
IPFS Gateway Joins APT28-Linked C2 Stack Spanning Three Autonomous Systems
Two new IP addresses expand the infrastructure of a trojanised-installer campaign active since September 2025, with one pointing to Protocol Labs' IPFS gateway layer. The decentralised hosting choice signals deliberate takedown resistance engineered into the network layer, complicating conventional provider-level disruption.
Two new IP addresses have been added to the infrastructure footprint of a delivery campaign that has been circulating trojanised installers and adware components since at least September 2025 — and one of them points somewhere unusual. IP 209.94.90.1, now part of the campaign's network layer, sits within ASN 40680, the address space operated by Protocol Labs, the organisation behind the InterPlanetary File System.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read