
Phorpiex Botnet Splits C2 Across Russian and AFRINIC Hosts to Resist Takedown
A 14-kilobyte Phorpiex worm sample beacons to two command-and-control servers placed in deliberately contrasting jurisdictions — one on a St. Petersburg-registered provider subnet, one in AFRINIC address space with no resolvable ASN. Both nodes expose the botnet's characteristic numbered flat-path staging structure, and the Prospero node carries a short-lived Let's Encrypt certificate for a financial-services-sounding domain as TLS cover.
A single 14-kilobyte Windows executable — compact enough to fit in a single memory page — is beaconing outward to two command-and-control servers that have been deliberately placed in different corners of the internet's address space. One sits inside a subnet allocated to Prospero OOO, a St. Petersburg-registered provider operating under AS200593 through RIPE NCC, and carries a short-lived Let's Encrypt certificate for the domain "ledgersinsured.com" as its TLS cover.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read