C&CMembers
C&C

LummaStealer Adds Isolated .qpon Node and 20 Hashes as Proton66 Cluster Holds

A follow-up snapshot of an active LummaStealer campaign reveals a structurally isolated second domain, recenjc.qpon, provisioned via a separate registrar, distinct IP, and a Traefik default self-signed certificate — entirely disconnected from the original eight-.su C2 cluster. The primary Proton66-hosted infrastructure remains intact and unrotated, while twenty new payload hashes expand the catalog, nineteen of which carry no VirusTotal metadata.

Jun 10, 2026, 06:49 (UTC+9)Last seenJun 10, 2026Severity100ByCTX TeamIOC47MITRE38RegionsES

Since CTX Team's earlier coverage of this LummaStealer campaign, the operator has added twenty new file hashes to the payload catalog and provisioned a structurally distinct second domain — recenjc.qpon — that sits entirely outside the tight infrastructure cohort binding the original eight command-and-control nodes. The earlier coverage documented a remarkably coherent C2 fabric: eight pseudo-random seven-character hostnames under the Soviet-era .su TLD, all batch-registered on a single day,…

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence