
Dual-TLD DGA Gives Kazakhstan Ransomware Campaign Sinkhole-Resistant C2
A financially motivated campaign targeting Kazakhstan pairs 18 DGA-generated domains across .ru and .su TLDs so that sinkholing one registry leaves the other fully operational. The infrastructure is backed by a Bulgarian VPS node presenting a German-language TLS cover identity, while the core payload — a UPX-packed trojan.bitmin/razy dropper with a deliberately corrupted PE header — dates to 2019 but points at demonstrably current C2 nodes.
Eighteen command-and-control domains generated by a single deterministic algorithm — split evenly across .ru and .su top-level domains, each carrying an identical 15-character vowel-heavy label structure — form the backbone of a financially motivated ransomware-adjacent campaign targeting Kazakhstan. The architecture is deliberate: by producing parallel domain sets from a common seed, the operator has engineered a C2 layer where sinkholing the .ru cluster leaves the structurally identical .su…
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read