
Cridex C2 Roster Ties Eight IPs to One Hardcoded URI Path
A Cridex/Dreidel trojan first seen in 2013 is still active in 2026, beaconing to eight geographically dispersed servers that all share an identical compiled-in URI path. Among the nodes is a Portuguese IP presenting a self-signed Windows Admin Center certificate that exposes an internal hostname, pointing to a compromised Hyper-V server used as a relay.
Eight IP addresses. Five autonomous systems. Four countries. One identical URI path burned into every beacon call. That is the architecture CTX Team documented when it mapped the command-and-control roster attached to a Cridex/Dreidel trojan sample that first appeared on VirusTotal in January 2013 but was re-observed as recently as June 2026.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read