Palo Alto Networks Unit 42 reported that a large share of malware command-and-control traffic is avoiding DNS-based detection by connecting directly to IP addresses. In an analysis of more than 4 million dynamic malware reports collected over 30 days, 20.11% of samples showed C2 activity, and 45.32% of those samples made at least one direct-to-IP connection. Those direct connections accounted for 23.17% of all observed C2 attempts, indicating that DNS-focused controls can miss a substantial portion of malicious outbound traffic.
The research linked this technique to multiple active threats, including Phorpiex ransomware droppers using hard-coded IP infrastructure, an obfuscated \GET data-exfiltration campaign hosted on Brazilian public cloud infrastructure, SectopRAT activity targeting educational institutions, and IoT botnets such as Mozi and a Mirai variant known as Boatnet. Unit 42 said the findings support a Zero Trust IP enforcement model that permits outbound connections only to IP addresses previously validated through trusted DNS resolution, aiming to close a visibility gap exploited by malware that communicates outside normal domain-based controls.

Get the actors, campaigns, and ATT&CK mapping behind it.
4 events from the most recent confirmed update back to the earliest known activity.
The report described two separate attackers operating SectopRAT infrastructure at 87.120.107[.]33 and 194.76.227[.]94 against educational institutions. SectopRAT mirrored victim browser traffic in real time and used the /churl and /fsave endpoints to exfiltrate visited URLs, session content, usernames, and plaintext passwords.
Unit 42 identified a persistent data exfiltration campaign using a non-standard obfuscated HTTP request format beginning with "\GET" and carrying encoded payloads. The infrastructure was hosted on public cloud infrastructure in Brazil, rotated ports and IPs regularly, and samples were found affecting government, airline, and university sectors.
The analysis identified suspicious HTTP GET requests to 178.16.54[.]109 tied to Phorpiex/Trik activity, including retrieval of a malware binary from hxxp://178.16.54[.]109/st.exe. Unit 42 said the IP hosted multiple malicious samples used in staged payload delivery, including configuration fetching and later ransomware-related components.
Unit 42 published analysis of more than 4 million Advanced WildFire dynamic analysis reports collected over a 30-day period, finding that 20.11% of malware samples showed C2 activity and that 45.32% of those made at least one direct-to-IP connection without a preceding DNS query. The report concluded that DNS-focused defenses miss a substantial share of malicious outbound traffic and proposed Zero Trust IP enforcement to block unsanctioned IP destinations.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 20 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.