FILEMembers
FILE

LummaStealer Campaign Hides Nine C2 Domains Behind One Server

Eight .su domains registered in a single December 2025 batch share one self-signed TLS certificate and one IP address, forming a deceptively large-looking C2 cluster for a LummaStealer campaign targeting India. A ninth domain, pre-staged on a separate registrar before its own name existed, reveals deliberate compartmentalisation built to survive partial takedown.

Jun 25, 2026, 10:07 (UTC+9)Last seenJun 25, 2026Severity100ByCTX TeamIOC36MITRE31RegionsIN

Nine command-and-control domains provisioned in a single week in December 2025 form the backbone of an active LummaStealer campaign targeting India — and the infrastructure's construction reveals an operator who planned for partial takedown from the outset. Eight of those domains share a single self-signed TLS certificate serial and, in seven cases, a single resolving IP address, meaning the elaborate domain pool amounts to DNS-level wallpaper over one physical server.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence