logo

Hackers Exploit Shared CDN Edge IPs to Evade Protective DNS Filtering

ID: d195b8bd-03ff-505f-b8f6-3dfbfc544363

STIX ID: report--d195b8bd-03ff-505f-b8f6-3dfbfc544363

Feed Name: GBHackers

Threat Score
70/100

Date Published: 2026-05-27

Date Updated: 2026-05-27

Author: Divya

...
...

ADAMnetworks describes “Underminr,” a stealthy evasion technique that leverages shared CDN edge IPs to route malicious traffic while DNS lookups appear to target benign domains. By initiating TLS connections with attacker-controlled SNI or Host values that differ from the resolved DNS name (or by connecting directly to CDN IPs or using ECH), adversaries can bypass DNS-based protections, establish covert C2 channels, and exfiltrate data; the report details attack modes, links the behavior to known APT tactics, and recommends correlating DNS, network, and application-layer signals for detection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.