C&CMembers
C&C

Proxyware Cluster Swaps Infrastructure, Keeps Same Signed Binaries

CTX Team's latest snapshot shows 18 new domains and 8 new IPs joining a proxyware-and-stealer cluster while 19 domains and 21 IPs from the prior window went dark. Beneath that churn, the same Bright Data Ltd.- and WEILAI NETWORK-signed binary families continue to anchor delivery unchanged.

Jul 21, 2026, 05:47 (UTC+9)Last seenJul 21, 2026Severity100ByCTX TeamActorCactusCactus Ransomware GroupIOC201MITRE19

Eighteen new domains and eight new IPs have joined a proxyware-and-stealer cluster CTX Team has been tracking since mid-July, while nineteen domains and twenty-one IPs from the prior snapshot have gone dark. That is a substantial share of the observable hosting layer turning over in a matter of days. What has not moved at all is the delivery pipeline underneath it: the same two Authenticode-signed binary families — one carrying a Bright Data Ltd.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence