FILEMembers
FILE

Allaple Worm Hijacks 20 German Business Servers as Silent C2 Relays

An Allaple worm campaign tracked from February through June 2026 has quietly compromised twenty static-address Deutsche Telekom business servers, using their legitimate TLS certificates and clean reputations as cover for command-and-control relay traffic. Every node carries zero malicious detections across 91 scanning engines, making the relay fabric analytically invisible to conventional network-layer detection.

Jun 10, 2026, 07:34 (UTC+9)Last seenJun 10, 2026Severity60ByCTX TeamIOC70MITRE25RegionsUS

Twenty static IP addresses, all assigned to small German businesses on Deutsche Telekom AG's T-DSL Business service, all falling within the same RIPE-registered netblock — 217.86.128.0 through 217.86.255.255, designated DTAG-STATIC02 — form the operational backbone of an Allaple worm campaign that CTX Team has tracked from February through June 2026. None of the twenty endpoints carry a single malicious detection across 91 scanning engines on VirusTotal.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence