LiveActive security incident?Get immediate response
MITRE ATT&CK® Technique

T1568.001: Fast Flux DNS

Adversaries may use Fast Flux DNS to hide a command and control channel behind an array of rapidly changing IP addresses linked to a single domain resolution. This technique uses a fully qualified domain name, with multiple IP addresses assigned to it which are swapped with high frequency, using a combination of round robin IP addressing and short Time-To-Live (TTL) for a DNS resource record.[1][2][3]

The simplest, "single-flux" method, involves registering and de-registering an addresses as part of the DNS A (address) record list for a single DNS name. These registrations have a five-minute average lifespan, resulting in a constant shuffle of IP address resolution.[3]

In contrast, the "double-flux" method registers and de-registers an address as part of the DNS Name Server record list for the DNS zone, providing additional resilience for the connection. With double-flux additional hosts can act as a proxy to the C2 host, further insulating the true source of the C2 channel.

EnterpriseT1568.001Sub-techniqueObject v1.1Modified
Glexia's Take · Automated analysis

Security context for executives and security teams

Automation confidenceHigh

Fast Flux DNS matters because it can keep command-and-control reachable while making blocking by a single IP address unreliable. For leaders, the practical issue is whether DNS, egress, and incident response processes can recognize and respond to rapidly changing infrastructure tied to one domain across Linux, macOS, Windows, and ESXi environments.

Executive priority

Prioritize this as a resilience and response-readiness issue, not just a malware indicator issue. Teams should be able to show whether they collect DNS evidence, can correlate short-lived domain-to-IP mappings, and have a process for containment when IP-based blocking is insufficient. The ATT&CK relationships to multiple groups and RAT/Trojan software make this a useful control-validation scenario for managed detection, IR preparation, and audit evidence around command-and-control monitoring.

Technical view

This is a command-and-control sub-technique of Dynamic Resolution. Validate coverage for domains that resolve to many changing A records with short TTLs, and for possible double-flux patterns where name server records also change. Because ATT&CK provides no official detection text for this object, use the related DET0485 detection strategy as the ATT&CK-supported detection context and test whether local telemetry can support fast-flux analytics without depending only on static IP indicators.

Likely telemetry

  • DNS query and response logs from recursive resolvers or DNS security controls
  • Passive DNS or historical domain-to-IP resolution records
  • DNS TTL values, A record churn, and name server record changes
  • Network egress logs such as firewall, proxy, or flow records showing repeated connections to changing IPs for the same domain
  • Endpoint network connection telemetry from Linux, macOS, Windows, and ESXi where available

Detection direction

  • Validate analytics for high-frequency IP rotation behind a single fully qualified domain name, especially with short TTL values.
  • Look for single-flux behavior in A record churn and double-flux behavior involving changing name server records.
  • Correlate DNS observations with outbound connections so detections are not limited to one IP address that may disappear quickly.
  • Tune for legitimate high-availability or content-delivery patterns to reduce false positives; the key distinction requires local baselines and domain context.
  • Use relationship context carefully: ATT&CK records use by menuPass, Gamaredon Group, TA505, gh0st RAT, njRAT, and Amadey, but local attribution should not be inferred from fast-flux behavior alone.

Mitigation priorities

  • Confirm DNS logging retention and accessibility before an incident; without historical resolution data, response teams may lose the infrastructure trail.
  • Strengthen egress control and investigation workflows around domains, not only IP addresses.
  • Ensure SOC playbooks include rapid domain containment, resolver-level blocking where appropriate, and review of affected hosts that contacted rotating infrastructure.
  • Review whether managed detection or internal detection engineering explicitly covers Dynamic Resolution and the related DET0485 fast-flux detection strategy.
  • Use incident response exercises to test whether teams can preserve DNS, network, and endpoint evidence across supported platforms.
Additional notes and limits

ATT&CK identifies this as T1568.001, Fast Flux DNS, a command-and-control sub-technique under Dynamic Resolution. The core defensive value is validating whether the organization can detect and respond to C2 infrastructure designed to outlast simple IP blocking. Relationship context shows ATT&CK-recorded use by several groups and software families, which supports prioritizing detection validation but does not prove current exposure or attribution.

The official ATT&CK detection field is not provided for this object. Recommendations therefore rely on the supplied behavior description, platforms, tactics, external references, and the relationship stating that DET0485 detects this object. Local DNS architecture, logging retention, encrypted DNS use, resolver visibility, and egress-control design will determine actual coverage.

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Official MITRE ATT&CK definition

Fast Flux DNS

Adversaries may use Fast Flux DNS to hide a command and control channel behind an array of rapidly changing IP addresses linked to a single domain resolution. This technique uses a fully qualified domain name, with multiple IP addresses assigned to it which are swapped with high frequency, using a combination of round robin IP addressing and short Time-To-Live (TTL) for a DNS resource record.[1][2][3]

The simplest, "single-flux" method, involves registering and de-registering an addresses as part of the DNS A (address) record list for a single DNS name. These registrations have a five-minute average lifespan, resulting in a constant shuffle of IP address resolution.[3]

In contrast, the "double-flux" method registers and de-registers an address as part of the DNS Name Server record list for the DNS zone, providing additional resilience for the connection. With double-flux additional hosts can act as a proxy to the C2 host, further insulating the true source of the C2 channel.

View the same entry on attack.mitre.org (MITRE-hosted reference; in-page links above use the Glexia ATT&CK library.)

Glexia analysis

How security teams should use this page

Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.

ATT&CK relationship table

Related techniques

This mirrors the MITRE pattern of making group, software, campaign, and technique relationships scannable. Relationship notes come from mirrored ATT&CK relationship text when available.

1 rows
DomainIDNameRelationship / procedure
EnterpriseT1568Dynamic ResolutionThis object subtechnique of Dynamic Resolution.
Associated objects

Groups, software, and campaigns

GroupEnterprise

G0045: menuPass

menuPass is a threat group that has been active since at least 2006. Individual members of menuPass are known to have acted in association with the Chinese Ministry of State Security's (MSS) Tianjin State Security Bureau and worked for the Huaying Haitai Science and Technology Development Company.[1][2]

menuPass has targeted healthcare, defense, aerospace, finance, maritime, biotechnology, energy, and government sectors globally, with an emphasis on Japanese organizations. In 2016 and 2017, the group is known to have targeted managed IT service providers (MSPs), manufacturing and mining companies, and a university.[3][4][5][6][7][1][2]

GroupEnterprise

G0092: TA505

TA505 is a cyber criminal group that has been active since at least 2014. TA505 is known for frequently changing malware, driving global trends in criminal malware distribution, and ransomware campaigns involving Clop.[1][2][3][4][5]

GroupEnterprise

G0047: Gamaredon Group

Gamaredon Group is a suspected Russian cyber espionage group that has targeted military, law enforcement, judiciary, non-profit, and non-governmental organizations in Ukraine since at least 2013. The name Gamaredon Group derives from a misspelling of the word "Armageddon," found in early campaigns.[1][2][3][4][5]

In November 2021, the Ukrainian government publicly attributed Gamaredon Group to Russia’s Federal Security Service (FSB) Center 18, an assessment later supported by multiple independent cybersecurity researchers. [6][5]

MalwareEnterprise

S0385: njRAT

njRAT is a remote access tool (RAT) that was first observed in 2012. It has been used by threat actors in the Middle East.[1]

Windows
Relationship explorer

All related ATT&CK context

Change history

Object version and sync metadata

The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.

ATT&CK release
19.1
Object version
1.1
Created
Modified
Raw hash
2759e9319b70db0e...
Imported snapshots across ATT&CK releases(1)
ReleaseBundle importedObject versionModifiedStatusRaw hash
19.11.1Current bundle2759e9319b70…
Raw source

Mirrored ATT&CK source object

The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.

Source references

External references and citations

MITRE external references are preserved separately from Glexia analysis so citations remain traceable to their original source records.

  1. [1]
    MehtaFastFluxPt1

    Mehta, L. (2014, December 17). Fast Flux Networks Working and Detection, Part 1. Retrieved March 6, 2017.

    Open source URL
  2. [2]
    MehtaFastFluxPt2

    Mehta, L. (2014, December 23). Fast Flux Networks Working and Detection, Part 2. Retrieved March 6, 2017.

    Open source URL
  3. [3]
    Fast Flux - Welivesecurity

    Albors, Josep. (2017, January 12). Fast Flux networks: What are they and how do they work?. Retrieved March 11, 2020.

    Open source URL
  4. [4]
    Korean FSI TA505 2020

    Financial Security Institute. (2020, February 28). Profiling of TA505 Threat Group That Continues to Attack the Financial Sector. Retrieved July 14, 2022.

    Open source URL
  5. [5]
    District Court of NY APT10 Indictment December 2018

    US District Court Southern District of New York. (2018, December 17). United States v. Zhu Hua Indictment. Retrieved December 17, 2020.

    Open source URL
  6. [6]
    Trend Micro TA505 June 2019

    Hiroaki, H. and Lu, L. (2019, June 12). Shifting Tactics: Breaking Down TA505 Group’s Use of HTML, RATs and Other Techniques in Latest Campaigns. Retrieved May 29, 2020.

    Open source URL
  7. [7]
    Gh0stRAT ATT March 2019

    Quinn, J. (2019, March 25). The odd case of a Gh0stRAT variant. Retrieved July 15, 2020.

    Open source URL
  8. [8]
    unit42_gamaredon_dec2022

    Unit 42. (2022, December 20). Russia’s Trident Ursa (aka Gamaredon APT) Cyber Conflict Operations Unwavering Since Invasion of Ukraine. Retrieved September 12, 2024.

    Open source URL
  9. [9]
    ESET Gamaredon Sept2024

    Rusnák, Z. (2024, September 26). Cyberespionage the Gamaredon way: Analysis of toolset used to spy on Ukraine in 2022 and 2023. Retrieved October 30, 2024.

    Open source URL
  10. [10]
    SilentPush_GamaredonFastFlux_Sept2023

    Silent Push. (2023, September 7). From Russia with a 71: Uncovering Gamaredon's fast flux infrastructure. New Apex domains and ASN/IP diversity patterns discovered. Retrieved July 28, 2025.

    Open source URL
  11. [11]
    Huntio_GamaredonFlux_Apr2025

    Hunt.io. (2025, April 8). State-Sponsored Tactics: How Gamaredon and ShadowPad Operate and Rotate Their Infrastructure. Retrieved July 23, 2025.

    Open source URL
  12. [12]
    Trend Micro njRAT 2018

    Pascual, C. (2018, November 27). AutoIt-Compiled Worm Affecting Removable Media Delivers Fileless Version of BLADABINDI/njRAT Backdoor. Retrieved June 4, 2019.

    Open source URL
  13. [13]
    Fast Flux - Welivesecurity

    Albors, Josep. (2017, January 12). Fast Flux networks: What are they and how do they work?. Retrieved March 11, 2020.

    Open source URL
  14. [14]
    Fast Flux - Welivesecurity

    Albors, Josep. (2017, January 12). Fast Flux networks: What are they and how do they work?. Retrieved March 11, 2020.

    Open source URL
  15. [15]
    MehtaFastFluxPt1

    Mehta, L. (2014, December 17). Fast Flux Networks Working and Detection, Part 1. Retrieved March 6, 2017.

    Open source URL
  16. [16]
    MehtaFastFluxPt1

    Mehta, L. (2014, December 17). Fast Flux Networks Working and Detection, Part 1. Retrieved March 6, 2017.

    Open source URL
  17. [17]
    MehtaFastFluxPt2

    Mehta, L. (2014, December 23). Fast Flux Networks Working and Detection, Part 2. Retrieved March 6, 2017.

    Open source URL
  18. [18]
    MehtaFastFluxPt2

    Mehta, L. (2014, December 23). Fast Flux Networks Working and Detection, Part 2. Retrieved March 6, 2017.

    Open source URL
  19. [19]
    mitre-attackT1568.001
    Open source URL
  20. [20]
    mitre-attackT1568.001
    Open source URL
  21. [21]
    mitre-attackT1568.001
    Open source URL
  22. [22]
    Korean FSI TA505 2020

    Financial Security Institute. (2020, February 28). Profiling of TA505 Threat Group That Continues to Attack the Financial Sector. Retrieved July 14, 2022.

    Open source URL
  23. [23]
    District Court of NY APT10 Indictment December 2018

    US District Court Southern District of New York. (2018, December 17). United States v. Zhu Hua Indictment. Retrieved December 17, 2020.

    Open source URL
  24. [24]
    Trend Micro TA505 June 2019

    Hiroaki, H. and Lu, L. (2019, June 12). Shifting Tactics: Breaking Down TA505 Group’s Use of HTML, RATs and Other Techniques in Latest Campaigns. Retrieved May 29, 2020.

    Open source URL
  25. [25]
    Gh0stRAT ATT March 2019

    Quinn, J. (2019, March 25). The odd case of a Gh0stRAT variant. Retrieved July 15, 2020.

    Open source URL
  26. [26]
    ESET Gamaredon Sept2024

    Rusnák, Z. (2024, September 26). Cyberespionage the Gamaredon way: Analysis of toolset used to spy on Ukraine in 2022 and 2023. Retrieved October 30, 2024.

    Open source URL
  27. [27]
    Huntio_GamaredonFlux_Apr2025

    Hunt.io. (2025, April 8). State-Sponsored Tactics: How Gamaredon and ShadowPad Operate and Rotate Their Infrastructure. Retrieved July 23, 2025.

    Open source URL
  28. [28]
    SilentPush_GamaredonFastFlux_Sept2023

    Silent Push. (2023, September 7). From Russia with a 71: Uncovering Gamaredon's fast flux infrastructure. New Apex domains and ASN/IP diversity patterns discovered. Retrieved July 28, 2025.

    Open source URL
  29. [29]
    unit42_gamaredon_dec2022

    Unit 42. (2022, December 20). Russia’s Trident Ursa (aka Gamaredon APT) Cyber Conflict Operations Unwavering Since Invasion of Ukraine. Retrieved September 12, 2024.

    Open source URL
Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.