C&CMembers
C&C

Cridex C2 Roster Ties Eight IPs to One Hardcoded URI Path

A Cridex/Dreidel trojan first seen in 2013 is still active in 2026, beaconing to eight geographically dispersed servers that all share an identical compiled-in URI path. Among the nodes is a Portuguese IP presenting a self-signed Windows Admin Center certificate that exposes an internal hostname, pointing to a compromised Hyper-V server used as a relay.

Jun 20, 2026, 04:26 (UTC+9)Last seenJun 20, 2026Severity92ByCTX TeamIOC22MITRE20

Eight IP addresses. Five autonomous systems. Four countries. One identical URI path burned into every beacon call. That is the architecture CTX Team documented when it mapped the command-and-control roster attached to a Cridex/Dreidel trojan sample that first appeared on VirusTotal in January 2013 but was re-observed as recently as June 2026.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence