C&CMembers
C&C

WireVPN Campaign Adds 132 Domains and a PBot Stealer Component

The Trojan.Jumper/WireVPN campaign has expanded from a 15-domain operation into a multi-continent hosting fabric of 55 new IPs and 132 domains organised across five fingerprint clusters. A newly introduced fourth payload component — a legitimately signed Bright Data SDK classified by sandbox analysis as a PBot stealer — shifts the campaign from traffic-relay abuse toward active credential harvesting.

May 27, 2026, 18:11 (UTC+9)Last seenMay 27, 2026Severity100ByCTX TeamActorSpace PiratesWebwormIOC210MITRE14

Fifty-five new command-and-control IPs and 132 additional domains have joined the Trojan.Jumper/WireVPN campaign's observable footprint since CTX Team's earlier coverage, transforming what was a 15-domain, 9-ASN operation into a multi-continent hosting fabric organised across five named fingerprint clusters. The expansion is not random: every cluster is bound by a shared certificate issuer, autonomous system, or registrar identity, and the core payload chain — three PE32 executables all signed…

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence