logo

Fast Flux: A National Security Threat

ID: d21f0a27-9ccf-574d-88fe-7cb49651adee

STIX ID: report--d21f0a27-9ccf-574d-88fe-7cb49651adee

Feed Name: CISA Cybersecurity Advisories

Threat Score
70/100

Date Published: 2025-04-01

Date Updated: 2026-04-19

Author: CISA

...
...

This joint advisory from NSA, CISA, FBI, ASD/ACSC, CCCS and NCSC-NZ warns that fast flux — rapidly rotating DNS records and, in double flux, frequently changing name servers — is being used by cybercriminals and APTs to obscure C2, sustain phishing sites, and enable bulletproof hosting; it defines single- and double-flux, cites observed abuse (including ransomware and Gamaredon), and provides practical detection (DNS entropy, TTL analysis, IP/geolocation inconsistency, flow data, reputational feeds) and mitigation guidance (blocking/sinkholing, reputational filtering, enhanced logging, information sharing, and phishing awareness) for ISPs, PDNS providers, and organizations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.