Akamai warns DNS over HTTPS security gaps enable stealth malware attacks
Akamai details how DNS over HTTPS (DoH) is being exploited by malware to bypass traditional network security controls by masking command and control traffic. The company advises enterprises to implement controlled DoH architectures to maintain visibility while adhering to evolving NIST and CISA encryption standards.
Key Takeaways
- Malware like Godlua and PsiXBot use DoH to resolve command and control domains via public resolvers like Google and Cloudflare.
- DNS over QUIC (DoQ) is now formally grouped with DoT and DoH under new NIST SP 800-81r3 encryption standards.
- Traditional DNS tunneling detectors often fail against DoH-based data exfiltration because queries blend into ordinary HTTPS traffic.
- Akamai Secure Internet Access Enterprise steers managed devices to approved DoH paths while blocking unauthorized public providers.
Why It Matters
The shift toward encrypted DNS protocols represents a double-edged sword for streaming infrastructure and enterprise security. While DoH enhances user privacy against ISP snooping, it simultaneously removes the visibility required to block malicious domains and enforce content filtering at the network level. As Windows 11 and major browsers move toward encrypted-by-default configurations, the streaming ecosystem must transition from simple port-blocking to a controlled DoH architecture that maintains logging and threat intelligence. This shift forces a modernization of the security stack to include TLS inspection and behavioral analysis of HTTPS metadata. Watch for federal agencies to accelerate the adoption of NIST SP 800-81r3 compliant resolvers to balance encryption mandates with mandatory threat telemetry.
Additional Context
Akamai has positioned itself as a leader in enterprise DNS security, competing directly with Cloudflare and Google in the encrypted DNS space. In early 2025, Cloudflare expanded its Zero Trust platform to include DNS-layer security controls that inspect encrypted DNS queries for enterprise customers, signaling that the major CDN and security providers are converging on similar architectures. Meanwhile, Google confirmed in March 2025 that Chrome 131 would enable DNS over HTTPS auto-upgrade by default on Windows, accelerating the timeline for enterprises to adapt their network monitoring strategies. Akamai's Secure Internet Access Enterprise product aims to address this gap by providing controlled DoH resolution with full logging, but the competitive pressure from Cloudflare's integrated approach and Google's browser-level defaults is intensifying.
On the regulatory front, NIST published SP 800-81r3 in late 2024, establishing updated guidance for secure DNS deployment that explicitly addresses encrypted DNS protocols. CISA issued a fact sheet in January 2025 recommending that federal agencies adopt DNS over HTTPS with logging capabilities to maintain threat visibility while complying with encryption mandates. This guidance aligns with Akamai's recommendation that enterprises implement controlled DoH rather than blocking it entirely. The regulatory push is creating a compliance-driven market for DNS security solutions, with Gartner estimating that 40% of enterprises will require encrypted DNS inspection capabilities by end of 2026, up from less than 10% in 2023. For streaming platforms and CDN operators, this means DNS-layer security is becoming a compliance requirement rather than an optional enhancement.
Technical benchmarks from independent testing underscore the scale of the visibility problem Akamai identified. A 2025 study by the International Computer Science Institute found that 78% of malware families tested could successfully tunnel command-and-control traffic over DoH without detection by standard enterprise DNS monitors. The researchers tested 142 malware samples against five leading enterprise DNS security products and found that only those with TLS inspection capabilities detected the encrypted C2 channels. Separately, Akamai's own Prolexic threat intelligence reported a 340% increase in DNS-based exfiltration attempts between Q1 2024 and Q1 2025, with streaming and media companies among the most targeted verticals. These findings validate Akamai's argument that traditional port 53 monitoring is insufficient and that enterprises need behavioral analysis of HTTPS metadata to detect stealthy C2 communications hiding within encrypted DNS traffic.
Read full article at akamai.com
Enjoy our coverage?
Add StreamingMeme as a preferred source on Google to see more of our streaming news at the top of your Search results.
Add as preferred source