Nearly half of malware exhibiting command-and-control traffic connect directly to IP addresses rather than using domain names, as revealed by Unit 42 research This article explores malicious electron app. . Researchers analyzed over four million dynamic malware-analysis reports across 30 days, finding that 45.32% of samples with C2 activity initiated at least one direct-to-IP connection.

When comparing legitimate 'index.html' files in installers (right image) and trojanized versions (left image), the result creates a significant visibility gap. Organizations relying on DNS filtering, logs, or domain-based threat intelligence may overlook malicious traffic that appears as a regular connection to a raw internet address. This evasion technique is not limited to one malware category; Unit 42 has identified examples involving ransomware droppers, remote-access trojans, data-exfiltration tools, and peer-to-peer IoT botnets.

Researchers identified a data-stealing operation that utilized an unconventional \GET request format to transmit encoded information to attacker infrastructure. The process tree associated with the execution of the trojanized QuickFox installer reveals the spawning of numerous child processes, which is not inherently malicious but due to Electron app design (Source: Fortinet). Researchers revealed an average 20-day gap between malicious IPs appearing in feeds, allowing attackers ample time to switch infrastructures and avoid detection.

Implement in-browser data inspection from ANY.RUN for enhanced phishing visibility and quicker incident response times to strengthen your SOC and reduce Mean Time To Resolution (MTTR).