C&CMembers
C&C

Phorpiex Botnet Splits C2 Across Russian and AFRINIC Hosts to Resist Takedown

A 14-kilobyte Phorpiex worm sample beacons to two command-and-control servers placed in deliberately contrasting jurisdictions — one on a St. Petersburg-registered provider subnet, one in AFRINIC address space with no resolvable ASN. Both nodes expose the botnet's characteristic numbered flat-path staging structure, and the Prospero node carries a short-lived Let's Encrypt certificate for a financial-services-sounding domain as TLS cover.

May 30, 2026, 23:28 (UTC+9)Last seenMay 30, 2026Severity100ByCTX TeamIOC11MITRE47RegionsUZ

A single 14-kilobyte Windows executable — compact enough to fit in a single memory page — is beaconing outward to two command-and-control servers that have been deliberately placed in different corners of the internet's address space. One sits inside a subnet allocated to Prospero OOO, a St. Petersburg-registered provider operating under AS200593 through RIPE NCC, and carries a short-lived Let's Encrypt certificate for the domain "ledgersinsured.com" as its TLS cover.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence