
njRAT Campaign Hides C2 Behind Free Cloud Platforms for Three Years
An njRAT operator has routed command-and-control traffic through Cloudflare Pages, Netlify, and Render since at least 2023, exploiting shared wildcard TLS certificates to make per-subdomain blocking impractical. The campaign's 2026 payload generation adds .NET Reactor obfuscation and a UAC bypass while preserving an identical build-pipeline fingerprint across all four years.
An njRAT operator running a build pipeline that has remained functionally intact since at least February 2023 has systematically routed command-and-control traffic through Cloudflare Pages, Netlify, and Render — three free-tier hosting platforms whose shared wildcard TLS certificates make per-subdomain blocking operationally impractical without disrupting entire legitimate services.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read