The Tool Desk
Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →Attackers have used IPFS addresses and gateways to deliver phishing pages, credentials-stealing lures, malware payloads, and command-and-control traffic. IPFS can make a one-server takedown or a block on one gateway insufficient, but it does not make malicious content impossible to remove or guarantee that content will stay available. The system is legitimate infrastructure; defenders need to distinguish malicious resources from normal IPFS use.
How IPFS hosting works
The InterPlanetary File System (IPFS) is a peer-to-peer system that identifies content by what it is, rather than by the network location of one particular server. A content identifier, or CID, is derived using cryptographic hashing and also encodes information such as the content’s format. It is not simply a conventional file hash. If the same content is added on different nodes using the same settings, it can have the same CID; changing the content produces a different CID.
IPFS participants can store and provide content. People who do not run an IPFS node can access it through a gateway, which makes an IPFS resource reachable through a conventional web browser. That gateway access is one reason an attacker can use IPFS without requiring a victim to install IPFS software.
Copies held across nodes and access through multiple gateways can complicate removal: taking down one server or blocking one hostname may leave another route to the same content. But distribution is not a guarantee that every object has multiple copies, and a CID does not itself ensure that anyone still stores or serves the material.
Do these 3 things before closing this tab:
1Repair Windows errors before they cause bigger problems2Scan for outdated or missing drivers - takes under a minute3Clear out junk files and repair common Windows errors#1 Best Overall
How attackers have used IPFS
Palo Alto Networks Unit 42 reported on April 19, 2023, that its analysts observed IPFS being used for malicious activity during 2022. Its examples span several roles, rather than one single malware-hosting pattern:
- Phishing and credential theft: IPFS gateways and addresses can serve phishing content or form part of credential-stealing activity.
- Payload delivery and staging: Unit 42 described an OriginLogger attachment that made an HTTP GET request to an IPFS gateway to retrieve a payload. It also reported XLoader payload addresses on IPFS, XMRig payload hosting, Dark Utilities using IPFS as a delivery channel, and Metasploit payloads hosted at IPFS addresses.
- Command and control: Unit 42 described IPStorm using IPFS/libp2p for peer-to-peer C2 communications.
These are historical observations reported in 2023 about activity seen in 2022 and early 2023; they do not establish that those particular indicators remain active or describe the volume of malicious IPFS activity today. A 2019 academic preprint by Constantinos Patsakis and Fran Casino went further than file hosting, describing and experimentally validating a proposed decentralized bot-management approach using IPFS. That work demonstrates a possible design, not proof that a current named campaign uses it.
Rank #2
Unit 42 also reported changes in its own measurements: it observed an 893% increase in IPFS-related traffic from the last quarter of 2021 to the last quarter of 2022, and calculated an increase of more than 27,000% in IPFS-related VirusTotal reports over that period. For the shorter comparison between the final quarter of 2021 and the first quarter of 2022, it reported a 178% rise in its detected IPFS-related traffic and more than a 6,500% rise in VirusTotal reports. These are Palo Alto Networks’ historical, measurement-specific figures—not a measure of the share of IPFS traffic that was malicious, or of present-day prevalence.
Why removal and blocking can be difficult
A conventional takedown often targets a server or domain. With IPFS, the CID identifies content while gateways provide routes to it. If content remains available from another node or gateway, removing one copy or blocking one gateway may not end access. In a Virus Bulletin paper presented October 4–6, 2023, Trend Micro researchers reported accessing one CID through as many as 165 gateways in their study. That is a measured maximum in that study, not a property of every CID.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
IPFS is not automatically permanent. Official IPFS documentation explains that nodes have finite storage and may remove cached content during garbage collection. Pinning is the mechanism for deliberately retaining content on a node and protecting it from that node’s garbage collection. A malicious object can therefore become unavailable if no node continues to provide it, even though removing it from one location does not prove all copies are gone.
“Bulletproof” is consequently an overstatement if it means impossible to block, remove, or lose. The practical challenge is that a single-host response may not cover every route to content, and broad network-level blocking can also disrupt legitimate traffic.
Rank #4
What defenders can block or detect
Controls work at different layers. A full gateway URL is precise but may miss other gateways; a CID can identify the same content across known gateways, but defenders need a way to apply it where the content is encountered. Domain, IP-range, or autonomous-system rules can have wider reach, with correspondingly greater risk of blocking unrelated services. Endpoint protection may detect a file after it is downloaded even when a gateway or network filter does not inspect it first.
| Control scope | What it can address | Limit or trade-off |
|---|---|---|
| Full gateway URL | A known resource at a specific gateway. | A different gateway can provide another route to the CID. |
| CID on known gateways | The identified content when accessed through gateways covered by the rule. | Coverage depends on which gateways the control knows or can inspect. |
| Gateway or domain | Traffic to a particular access point or domain. | Blocking only one gateway can be bypassed through another; a domain may serve legitimate content too. |
| IP range or ASN | A broader set of network destinations. | Can affect unrelated services sharing infrastructure; requires careful scoping and review. |
| Endpoint detection | Suspicious or malicious files that reach a device. | May detect only after delivery and does not by itself prevent all access to a resource. |
Trend Micro’s 2023 paper concluded that blocking only one full gateway URL has limited usefulness, and discussed blocking a CID on known gateways or using patterns that cover CIDs on unknown gateways. Those are approaches described by the researchers, not a guarantee that every security product supports them. In the same paper, the authors reported that their EICAR test file was detected by Trend Micro Titanium after it reached the filesystem. That single test was not a comparison of security products and does not establish that antivirus engines generally detect every malicious IPFS payload.
Quick wins for a faster PC:
Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Clear out junk files and repair common Windows errorsFree Scan →Scan for outdated or missing drivers - takes under a minuteDriver Scan →Unit 42 describes DNS Security, URL filtering, endpoint protection, and next-generation firewall capabilities as ways its own products can analyze or block malicious IPFS domains, payloads, and C2 domains. This is a vendor description of its capabilities, not independent comparative testing.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.A proportionate response for security teams
- Investigate the specific resource. Preserve the observed URL, CID, timestamp, process, and network context. Treat the presence of IPFS alone as insufficient evidence that activity is malicious.
- Block at the narrowest useful scope. Prefer high-confidence URL or CID rules where the tools support them; add gateway, domain, or network rules only when evidence and operational needs justify the broader scope.
- Check more than one layer. Review DNS and network telemetry for access attempts, and use endpoint detection to inspect files and processes on affected devices. A gateway-level block may not cover alternate gateways, while an endpoint alert may occur after a download.
- Review broad rules for collateral impact. The November 19, 2025 joint guidance from CISA, NSA, DC3, FBI, and partner agencies warns that bulletproof-hosting infrastructure can be mixed into legitimate internet infrastructure. It recommends high-confidence malicious-resource lists, traffic analysis, regular list reviews, and sharing threat intelligence. That advisory concerns bulletproof hosting generally, not IPFS specifically, but its warning is relevant when considering broad IP or ASN blocks.
- Refresh and retire indicators. Reassess block lists as infrastructure and threat intelligence change. Historical campaign indicators should not be assumed to remain malicious or active without current validation.
A 2023 preprint by Christos Karapapas, George C. Polyzos, and Constantinos Patsakis describes a study that took three daily snapshots of IPFS nodes during a month, analyzed nodes by IP address against threat-intelligence feeds, and evaluated a prototype filter. It offers a research direction for node-level analysis; its study design should not be treated as a measure of current whole-network prevalence.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

