APTMembers
APT

Ludashi Campaign Expands C2 Layer With Cloud Proxy Evasion

New analysis reveals 21 IPs, six domains, and seven URLs added to the Ludashi signed-binary campaign while zero new file payloads appeared. Operators have built a four-subdomain C2 cluster and a secondary domain pair that routes traffic through Tencent API Gateway and a third-party reverse proxy, hiding the true backend from TLS inspection.

May 29, 2026, 10:16 (UTC+9)Last seenMay 29, 2026Severity100ByCTX TeamActorTA551ShathakIOC53MITRE12

Since CTX Team's earlier coverage of this campaign, the observable payload set has contracted while the network infrastructure has expanded dramatically — 21 new IP addresses, six new C2 domains, and seven new URLs have entered the picture, with zero new file payloads added. The delta is entirely in the network layer, and what it reveals is a meaningful escalation in how the operators route and obscure their command-and-control traffic.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence