logo

US, Australia, Canada warn of ‘fast flux’ scheme used by ransomware gangs

ID: 5aa24b9d-385e-511c-ac0a-67122ad6ad18

STIX ID: report--5aa24b9d-385e-511c-ac0a-67122ad6ad18

Feed Name: The Record from Recorded Future News

Threat Score
70/100

Date Published: 2025-04-03

Date Updated: 2026-05-01

...
...

Cybersecurity agencies warn that cybercriminals and nation-state actors increasingly use the fast flux DNS technique—frequently via botnets and bulletproof hosting—to rapidly rotate IPs (single flux) and name servers (double flux), enabling resilient command-and-control, evasion of IP blocking and law enforcement takedowns; the advisory cites use by ransomware groups (Hive, Nefilim) and Russian-aligned Gamaredon and highlights the renewed operational refinement and broad adoption of the technique.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.