Unit 42
Read post

Almost Half of Malware Samples Communicate Direct to IP

Analysis of 4 million dynamic analysis reports reveals that 45.32% of malware samples with C2 activity bypass DNS entirely by connecting directly to hard-coded IP addresses. This 'direct-to-IP' (D2IP) behavior renders DNS-based defenses blind to nearly half of malware C2 traffic. The research introduces Zero Trust IP (ZT-IP), a network-level enforcement approach that only permits outbound connections to IP addresses previously resolved via a trusted DNS response. Real-world threats uncovered through ZT-IP analysis include Phorpiex ransomware droppers, a persistent data exfiltration campaign using obfuscated \GET HTTP requests, SectopRAT targeting educational institutions, and Mozi/Boatnet IoT botnets targeting legacy hardware across 14 architectures. Indicators of compromise and a technical appendix explaining ZT-IP mechanics are included.

    #security#malware
Aug 04•11m read time•From unit42.paloaltonetworks.com
Post cover image
Table of contents
Executive SummaryThe DNS Visibility GapThreats Discovered Through ZT-IP AnalysisConclusionIndicators of CompromiseA dditional ResourcesAppendix: What Is ZT-IP?
80 Impressions
Unit 42's image
Unit 42

Unit42 is a cybersecurity research team known for its analysis of cyber threats, malware, and cyber...

63 Followers

•

72 Upvotes

Would you recommend this post?

Copy link
WhatsApp
Facebook
X
New Squad
  • © 2026 Daily Dev Ltd.
  • Guidelines
  • Explore
  • Tags
  • Sources
  • Squads
  • Leaderboard