
Proxyware Cluster Swaps Infrastructure, Keeps Same Signed Binaries
CTX Team's latest snapshot shows 18 new domains and 8 new IPs joining a proxyware-and-stealer cluster while 19 domains and 21 IPs from the prior window went dark. Beneath that churn, the same Bright Data Ltd.- and WEILAI NETWORK-signed binary families continue to anchor delivery unchanged.
Eighteen new domains and eight new IPs have joined a proxyware-and-stealer cluster CTX Team has been tracking since mid-July, while nineteen domains and twenty-one IPs from the prior snapshot have gone dark. That is a substantial share of the observable hosting layer turning over in a matter of days. What has not moved at all is the delivery pipeline underneath it: the same two Authenticode-signed binary families — one carrying a Bright Data Ltd.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read