C&CMembers
C&C

A Log Shop That Never Reboots Its Servers

CTX Team tracking shows 18 of 47 stolen-data files tied to a credential-harvesting collection point turned over in the latest sweep, while the domain, IP, and seven URLs behind it stayed completely unchanged. The pattern points to a resale pipeline that gets restocked on a schedule rather than an actor moving between targets.

Sep 28, 2026, 06:32 (UTC+9)Last seenSep 28, 2026Severity100ByCTX TeamIOC57MITRE55RegionsUS

Eighteen of the forty-seven files CTX Team has tracked against this collection point turned over in the most recent sweep — new stolen-data artifacts rotating in, old ones rotating out — while every piece of network infrastructure behind the operation stayed exactly where it was. The domain, the IP, and the seven URLs tied to this cluster show zero change.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence