<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Unit 42 Research: Nearly half of all malware connects directly to IP addresses in Advanced IP Defense Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/advanced-ip-defense-discussions/unit-42-research-nearly-half-of-all-malware-connects-directly-to/m-p/1263024#M2</link>
    <description>&lt;P&gt;For those of you who are curious, one of the trends we've been tracking that led to the development of Advanced IP Defense is this evasive technique of malware connecting directly to IP addresses — meaning they're circumventing standard inspections on the URL or domain layers.&lt;BR /&gt;&lt;BR /&gt;Check out this &lt;A href="https://unit42.paloaltonetworks.com/malware-bypass-dns-direct-to-ip/" target="_self"&gt;Unit 42 research blog&lt;/A&gt; digging into this trend. Also check out this &lt;A href="https://www.paloaltonetworks.com/resources/research/attackers-are-evading-threat-prevention-at-internet-edge" target="_self"&gt;threat report&lt;/A&gt; for the broader trends beyond direct-to-IP evasions.&lt;/P&gt;</description>
    <pubDate>Fri, 28 Aug 2026 18:05:24 GMT</pubDate>
    <dc:creator>davchen</dc:creator>
    <dc:date>2026-08-28T18:05:24Z</dc:date>
    <item>
      <title>Unit 42 Research: Nearly half of all malware connects directly to IP addresses</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-ip-defense-discussions/unit-42-research-nearly-half-of-all-malware-connects-directly-to/m-p/1263024#M2</link>
      <description>&lt;P&gt;For those of you who are curious, one of the trends we've been tracking that led to the development of Advanced IP Defense is this evasive technique of malware connecting directly to IP addresses — meaning they're circumventing standard inspections on the URL or domain layers.&lt;BR /&gt;&lt;BR /&gt;Check out this &lt;A href="https://unit42.paloaltonetworks.com/malware-bypass-dns-direct-to-ip/" target="_self"&gt;Unit 42 research blog&lt;/A&gt; digging into this trend. Also check out this &lt;A href="https://www.paloaltonetworks.com/resources/research/attackers-are-evading-threat-prevention-at-internet-edge" target="_self"&gt;threat report&lt;/A&gt; for the broader trends beyond direct-to-IP evasions.&lt;/P&gt;</description>
      <pubDate>Fri, 28 Aug 2026 18:05:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-ip-defense-discussions/unit-42-research-nearly-half-of-all-malware-connects-directly-to/m-p/1263024#M2</guid>
      <dc:creator>davchen</dc:creator>
      <dc:date>2026-08-28T18:05:24Z</dc:date>
    </item>
  </channel>
</rss>

