
LummaStealer Campaign Hides Nine C2 Domains Behind One Server
Eight .su domains registered in a single December 2025 batch share one self-signed TLS certificate and one IP address, forming a deceptively large-looking C2 cluster for a LummaStealer campaign targeting India. A ninth domain, pre-staged on a separate registrar before its own name existed, reveals deliberate compartmentalisation built to survive partial takedown.
Nine command-and-control domains provisioned in a single week in December 2025 form the backbone of an active LummaStealer campaign targeting India — and the infrastructure's construction reveals an operator who planned for partial takedown from the outset. Eight of those domains share a single self-signed TLS certificate serial and, in seven cases, a single resolving IP address, meaning the elaborate domain pool amounts to DNS-level wallpaper over one physical server.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read