HomeIntelligenceBrief
BREACH BRIEF🟠 High ThreatIntel

Almost Half of Malware Samples Bypass DNS and Communicate Directly to IP Addresses

Unit 42 found 45 % of malware with C2 activity connects straight to hard‑coded IPs, evading DNS filters. This highlights a control gap that SOC 2 auditors will probe when reviewing outbound‑traffic monitoring and evidence collection.

LiveThreat™ Intelligence · 📅 August 05, 2026· 📰 unit42.paloaltonetworks.com
🟠
Severity
High
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
4 sector(s)
Actions
3 recommended
📰
Source
unit42.paloaltonetworks.com

Almost Half of Malware Samples Bypass DNS and Communicate Directly to IP Addresses

What Happened — Unit 42 analyzed 4 million sandbox runs and found that 45.32 % of malware samples that exhibit any command‑and‑control (C2) activity connect directly to hard‑coded IP addresses, completely sidestepping DNS. Those direct‑to‑IP (D2IP) connections represent 23.17 % of all C2 traffic observed.

Why It Matters for Compliance & Audit Readiness

  • DNS‑based controls are a common evidence source for SOC 2 CC6 (System and Communications Protection) and for demonstrating “monitoring of network traffic” – a gap here means you may lack auditable proof of blocking malicious outbound traffic.
  • Continuous‑control monitoring must capture both DNS queries and raw IP flows; otherwise you cannot produce a defensible audit trail that shows you mitigated a known control weakness.
  • Mapping this D2IP behavior to your control library (e.g., NIST 800‑53 SC‑7, ISO 27001 A.13.1) and collecting continuous evidence is exactly the scenario where Verisq’s Control Mapping capability helps you close the gap and generate SOC 2‑ready artifacts.

Who Is Affected — Enterprises across technology, finance, healthcare, and manufacturing that rely on DNS filtering as a primary outbound‑traffic control.

Recommended Actions

  • Extend outbound‑traffic monitoring to include raw IP connections and correlate them with any prior DNS resolution events.
  • Map the “no‑DNS‑lookup” C2 pattern to SOC 2 CC6 and create a continuous evidence collection pipeline (e.g., NetFlow, Zeek, firewall logs).
  • Validate that your DNS security platform can flag or block hard‑coded IP destinations, and document the control in your audit evidence repository.

Technical Notes — The study covers ransomware droppers (e.g., Phorpiex), P2P IoT botnets (Mozi), and custom exfiltration tools that embed IPv4 literals in binaries. No specific CVE is cited; the issue is a misconfiguration / control gap in DNS‑centric defenses. Source: Palo Alto Unit 42 – Malware Bypass DNS – Direct‑to‑IP

📰 Original Source
https://unit42.paloaltonetworks.com/malware-bypass-dns-direct-to-ip/

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Every gap like this maps to a control you can evidence.

The Verisq AI Trust Operations platform maps incidents to your control framework and collects the evidence continuously — so your Trust Center shows proof, not promises, when a buyer or auditor asks.

Explore the Verisq AI Trust Operations platform →