CYBERSECURITYTRACKER
TRACKING7,004 stories in this site build1,474 vulnerability news stories in this site build
Permanent story citation

Almost Half of Malware Samples Communicate Direct to IP

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 3822

As cited

Copy frozen at (site build).

threat intel

Almost Half of Malware Samples Communicate Direct to IP

Nearly half of command and control (C2) malware samples bypass domain name system (DNS) resolution by connecting directly to IP addresses, reducing visibility for defenders relying on DNS-based detection. Organizations can strengthen defenses through zero trust approaches that enforce strict IP-level network controls.

Why it matters: Security teams need to expand detection beyond DNS monitoring to catch C2 communications that use direct IP connections, as traditional DNS-based defenses miss roughly half of active malware traffic.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary