Executive Summary
In August 2026, Palo Alto Networks' Unit 42 reported that nearly half (45.32%) of malware samples with command-and-control (C2) activity bypass DNS by communicating directly to IP addresses. This tactic allows malware to evade DNS-based defenses, posing significant challenges to traditional security measures. The analysis highlighted threats such as Phorpiex ransomware droppers, Mozi P2P botnets, and data exfiltration campaigns utilizing obfuscated HTTP requests.
This trend underscores the need for enhanced network-level enforcement mechanisms, like Zero Trust IP (ZT-IP), which applies zero trust principles to IP-based traffic. Implementing such measures is crucial to detect and mitigate threats that circumvent DNS, ensuring robust protection against evolving malware tactics.
Why This Matters Now
The increasing prevalence of malware bypassing DNS underscores the urgency for organizations to adopt advanced security measures like Zero Trust IP (ZT-IP) to effectively detect and mitigate these evolving threats.
Attack Path Analysis
The Phorpiex botnet initiates attacks by distributing malicious LNK files via phishing emails, leading to the execution of ransomware payloads. Upon execution, the malware establishes persistence and may escalate privileges to gain higher-level access. It then moves laterally within the network to infect additional systems. The malware establishes command and control channels to receive instructions and exfiltrate data. Finally, it encrypts critical data, rendering it inaccessible and demanding ransom payments.
Kill Chain Progression
Initial Compromise
Description
Phorpiex botnet distributes phishing emails containing malicious LNK files that, when executed, initiate the infection process.
Related CVEs
CVE-2017-17215
CVSS 8.8Huawei HG532 routers contain a remote code execution vulnerability due to improper input validation in the TR-064 service.
Affected Products:
Huawei HG532 – All versions
Exploit Status:
exploited in the wildCVE-2018-10561
CVSS 9.8GPON routers are vulnerable to authentication bypass, allowing remote attackers to execute arbitrary commands.
Affected Products:
Multiple GPON Routers – All versions
Exploit Status:
exploited in the wildCVE-2018-10562
CVSS 9.8GPON routers contain a command injection vulnerability that allows remote attackers to execute arbitrary commands.
Affected Products:
Multiple GPON Routers – All versions
Exploit Status:
exploited in the wildCVE-2014-8361
CVSS 9.8Devices using the Realtek SDK are vulnerable to a command injection flaw in the 'formSysCmd' function, allowing remote code execution.
Affected Products:
Multiple Devices using Realtek SDK – All versions
Exploit Status:
exploited in the wild
MITRE ATT&CK® Techniques
Non-Application Layer Protocol
Traffic Signaling
Application Layer Protocol
Non-Standard Port
Dynamic Resolution
Ingress Tool Transfer
Data Obfuscation
Proxy
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Change Control Processes
Control ID: 6.4.1
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA – ICT Risk Management Framework
Control ID: Article 5
CISA ZTMM 2.0 – Network and Environment
Control ID: Pillar 3
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Financial Services
Direct-to-IP malware bypasses DNS security controls, exposing financial institutions to command-and-control communications, data exfiltration, and ransomware threats requiring zero-trust network segmentation.
Government Administration
Government entities face heightened risk from multi-vector campaigns using D2IP connections for persistent data exfiltration, requiring enhanced egress filtering and encrypted traffic inspection capabilities.
Higher Education/Acadamia
Educational institutions targeted by SectopRAT campaigns suffer browser traffic mirroring and credential harvesting through direct-IP connections, compromising SSO systems and learning management platforms.
Airlines/Aviation
Aviation sector impacted by obfuscated GET exfiltration campaigns targeting high-value sectors, requiring multicloud visibility controls and anomaly detection for cloud-hosted command-and-control infrastructure.
Sources
- Almost Half of Malware Samples Communicate Direct to IPhttps://unit42.paloaltonetworks.com/malware-bypass-dns-direct-to-ip/Verified
- How to proactively defend against Mozi IoT botnethttps://www.microsoft.com/en-us/security/blog/2021/08/19/how-to-proactively-defend-against-mozi-iot-botnet/Verified
- Infamous IoT botnet Mozi taken down via a kill switchhttps://www.eset.com/sg/about/newsroom/press-releases1/announcements/eset-research-infamous-iot-botnet-mozi-taken-down-via-a-kill-switch/Verified
- Mozi IoT Botnet: Here's What MSSPs Need to Knowhttps://www.msspalert.com/news/mozi-iot-botnet-informationVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Aviatrix Zero Trust CNSF is pertinent to this incident as it would likely limit the Phorpiex botnet's ability to propagate and exfiltrate data by enforcing strict segmentation and identity-based access controls.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: The CNSF would likely limit the malware's ability to communicate with external command and control servers, reducing the risk of successful initial compromise.
Control: Zero Trust Segmentation
Mitigation: Zero Trust Segmentation would likely limit the malware's ability to access sensitive resources, reducing the impact of privilege escalation.
Control: East-West Traffic Security
Mitigation: East-West Traffic Security would likely limit the malware's ability to move laterally, reducing the spread of infection within the network.
Control: Multicloud Visibility & Control
Mitigation: Multicloud Visibility & Control would likely limit the malware's ability to establish command and control channels, reducing the risk of data exfiltration.
Control: Egress Security & Policy Enforcement
Mitigation: Egress Security & Policy Enforcement would likely limit the malware's ability to exfiltrate data, reducing the risk of data loss.
While the malware may still encrypt data, the overall impact would likely be limited due to constrained lateral movement and data exfiltration capabilities.
Impact at a Glance
Affected Business Functions
- Network Operations
- Data Security
- Customer Services
Estimated downtime: 7 days
Estimated loss: $500,000
Potential exposure of sensitive customer data and internal communications.
Recommended Actions
Key Takeaways & Next Steps
- • Implement robust email filtering and user training to prevent phishing attacks.
- • Enforce strict privilege management to limit the impact of potential escalations.
- • Deploy network segmentation to contain lateral movement of malware.
- • Utilize advanced threat detection systems to identify and block command and control communications.
- • Regularly back up critical data and maintain an incident response plan to mitigate ransomware impacts.



