
Ludashi C2 Expands: Two .cn Clusters, Shared IPs, and a New Browser Injector
Nine new domains and 13 IP addresses have extended the Ludashi campaign's infrastructure, with two parallel .cn domain families now confirmed as operator-linked via shared A-records. The newest payload, MasterBHO.dll, is a browser helper object first seen 13 days before this analysis and carries the lowest detection ratio in the catalog.
Nine new domains and 13 IP addresses have been added to the Ludashi campaign's observable footprint since CTX Team's earlier coverage, and the infrastructure picture they complete is more deliberate than the raw count suggests. Two parallel command-and-control domain families — whnuowo.cn and tjbxldkj.cn — are now fully mapped, their subdomains provisioned in coordinated batches under iTrust DV wildcard certificates, their config endpoints resolving to a single shared IP that stitches the two…
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read