error
Confirmed errors are fixed and listed on /corrections.