APTMembers
APT

IPFS Gateway Joins APT28-Linked C2 Stack Spanning Three Autonomous Systems

Two new IP addresses expand the infrastructure of a trojanised-installer campaign active since September 2025, with one pointing to Protocol Labs' IPFS gateway layer. The decentralised hosting choice signals deliberate takedown resistance engineered into the network layer, complicating conventional provider-level disruption.

Jun 9, 2026, 11:38 (UTC+9)Last seenJun 9, 2026Severity100ByCTX TeamActorAPT28StrontiumIOC11MITRE13

Two new IP addresses have been added to the infrastructure footprint of a delivery campaign that has been circulating trojanised installers and adware components since at least September 2025 — and one of them points somewhere unusual. IP 209.94.90.1, now part of the campaign's network layer, sits within ASN 40680, the address space operated by Protocol Labs, the organisation behind the InterPlanetary File System.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence