FBI, CISA warns of new Fast Flux DNS evasion being used by cyber gangs

 FBI, CISA warns of new Fast Flux DNS evasion being used by cyber gangs

Published on April 4, 2025 | Category: tech

FBI, CISA warns of new Fast Flux DNS evasion being used by cyber gangs

News
By Sead Fadilpašić published

Agencies are urging organizations take a unified stand

Abstract image of cyber security in action.
OpenVPN-protokollet - därför är det så bra (Image credit: Shutterstock)

  • CISA, FBI, and partners warn of 'fast flux' attacks
  • The technique involves attackers rapidly changing the IP addresses of their malicious domains
  • To tackle the threat, organizations should go for a multi-layered approach

The US Cybersecurity and Infrastructure Agency (CISA) has warned government agencies, internet service providers (ISP), and other organizations, about so-called “fast flux attacks” which, it says, are becoming a growing problem in cyberspace.

Fast flux attacks are a technique where attackers rapidly change the IP addresses associated with a malicious domain using a botnet, making it difficult to track and take down.

This method helps hide phishing sites, malware distribution networks, and command-and-control servers by leveraging a constantly shifting pool of compromised hosts.

Monitor your credit score with TransUnion starting at $29.95/month

Monitor your credit score with TransUnion starting at $29.95/month

TransUnion is a credit monitoring service that helps you stay on top of your financial health. With real-time alerts, credit score tracking, and identity theft protection, it ensures you never miss important changes. You'll benefit from a customizable online interface with clear insights into your credit profile. Businesses also benefit from TransUnion’s advanced risk assessment tools.

Preferred partner (What does this mean?)

View Deal

Mitigating the threat

CISA published a new security advisory to warn about the threat, together with the FBI, NSA, Australian Signals Directorate’s Australian Cyber Security Centre (ASD’s ACSC), Canadian Centre for Cyber Security (CCCS), and New Zealand National Cyber Security Centre (NCSC-NZ).

“Many networks have a gap in their defenses for detecting and blocking a malicious technique known as “fast flux,” the advisory says.

“This advisory is meant to encourage service providers, especially Protective DNS (PDNS) providers, to help mitigate this threat by taking proactive steps to develop accurate, reliable, and timely fast flux detection analytics and blocking capabilities for their customers.”

CISA also provided guidance on how to detect and mitigate fast flux attacks, which includes adopting a multi-layered approach through DNS analysis, network monitoring, and threat intelligence.

Are you a pro? Subscribe to our newsletter

Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!

By submitting your information you agree to the Terms & Conditions and Privacy Policy and are aged 16 or over.

It further stated agencies should work together on building and deploying scalable solutions that will “close the ongoing gap” in network defenses.

Finally, the agencies stressed that some legitimate activity, such as common content delivery network (CDN) behaviors, “may look like” malicious fast flux activity.

“Protective DNS services, service providers, and network defenders should make reasonable efforts, such as allowlisting expected CDN services, to avoid blocking or impeding legitimate content,” the advisory concludes.

Via The Register

You might also like

  • Security experts take down spam network hitting millions of iOS devices
  • We've rounded up the best password managers
  • Take a look at our guide to the best authenticator app
Sead Fadilpašić

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

You must confirm your public display name before commenting

Please logout and then login again, you will then be prompted to enter your display name.

More about security
Abstract image of cyber security in action.

Australia's largest pension funds hit by hackers, thousands of dollars stolen

Fraud

Businesses are losing millions to fraud every year

Latest
An Apple MacBook Air with M2 chip on a green background with text saying Lowest Price.

Skip the latest model and save $250 on the powerful Apple MacBook Air M2

See more latest
Most Popular
A laptop with the Windows 11 desktop on screen, glowing, while on a work desk
Windows 11 is getting a very handy change to the taskbar, as Microsoft takes a leaf from Apple’s Mac playbook
An image of network security icons for a network encircling a digital blue earth.
NSA chief and US Cyber Command head ousted
A rocket taking off and an Amazon Project Kuiper terminal on a roof
Amazon's Starlink rival is ready for lift-off next week – and promises to deliver satellite broadband 'later this year'
Apple iPad mini A17 Pro
The iPad mini could be the next Apple tablet to get an OLED display – and I think that makes perfect sense
The Google Pixel 9 Pro, iPhone 16 Pro Max and Samsung Galaxy S25 Ultra
Are modern smartphone designs boring? We asked 1,500 people, and the results are damning
Google Pixel 9 Pro XL review camera
Detailed Google Pixel 10 camera specs have seemingly leaked, pointing to an extra lens and worse sensors
Windows 365 Link
Microsoft's new thin client Windows 365 cloud PC is on sale now
Stress
Google co-founder says 60-hour working week is "sweet spot"
The Samsung Galaxy Ring in a charging case
A future Samsung Galaxy Ring could get a unique and intriguing new way of charging
Sue Storm using her force-field powers in The Fantastic Four: First Steps
CinemaCon 2025 teaser for The Fantastic Four: First Steps just confirmed a big fan theory about Sue Storm in the Marvel movie

Related Articles

Spotify is about to be flooded with AI-made ads, and I wonder if it will make much of a difference to businesses

Spotify’s new AI-powered ad tool may not be the solution they claim....

Read More
CinemaCon 2025 live – first Avatar 3 reaction, juicy Fantastic Four news,

CinemaCon 2025 is officially underway – here are all new movie announc...

Read More
NYT Wordle today — answer and my hints for game #1385, Friday, April 4

Looking for Wordle hints? I can help. Plus get the answers to Wordle t...

Read More