As cited
Copy frozen at (site build).
threat intel
Almost Half of Malware Samples Communicate Direct to IP
Nearly half of command and control (C2) malware samples bypass domain name system (DNS) resolution by connecting directly to IP addresses, reducing visibility for defenders relying on DNS-based detection. Organizations can strengthen defenses through zero trust approaches that enforce strict IP-level network controls.
Why it matters: Security teams need to expand detection beyond DNS monitoring to catch C2 communications that use direct IP connections, as traditional DNS-based defenses miss roughly half of active malware traffic.
- Source published
- First seen by Cybersecurity Tracker