Almost Half of Malware Samples Communicate Direct to IP
Almost half (45.32%) of malware samples with Command & Control (C2) activity bypass DNS entirely, communicating directly to IP addresses. This behavior, known as D2IP, is prevalent across various threat types, including ransomware droppers, P2P botnets, and data exfiltration campaigns. Researchers at Palo Alto Unit 42 highlight this gap in DNS-based security, introducing Zero Trust IP (ZT-IP) as a network-level enforcement mechanism to block these direct IP connections. The findings reveal a significant number of attacks originating from malicious IP addresses and demonstrate the effectiveness of ZT-IP in uncovering threats that traditional DNS security measures miss.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data
