CTXThreat News
All ArticlesAPTC&CFILE
Sign in

All Articles

All608APT201C&C218FILE189
  • C&CMembersJun 29, 2026, 05:23 (UTC+9)

    Lumma Stealer Hides Behind Iranian ISP and Seychelles Shell in Domainless C2

    Four raw IP addresses. No domains. One hardcoded path. That is the entirety of the network-layer architecture behind a Lumma Stealer campaign that has been circulating since October 2025 under the filename "BTC CRACKER.exe" — a lure aimed squarely at cryptocurrency users who believe they are downloading a wallet-cracking utility.

    #LummaStealer#Diamotrix#bulletproofhosting#cryptocurrencytheft#domainlessC2#FarahooshDenaPLC#OmegatechLTD#credentialharvesting
    IOCf1 · i4 · d0 · u8MITRE33RegionsUS
  • C&CMembersJun 29, 2026, 01:09 (UTC+9)

    Layered Windows Trojan Campaign Hits India With Zero-Detection Loader

    Six unsigned Windows executables and DLLs, all carrying copyright strings dated decades into the future, have surfaced across a three-week window targeting India — the product of a disciplined build operation that deploys three structurally distinct payload layers, beacons to a Dynu dynamic-DNS node over deliberately malformed HTTP requests, and has achieved complete evasion of all 76 antivirus engines for its most recently submitted loader stage.

    #ABMRisk#Kepavll#UPX-packedDLL#PEiDloader#dynamicDNSC2#sandboxevasion#India#Windowstrojan
    IOCf6 · i2 · d14 · u0MITRE22RegionsIN
  • C&CMembersJun 28, 2026, 10:02 (UTC+9)

    2345Pinyin Pipeline Grows Fallback Channel as Fuzhou IP Breaks Brand Pattern

    Two newly observed IP addresses have extended the confirmed update-and-configuration infrastructure behind the 2345Pinyin input-method editor to five distinct Chinese carrier networks — and one of those IPs presents a TLS certificate that sits entirely outside the established brand ecosystem the pipeline has relied on for years.

    #2345Pinyin#IMEadware#C2infrastructure#TLScertificateabuse#Chinacarriernetworks#ad-injection#supplychaindelivery#certfallback.com
    IOCf44 · i5 · d0 · u0MITRE24RegionsCN
  • C&CMembersJun 28, 2026, 06:04 (UTC+9)

    Aged Vietnamese Domain Reissued as C2 Behind Evasive .NET Loader

    A three-year-old Vietnamese domain, canhtrang.com, has resurfaced with a freshly issued 89-day TLS certificate and a self-signed administrative host that binds directly to a single evasive Windows loader — a pattern that looks less like a new campaign standing up infrastructure from scratch than an old, ordinary-looking licensing backend being quietly repurposed for command-and-control. The domain's free., lic., and ping.

    #commandandcontrol#Vietnamhostinginfrastructure#TLScertificateabuse#loadermalware#.NETpacker#softwarelicensingabuse#sandboxevasion#domainrepurposing
    IOCf3 · i2 · d1 · u9MITRE23
  • C&CMembersJun 28, 2026, 05:50 (UTC+9)

    Cridex C2 Pool Spans Seven Nodes Across Four Continents on One Encoded Path

    At least seven command-and-control nodes spread across Indonesia, Brazil, Thailand, Mexico, and three additional unattributed locations are currently bound by a single hardcoded encoded URI path — /VJuPpCAAA/Vxi22CAAA/AHYe — embedded in a Cridex banking trojan payload that first surfaced in October 2012 and continues to generate active threat-feed hits.

    #Cridex#Zbot#bankingtrojan#C2infrastructure#invoicelure#multi-noderesilience#Indonesia#Mexico
    IOCf3 · i4 · d0 · u12MITRE25
  • C&CMembersJun 28, 2026, 02:03 (UTC+9)

    One Plesk Cert Ties Four Lumma Stealer .su Domains Together

    Four freshly minted .su domains — bendavo.su, conxmsw.su, narroxp.su and squeaue.su — all resolve to the same Russian-hosted IP address, share the same pair of nameservers, and present, byte for byte, an identical TLS certificate. That last detail is the tell: the certificate's subject alternative name literally hard-codes the hosting IP address into its hostname, a fingerprint that exposes what looks like four independent command-and-control domains as a single rotating front end sitting…

    #LummaStealer#commandandcontrolinfrastructure#Pleskpanel#Proton66#domainrotation#VBAmacromalware#Wextractmasquerading#commodityinfostealer
    IOCf18 · i2 · d5 · u9RegionsCL · RO
  • C&CMembersJun 27, 2026, 09:20 (UTC+9)

    36 'sslsecure' Domains Mask a Templated Adware Pipeline

    Thirty-six hostnames sit behind an indicator set that VirusTotal enrichment and registrar records tie to a single naming convention: sslsecure<N>.com, reproduced apex-for-apex with an identical api.v2., track.v2., and staticrr. subdomain triplet bolted onto each one. The pattern runs from sslsecure2.com through sslsecure10.com, and it isn't cosmetic — it's a templated hosting fabric built to look, at a glance, like generic SSL or security infrastructure rather than adware plumbing.

    #domaiq#PUP/adware#domaininfrastructure#registrarabuse#codesigningabuse#USretailsector#ztomy.comnameservers#masquerading
    IOCf2 · i1 · d36 · u0MITRE29RegionsUSIndustriesRetail
  • C&CPublicJun 27, 2026, 05:28 (UTC+9)

    Amadey Credential Stealer Slips Past Sandbox Despite 60/79 AV Flags

    Sixty of seventy-nine antivirus engines call it outright malicious. Feed the same file to a sandbox, and it comes back clean — "undetected," classified only as UNKNOWN_VERDICT, zero out of one dynamic runs flagging anything at all. That is the story sitting inside a single Amadey-linked credential-stealer DLL, tracked internally as cred.dll, and it is a more useful data point than most of the noisier campaign narratives this desk sees in a given week: a textbook illustration of how a passive…

    #Amadey#credentialstealer#DLLmalware#sandboxevasion#C2infrastructure#Russia#YARAdetection#Pleskhosting
    IOCf2 · i1 · d0 · u1MITRE10RegionsBG
  • C&CMembersJun 27, 2026, 05:07 (UTC+9)

    A 2012 Domain Registration Still Feeds a Fake Firefox Installer Today

    Three domains bulk-registered on a single day in October 2012 are still actively serving software downloads today, and CTX Team's infrastructure mapping ties the pair of IP addresses behind their apparent callback layer to a shared TLS certificate spanning two European countries under one Brazilian CDN provider's autonomous system.

    #DealPly#PUPdistribution#Baixaki#AzionTechnologies#code-signingbypass#Firefoximpersonation#CDNinfrastructure#Brazil
    IOCf7 · i2 · d3 · u1MITRE34RegionsBRIndustriesTechnology
  • C&CPublicJun 26, 2026, 17:36 (UTC+9)

    Upatre C2 Network Hides in Hungarian and Rural US ISP Space

    A 74-kilobyte Windows executable disguised as a scanned business document sits at the centre of a command-and-control network that deliberately avoids the commercial hosting fabric most threat-intelligence feeds are tuned to watch. Both enriched relay nodes in this campaign occupy address space belonging to small, non-commercial internet service providers — one a Hungarian broadband operator in Budapest, the other a rural telephone cooperative in the American Midwest — while three additional C2…

    #Upatre#C2infrastructure#spearphishingattachment#foodandbeverages#Italy#regionalISPabuse#downloadermalware#PE32stub
    IOCf3 · i2 · d0 · u5RegionsITIndustriesFood & Beverages
  • C&CMembersJun 26, 2026, 17:23 (UTC+9)

    1997-Timestamped Malware Resurfaces With 2025 C2 Infrastructure

    A single unsigned Win32 executable, first submitted to VirusTotal in June 2015 and carrying a PE timestamp deliberately set to October 1997, is appearing alongside command-and-control infrastructure provisioned as recently as December 2025 — a temporal gap of more than a decade that sits at the heart of one of the more analytically interesting evasion puzzles CTX Team has examined this cycle. The payload targets consulting-sector organisations in the United States.

    #consultingsector#PEtimestampmanipulation#sandboxevasion#C2infrastructure#indicatorremoval#packedmalware#UnitedStates#debuggerevasion
    IOCf3 · i2 · d0 · u5MITRE16RegionsUSIndustriesConsulting
  • C&CPublicJun 26, 2026, 09:35 (UTC+9)

    Cracked-Software Lure Bundles Three RAT Families From One Build Pipeline

    A trojanised archive circulating under the name "Onimai 1.7.1" — presented to prospective victims as a cracked copy of a software application — packages three distinct remote-access trojan families into a single deployment bundle, all compiled from what the evidence indicates is a unified .NET build pipeline and routed through the playit.gg public tunnelling service to a self-signed command-and-control node registered in the Seychelles but geolocated in Germany.

    #MrThunker#QuasarRAT#XWorm#VenomRAT#cracked-softwarelure#playit.ggtunnelling#FodyCosturapacking#commodityRAT
    IOCf9 · i1 · d0 · u1
  • C&CPublicJun 25, 2026, 17:58 (UTC+9)

    Finance-Lure VBScript Spoofs CSV Type to Evade Static Scanners

    Three new file variants have surfaced in an ongoing Formbook delivery campaign that CTX Team has been tracking since its prior coverage (earlier coverage), and the most significant change is not a new payload family or a fresh infrastructure node — it is a quiet manipulation of file-type metadata. The outer ZIP container drops a VBScript downloader whose file magic is reported as "CSV text" despite carrying a .vbs extension and an uncompressed size of nearly two megabytes, a type-confusion…

    #Formbook#VBScript#file-typespoofing#financelure#commodityinfostealer#phishingattachment#C2infrastructure#accounts-payabletargeting
    IOCf3 · i0 · d1 · u2RegionsBD · BE · CA · CHIndustriesAerospace · Construction · Consulting
  • C&CMembersJun 25, 2026, 17:35 (UTC+9)

    One Ukrainian IP, Four One-Letter Payloads, Zero Sandbox Alarms

    A 182-kilobyte Windows executable that 63 of 75 static antivirus engines flag as malicious walks through dynamic analysis without triggering a single sandbox alarm. That contradiction — near-universal static detection paired with a 99-confidence CLEAN verdict from Zenbox — sits at the centre of an active Phorpiex-and-GandCrab distribution operation whose entire observable infrastructure collapses to a single Ukrainian IP address, 92.63.197.106, operating under ASN 211736 (FOP Dmytro Nedilskyi).

    #Phorpiex#GandCrab#sandboxevasion#single-IPinfrastructure#ransomwaredistribution#Ukraine#wormpropagation#dropper
    IOCf4 · i1 · d0 · u6MITRE38RegionsCN
  • C&CPublicJun 25, 2026, 05:44 (UTC+9)

    Purchase-Order VBS Downloader Now Delivers XWorm, Not Formbook

    A VBS script disguised with a CSV file signature — the same purchase-order-themed downloader CTX Team tracked in earlier coverage of this delivery chain — now sandboxes to a different terminal payload entirely. Where the prior reporting on this lineage centered on a Formbook loader, the newly submitted sample returns a 3/3 malicious consensus across CAPE Sandbox, Zenbox, and Yomi Hunter, with the sandbox layer explicitly naming the deployed family as XWorm, a commodity remote-access trojan.

    #XWorm#Formbook#VBScriptdownloader#purchaseorderlure#basefile.click#KeyAuth#remoteaccesstrojan#phishing
    IOCf3 · i0 · d1 · u2RegionsAT · AU · BD · CAIndustriesCommercial Services · Education & Research · Government
  • C&CPublicJun 25, 2026, 01:55 (UTC+9)

    DCRat Campaign Hides C2 Traffic Behind Fake Google Analytics TLS Cert

    A single attacker-controlled domain is currently staging a DCRat remote-access trojan behind a TLS certificate whose subject common name reads *.google-analytics.com — a deliberate impersonation of Google's telemetry infrastructure designed to make outbound C2 traffic appear, to any network sensor performing only certificate-level inspection, as routine analytics beaconing.

    #ManicMenagerie#DCRat#TLScertificateimpersonation#Germany#bulletproofhosting#authenticodeevasion#C2infrastructure#packedmalware
    ActorsManic MenagerieIOCf1 · i1 · d1 · u2RegionsDE
  • C&CMembersJun 24, 2026, 13:54 (UTC+9)

    Upatre Downloader Returns With Anti-Analysis Stack Shielding FTP C2

    Three Windows PE droppers surfaced in CTX Team's feed on June 24, 2026, carrying a threat label that many defenders might dismiss on sight: Upatre, a downloader family old enough to have been circulating when the Czech ISP subnet it now phones home to was first registered. That familiarity is precisely the risk. The current cluster — tracked as CTX4uky7ju34a — pairs the family's well-worn FTP-based payload retrieval with a layered anti-analysis stack that sequences time-based sandbox checks…

    #Upatre#FTPC2#anti-analysisevasion#CzechRepublicinfrastructure#downloader#sandboxevasion#securitytooldisablement#post-executioncleanup
    IOCf3 · i1 · d0 · u4MITRE13
  • C&CMembersJun 24, 2026, 10:03 (UTC+9)

    One PHP Path, Four Servers, Ten Years: Inside an APT's C2 Framework

    Four IP addresses. One identical endpoint. The string /upload/_dispatch.php — replicated without variation across a quartet of Russian-hosted servers — is the clearest fingerprint CTX Team has extracted from a campaign carrying espionage motivation and APT classification in the threat record. The infrastructure has been operationally maintained from at least mid-2016 through confirmed certificate activity in June 2026, a decade-long window that makes the uniformity of that PHP path all the more…

    #APT#C2infrastructure#PHPframework#Turkeyespionage#masquerading#dynamicimportresolution#self-signedcertificate#OPSECfailure
    IOCf14 · i2 · d11 · u7RegionsTR
  • C&CPublicJun 23, 2026, 17:22 (UTC+9)

    SWIFT-Lure ZIP Drops Formbook via 2 MB Sleep-Padded VBScript

    A thirteen-kilobyte ZIP file named "Swift-015062026.zip" is circulating across at least 35 countries, carrying a single child file that expands to nearly two megabytes of VBScript — a deliberate size anomaly engineered to exhaust static scanners and outlast the time-boxed execution windows that automated sandboxes rely on. When a recipient opens the archive and runs the enclosed script, they are handing a Formbook infostealer a foothold on their machine, with credentials, keystrokes,…

    #Formbook#VBScriptdropper#SWIFT-themedphishing#sandboxevasion#basefile.click#financialservices#infostealer#spear-phishingattachment
    IOCf3 · i0 · d1 · u2RegionsAT · BA · BD · BEIndustriesAerospace · Construction · Consulting
  • C&CMembersJun 23, 2026, 09:22 (UTC+9)

    WoodyRAT C2 Expands With Ukrainian Node, Traefik Relay, and .biz Domain Pair

    Since CTX Team's earlier coverage of this WoodyRAT-attributed infostealer campaign, the operator has not stood still. Fifteen new file indicators and five new domains have entered the observable set, but the most analytically significant additions are structural rather than volumetric: a Ukrainian-hosted C2 node (195.211.191.95, AS208949, Hbing Limited) that bridges into the existing German hosting cluster via a shared operator-generated wildcard certificate, two freshly registered .biz domains…

    #WoodyRAT#infostealer#C2infrastructure#cryptocurrencywallettheft#Traefikreverseproxy#bulletproofhosting#Ukraine#Telegramexfiltration
    IOCf42 · i4 · d5 · u7MITRE62
  • C&CMembersJun 22, 2026, 17:26 (UTC+9)

    Nine-File Toolchain With Zero PE Imports Targets Six Countries via Dedicated AS

    Nine Windows executables, zero PE imports between them, and a dedicated binary whose sole purpose is to kill endpoint defenses before the rest of the payload stack arrives — this is the operational profile of a campaign CTX Team has been tracking since late May 2026, one that pairs an unusually complete evasion architecture with a purpose-built autonomous system that its operator has been quietly expanding for the better part of a year.

    #WoodyRAT#BazarLoader#Amadey#ClipBanker#EDRbypass#AS214351#credentialharvesting#reflectiveDLLinjection
    IOCf26 · i3 · d5 · u6MITRE66RegionsDZ · ES · ID · IT
  • C&CMembersJun 21, 2026, 16:41 (UTC+9)

    Phorpiex Botnet Adds Kernel Driver and Go Wallet Stealer in 2026 Upgrade

    A Phorpiex botnet campaign active since early June 2026 has added two capabilities that sit well outside the family's historical playbook: a Bring-Your-Own-Vulnerable-Driver kernel component and a Go-runtime infostealer purpose-built to drain cryptocurrency wallet browser extensions. The combination — mass SMTP propagation, XOR-obfuscated PE droppers, XMRig cryptomining, kernel-driver abuse, and browser-extension credential harvesting, all consolidated on four command-and-control IPs inside a…

    #Phorpiex#XMRig#BYOVD#WinRing0#Goinfostealer#cryptocurrencywalletharvesting#AS202412#Spain
    IOCf15 · i6 · d9 · u5MITRE36RegionsES · UZ
  • C&CMembersJun 21, 2026, 08:25 (UTC+9)

    37-Node Tox C2 Network Powers Resilient Browser Credential Stealer

    A packed Windows credential stealer is communicating with its operators through five numbered Tox-protocol subdomains distributed across two operator-controlled domains — tox1.mf-net.eu through tox4.mf-net.eu and tox.libre.tw — backed by a relay network of 37 IP addresses spanning four distinct ASN cohorts that include FranTech Solutions (AS53667), iFog GmbH (AS34927), Hetzner Online GmbH (AS24940), and M247 Europe SRL (AS9009).

    #BrowserStealerGeneric#Toxprotocol#credentialtheft#bulletproofhosting#DNS-over-HTTPSevasion#Let'sEncryptcertificateabuse#FranTechSolutions#Windowsmalware
    IOCf1 · i37 · d3 · u5MITRE10
  • C&CMembersJun 21, 2026, 04:14 (UTC+9)

    17-Year-Old Kernel Driver Powers 2026 Monero Mining Campaign

    A financially motivated campaign active during the week of June 19–20, 2026 is deploying XMRig 6.26.0 Monero miners behind a three-layer evasion stack that most commodity cryptomining operations never bother to assemble: a LOLDrivers-listed vulnerable kernel driver to undermine endpoint defences, a self-signed loader dressed up with a same-day certificate to slip past casual signature checks, and a game-themed NSIS dropper to carry the whole package past users who think they are installing a…

    #XMRig#WinRing0x64.sys#BYOVD#Monerocryptomining#LOLDrivers#NSISdropper#maliciouskerneldriver#game-themedlure
    IOCf53 · i1 · d3 · u0MITRE36
  • C&CMembersJun 20, 2026, 08:28 (UTC+9)

    Nine No-IP Subdomains, One Account: A .NET Trojan C2 Still Active in 2026

    A single No-IP dynamic DNS account holds nine sequentially enumerated subdomains — incorrect.no-ip.biz through 8incorrect.no-ip.biz — each configured with 60-second TTL A records pointing to European residential IP addresses, each sharing the same nameserver cluster (NF1 through NF5.NO-IP.COM), and each ready to absorb C2 traffic the moment any sibling is blocked or sinkholed.

    #trojan.barys#MSILtrojan#No-IPDDNS#C2infrastructure#dynamicDNSabuse#imphashclustering#EuropeanresidentialIPs#defenseevasion
    IOCf3 · i2 · d9 · u0MITRE37RegionsFR
  • C&CMembersJun 20, 2026, 04:26 (UTC+9)

    Cridex C2 Roster Ties Eight IPs to One Hardcoded URI Path

    Eight IP addresses. Five autonomous systems. Four countries. One identical URI path burned into every beacon call. That is the architecture CTX Team documented when it mapped the command-and-control roster attached to a Cridex/Dreidel trojan sample that first appeared on VirusTotal in January 2013 but was re-observed as recently as June 2026.

    #Cridex#Dreidel#C2infrastructure#hardcodedURI#compromisedserver#TLScertificateabuse#Canadahosting#Portugal
    IOCf2 · i4 · d0 · u16MITRE20
  • C&CPublicJun 19, 2026, 04:26 (UTC+9)

    XWorm RAT Hides Behind Purchase-Order ZIP and Pre-Armed Wildcard Infrastructure

    ##Purchase-Order ZIP Conceals a Three-Stage XWorm Delivery Chain Built on Pre-Armed Wildcard Infrastructure A compact, eleven-kilobyte ZIP archive named PO-000172483.zip is the opening move in a campaign that unfolds across five deliberate stages — evasion-hardened VBS execution, a stealthy compile-after-delivery intermediate, and XWorm RAT C2 over a Turkish-geolocated IP whose hosting fabric was provisioned weeks before the first malicious file appeared on the internet.

    #XWorm#VBSdownloader#compile-after-delivery#purchase-orderlure#wildcardTLSinfrastructure#manufacturing#WhiteLabelServices#multi-stagedeliverychain
    IOCf9 · i1 · d2 · u3RegionsAT · BD · BR · CHIndustriesAerospace · Agriculture · Automotive
  • C&CMembersJun 18, 2026, 20:06 (UTC+9)

    Phorpiex Clipbanker Uses Six Greek-Letter C2 Endpoints to Steal Crypto

    A 103-kilobyte Windows executable named wescgsvcs.exe — crafted to blend visually with legitimate Windows service binaries — has been quietly draining cryptocurrency wallets through one of the more methodical evasion stacks CTX Team has documented in this family class. The binary, confirmed as a Phorpiex/Fragtor trojan with a clipbanker payload, beacons to a single command-and-control server at 185.215.113.84 that exposes exactly six HTTP endpoints named in Greek alphabetical order: alpha,…

    #Phorpiex#Fragtor#clipbanker#cryptocurrencytheft#command-and-controlinfrastructure#sandboxevasion#timestomping#clipboardhijacking
    IOCf4 · i1 · d0 · u7MITRE31
  • C&CMembersJun 17, 2026, 20:27 (UTC+9)

    Phorpiex Rotates All Payloads Again as C2 Holds Firm for Ninth Wave

    ##Phorpiex Swaps Its Entire Payload Stack — Again — While C2 Holds Firm for a Ninth Consecutive Wave Since earlier coverage documented the Phorpiex/Trik operator's discipline of rotating binaries while leaving command-and-control infrastructure untouched, that pattern has completed another full cycle. All three payload files present in this snapshot are new arrivals; all three files from the prior snapshot have been retired.

    #Phorpiex#Trik#payloadrotation#sandboxevasion#C2infrastructure#telecommunications#Kazakhstan#Pakistan
    IOCf3 · i2 · d0 · u4MITRE35RegionsKZ · PKIndustriesTelecommunications
  • C&CMembersJun 17, 2026, 08:34 (UTC+9)

    Stealc v2 Bypasses Chrome 127 Encryption in Crypto-Theft Campaign

    A financially motivated operator has deployed a multi-stage credential-theft campaign built around two Stealc v2 payloads that implement a post-Chrome-127 app-bound encryption key decryptor — a deliberate capability upgrade that allows the malware to extract browser-stored credentials from modern Chrome profiles that earlier Stealc variants and most competing infostealers cannot reach.

    #Stealcv2#DiamotrixClipper#Chromiumapp-boundencryptionbypass#reflectiveDLLinjection#clipbanker#bulletproofhosting#cryptocurrencytheft#infostealer
    IOCf11 · i5 · d0 · u10MITRE51RegionsCA
  • C&CMembersJun 17, 2026, 08:03 (UTC+9)

    Sality Botnet Hides C2 Traffic in GIF Requests Across Italian and Polish Hosts

    Twenty-four HTTP GET requests. Two geographically disparate web servers. One 5-kilobyte image file. On the surface, a routine web browser fetching a logo. Underneath, an active Sality botnet cluster routing encrypted bot check-ins through parameterised image requests to compromised shared-hosting accounts in Italy and Poland — a beaconing architecture that has been generating fresh C2 traffic into mid-2026 from a core payload first submitted to VirusTotal in July 2010.

    #Sality#SaltySpider#C2infrastructure#sharedhostingabuse#GIFsteganography#USBpropagation#Bangladesh#Tofsee
    ActorsSalty Spider · KuKuIOCf24 · i2 · d2 · u24RegionsBD
  • C&CMembersJun 14, 2026, 22:59 (UTC+9)

    Emotet C2 Hides Behind WordPress Paths on Aged Compromised Domains

    Two compromised websites — one a Turkish-language platform, the other a social media aggregator — are currently serving as active command-and-control relay nodes for an Emotet campaign cluster, with their WordPress administrative and content directories repurposed as beaconing endpoints. The infrastructure fingerprint CTX Team has documented is precise: dotasarim.com/wp-admin/Dyz and socialplaymedia.com/wp-content/Czj function as the actual C2 URLs, their paths indistinguishable at a glance…

    #Emotet#Emotetepoch2#TA542#WordPressC2#command-and-controlinfrastructure#macro-enabledlure#TimewebASN9123#compromisedwebsites
    ActorsEmotet Group · TA542IOCf3 · i1 · d2 · u4
  • C&CPublicJun 14, 2026, 14:39 (UTC+9)

    Phorpiex Worm's Three-Layer Evasion Stack Keeps 20 AV Engines Blind

    A 77-kilobyte Windows executable — small enough to be dismissed as a stub, old enough to have first appeared on VirusTotal in October 2020 — is still generating active C2-server feed hits as of mid-2026. The sample, carrying the threat label trojan.phorpiex/zard and the deceptively mundane meaningful name DriveMgr.exe, is not remarkable for its size or age alone.

    #Phorpiex#Zard#worm#packedPE#C2infrastructure#TLSevasion#MEVSPACE#Guatemala
    IOCf3 · i2 · d0 · u3MITRE34RegionsGT
  • C&CMembersJun 14, 2026, 02:57 (UTC+9)

    Two Ghost Payloads Blind Analysts as Emotet Relay Cluster Holds Steady

    Since CTX Team's earlier coverage of this Emotet C2 cluster — documented in the prior article tracking the campaign's 89-day Let's Encrypt rotation pattern — two new file samples have entered the payload layer with zero VirusTotal enrichment: no file type, no detection ratio, no behavioural tags, no signer data. The infrastructure they connect to is unchanged and already fingerprinted. The payloads themselves are, at this moment, analytically invisible.

    #Emotet#TA542#MummySpider#C2infrastructure#Let'sEncryptcertificaterotation#WordPressrelay#payloadcycling#Romania
    ActorsEmotet Group · TA542IOCf3 · i1 · d3 · u4RegionsRO
  • C&CMembersJun 14, 2026, 02:41 (UTC+9)

    Emotet-Labeled Loader's TLS Handshake Trips Dridex IDS Rules

    A Win32 loader DLL tracked in this cluster — 65 of 77 engines flag it, and Zenbox, VMRay, and C2AE all name it Emotet in a unanimous 3/3 sandbox verdict — trips two independent intrusion-detection rules built for an entirely different crimeware family. The DLL's outbound TLS handshake fires "ET JA3 Hash - [Abuse.ch] Possible Dridex" from Proofpoint's Emerging Threats Open ruleset and a second hit from Abuse.ch's SSLBL malicious JA3 fingerprint list, also tagged Dridex.

    #Emotet#Dridex#JA3fingerprint#Excel4macromaldoc#loaderDLL#TA542#commodityhostinginfrastructure#sandbox-evasion
    ActorsEmotet Group · TA542IOCf4 · i3 · d2 · u7RegionsRO
  • C&CMembersJun 13, 2026, 14:47 (UTC+9)

    BazLoader, Amadey, and StealC V2 Chain Targets Algeria and Italy via Single German /24

    A 170-kilobyte PE32 dropper first submitted to public scanning infrastructure on 12 June 2026 is the entry point for one of the more operationally compact espionage-oriented loader chains CTX Team has tracked this quarter. The binary — identified as BazLoader/egairtigado and observed in the wild as sprd2.exe — touches down in the user Temp directory, copies itself to C:\Windows\8amu8dw.exe, and immediately begins beaconing over raw IPv4 HTTP to a pair of hosts consolidated within the…

    #BazLoader#Amadey#StealCV2#WoodyRAT#AS214351#credentialharvesting#Algeria#Italy
    IOCf30 · i2 · d0 · u5MITRE62RegionsDZ · IT
  • C&CMembersJun 13, 2026, 14:32 (UTC+9)

    woody_rat Stealer Drains Exodus and ElectronCash Wallets via Telegram Log Market

    ##Wallet Vaults Cracked Open: How a woody_rat Infostealer Pipeline Drains Exodus and ElectronCash in a Single Pass A woody_rat operation tracked by CTX Team has been systematically dismantling the cryptocurrency holdings of technology-sector victims in Egypt and Hungary, harvesting the full wallet store of both Exodus and ElectronCash installations in a single automated sweep — then packaging the stolen files into dated log archives and routing them through a Telegram bot channel for downstream…

    #woody_rat#infostealer#Exoduswallet#ElectronCash#Telegramlogmarket#cryptocurrencytheft#Egypt#Hungary
    IOCf68 · i2 · d0 · u3MITRE62RegionsEG · HUIndustriesTechnology
  • C&CPublicJun 13, 2026, 10:39 (UTC+9)

    Fake Android Toolkit Delivers Sandbox-Proof Python Spyware

    A self-extracting RAR archive named "Android Win Tool v1.9.6" is circulating as a trojanized utility lure, staging a PyInstaller-packed Python trojan and a secondary unsigned PE payload that beacon to parameterized HTTPS endpoints across a purpose-built two-tier command-and-control infrastructure. The campaign — tracked by CTX Team under threat record CTXkz7eez4uc5 with severity 100 and confidence 85 — is distinguished not by any single technique but by the deliberate layering of evasion…

    #PyInstallertrojan#sandboxevasion#espionage#C2infrastructure#SFXarchivelure#Androidtoolkitlure#Let'sEncryptautomation#spyware
    IOCf26 · i2 · d3 · u3
  • C&CPublicJun 13, 2026, 10:27 (UTC+9)

    Phorpiex Relay Cluster Exposed by Misplaced TLS Certificate on Spam Domain

    Five mail-themed domains provisioned across two registrar accounts, a freshly compiled 18 KB loader carrying an XOR-obfuscated C2 address, and a TLS certificate whose subject field names a spam-trap tracking domain — together these artefacts paint a Phorpiex spam botnet operation whose infrastructure cohesion is unusually legible.

    #Phorpiex#spambotnet#mailrelayinfrastructure#TLScertificateanomaly#XORobfuscation#domainregistration#C2servers#HondurasKyrgyzstanUnitedStates
    IOCf4 · i4 · d54 · u1RegionsHN · KG · US
  • C&CMembersJun 11, 2026, 19:10 (UTC+9)

    Twenty IPs, One Certificate: How a Phorpiex C2 Pool Mimics 2345.com

    Eight of the twenty IP addresses flagged as command-and-control infrastructure for a financially motivated operation tracked under the phorpiex family sit inside a single China Telecom autonomous system, AS4811 — and five of those nodes present an identical TLS certificate, serial d3d9e9261c1c88d957e704d69617a469, whose subject reads *.2345.com.

    #Phorpiex#C2infrastructure#TLScertificatereuse#ChinaTelecomAS4811#2345.comspoofing#adware/PUAinstaller#sslTrusCA#financiallymotivatedthreatactor
    IOCf3 · i27 · d0 · u0MITRE20RegionsCN
  • C&CMembersJun 11, 2026, 15:27 (UTC+9)

    Amadey Stealer Runs 67-IP C2 Pool Engineered to Outlast Blocklists

    Sixty-seven IP addresses. One stealer binary. And an infrastructure architecture so deliberately fragmented that no single takedown pathway touches more than a fraction of it. That is the operational picture CTX Team has assembled around a currently active Amadey stealer deployment — a campaign whose most distinctive feature is not the malware itself but the tiered, multi-continent command-and-control fabric the operators have constructed around it.

    #Amadey#stealer-as-a-service#C2infrastructure#KoreaTelecomAS4766#Let'sEncryptcertificaterotation#Brazilacademicnetwork#credentialharvesting#processinjection
    IOCf1 · i67 · d0 · u2MITRE30
  • C&CMembersJun 11, 2026, 14:58 (UTC+9)

    MSIL/Bobik Dropper Stays Live as Mystery Second File Hints at New Payload

    A 982-kilobyte unsigned .NET assembly — its PE timestamp deliberately forged to the year 2085 to confound timeline-based triage, its primary code section packed to an entropy of 7.64 — has been confirmed active as recently as 23 June 2026, deploying an XMRig-compatible cryptocurrency miner and PureLog credential stealer simultaneously to compromised endpoints across six industry verticals and 42 countries.

    #MSIL/Bobik#PureLogStealer#XMRig#Contaboinfrastructure#credentialtheft#cryptocurrencymining#packed.NETdropper#multi-countrytargeting
    IOCf2 · i1 · d0 · u3MITRE37RegionsAR · AT · AU · BEIndustriesCommercial Services · Education & Research · Government
  • C&CMembersJun 11, 2026, 10:46 (UTC+9)

    Dutch VPS and Borrowed ISP Relays Power Ranapama Infostealer C2

    A Let's Encrypt certificate minted on 29 January 2026 for the domain aceinco.com — valid for exactly 89 days, hosted on a LeaseWeb Netherlands VPS at 85.17.31.111 (AS60781) — is the clearest fingerprint of operator-controlled infrastructure in a 57-IP command-and-control network assembled around the ranapama infostealer. Everything else in the observable pool appears to be borrowed: compromised Korea Telecom broadband endpoints, hijacked subscriber lines on a Belarusian mobile carrier, and at…

    #ranapama#infostealer#commandandcontrol#LeaseWeb#KoreaTelecom#SOHOroutercompromise#credentialharvesting#processinjection
    IOCf1 · i57 · d0 · u0MITRE30
  • C&CMembersJun 10, 2026, 14:56 (UTC+9)

    Five Unrelated Domains Share One 89-Day Certificate Fingerprint

    Five infrastructure nodes with no obvious business relationship to one another — the domains resolvent.net, bvwebdesign.nl, platynum.ch and sjd.se, plus the bare IP 135.125.247.10 — all carry a Let's Encrypt TLS certificate with an identical 89-day validity span, and all five were issued within a six-week window between April 22 and June 8, 2026.

    #c2infrastructure#Let'sEncryptcertificateautomation#Netskyworm#domainreactivation#TLScertificatefingerprinting#resellerhostingabuse#threatintelligencefeed#SMTPmass-mailer
    IOCf11 · i7 · d5 · u0MITRE22RegionsNZ
  • C&CMembersJun 10, 2026, 13:03 (UTC+9)

    Phorpiex Swaps Three Payloads While C2 Infrastructure Holds Firm

    Three new PE32 executables have entered the Phorpiex botnet's active file set while three prior payloads were simultaneously retired — a clean swap that leaves the campaign's command-and-control backbone untouched for the eighth consecutive observation window. The rotation is surgical: the two C2 IP addresses, the wildcard certificate architecture anchored to *.certsdom.com, and the staging URL pattern under tsrv2.top all persist unchanged, while the operator pushes fresh binaries through the…

    #Phorpiex#emailworm#botnet#Pakistan#telecommunications#payloadrotation#C2infrastructure#sandboxevasion
    IOCf3 · i2 · d0 · u4MITRE33RegionsPKIndustriesTelecommunications
  • C&CMembersJun 10, 2026, 06:49 (UTC+9)

    LummaStealer Adds Isolated .qpon Node and 20 Hashes as Proton66 Cluster Holds

    Since CTX Team's earlier coverage of this LummaStealer campaign, the operator has added twenty new file hashes to the payload catalog and provisioned a structurally distinct second domain — recenjc.qpon — that sits entirely outside the tight infrastructure cohort binding the original eight command-and-control nodes. The earlier coverage documented a remarkably coherent C2 fabric: eight pseudo-random seven-character hostnames under the Soviet-era .su TLD, all batch-registered on a single day,…

    #LummaStealer#Proton66#C2infrastructure#credentialtheft#Spain#bulletproofhosting#malware-as-a-service#Traefikmisconfiguration
    IOCf20 · i1 · d9 · u17MITRE38RegionsES
  • C&CMembersJun 9, 2026, 19:37 (UTC+9)

    Dual-TLD DGA Gives Kazakhstan Ransomware Campaign Sinkhole-Resistant C2

    Eighteen command-and-control domains generated by a single deterministic algorithm — split evenly across .ru and .su top-level domains, each carrying an identical 15-character vowel-heavy label structure — form the backbone of a financially motivated ransomware-adjacent campaign targeting Kazakhstan. The architecture is deliberate: by producing parallel domain sets from a common seed, the operator has engineered a C2 layer where sinkholing the .ru cluster leaves the structurally identical .su…

    #trojan.bitmin/razy#domaingenerationalgorithm#Kazakhstan#dual-TLDC2#UPXpacking#TLSmasquerade#removablemediapropagation#ransomware
    IOCf3 · i2 · d18 · u20MITRE39RegionsKZ
  • C&CMembersJun 9, 2026, 07:51 (UTC+9)

    Same Cert Cadence Links Phishing Site to Domain Farm

    Three domains that have nothing else in common — a Spanish site already flagged for phishing, and two hosts sitting under a fifteen-year-old apex — were all issued Let's Encrypt certificates through the identical "YR2" intermediate, with identical 89-day validity windows opened within a nine-day span. lavers.es, which alphaMountain.ai categorizes as Phishing, picked up a YR2 certificate valid 2026-06-05 through 2026-09-03. treddle.nuronapp.com got one valid 2026-05-29 through 2026-08-27.

    #Let'sEncryptcertificateabuse#domainfarming#wildcardSANexposure#PUAdownloader#revokedcode-signingcertificate#multi-ASNinfrastructure#phishing#trojanizedsoftwareupdater
    IOCf2 · i5 · d7 · u0MITRE12IndustriesTelecommunications
  • C&CMembersJun 9, 2026, 03:58 (UTC+9)

    One GlobalSign Certificate Anchors 20 Malicious Files in Chinese Utility Trojan Campaign

    A GlobalSign code-signing certificate issued to the Chinese entity 沧州句号网络科技有限公司 (Cangzhou Juhao Network Technology Co., Ltd.) has served as the operational backbone for at least 20 malicious Windows executables and DLLs spanning two distinct build waves — one in May 2025 and a second in September 2025 — all delivered through a Wangsu (ChinaNetCenter) CDN-fronted infrastructure that renders conventional IP-layer blocking effectively useless.

    #SaltySpider#SoftCnApp#DeepData#code-signingabuse#CDNfronting#sandboxevasion#Chinese-languageWindowsusers#DLLsideloading
    ActorsSalty Spider · KuKuIOCf27 · i40 · d2 · u3
  • C&CMembersJun 8, 2026, 23:57 (UTC+9)

    Ludashi Adware Operator Pre-Positions Second DigiCert Certificate as Revocation Insurance

    Eleven Windows PE files. Two distinct Chinese legal entities. A single DigiCert Trusted G4 code-signing root. And, as of this writing, every certificate still valid. The Ludashi adware campaign documented in earlier coverage has extended its operational footprint in ways that reveal deliberate, forward-looking infrastructure management rather than reactive patching.

    #Ludashi#adware#code-signingabuse#certificaterotation#CDNinfrastructure#sandboxevasion#China#PolarWind
    ActorsFIN6 · Skeleton SpiderIOCf31 · i60 · d0 · u1MITRE5
2
Of4
CTXThreat News

A cyber threat intelligence newsroom published by SANDS Lab. Korean and English coverage.
Articles are automatically analyzed and written by AI, so some content may contain errors or inaccuracies.

Categories
  • APT
  • C&C
  • FILE
Publication
  • Source: CTX Threat Intelligence
  • sandslab.io
  • © 2026 SANDS Lab, Inc.