unit42.paloaltonetworks.com 8/4/2026, 1:12:29 PM · external

Nearly half of malware talks straight to IPs, bypassing DNS

Nearly half of malware talks straight to IPs, bypassing DNS
CyberSIXT Evidence Panel Source marked as original reporting
Threat Actor
Phorpiex

THE Palo Alto Networks report discusses the prevalence of malware samples bypassing DNS and communicating directly to IP addresses, termed direct-to-IP (D2IP) communication. Findings from over 4 million reports indicate that about 45.32% of malware with command-and-control (C2) activity utilizes D2IP connections. This communication evades traditional DNS-based security, leading to a gap in threat visibility.

The article introduces Zero Trust IP (ZT-IP), a security model that applies zero trust principles to IP traffic, ensuring that only connections sanctioned by DNS responses are allowed. The report outlines various threats identified through ZT-IP analysis, including Phorpiex ransomware, an obfuscation tactic using \GET for data exfiltration, and specific IoT botnets like Mozi. Recommendations for Palo Alto Networks products are included, emphasizing enhanced protection against these threats.

View full article

Article by CyberSIXT