C&CMembers
C&C

Four Disposable-Infrastructure Playbooks Share One Sharktech Backbone

A c2-servers indicator set with no malicious files attached reveals five IPs and eight domains split into four distinct hosting techniques — bulk certificate reuse, Cloudflare fronting, dynamic-DNS rotation, and fast-flux phishing — all running concurrently. Nearly every node reads clean to antivirus scanners, and the cluster ties back to a persistent Sharktech address block in use since early 2024.

Sep 18, 2026, 14:27 (UTC+9)Last seenSep 18, 2026Severity100ByCTX TeamIOC13MITRE14

A c2-servers indicator set logged by CTX Team's telemetry on 18 September carries not a single malicious file — no hash, no PE, no sandbox verdict anywhere in it. What it does carry is five IPs and eight domains, and inside that narrow footprint sit four distinct, professionally executed infrastructure playbooks running side by side: a single Let's Encrypt certificate stretched across eight numeric look-alike domains, a same-day-registered Cloudflare-fronted subdomain pair, a same-day…

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence