
37-Node Tox C2 Network Powers Resilient Browser Credential Stealer
A packed 64-bit Windows credential stealer communicates through five Tox-protocol subdomains across two operator-controlled domains, backed by 37 relay IPs spanning bulletproof and privacy-first hosting providers. The campaign deploys automated Let's Encrypt certificate rotation, wildcard SANs, and Google DNS-over-HTTPS to defeat sandbox analysis and DNS-layer monitoring. CTX Team rates the cluster at severity 86, confidence 85.
A packed Windows credential stealer is communicating with its operators through five numbered Tox-protocol subdomains distributed across two operator-controlled domains — tox1.mf-net.eu through tox4.mf-net.eu and tox.libre.tw — backed by a relay network of 37 IP addresses spanning four distinct ASN cohorts that include FranTech Solutions (AS53667), iFog GmbH (AS34927), Hetzner Online GmbH (AS24940), and M247 Europe SRL (AS9009).
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read