C&CMembers
C&C

WoodyRAT C2 Expands With Ukrainian Node, Traefik Relay, and .biz Domain Pair

A new Ukrainian C2 node, two Dynadot-registered .biz domains, and a Traefik reverse-proxy relay have been added to the WoodyRAT-attributed infostealer campaign documented in a prior CTX Team report. A shared self-signed wildcard certificate cryptographically binds the Ukrainian node to the .biz domain pair, confirming a single operator is building a layered, geographically dispersed relay architecture. The stealer's collection loop has harvested Exodus wallet seed files and Pidgin credentials from at least one host across a 28-month window, with stolen logs distributed through Telegram bot channels consistent with a log-market resale model.

Jun 23, 2026, 09:22 (UTC+9)Last seenJun 23, 2026Severity100ByCTX TeamIOC58MITRE62

Since CTX Team's earlier coverage of this WoodyRAT-attributed infostealer campaign, the operator has not stood still. Fifteen new file indicators and five new domains have entered the observable set, but the most analytically significant additions are structural rather than volumetric: a Ukrainian-hosted C2 node (195.211.191.95, AS208949, Hbing Limited) that bridges into the existing German hosting cluster via a shared operator-generated wildcard certificate, two freshly registered .biz domains…

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence