Fast Flux: A National Security Threat
ID: d21f0a27-9ccf-574d-88fe-7cb49651adee
STIX ID: report--d21f0a27-9ccf-574d-88fe-7cb49651adee
Feed Name: CISA Cybersecurity Advisories
This joint advisory from NSA, CISA, FBI, ASD/ACSC, CCCS and NCSC-NZ warns that fast flux — rapidly rotating DNS records and, in double flux, frequently changing name servers — is being used by cybercriminals and APTs to obscure C2, sustain phishing sites, and enable bulletproof hosting; it defines single- and double-flux, cites observed abuse (including ransomware and Gamaredon), and provides practical detection (DNS entropy, TTL analysis, IP/geolocation inconsistency, flow data, reputational feeds) and mitigation guidance (blocking/sinkholing, reputational filtering, enhanced logging, information sharing, and phishing awareness) for ISPs, PDNS providers, and organizations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
