C&CMembers
C&C

Three-Layer Evasion Stack Targets Education Networks via Per-Victim Phishing URLs

A spearphishing campaign against the education and research sector is routing victims through a DGA-tagged C2 domain that fingerprints browser environments before firing its redirect. The infrastructure stacks fast-flux DNS, a CNAME hop through an unanalysed secondary domain, and freshly provisioned IPs that register near-zero detections across 91 scanning engines.

May 31, 2026, 04:56 (UTC+9)Last seenMay 31, 2026Severity100ByCTX TeamIOC16MITRE10

Thirteen individualised phishing URLs, each carrying a distinct base64-encoded payload that fingerprints the victim's browser before deciding whether to proceed — that is the opening move of a campaign CTX Team has been tracking against the education and research sector, built on infrastructure that layers domain-generation algorithm tagging, fast-flux DNS across eight A-records at 60-second TTLs, and a CNAME redirect through a secondary unanalysed domain, all backed by freshly provisioned…

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence