Unit 42 analysis of 4 million dynamic analysis reports reveals that 45.32% of malware samples with C2 activity communicate directly to hard-coded IP addresses without DNS resolution, rendering DNS-based security controls ineffective. The article introduces ZT-IP (Zero Trust IP), a network-level enforcement approach that blocks outbound connections to IPs not previously sanctioned by a DNS response. Multiple active threats are documented including Phorpiex ransomware droppers, a custom \GET exfiltration campaign, SectopRAT credential harvesting, and Mozi/Boatnet IoT botnets — all leveraging D2IP communication to evade detection.
ZT-IP
1 post
Almost Half of Malware Samples Communicate Direct to IP