CISA, FBI, NSA and international cybersecurity agencies are calling on organizations and DNS providers to address the “Fast Flux” evasion technique, which is being used by state-sponsored malicious actors and ransomware gangs.
See also: Hackers install backdoor in Unitree Go1 robot dogs

Although this technique is not new, its effectiveness has been documented and proven repeatedly in real cyberattacks.
The Fast Flux technique is a DNS method used to avoid detection and maintain a resilient infrastructure, used for command and control (C2), phishing, and malware distribution.
This involves rapidly changing DNS records (IP addresses and/or name servers), making it difficult for defenders to detect the source of malicious activity and block it.
Often, this process is supported by botnets consisting of large networked groups of compromised systems, which act as intermediaries or relays to facilitate these rapid changes.
See also: Russian hackers develop SilentPrism and DarkWisp backdoors
The CISA announcement highlights two main types of the technique, namely Single Flux and Double Flux .
When using Single Flux, attackers often rotate the IP addresses associated with a domain name in DNS responses. With Double Flux, in addition to rotating the IP addresses for the domain, the DNS servers also change rapidly, adding an extra layer of concealment that makes takedown attempts even more difficult.

CISA reports that the Fast Flux technique is widely used by malicious actors of various levels, from low-level cybercriminals to highly sophisticated state-owned hackers.
The organization highlights the cases of Gamaredon, Hive ransomware, Nefilim ransomware , and bulletproof hosting service providers , all of which use the Fast Flux technique to evade law enforcement and takedown efforts that could disrupt their operations.
To address the issue, CISA recommends using DNS/IP block lists and firewall rules to prevent access to the Fast Flux infrastructure and, where possible, routing traffic to internal servers for further analysis.
Additionally, it is recommended to use reputation scoring to block traffic, implement central logging and immediate notification of DNS anomalies, and participate in information sharing networks
See also: Phishing: Using SVG files to avoid detection
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Ransomware gangs are criminal groups that use malicious software (ransomware) to lock down files or systems and demand a ransom from their victims in exchange for restoring access. Ransomware can infiltrate computers or networks through phishing emails, exploiting vulnerabilities, or other methods, and once installed, it encrypts the victim's data. These gangs are not limited to ransomware attacks. Many of them are involved in other forms of cybercrime, such as theft or selling sensitive information on the Dark Web.
Source: bleepingcomputer
