Almost Half of Malware Samples Communicate Direct to IP
ID: f6808445-eb9d-5e4f-877a-01171bd3dbec
STIX ID: report--f6808445-eb9d-5e4f-877a-01171bd3dbec
Feed Name: Palo Alto Networks Unit 42
Date Published: 2026-08-04
Date Updated: 2026-08-04
Author: Shu Wang, Zhanhao Chen and Daiping Liu
This report examines the prevalence and impact of malware that bypasses DNS by making direct-to-IP (D2IP) connections, quantifying D2IP activity across 4 million dynamic analysis reports and describing multiple active threats (Phorpiex ransomware droppers, an obfuscated “\GET” exfiltration campaign, SectopRAT browser-proxy campaigns, and IoT botnets Mozi and Boatnet). It documents indicators of compromise (malicious IPs and sample hashes), operational behaviors (hard-coded IPs, payload delivery, port/IP rotation), and proposes ZT-IP—a zero-trust, DNS-sanctioned IP enforcement model—to close the DNS visibility gap.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
