C&CMembers
C&C

Dual-TLD DGA Gives Kazakhstan Ransomware Campaign Sinkhole-Resistant C2

A financially motivated campaign targeting Kazakhstan pairs 18 DGA-generated domains across .ru and .su TLDs so that sinkholing one registry leaves the other fully operational. The infrastructure is backed by a Bulgarian VPS node presenting a German-language TLS cover identity, while the core payload — a UPX-packed trojan.bitmin/razy dropper with a deliberately corrupted PE header — dates to 2019 but points at demonstrably current C2 nodes.

Jun 9, 2026, 19:37 (UTC+9)Last seenJun 10, 2026Severity100ByCTX TeamIOC43MITRE39RegionsKZ

Eighteen command-and-control domains generated by a single deterministic algorithm — split evenly across .ru and .su top-level domains, each carrying an identical 15-character vowel-heavy label structure — form the backbone of a financially motivated ransomware-adjacent campaign targeting Kazakhstan. The architecture is deliberate: by producing parallel domain sets from a common seed, the operator has engineered a C2 layer where sinkholing the .ru cluster leaves the structurally identical .su…

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence