DNS, DHCP & IP Address Management appliances
For Microsoft DNS & DHCP servers
For open source DNS & DHCP servers
Cloud-based visualization of analytics across DDI architecture
Manage multi-vendor cloud DNS servers centrally
RIR Declaration Management and Automation
Automated network device configuration and management
Centralized visibility over all your clouds
A single source of truth for your network automation
Why DDI is an Obvious Starting Point
DNS Threat Intelligence for proactive defense
Intelligence Insights for Threat Detection and Investigation
Adaptive DNS security for service continuity and data protection
Improve Application Access Control to prevent spread of attacks
Protect users and block DNS-based malware activity
Carrier-grade DNS DDoS attack protection
Optimize application delivery performance from the edge
for Proactive Network Security
Visibility, analytics and micro segmentation for effective Zero Trust strategy
Enable work from anywhere by controlling access, security and data privacy
Simplify management and control costs across AWS, Azure and GCP environments
Policy enforcement, risk management, and automation for simplifying compliance
Risk-free migration to reduce DDI complexity and cost
Move risk-free to improve performance, security and costs
Automate management, unify control and strengthen security of connected devices
Protect your network against all DNS attacks, data exfiltration and ransomware
Enable zero touch operations for network management and security
Improve resiliency, deployment velocity and user experience for SD-WAN projects
Integrated DNS, DHCP, IPAM services to simplify, automate and secure your network.
Simplify design, deployment and management of critical DDI services for telcos
Optimize administration and security of critical DDI services for healthcare
Simplify and automate management of critical DDI services for finance
Simplify and automate management of critical DDI services for higher education
Simplify and automate management of critical DDI services for retail
Simplify Management and Automation for Network Operations Teams
Elevate SecOps Efficiency by Simplifying Threat Response
Enable DevOps practices to deliver consistent network operations.
Open architecture for DDI integration
Technology partnerships for network security & management ecosystems
Extend security perimeters and strengthen network defenses
Submit requests for temporary licenses
Submit access requests for EfficientIP knowledge platforms
Submit membership requests for EfficientIP Community
Strengthen your network security with insights from the Forrester 2025 Study on DNS Security.
Customer-centric DDI project delivery and training
Acquire the skills needed to manage EfficientIP SOLIDserverâ„¢
Identify vulnerabilities with an assessment of your DNS traffic
Test your protection against data breaches via DNS
Dedicated representation for your organization inside EfficientIP
Explore content which helps manage and automate your network and cloud operations
Read content which strengthens protection of your network, apps, users and data
Learn how to enhance your app delivery performance to improve resilience and UX
See all your assets in one place
This enterprise-grade cloud platform allows you to improve visibility, enhance operational efficiency, and optimize network performance effortlessly.
Who we are and what we do
Meet the team of leaders guiding our global growth
Technology partnerships for network security and management ecosystems
Make your cloud projects successful with insights from the 2025 EMA Hybrid Multi-cloud Report.
Discover the benefits of the SmartPartner global channel program
Become a part of the innovation
The latest updates, release information, and global events
EfficientIP’s H1 2026 threat intelligence research shows DGA activity strengthening before the broader malware surge. Combined with other DNS signals, it can help defenders recognize emerging threat infrastructure earlier.
October 8, 2026 | Written by: Yaëlle Harel | DNS Security
Summary
Tags
CyberthreatDNS SecurityMalwareThreat IntelligenceThreat Report
Can You Detect an Attack While It Is Still Being Prepared? Attackers leave DNS breadcrumbs in plain sight before they strike . EfficientIP’s H1 2026 research shows how DGA activity can serve as an early Malware Indicator, helping defenders recognize emerging infrastructure
On a Sunday morning in October 2025, the Louvre museum had been open for barely half an hour when a truck equipped with a furniture lift pulled up outside. Men dressed as renovation workers set out traffic cones, raised the lift and climbed toward a gallery window.Minutes later, they escaped on scooters with crown jewels stolen from one of the world’s most famous museums.The preparations had unfolded in plain sight. A vehicle, equipment, people apparently going about their work. Together, they were the opening moves of a robbery.The story raises a question that extends well beyond physical security: how do you recognize preparations for an attack while they still resemble ordinary activity?
Cyberattackers need infrastructure too. They generate domain names, register selected addresses and prepare systems to support malicious communications. As that infrastructure develops, it can leave breadcrumbs in DNS.Newly observed domains appearing in DNS traffic for the first time. Devices repeatedly querying domains that do not exist. Hundreds of domain names follow the same pattern, with some later registered and activated as command-and-control infrastructure.Each observation can have an innocent explanation. But relationships between them can reveal something worth investigating. Recognizing those relationships is what gives DNS threat intelligence its value for earlier malware detection.EfficientIP’s H1 2026 DNS Threat Intelligence Report shows why following that trail matters — and why DGA activity can serve as an early Malware Indicator.
The H1 2026 DNS Threat Intelligence Report reveals a substantial shift in the threat landscape. Total threat signals increased 24% compared with H2 2025, rising from 11.2 billion to 13.9 billion hits. Malware nearly doubled to 3.84 billion hits and became the leading threat category, moving from fourth to first place.
Other parts of the landscape shifted too. Newly observed domains nearly doubled, highlighting the continued emergence of fresh infrastructure. Phishing activity rotated sharply across sectors and brands, with Logistics & Couriers becoming one of the biggest movers. At the same time, established DGA families persisted or returned while new families emerged with different patterns of generation, registration and activity.But one finding was particularly important for malware detection: before the strongest surge in malicious activity became visible, DNS was already leaving clues. DGA activity strengthened first, followed by an acceleration in newly observed domains as malicious activity increased.These signals are the DNS breadcrumbs. Individually, they may reveal only part of the picture. Together, they can show how malicious infrastructure is taking shape over time.
Simplify & Secure Your Network
Our goal is to help companies face the challenges of modern infrastructures and digital transformation.
The value of these breadcrumbs comes from the sequence in which they appear.Domain generation algorithms (DGAs) can create large numbers of domains that malware uses to locate command-and-control infrastructure. Devices may begin querying those domains weeks or even months before some are registered or activated, leaving traces in DNS while the infrastructure is still taking shape. That is what makes DGA activity valuable as an early Malware Indicator.Newly observed domains provide another piece of the trail. They show where fresh domain infrastructure is beginning to appear in DNS traffic and can help track how that infrastructure evolves as activity develops.
The two signals answer different questions. DGA activity can reveal patterns associated with infrastructure being prepared, while newly observed domains help show fresh infrastructure becoming visible and active.Neither signal is conclusive on its own. But when DNS threat intelligence connects them with device behavior, registration activity and infrastructure relationships, the breadcrumbs begin to form a pattern.Like the clues before the Louvre robbery, these DNS breadcrumbs can be hiding in plain sight. They are only valuable if someone is paying attention early enough to connect them before the bigger picture becomes obvious.
The malware surge is only one part of the H1 2026 picture. The DNS Threat Report also shows how quickly the threat landscape can shift beneath headline trends.Phishing is a good example. Overall phishing activity declined, but targeting changed significantly across sectors and brands.Which sectors moved up the rankings? Which brands drove the change? And how much of that movement came from a small number of active campaigns?The report also looks more closely at the malware surge itself, showing how activity developed in distinct waves rather than as a single continuous rise.And it follows five DGA families to show that there is no single DGA lifecycle. Some persist, some disappear and return, some generate far more domains than are ever registered, and some continue attracting queries even after domains have expired.Together, the malware, phishing and DGA investigations show how much can change beneath the surface of a six-month total.
The practical challenge is turning early signals into earlier action.As with the Louvre robbery, the clues may already be visible before the main event. The difference is whether anyone is looking closely enough to connect them.Make sure DNS monitoring captures failed lookups, repeated requests and enough history to reveal patterns over time. Then connect those signals to the devices generating them and enrich them with endpoint, network and infrastructure context.Most importantly, define what happens next. Teams should know when an emerging pattern stays under observation, when it triggers investigation and when it justifies protective action.One question can expose the gap:If several devices repeatedly queried a related group of domains that did not resolve, would your SOC recognize the pattern and know what to do next?For security leaders, the measure of useful DNS threat intelligence is simple: did it help connect the dots and bring the investigation forward?
The report’s findings are produced by EfficientIP’s AI-driven DNS Threat Intelligence platform, which analyzes more than 150 billion DNS transactions daily, observes more than 500,000 newly observed domains each day and tracks 187 DGA families. Together, these signals provide the scale and context needed to identify patterns in emerging infrastructure without relying on any single indicator.It combines linguistic, visual and behavioral analysis with graph theory to detect and connect activity across malware, phishing, DGA activity and emerging domain infrastructure. The H1 2026 data reflects that breadth: 3.84 billion malware detections, nearly 69,000 devices per day on average generating non-resolving queries matching DGA families, and around 17 C&C domains associated with DGA families opening each day.
These signals become more valuable when detection leads to action. Within EfficientIP’s 360° DNS Security solution, DNS Threat Intelligence supports earlier investigation, while the DNS Threat Pulse feed brings domain intelligence into DNS filtering policies. Adaptive countermeasures automate a targeted response as the evidence strengthens, applying protection where it is needed without unnecessarily disrupting legitimate activity.So, can DNS reveal signs of a malware threat before the broader attack becomes visible? The H1 2026 findings show that it can.The breadcrumbs may already be there. The advantage comes from seeing them early enough to investigate and respond while the threat is still taking shape. Want to see where those breadcrumbs lead? Read the full H1 2026 DNS Threat Intelligence Report to explore the evidence behind the trends.
DGA activity can reveal related domain-generation patterns and query behavior before all associated infrastructure becomes operational. In H1 2026, DGA momentum strengthened before the broader malicious-activity surge. It supports earlier investigation without establishing that a specific attack will follow.
Newly observed domains show where fresh domain activity is appearing in monitored DNS data. Combined with behavioral signals and infrastructure relationships, they can help identify emerging threats. Newness alone does not establish that a domain is malicious.
Yes. Requests to non-resolving domains can reveal recurring patterns associated with domain generation algorithms or suspicious device behavior. Failed lookups also have legitimate causes, so investigators should assess them alongside other evidence.
Follow the DNS breadcrumbs in EfficientIP’s H1 2026 DNS Threat Intelligence Report. Explore malware trends, emerging infrastructure signals, and five DGA family investigations to understand what deserves closer attention in your environment
Talk to an expert
Summarize
Networks
Explore content highlighting the value EfficientIP solutions bring to your network