C&CMembers
C&C

37-Node Tox C2 Network Powers Resilient Browser Credential Stealer

A packed 64-bit Windows credential stealer communicates through five Tox-protocol subdomains across two operator-controlled domains, backed by 37 relay IPs spanning bulletproof and privacy-first hosting providers. The campaign deploys automated Let's Encrypt certificate rotation, wildcard SANs, and Google DNS-over-HTTPS to defeat sandbox analysis and DNS-layer monitoring. CTX Team rates the cluster at severity 86, confidence 85.

Jun 21, 2026, 08:25 (UTC+9)Last seenJun 21, 2026Severity86ByCTX TeamIOC46MITRE10

A packed Windows credential stealer is communicating with its operators through five numbered Tox-protocol subdomains distributed across two operator-controlled domains — tox1.mf-net.eu through tox4.mf-net.eu and tox.libre.tw — backed by a relay network of 37 IP addresses spanning four distinct ASN cohorts that include FranTech Solutions (AS53667), iFog GmbH (AS34927), Hetzner Online GmbH (AS24940), and M247 Europe SRL (AS9009).

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence