FILEMembers
FILE

njRAT Campaign Hides C2 Behind Free Cloud Platforms for Three Years

An njRAT operator has routed command-and-control traffic through Cloudflare Pages, Netlify, and Render since at least 2023, exploiting shared wildcard TLS certificates to make per-subdomain blocking impractical. The campaign's 2026 payload generation adds .NET Reactor obfuscation and a UAC bypass while preserving an identical build-pipeline fingerprint across all four years.

Jun 26, 2026, 22:27 (UTC+9)Last seenJun 27, 2026Severity100ByCTX TeamIOC17MITRE32RegionsUS

An njRAT operator running a build pipeline that has remained functionally intact since at least February 2023 has systematically routed command-and-control traffic through Cloudflare Pages, Netlify, and Render — three free-tier hosting platforms whose shared wildcard TLS certificates make per-subdomain blocking operationally impractical without disrupting entire legitimate services.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence