
Ludashi Campaign Expands C2 Layer With Cloud Proxy Evasion
New analysis reveals 21 IPs, six domains, and seven URLs added to the Ludashi signed-binary campaign while zero new file payloads appeared. Operators have built a four-subdomain C2 cluster and a secondary domain pair that routes traffic through Tencent API Gateway and a third-party reverse proxy, hiding the true backend from TLS inspection.
Since CTX Team's earlier coverage of this campaign, the observable payload set has contracted while the network infrastructure has expanded dramatically — 21 new IP addresses, six new C2 domains, and seven new URLs have entered the picture, with zero new file payloads added. The delta is entirely in the network layer, and what it reveals is a meaningful escalation in how the operators route and obscure their command-and-control traffic.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read