APTMembers
APT

TA505 Loader Hides Behind Six-Year-Old Mozambique Academic Domain

A rockloader campaign tied to TA505 stages its payload on rcf.co.mz, a Mozambican academic domain registered in 2020 that still runs legitimate mail service. The operator appears to trade control for inherited trust, splitting delivery from a disposable DuckDNS-fronted callback node an ocean away.

Sep 14, 2026, 22:38 (UTC+9)Last seenSep 15, 2026Severity77ByCTX TeamActorTA505Hive0065IOC60RegionsDEIDIEITNG

The most telling artifact in this cluster isn't a binary — it's a URL. rcf.co.mz/mytimeiswriten.exe sits on a domain registered on 2020-05-03 through Mozambique's academic CIUEM Registrar, a domain that still carries active mail routing and a valid SPF record naming its own hosting IP. Rather than spinning up a fresh, throwaway domain that would trip every newly-registered-domain heuristic on the market, whoever is running this operation appears to have repurposed six years of accumulated…

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence