How to Keep Malware’s Rotating Infrastructure From Becoming a Detection Gap 

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Spread the love

You can’t detect today’s attacks with yesterday’s threat intelligence; that’s how you could briefly formulate the challenge many modern SOCs face. 

Indicators lose relevance quickly. New infrastructure appears daily. SOCs struggle to keep up. 

This is happening because malware campaigns increasingly rely on rotating domains, hosting infrastructure, and phishing flows.

Attackers don’t need to come up with a new model every time. The underlying methods remain the same, but rapidly changing infrastructure makes detection difficult. 

This detection gap increases the workload on analysts, as single-IOC blocking often becomes futile, and ultimately leaves the company more exposed to risk. 

Why Detecting Rotating Malware Infrastructure Is a Priority for Modern SOCs  

Threat actors who design malware that can spread across short-lived infrastructure, trusted services, and switching phishing techniques know weak spots of SOC teams very well.

Recent campaigns show how significant the scope of this detection challenge has become. 

A recent RMM phishing campaign investigated by ANY.RUN demonstrates the scale of the problem.

What initially appeared to be a Canada-focused campaign using fake tax documents was connected to a broader operation spanning 46 countries, with 45% of observed activity associated with the United States. 

Across the wider campaign, researchers identified 425 kit URLs across 240 hosts. Of those hosts, 94% were observed for only a single day.  

The infrastructure changed rapidly, but the attack model remained recognizable if you know where to look.   

Another investigation by ANY.RUN uncovered 3DBlast, a newly observed phishing kit targeting users in the United States.

It impersonates Microsoft 365, Office 365, and Google while changing both its infrastructure and the phishing techniques used against victims. 

Rather than depending on a single attack flow, the kit was observed using Browser-in-the-Browser (BitB), OAuth/device-code phishing, adversary-in-the-middle (AiTM), and DOM relay techniques.  

These (and many more) campaigns highlight a larger shift in the detection problem: the lifespan of individual indicators can be much shorter than the lifespan of the threat behind them. 

How to Stay Ahead of Infrastructure Changes 

To avoid detection gaps and anticipate threats with rotating infrastructure, SOC analysts need fresh threat data reaching their defenses quickly, broad visibility into emerging infrastructure, and enough context to investigate what gets through. 

Domains, URLs, IPs, and delivery infrastructure can change long before a campaign disappears. If detection relies on yesterday’s indicators, every infrastructure change can create a new gap. 

One of the key differentiators here is access to truly relevant threat intelligence. Threat Intelligence Feeds like TI Feeds by ANY.RUN continuously deliver fresh malicious indicators from real-world sandbox investigations directly into SIEM, SOAR, TIP, firewalls, and other security systems. 

Measurable outcomes of ANY.RUN Threat Intelligence 

The intelligence is built from threat data generated through investigations by 16,000 companies in ANY.RUN’s Interactive Sandbox.

With 99% unique IOCs and a near-zero false-positive rate achieved through filtering, teams gain fresh, relevant threat data without adding another stream of noise for analysts to process manually. 

The result is broader threat coverage, earlier detection, shorter MTTD and MTTR, and less manual work for Tier 1 and Tier 2 analysts.

Most importantly for rotating infrastructure, new malicious indicators can reach existing security controls quickly, reducing the window in which emerging infrastructure goes undetected. 

Keep detection current as threat infrastructure changes with fresh, filtered IOCs from ANY.RUN TI Feeds. Integrate in your SOC 

Fresh indicators help close detection gaps, but when an alert fires, teams still need to understand what is behind it.

Threat Intelligence Lookup by ANY.RUN lets analysts pivot from an IOC to related infrastructure, activity, and historical threat data, while linked Interactive Sandbox sessions provide behavioral evidence from the underlying attack. 

Actionable threat intelligence from ANY.RUN designed for faster threat detection.

Together, these capabilities give analysts the context to validate threats and make faster decisions, while TI Feeds continuously bring newly observed infrastructure into existing defenses. 

This creates a continuous cycle that keeps detection aligned with the threat itself: new infrastructure is observed, delivered into security controls, investigated with context, and used to strengthen coverage against what comes next. 

Threat intelligence from 16K+ SOCs for extended threat coverage and faster response. Explore TI Lookup for your team . 

Conclusion 

Rotating infrastructure does not necessarily mean attackers are constantly reinventing their campaigns. The domains, URLs, hosting, tools, and phishing flows may change rapidly while the underlying attack remains recognizable. 

For SOC leaders, the challenge is not to block every new IOC manually, but to ensure detection can keep pace with those changes.

Fresh threat intelligence delivered directly into existing security controls helps shorten the gap between new malicious infrastructure appearing and the SOC being able to detect it. 

The post How to Keep Malware’s Rotating Infrastructure From Becoming a Detection Gap  appeared first on Cyber Security News.