logo

For flux sake: CISA, annexable allies warn of hot DNS threat

ID: 2a49de68-43e4-5af0-9e79-ef2b5a879621

STIX ID: report--2a49de68-43e4-5af0-9e79-ef2b5a879621

Feed Name: The Register (Security)

Threat Score
70/100

Date Published: 2025-04-03

Date Updated: 2026-04-26

Author: Thomas Claburn

...
...

CISA and partner agencies issued an advisory on fast flux DNS techniques—where attackers rapidly change DNS records (single- and double-flux) to hide malicious servers and build resilient C2—highlighting detection challenges (low TTLs, high churn), recommending DNS filtering, anomaly detection, PDNS services, and other mitigations, and citing use by ransomware groups (Hive, Nefilim) and nation-state-linked actors (Gamaredon).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.