{"id":51110,"date":"2023-03-14T21:50:00","date_gmt":"2023-03-14T21:50:00","guid":{"rendered":"https:\/\/www.csoonline.com\/article\/3690518\/dns-data-shows-one-in-10-organizations-have-malware-traffic-on-their-networks.html#tk.rss_security"},"modified":"2023-03-14T21:50:00","modified_gmt":"2023-03-14T21:50:00","slug":"dns-data-shows-one-in-10-organizations-have-malware-traffic-on-their-networks","status":"publish","type":"post","link":"https:\/\/www.threatshub.org\/blog\/dns-data-shows-one-in-10-organizations-have-malware-traffic-on-their-networks\/","title":{"rendered":"DNS data shows one in 10 organizations have malware traffic on their networks"},"content":{"rendered":"<div><img decoding=\"async\" src=\"https:\/\/images.idgesg.net\/images\/article\/2023\/02\/hacker-laptop-digits-computer-screen-cyber-crime-cyber-crime-theft-money-digital-100937829-large.jpg?auto=webp&amp;quality=85,70\" class=\"ff-og-image-inserted\"><\/div>\n<p>During every quarter last year, between 10% and 16% of organizations had DNS traffic originating on their networks towards command-and-control (C2) servers associated with known botnets and various other malware threats, according to<a href=\"https:\/\/www.akamai.com\/blog\/security\/a-deep-dive-on-malicious-dns-traffic\" rel=\"nofollow\"> a report from cloud and content delivery network provider Akamai<\/a>.<\/p>\n<p>More than a quarter of that traffic went to servers belonging to initial access brokers, attackers who sell access into corporate networks to other cybercriminals, the report stated. \u201cAs we analyzed malicious DNS traffic of both enterprise and home users, we were able to spot several outbreaks and campaigns in the process, such as the spread of FluBot, an Android-based malware moving from country to country around the world, as well as the prevalence of various cybercriminal groups aimed at enterprises,\u201d Akamai said. \u201cPerhaps the best example is the significant presence of C2 traffic related to initial access brokers (IABs) that breach corporate networks and monetize access by peddling it to others, such as ransomware as a service (RaaS) groups.\u201d<\/p>\n<p>Akamai operates a large DNS infrastructure for its global CDN and other cloud and security services and is able to observe up to seven trillion DNS requests per day. Since DNS queries attempt to resolve the IP address of a domain name, Akamai can map requests that originate from corporate networks or home users to known malicious domains, including those that host phishing pages, serve malware, or are used for C2.<\/p>\n<h2>Malware could affect a very large pool of devices<\/h2>\n<p>According to the data, between 9% and 13% of all devices seen by Akamai making DNS requests every quarter, tried to reach a malware-serving domain. Between 4% and 6% tried to resolve known phishing domains and between 0.7% and 1% tried to resolve C2 domains.<\/p>\n<p>The percentage for C2 domains might seem small at first glance compared to malware domains but consider we&#8217;re talking about a very large pool of devices here, capable of generating 7 trillion DNS requests per day. A request to a malware-hosting domain doesn&#8217;t necessarily translate to a successful compromise because the malware might be detected and blocked before it executes on the device. However, a query for a C2 domain suggests an active malware infection.<\/p>\n<p>Organizations can have thousands or tens of thousands of devices on their networks and one single compromised device can lead to complete network takeovers, as in most ransomware cases, due to attackers employing lateral movement techniques to jump between internal systems. When Akamai&#8217;s C2 DNS data is viewed per organization, more than one in 10 organizations had an active compromise last year.<\/p>\n<aside class=\"nativo-promo nativo-promo-1 smartphone\" id> <\/aside>\n<p>\u201cBased on our DNS data, we saw that more than 30% of analyzed organizations with malicious C2 traffic are in the manufacturing sector,\u201d the Akamai researchers said. \u201cIn addition, companies in the business services (15%), high technology (14%), and commerce (12%) verticals have been impacted. The top two verticals in our DNS data (manufacturing and business services) also resonate with the top industries hit by Conti ransomware.\u201d<\/p>\n<h2>Botnets account for 44% of malicious traffic<\/h2>\n<p>Akamai broke the C2 traffic down further into several categories: botnets, initial access brokers (IABs), infostealers, ransomware, remote access trojans (RATs), and others. Botnets were the top category accounting for 44% of the malicious C2 traffic, not even taking into account some prominent botnets like <a href=\"https:\/\/www.csoonline.com\/article\/3688935\/5-top-threats-from-2022-most-likely-to-strike-in-2023.html\">Emotet<\/a> or Qakbot whose operators are in the business of selling access to systems and were therefore counted in the IAB category. However, most botnets can technically be used to deliver additional malware payloads and even if their owners don&#8217;t publicly sell this service, some have private deals. For example, the <a href=\"https:\/\/www.csoonline.com\/article\/3600457\/trickbot-explained-a-multi-purpose-crimeware-tool-that-haunted-businesses-for-years.html\">TrickBot<\/a> botnet had a private working relationship with the cybercriminals behind the <a href=\"https:\/\/www.csoonline.com\/article\/3541810\/ryuk-explained-targeted-devastatingly-effective-ransomware.html\">Ryuk<\/a> ransomware.<\/p>\n<aside class=\"nativo-promo nativo-promo-1 tablet desktop\" id> <\/aside>\n<p>The largest botnet observed by Akamai in C2 traffic originating from enterprise environments is QSnatch which relies on a piece of malware that specifically infects the firmware of outdated QNAP network-attached storage (NAS) devices. QSnatch first appeared in 2014 and remains active to date. According to <a href=\"https:\/\/www.cisa.gov\/news-events\/cybersecurity-advisories\/aa20-209a\" rel=\"nofollow\">a CISA advisory<\/a>, as of mid-2020, there were over 62,000 infected devices worldwide. QSnatch blocks security updates and is used for credential scraping, password logging, remote access, and data exfiltration.<\/p>\n<p>IABs were the second largest category in C2 DNS traffic \u2014the biggest threats in this group being Emotet, with 22% of all infected devices, and Qakbot with 4%. Emotet is one of the largest and longest-running botnets used for initial access into corporate networks by multiple cybercriminal groups. Moreover, over the years, Emotet has been used to deploy other botnets including TrickBot and Qakbot.<\/p>\n<h2>Malware with links to noted ransomware gangs<\/h2>\n<p>In 2021 law enforcement agencies from multiple countries including the US, the UK, Canada, Germany, and the Netherlands managed to take over the botnet&#8217;s command-and-control infrastructure. However, the takedown was short-lived, and the botnet is now back with a new iteration. Emotet started as an online banking trojan but has morphed into a malware delivery platform with multiple modules that also give its operators the ability to steal emails, launch DDoS attacks, and more. Emotet also had known relationships with ransomware gangs, most notably Conti.<\/p>\n<p>Like Emotet, Qakbot is another botnet that is being used to deliver additional payloads and has working relationships with ransomware gangs, for example, Black Basta. The malware is also known to leverage the Cobalt Strike penetration testing tool for additional functionality and persistence and has information-stealing capabilities.<\/p>\n<aside class=\"nativo-promo nativo-promo-2 tablet desktop smartphone\" id> <\/aside>\n<p>Although botnets are known to deliver ransomware, once deployed such programs have their own C2s that are also represented in Akamai&#8217;s DNS data. Over 9% of devices that generated C2 traffic did so to domain names associated with known ransomware threats. Of these, <a href=\"https:\/\/www.csoonline.com\/article\/3597298\/revil-ransomware-explained-a-widespread-extortion-operation.html\">REvil<\/a> and <a href=\"https:\/\/www.csoonline.com\/article\/3665871\/lockbit-explained-how-it-has-become-the-most-popular-ransomware.html\">LockBit<\/a> were the most common ones.<\/p>\n<p>\u201cOur recent analysis of the methodology of modern ransomware groups, such as the Conti group, showed that sophisticated attackers often assign operators to work \u2018hands on keyboard\u2019 in order to quickly and efficiently progress an attack,\u201d Akamai researchers said. \u201cThe ability to view and block C2 traffic can be pivotal to stopping an ongoing attack.\u201d<\/p>\n<p>Infostealers were the third most popular category by C2 traffic, accounting for 16% of devices observed by Akamai. As their name suggests, these malware programs are used to steal information that can be valuable for attackers and further other attacks, such as usernames and passwords for various services, authentication cookies stored in browsers, and other credentials stored locally in other applications. Ramnit, a modular infostealer that can also be used to deploy additional malware, was the top threat seen in this category. Other notable threats seen in C2 traffic included Cobalt Strike, the Agent Tesla RAT, the Pykspa worm, and the Virut polymorphic virus.<\/p>\n<div class=\"end-note\"> <!-- blx4 #2004 blox4.html --> <\/p>\n<div id class=\"blx blxParticleendnote blxM2004 blox4_html blxC51120\">\n<aside> <strong>Next read this<\/strong> <\/aside>\n<\/p><\/div>\n<\/p><\/div>\n<p> READ MORE <a href=\"https:\/\/www.csoonline.com\/article\/3690518\/dns-data-shows-one-in-10-organizations-have-malware-traffic-on-their-networks.html#tk.rss_security\">HERE<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Akamai report highlights how widespread malware threats remain, noting the dangers of threats specific to DNS infrastructure. READ MORE HERE&#8230;<\/p>\n","protected":false},"author":2,"featured_media":51111,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"colormag_page_layout":"default_layout","footnotes":""},"categories":[738],"tags":[4098,3754,28,6946],"class_list":["post-51110","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-networkworld","tag-akamai","tag-botnets","tag-malware","tag-threat-and-vulnerability-management"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.8 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>DNS data shows one in 10 organizations have malware traffic on their networks 2026 | ThreatsHub Cybersecurity News<\/title>\n<meta name=\"description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.threatshub.org\/blog\/dns-data-shows-one-in-10-organizations-have-malware-traffic-on-their-networks\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"DNS data shows one in 10 organizations have malware traffic on their networks 2026 | ThreatsHub Cybersecurity News\" \/>\n<meta property=\"og:description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.threatshub.org\/blog\/dns-data-shows-one-in-10-organizations-have-malware-traffic-on-their-networks\/\" \/>\n<meta property=\"og:site_name\" content=\"ThreatsHub Cybersecurity News\" \/>\n<meta property=\"article:published_time\" content=\"2023-03-14T21:50:00+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/images.idgesg.net\/images\/article\/2023\/02\/hacker-laptop-digits-computer-screen-cyber-crime-cyber-crime-theft-money-digital-100937829-large.jpg?auto=webp&amp;quality=85,70\" \/>\n<meta name=\"author\" content=\"TH Author\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@threatshub\" \/>\n<meta name=\"twitter:site\" content=\"@threatshub\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"TH Author\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"5 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/dns-data-shows-one-in-10-organizations-have-malware-traffic-on-their-networks\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/dns-data-shows-one-in-10-organizations-have-malware-traffic-on-their-networks\\\/\"},\"author\":{\"name\":\"TH Author\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\"},\"headline\":\"DNS data shows one in 10 organizations have malware traffic on their networks\",\"datePublished\":\"2023-03-14T21:50:00+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/dns-data-shows-one-in-10-organizations-have-malware-traffic-on-their-networks\\\/\"},\"wordCount\":1100,\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/dns-data-shows-one-in-10-organizations-have-malware-traffic-on-their-networks\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2023\\\/03\\\/dns-data-shows-one-in-10-organizations-have-malware-traffic-on-their-networks.jpg\",\"keywords\":[\"akamai\",\"botnets\",\"Malware\",\"Threat and Vulnerability Management\"],\"articleSection\":[\"Networkworld\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/dns-data-shows-one-in-10-organizations-have-malware-traffic-on-their-networks\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/dns-data-shows-one-in-10-organizations-have-malware-traffic-on-their-networks\\\/\",\"name\":\"DNS data shows one in 10 organizations have malware traffic on their networks 2026 | ThreatsHub Cybersecurity News\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/dns-data-shows-one-in-10-organizations-have-malware-traffic-on-their-networks\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/dns-data-shows-one-in-10-organizations-have-malware-traffic-on-their-networks\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2023\\\/03\\\/dns-data-shows-one-in-10-organizations-have-malware-traffic-on-their-networks.jpg\",\"datePublished\":\"2023-03-14T21:50:00+00:00\",\"description\":\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/dns-data-shows-one-in-10-organizations-have-malware-traffic-on-their-networks\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/dns-data-shows-one-in-10-organizations-have-malware-traffic-on-their-networks\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/dns-data-shows-one-in-10-organizations-have-malware-traffic-on-their-networks\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2023\\\/03\\\/dns-data-shows-one-in-10-organizations-have-malware-traffic-on-their-networks.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2023\\\/03\\\/dns-data-shows-one-in-10-organizations-have-malware-traffic-on-their-networks.jpg\",\"width\":150,\"height\":100},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/dns-data-shows-one-in-10-organizations-have-malware-traffic-on-their-networks\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"akamai\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/tag\\\/akamai\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"DNS data shows one in 10 organizations have malware traffic on their networks\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"name\":\"ThreatsHub Cybersecurity News\",\"description\":\"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"alternateName\":\"Threatshub.org\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\",\"name\":\"ThreatsHub.org\",\"alternateName\":\"Threatshub.org\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"width\":432,\"height\":435,\"caption\":\"ThreatsHub.org\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/threatshub\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\",\"name\":\"TH Author\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"caption\":\"TH Author\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"DNS data shows one in 10 organizations have malware traffic on their networks 2026 | ThreatsHub Cybersecurity News","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.threatshub.org\/blog\/dns-data-shows-one-in-10-organizations-have-malware-traffic-on-their-networks\/","og_locale":"en_US","og_type":"article","og_title":"DNS data shows one in 10 organizations have malware traffic on their networks 2026 | ThreatsHub Cybersecurity News","og_description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","og_url":"https:\/\/www.threatshub.org\/blog\/dns-data-shows-one-in-10-organizations-have-malware-traffic-on-their-networks\/","og_site_name":"ThreatsHub Cybersecurity News","article_published_time":"2023-03-14T21:50:00+00:00","og_image":[{"url":"https:\/\/images.idgesg.net\/images\/article\/2023\/02\/hacker-laptop-digits-computer-screen-cyber-crime-cyber-crime-theft-money-digital-100937829-large.jpg?auto=webp&amp;quality=85,70","type":"","width":"","height":""}],"author":"TH Author","twitter_card":"summary_large_image","twitter_creator":"@threatshub","twitter_site":"@threatshub","twitter_misc":{"Written by":"TH Author","Est. reading time":"5 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.threatshub.org\/blog\/dns-data-shows-one-in-10-organizations-have-malware-traffic-on-their-networks\/#article","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/dns-data-shows-one-in-10-organizations-have-malware-traffic-on-their-networks\/"},"author":{"name":"TH Author","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476"},"headline":"DNS data shows one in 10 organizations have malware traffic on their networks","datePublished":"2023-03-14T21:50:00+00:00","mainEntityOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/dns-data-shows-one-in-10-organizations-have-malware-traffic-on-their-networks\/"},"wordCount":1100,"publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/dns-data-shows-one-in-10-organizations-have-malware-traffic-on-their-networks\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2023\/03\/dns-data-shows-one-in-10-organizations-have-malware-traffic-on-their-networks.jpg","keywords":["akamai","botnets","Malware","Threat and Vulnerability Management"],"articleSection":["Networkworld"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.threatshub.org\/blog\/dns-data-shows-one-in-10-organizations-have-malware-traffic-on-their-networks\/","url":"https:\/\/www.threatshub.org\/blog\/dns-data-shows-one-in-10-organizations-have-malware-traffic-on-their-networks\/","name":"DNS data shows one in 10 organizations have malware traffic on their networks 2026 | ThreatsHub Cybersecurity News","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/dns-data-shows-one-in-10-organizations-have-malware-traffic-on-their-networks\/#primaryimage"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/dns-data-shows-one-in-10-organizations-have-malware-traffic-on-their-networks\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2023\/03\/dns-data-shows-one-in-10-organizations-have-malware-traffic-on-their-networks.jpg","datePublished":"2023-03-14T21:50:00+00:00","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","breadcrumb":{"@id":"https:\/\/www.threatshub.org\/blog\/dns-data-shows-one-in-10-organizations-have-malware-traffic-on-their-networks\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.threatshub.org\/blog\/dns-data-shows-one-in-10-organizations-have-malware-traffic-on-their-networks\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/dns-data-shows-one-in-10-organizations-have-malware-traffic-on-their-networks\/#primaryimage","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2023\/03\/dns-data-shows-one-in-10-organizations-have-malware-traffic-on-their-networks.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2023\/03\/dns-data-shows-one-in-10-organizations-have-malware-traffic-on-their-networks.jpg","width":150,"height":100},{"@type":"BreadcrumbList","@id":"https:\/\/www.threatshub.org\/blog\/dns-data-shows-one-in-10-organizations-have-malware-traffic-on-their-networks\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.threatshub.org\/blog\/"},{"@type":"ListItem","position":2,"name":"akamai","item":"https:\/\/www.threatshub.org\/blog\/tag\/akamai\/"},{"@type":"ListItem","position":3,"name":"DNS data shows one in 10 organizations have malware traffic on their networks"}]},{"@type":"WebSite","@id":"https:\/\/www.threatshub.org\/blog\/#website","url":"https:\/\/www.threatshub.org\/blog\/","name":"ThreatsHub Cybersecurity News","description":"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform","publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"alternateName":"Threatshub.org","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.threatshub.org\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.threatshub.org\/blog\/#organization","name":"ThreatsHub.org","alternateName":"Threatshub.org","url":"https:\/\/www.threatshub.org\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","width":432,"height":435,"caption":"ThreatsHub.org"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/threatshub"]},{"@type":"Person","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476","name":"TH Author","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","caption":"TH Author"}}]}},"_links":{"self":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/51110","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/comments?post=51110"}],"version-history":[{"count":0,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/51110\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media\/51111"}],"wp:attachment":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media?parent=51110"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/categories?post=51110"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/tags?post=51110"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}