
WireVPN Campaign Adds 132 Domains and a PBot Stealer Component
The Trojan.Jumper/WireVPN campaign has expanded from a 15-domain operation into a multi-continent hosting fabric of 55 new IPs and 132 domains organised across five fingerprint clusters. A newly introduced fourth payload component — a legitimately signed Bright Data SDK classified by sandbox analysis as a PBot stealer — shifts the campaign from traffic-relay abuse toward active credential harvesting.
Fifty-five new command-and-control IPs and 132 additional domains have joined the Trojan.Jumper/WireVPN campaign's observable footprint since CTX Team's earlier coverage, transforming what was a 15-domain, 9-ASN operation into a multi-continent hosting fabric organised across five named fingerprint clusters. The expansion is not random: every cluster is bound by a shared certificate issuer, autonomous system, or registrar identity, and the core payload chain — three PE32 executables all signed…
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read