
Allaple Worm Hijacks 20 German Business Servers as Silent C2 Relays
An Allaple worm campaign tracked from February through June 2026 has quietly compromised twenty static-address Deutsche Telekom business servers, using their legitimate TLS certificates and clean reputations as cover for command-and-control relay traffic. Every node carries zero malicious detections across 91 scanning engines, making the relay fabric analytically invisible to conventional network-layer detection.
Twenty static IP addresses, all assigned to small German businesses on Deutsche Telekom AG's T-DSL Business service, all falling within the same RIPE-registered netblock — 217.86.128.0 through 217.86.255.255, designated DTAG-STATIC02 — form the operational backbone of an Allaple worm campaign that CTX Team has tracked from February through June 2026. None of the twenty endpoints carry a single malicious detection across 91 scanning engines on VirusTotal.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read