
Sefnit C2 URI Unchanged for a Decade as Campaign Hits Thai Telecoms
A trojanized Setup.exe dropper beacons to four 'relocate'-prefixed domains via an identical gettasks.php task-polling URI first seen over ten years ago. The operator has spread registrations across four distinct registrars to frustrate bulk takedown, while masquerading the dropped payload as explorer.exe in the Windows Temp directory. The frozen protocol and layered infrastructure signal a deliberately mature evasion posture still active as of June 2026.
A single line of HTTP traffic — gettasks.php?protocol=0&protoversion=201&o=0&p=C:%5CUsers%5Cadmin%5CAppData%5CLocal%5CTemp%5Cexplorer.exe&f=7296000 — appears identically across four command-and-control domains whose registration dates span more than a decade, from a domain created in July 2013 through to one registered in January 2024.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read