/
Cyber Resilience

Fast Flux: The Old Trick Still Powering Modern Cyberattacks

Cybercriminals don’t always need new techniques. Sometimes, they simply find new ways to use old ones. For nearly two decades, “fast flux” has helped attackers keep phishing sites, malware infrastructure, and command-and-control systems online. Instead of tying a malicious domain to a single fixed server, attackers route traffic through a constantly changing pool of compromised devices.

These can include a router in your home, an office gateway, a modem, a computer, or another internet-connected device whose owner may not know it has been infected. Each device briefly acts as a relay, forwarding traffic to the attacker’s real infrastructure before another device takes its place. If defenders block one address, the domain just points somewhere else.

Fast flux infrastructure keeps moving, making it harder to track, block, and take down.

Fast flux is showing up in current cyberattacks

In June 2026, researchers reported that the Silent Ransom Group was using a fast flux network to hide infrastructure supporting its attacks across the legal, financial, and professional services sectors.

The nodes were spread across 18 countries and 22 internet service providers. They rotated the DNS records for two domains linked to the group, making the systems behind those domains harder to locate and block.

The group, also known as Luna Moth, Chatty Spider, and UNC3753, gains access through social engineering. Attackers pose as IT staff, call employees, launch screen-sharing sessions, or install remote-access tools.

The FBI has also warned that group members may enter offices and use storage devices to steal data or install malware. Once inside the network, the group moves laterally, steals sensitive data, and threatens to publish it.

Built to resist takedown

In April 2025, the NSA, CISA, FBI, and international partners warned that fast flux posed a serious national security threat. Criminal and state-backed groups use it to hide the systems behind phishing, malware, spying, and command-and-control activity.

Bulletproof hosting providers also sell infrastructure to cybercriminals and ignore efforts to shut it down. Fast flux helps them keep malicious services online by moving traffic across a changing network of systems.

Keeping cyberattacks alive

Fast flux has endured because it solves a basic attacker problem: how to stay connected when defenders begin blocking your infrastructure.

“It’s a resilience layer,” said Rachna Srivastava, senior product marketing manager at Illumio. “It’s a long-tail type of attack where it will continue to call home months later.”

That resilience has made fast flux useful across phishing, malware, ransomware, cybercrime infrastructure, and state-linked espionage.

Fast flux through the years

  • 2007 — Rock Phish
    Rock Phish targeted bank customers with fake websites. The sites stole login details. Fast flux moved them across infected computers, which helped them stay online.
  • 2007–2008 — Storm Worm
    Storm Worm spread through spam emails with fake news headlines and greeting cards. The links installed malware that pulled victims into one of the largest botnets of its era. Fast flux rotated the sites' IP addresses faster than blocklists could keep up.
  • 2009–2016 — Avalanche
    Avalanche supported malware, phishing, spam, and bank theft in more than 180 countries. Fast flux hid the network behind changing systems. Its shutdown involved 30 countries and more than 800,000 domains.
  • 2020–2022 — Nefilim
    Nefilim targeted large companies. It stole data, locked files, and demanded payment. Fast flux helped hide the systems behind the attacks.
  • 2021–2022 — Hive
    Hive hit more than 1,500 victims in over 80 countries. Targets included hospitals, schools, banks, and critical infrastructure. Fast flux helped keep parts of its network hidden.
  • 2022-2023 — Gamaredon
    Gamaredon used spearphishing and malware to target Ukrainian organizations, while fast flux DNS helped hide and protect its command-and-control infrastructure by rapidly rotating IP addresses.
  • 2024 — Unattributed Criminal Network
    Researchers found 193 domains tied to 2,960 IP addresses. The network supported malware, harmful websites, and command-and-control traffic.
  • 2025 — Criminal and State-Linked Actors
    U.S. and allied agencies warned that criminal and state-backed groups were using fast flux. It helped hide phishing, malware, spying, and command-and-control systems.
  • 2026 — Silent Ransom Group
    Silent Ransom Group targeted law firms and companies in finance, health care, insurance, and hospitality. Attackers posed as IT staff, stole data, and demanded payment. Fast flux hid the systems behind the attacks.

How to spot fast flux

Fast flux is difficult to stop because the infrastructure keeps changing. Each IP address may look like a new event, but the real threat is the pattern behind those changes.

Srivastava warned that defenders cannot investigate that pattern by hand.

“If you start doing this manually, you will be outrun,” she said.

There are a number of signs that can reveal fast flux activity:

  • Very short DNS time-to-live values
  • Repeated requests to the same domain
  • A growing set of unrelated IP addresses
  • Broad geographic spread
  •  Frequent name-server changes
  • Mismatched proxy or certificate behavior

None of these signals proves fast flux on its own. But together, they can show that a domain is behaving in a way that does not fit typical traffic patterns.

Why visibility matters

Security teams need to connect DNS activity with network flows, endpoints, processes, and workloads. They need to know which process requested the domain, which IP addresses came back, which system opened the connection, and whether that traffic fits the workload’s normal dependency map.

Without that context, teams are left chasing short-lived indicators. With it, they can see which workload is communicating with suspicious infrastructure and what that workload can reach next.

Once a system is compromised, the technique can help the attacker keep calling home, steal data, distribute malware, or look for another victim. It can also blend with ordinary browsing traffic, allowing the connection to remain active long after the first intrusion.

How segmentation stops it

Segmentation does not stop a malicious domain from rotating across external IP addresses. It contains the risk inside the environment. Teams can isolate an affected workload, restrict east-west traffic, and block paths that have no business purpose.

They can also ring-fence critical assets such as domain controllers, management planes, regulated applications, and other sensitive systems. An infected endpoint should not have an open route to those resources.

Teams can use granular allow rules, default-deny policies, and rapid quarantine to control the blast radius. They can then use the dependency map to tighten policy around the most important workloads first.

The goal is not to predict every IP address the attacker will use next. It is to make sure a compromised system cannot turn one connection into wider access.

As Srivastava put it: “Segmentation will control regardless of what that fast flux C2 infrastructure is going to do next.”

Fast flux keeps attackers connected. Illumio keeps them from spreading.

Schedule a breach containment demo to see how Illumio gives security teams the visibility to detect suspicious workload behavior and the segmentation to stop lateral movement before it becomes a breach.

Related articles

Experience Illumio Insights today

See how AI-powered observability helps you detect, understand, and contain threats faster.