{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/sectoprat/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Phorpiex","SectopRAT","Mozi","Mirai"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":[],"content_html":"\u003cp\u003eResearch from Unit 42 indicates that approximately 45% of malware samples with command-and-control (C2) activity bypass DNS resolution, instead initiating direct-to-IP (D2IP) connections. This behavior is prevalent across various threats, including Phorpiex ransomware droppers, SectopRAT, and Mozi botnet variants. Attackers utilize hardcoded IP addresses within malware binaries to evade DNS sinkholing and anomaly detection systems that rely on domain-based reputation.\u003c/p\u003e\n\u003cp\u003eThe research highlights that D2IP traffic accounts for over 23% of total C2 connection attempts. Attackers leverage this technique for diverse objectives, ranging from staged payload delivery and P2P mesh communication to obfuscated data exfiltration protocols (e.g., the \\GET protocol). This evasion strategy effectively bypasses traditional DNS-based security controls, necessitating network-level zero trust IP (ZT-IP) enforcement that verifies the legitimacy of outbound connections against historical DNS resolution context.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eMalware binary is executed on the victim host (e.g., via phish-delivered dropper).\u003c/li\u003e\n\u003cli\u003eThe malware performs internal checks or staging; no DNS queries are initiated for C2 resolution.\u003c/li\u003e\n\u003cli\u003eThe malware initiates a raw TCP or UDP connection directly to a hardcoded C2 IP address.\u003c/li\u003e\n\u003cli\u003eThe connection establishes a C2 channel (e.g., WebSocket for backdoors or \\GET protocol for exfiltration).\u003c/li\u003e\n\u003cli\u003eThe attacker transmits configuration data or malicious payloads (e.g., ransomware modules) over the direct connection.\u003c/li\u003e\n\u003cli\u003eThe malware exfiltrates sensitive browser data or form fields (e.g., SectopRAT /churl and /fsave endpoints).\u003c/li\u003e\n\u003cli\u003eThe connection persists or rotates IPs/ports based on attacker operational security requirements.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful D2IP communication facilitates silent C2 channel establishment, bypassing perimeter security that lacks DNS context. Observed campaigns impact high-value sectors, including government entities, airlines, and universities. Threats like SectopRAT enable real-time mirror exfiltration of browser traffic, including authenticated session pages and plaintext credentials, leading to significant risk of unauthorized access and lateral movement.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImplement Zero Trust IP (ZT-IP) enforcement at the firewall level to verify outbound connections against sanctioned DNS responses.\u003c/li\u003e\n\u003cli\u003eMonitor network traffic for persistent outbound TCP/UDP connections to untrusted external IP addresses that lack a corresponding preceding DNS query.\u003c/li\u003e\n\u003cli\u003eDeploy the provided IOCs (154.92.19.71, 178.16.54.109, etc.) to network blocklists, acknowledging potential overlap with shared cloud infrastructure.\u003c/li\u003e\n\u003cli\u003eUtilize EDR telemetry to hunt for suspicious processes (e.g., non-browser binaries) initiating direct network connections to external IP ranges without DNS lookup activity.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-04T13:34:18Z","date_published":"2026-08-04T13:34:18Z","id":"https://feed.craftedsignal.io/briefs/2026-08-malware-d2ip/","summary":"Nearly half of malware samples with command-and-control activity bypass DNS resolution by connecting directly to hardcoded IP addresses, rendering traditional DNS-based defenses ineffective.","title":"Prevalence of Direct-to-IP Malware Command and Control","url":"https://feed.craftedsignal.io/briefs/2026-08-malware-d2ip/"}],"language":"en","title":"CraftedSignal Threat Feed - SectopRAT","version":"https://jsonfeed.org/version/1.1"}