logo

Almost Half of Malware Samples Communicate Direct to IP

ID: f6808445-eb9d-5e4f-877a-01171bd3dbec

STIX ID: report--f6808445-eb9d-5e4f-877a-01171bd3dbec

Feed Name: Palo Alto Networks Unit 42

Threat Score
75/100

Date Published: 2026-08-04

Date Updated: 2026-08-04

Author: Shu Wang, Zhanhao Chen and Daiping Liu

...
...

This report examines the prevalence and impact of malware that bypasses DNS by making direct-to-IP (D2IP) connections, quantifying D2IP activity across 4 million dynamic analysis reports and describing multiple active threats (Phorpiex ransomware droppers, an obfuscated “\GET” exfiltration campaign, SectopRAT browser-proxy campaigns, and IoT botnets Mozi and Boatnet). It documents indicators of compromise (malicious IPs and sample hashes), operational behaviors (hard-coded IPs, payload delivery, port/IP rotation), and proposes ZT-IP—a zero-trust, DNS-sanctioned IP enforcement model—to close the DNS visibility gap.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.