C&CMembers
C&C

Ludashi C2 Expands: Two .cn Clusters, Shared IPs, and a New Browser Injector

Nine new domains and 13 IP addresses have extended the Ludashi campaign's infrastructure, with two parallel .cn domain families now confirmed as operator-linked via shared A-records. The newest payload, MasterBHO.dll, is a browser helper object first seen 13 days before this analysis and carries the lowest detection ratio in the catalog.

Jun 1, 2026, 06:27 (UTC+9)Last seenJun 1, 2026Severity100ByCTX TeamActorFIN6Skeleton SpiderIOC59MITRE9

Nine new domains and 13 IP addresses have been added to the Ludashi campaign's observable footprint since CTX Team's earlier coverage, and the infrastructure picture they complete is more deliberate than the raw count suggests. Two parallel command-and-control domain families — whnuowo.cn and tjbxldkj.cn — are now fully mapped, their subdomains provisioned in coordinated batches under iTrust DV wildcard certificates, their config endpoints resolving to a single shared IP that stitches the two…

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence